If your small or medium-sized business bids on federal defense contracts, cybersecurity is no longer just an IT concern; it is a baseline legal requirement. The Cybersecurity Maturity Model Certification (CMMC) dictates whether your company can legally win, renew, or keep Department of Defense (DoD) contracts.
Recent regulation changes in 2026 have changed the immediate enforcement timeline, confusing many defense contractors. Here’s what CMMC is, what the specific technical requirements look like, how the scoring system works, and where the deadlines stand right now.
What is CMMC?
The Cybersecurity Maturity Model Certification (CMMC) is a framework developed by the DoD to ensure defense contractors secure sensitive government data.
For years, contractors simply self-attested that they met federal cybersecurity standards. However, as cyber incidents and data breaches within the defense supply chain continued to rise, the government transitioned to the CMMC framework. The goal is simple: verify that contractors actually have the required security controls in place rather than just taking their word for it.
CMMC specifically targets two types of data:
- FCI (Federal Contract Information): Basic administrative or operational information not intended for public release.
- CUI (Controlled Unclassified Information): Sensitive information that requires strict safeguarding. This includes technical blueprints, engineering data, research files, or specific manufacturing specifications.
The 3 Levels of CMMC 2.0 Requirements
CMMC scales based on the type of data your organization handles. Each level builds on the requirements of the previous one.
Level 1: Foundational
- Who needs it: Contractors handling only FCI.
- Requirements: 15 basic cybersecurity practices sourced from FAR 52.204-21. These are fundamental IT hygiene standards, such as enforcing strong passwords, installing antivirus software, and enforcing basic access controls.
- Assessment: Requires an annual self-assessment and affirmation from a senior company official, which you must submit to the Supplier Performance Risk System (SPRS).
Level 2: Advanced
- Who needs it: Contractors handling the more sensitive CUI.
- Requirements: 110 specific security controls aligned entirely with the National Institute of Standards and Technology (NIST) Special Publication 800-171 Revision 2.
- Assessment: Originally required a strict third-party assessment by a Certified Third-Party Assessment Organization (C3PAO). The DoD recently adjusted the rollout phase for this third-party audit requirement (more below).
Level 3: Expert
- Who needs it: A small subset of contractors working on the highest-priority, most critical defense programs.
- Requirements: The 110 controls from Level 2, plus 24 enhanced controls based on NIST SP 800-172.
- Assessment: Requires strict, government-led assessments by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).
Inside the Requirements: What Are NIST 800-171 Controls?
Saying you need to implement “110 controls” for Level 2 sounds abstract. In practice, these controls cover 14 different families of cybersecurity and physical security.
To give you an idea of what the DoD expects, here are a few practical examples of what you must implement to achieve Level 2 compliance:
- Access Control: You cannot share generic logins. Every employee must have a unique identifier, and their access must be restricted strictly to the files they need to do their job.
- Identification and Authentication: You must enforce Multi-Factor Authentication (MFA) for all network access, both local and remote.
- Audit and Accountability: Your IT system must track and log exactly who logs into your network, when they log in, and what files they modify.
- Physical Protection: Compliance is not just digital. You must physically escort visitors in your facility, maintain physical access logs, and ensure unauthorized individuals cannot walk onto the manufacturing floor or into the server room and see CUI.
The SPRS Scoring System Explained
To prove you meet these controls, you must calculate and submit a score to the government’s SPRS database. The scoring system is highly unusual and often trips up first-time contractors.
You do not get a standard score out of 100. Instead, the SPRS score ranges from a maximum of +110 down to a minimum of -203.
You start with a perfect score of 110. For every control you have not fully implemented, you subtract points. Because some security controls are deemed more critical than others, missing a single control can cost you 1, 3, or even 5 points. For example, failing to implement MFA will immediately deduct 5 points from your score.
If your score falls below 110, you must create a Plan of Action and Milestones (POA&M) detailing exactly how and when you will fix the remaining gaps.
The Real Cost of Non-Compliance
Failing to meet these standards carries serious business risks.
- Loss of Revenue: Contracting officers check SPRS before awarding contracts. If your score is missing or too low, they will simply award the contract to your compliant competitor.
- The False Claims Act: The Department of Justice launched the Civil Cyber-Fraud Initiative specifically to target contractors who lie about their cybersecurity status. If you submit a perfect 110 score to SPRS but do not actually have the controls in place, your company faces massive financial penalties. Whistleblowers (including your own employees) are financially incentivized to report false claims.
2026 Timeline Updates: What You Must Know Right Now
The CMMC rollout was originally structured in four phases. Phase 1 officially took effect on November 10, 2025, legally requiring contractors to complete Level 1 or Level 2 self-assessments as a condition of contract award.
However, contractors must be aware of a critical shift that occurred in mid-2026. On July 13, 2026, the DoD officially suspended the CMMC Phase 2 requirements (which would have mandated strict third-party C3PAO certifications by November 10, 2026) pending a comprehensive program review.
What this means for your business today:
- Self-assessments are still mandatory. Phase 1 remains completely in force. You cannot win or renew a DoD contract right now without a current CMMC status and SPRS score on file.
- Third-party audits are paused, not canceled. Contracting officers cannot currently disqualify you for lacking a C3PAO certification, but the 110 NIST 800-171 controls still absolutely apply to anyone handling CUI
- Now is the time to close gaps. The temporary suspension of Phase 2 gives contractors a brief window to fix vulnerabilities before mandatory third-party audits inevitably resume.
Common Pitfalls: An Expert Perspective
At KT Connections, we work directly with SMBs attempting to secure their IT environments. When companies try to handle CMMC internally, we consistently see three major mistakes:
- Underestimating the timeline: Implementing 110 security controls takes the average business 9 to 18 months. Writing the required policies alone can take hundreds of hours.
- Confusing general IT with compliance: Having a managed IT provider fix your printers and run your backups does not mean you are compliant. Compliance requires specialized security documentation, uninterrupted monitoring, and specific hardware configurations.
- Missing the System Security Plan (SSP): Your SSP is the core document that defines your network boundaries and how you meet NIST requirements. Without an SSP, you are not allowed to calculate an SPRS score at all.
Your Next Steps for Compliance
Waiting for the government to finalize the Phase 2 review is a massive risk. If you wait until third-party audits are required again, assessment bottlenecks will prevent you from getting certified in time.
Take these three steps immediately:
- Locate your data: Review your current and anticipated contracts for DFARS 252.204-7012 clauses and identify if you handle CUI.
- Build your SSP: Create your System Security Plan to map out your exact data flow and network boundaries.
- Submit your score: Complete your self-assessment, identify your gaps in a POA&M, and have a senior executive submit your score to SPRS.
How KT Connections Can Help
For small to medium-sized businesses, compliance isn’t simply about passing a test; it is about staying eligible for revenue. Figuring out network segmentation, encryption standards, and continuous monitoring on your own drains resources away from your core operations.
At KT Connections, we help SMBs build robust, secure IT environments. For clients in the defense supply chain, our cybersecurity services and monitoring provide the technical controls and oversight needed to keep your business compliant with CMMC and NIST standards. We help you conduct accurate gap assessments, carry out necessary safeguards, and maintain the continuous network monitoring required to keep your contracts secure.
Don’t wait until a contract renewal is on the line. Schedule a Consultation or Audit with KT Connections today to ensure your defense revenue is protected.