Skip to content
CMMC 2.0 · DFARS 252.204-7021 · NIST SP 800-171

CMMC 2.0 compliance for defense contractors.

CMMC Phase 2 third-party assessment was suspended on 13 July 2026, but DFARS 252.204-7012, self-assessments, SPRS scoring and annual affirmations were not. Aegis Firma helps prime contractors and suppliers build and maintain the 110-practice NIST SP 800-171 programme behind all of it.

110

NIST 800-171 practices

−203

minimum possible SPRS score

Level 2

scope for most CUI-handling DoD contracts

Suspended

Phase 2 C3PAO assessment, since 13 Jul 2026

Compliance challenges in defense contractor cmmc

CMMC 2.0 (Cybersecurity Maturity Model Certification) governs how DoD contracts handling CUI (Controlled Unclassified Information) are secured. Level 1 requires annual self-assessment. Under 32 CFR 170.17 Level 2 requires a third-party C3PAO assessment — but Phase 2, which would have made that a condition of award, was suspended on 13 July 2026 pending a reform review. Self-assessment, DFARS 252.204-7012 and annual affirmation obligations continue, and your SPRS score remains visible to contracting officers.

Critical risk

DFARS 252.204-7012 never paused

The Phase 2 suspension removed Level 2 and Level 3 assessment requirements from solicitations — it did not touch DFARS 252.204-7012 safeguarding and incident-reporting duties, Phase 1 self-assessments, SPRS score posting or annual affirmations. Missing or outdated self-assessments still weaken every bid, for primes and sub-contractors alike.

Critical risk

SPRS score transparency

Your SPRS (Supplier Performance Risk System) score is visible to all DoD contracting officers. A low or negative score directly impacts contract award probability and may trigger additional scrutiny.

High risk

Flow-down to sub-contractors

Prime contractors must flow down CMMC requirements to all sub-contractors who touch CUI. Missing sub-contractor compliance is a prime contractor liability.

High risk

Evidence documentation gaps

Most self-assessed companies lack the written policies, system security plans, and evidence artefacts required to support their SPRS score during a DoD audit or C3PAO assessment.

High risk

CUI identification and marking

You must identify, mark, and protect all CUI in your possession. Most organisations underestimate how much CUI they hold — emails, drawings, specs, and contracts often qualify.

Critical risk

AI tools and CUI data handling

Using cloud AI tools (ChatGPT, Copilot, etc.) to process CUI without FedRAMP-authorised alternatives is a direct CMMC and DFARS violation that could void your assessment.

How Aegis Firma helps

CMMC 2.0 gap assessment

Answer 110 practice questions across 17 domains and get your SPRS score instantly. See exactly which practices are failing and what evidence is needed to remediate.

System Security Plan (SSP) generator

Auto-populate NIST SP 800-171 SSP templates from your assessment answers. Produces a C3PAO-ready document within hours rather than weeks.

POA&M tracker

Track every gap with a Plan of Action & Milestones, assign owners, set target dates, and generate the rolling POA&M report contracting officers expect.

CUI inventory and data flows

Map where CUI lives in your organisation, document data flows, and generate the required access control and protection evidence.

AI tools CUI compliance checker

Scan your approved AI tool list against FedRAMP authorisation status. Flag any tools processing CUI without authorisation before your C3PAO assessment.

Policy library — all 17 CMMC domains

Pre-built, editable security policies for all 17 CMMC domains (Access Control, Incident Response, Risk Assessment, etc.) ready to publish and evidence.

Frequently asked questions

When is CMMC 2.0 fully enforced?

DoD began inserting CMMC requirements into contracts in Q4 2024 under the CMMC Final Rule (effective December 16, 2024), and Level 1 and Level 2 self-assessment requirements are already in many contracts. Phase 2 — which would have made a third-party C3PAO Level 2 assessment a condition of award from November 10, 2026 — was suspended by the Department of War on July 13, 2026, and the later phases were frozen pending a CMMC Reform Task Force review; Level 2 and Level 3 assessment requirements are being removed from active solicitations and contracts. The 32 CFR program rule and the DFARS were not rescinded, so this is a suspension rather than a repeal, and full enforcement timing now depends on the outcome of that review.

What is an acceptable SPRS score for DoD contracting?

There is no official minimum SPRS score for contract eligibility. However, a score significantly below 0 (the DoD average is around +88) is a contracting risk signal. Scores are public in SPRS. A negative score combined with no remediation plan is likely to disqualify bids at the discretion of the contracting officer.

Do we need to assess sub-contractors under CMMC?

Yes. DFARS 252.204-7021 requires prime contractors to ensure their sub-contractors who handle CUI are at or above the applicable CMMC level. You are responsible for flow-down compliance. Aegis Firma provides a sub-contractor assessment request workflow to collect evidence from your supply chain.

Can we use commercial AI tools like ChatGPT for CUI?

No. Processing CUI in non-FedRAMP-authorised cloud services is a CMMC violation under AC.2.006 and SC.3.177. If employees are using commercial AI tools on CUI, this must be remediated before your C3PAO assessment. Aegis Firma can identify which AI tools in your stack are FedRAMP authorised.

Cancel anytime · 7-day refund eligibility · no contracts

Start your compliance programme today

Start CMMC programme — free