Current: Phase II suspended July 13, 2026. Phase I self-assessment requirements remain.Read the update →
Read upstream.

Official source directory

Our editorial rule is simple: current program status comes from the department, CMMC contract language comes from Acquisition.gov / the DFARS, NIST requirements come from NIST, and CUI categories come from the National Archives. Vendor blogs can be useful for implementation ideas, but they are not the source of the requirement.

Current research note — Aug. 24, 2026

The July 13, 2026 suspension of CMMC Phase II is treated as a high-priority update across this site. Older rollout schedules are not used as the sole basis for current guidance.

U.S. Department of War CIOCybersecurity Maturity Model Certification — current program statusCurrent implementation status, assessment levels, affirmations, POA&M rules, and the July 2026 Phase II suspension.U.S. Department of WarDepartment suspends CMMC Phase II requirementsPrimary announcement dated July 13, 2026. Phase I self-assessments remain in place while Phase II is reviewed.U.S. Department of War CIOCMMC Resources & DocumentationOfficial rule, assessment, scoping, and program documentation hub.Acquisition.govDFARS Subpart 204.75 — Cybersecurity Maturity Model CertificationCurrent contracting procedures and prescriptions for CMMC clauses.Acquisition.govDFARS 252.204-7021 — Contractor Compliance with CMMC Level RequirementsCurrent CMMC contract clause, including current status, affirmations, POA&M closeout, and system UID concepts.Acquisition.govDFARS 252.204-7025 — Notice of CMMC Level RequirementsSolicitation provision describing required CMMC level and CMMC UIDs.Acquisition.govDFARS 252.204-7012 — Safeguarding Covered Defense InformationCore safeguarding, cloud, incident reporting, preservation, and subcontract flowdown obligations.Acquisition.govDFARS 204.7302 — NIST SP 800-171 assessment policyRequires a current NIST SP 800-171 DoD Assessment for covered systems when applicable.Acquisition.govDFARS 204.7303 — NIST SP 800-171 assessment proceduresExplains contracting officer verification of assessment scores in SPRS.Acquisition.govDFARS 252.204-7020 — NIST SP 800-171 DoD Assessment RequirementsCurrent clause covering NIST SP 800-171 DoD Assessment requirements, SPRS posting, subcontract checks, and the normal three-year currency window.U.S. Department of War CIOCMMC Assessment Guide — Level 1Official Level 1 self-assessment guide for the FAR 52.204-21 safeguarding requirements.U.S. Department of War CIOCMMC Scoping Guide — Level 2Official Level 2 scoping guidance for CUI assets, Security Protection Assets, specialized assets, contractor risk-managed assets, and external service dependencies.U.S. Department of War CIOCMMC Level 2 Assessment GuideOfficial Level 2 assessment guidance listed in the current CMMC resources directory; use the directory to obtain the current posted version.NISTNIST SP 800-171 Rev. 3May 2024 final revision of NIST's CUI protection requirements.NISTNIST SP 800-171A Rev. 3Assessment procedures for NIST SP 800-171 Rev. 3.U.S. Department of WarClass deviation maintains NIST SP 800-171 Rev. 2 for covered contractor systemsExplains why Rev. 2 remains the assessment baseline for current CMMC while Rev. 3 transition is handled separately.Acquisition.govFAR 52.204-21 — Basic Safeguarding of Covered Contractor Information SystemsFifteen basic safeguarding requirements associated with CMMC Level 1.National Archives and Records AdministrationCUI RegistryAuthoritative categories and safeguarding/dissemination authorities for Controlled Unclassified Information.Acquisition.govDFARS 212.371 — COTS inapplicabilityLists cybersecurity clauses that do not apply to contracts or subcontracts solely for COTS items.U.S. Department of War CIOCMMC Program Frequently Asked QuestionsOfficial FAQ, including guidance for cloud service providers, MSPs, MSSPs, and other external service providers. Check the document's own revision/date on open, since the filename version can change independent of this citation.U.S. Department of Defense CIOFedRAMP Moderate Equivalency for Cloud Service Provider Cloud Service OfferingsDecember 21, 2023 memorandum defining the evidence and independent-assessment expectations for FedRAMP Moderate equivalency.Federal RegisterCybersecurity Maturity Model Certification (CMMC) Program Final Rule — 32 CFR Part 170Final CMMC program rule, including assessment, affirmation, POA&M eligibility, scoring, and 180-day closeout requirements.NISTNIST SP 800-171 Rev. 2 — Protecting CUI in Nonfederal SystemsThe Rev. 2 security requirements used by current CMMC Level 2 assessments under 32 CFR Part 170 and the current DoD CMMC implementation baseline.NISTNIST SP 800-171A — Assessing the Rev. 2 CUI Security RequirementsJune 2018 assessment procedures referenced by 32 CFR Part 170 for current CMMC Level 2 self-assessments and certification assessments.National Archives and Records AdministrationCUI MarkingsGovernment-wide CUI category, banner-marking, specified-authority, and category-marking reference.National Archives and Records AdministrationCUI Resources — marking, email, coversheet, media and destruction toolsOfficial CUI marking handbook, email-marking tip, coversheet, destruction label, and media-label resources.National Archives and Records AdministrationCUI DecontrolGovernment-wide principles for removing CUI safeguarding and dissemination controls when authorized.NISTNIST SP 800-88 Rev. 2 — Guidelines for Media SanitizationSeptember 2025 final guidance for building a media sanitization program, selecting appropriate techniques, and validating sanitization outcomes; supersedes Rev. 1.