Vigilant Cybersecurity

CMMC for Alaska's defense industrial base

CMMC Readiness: Prepare Your Organization

Protecting the Mission. Securing the Supply Chain.

The Cybersecurity Maturity Model Certification (CMMC) program sets the cybersecurity requirements for Department of War contractors and subcontractors that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Third-party certification is on pause, but the safeguarding requirements behind CMMC already apply through FAR and DFARS clauses. Whether you're a prime or a sub, readiness protects both your contract eligibility and the mission.

Where CMMC stands right now

Updated September 27, 2026

Phase 2

On hold

On July 13, 2026, the Department of War CIO suspended the November 2026 Phase 2 transition, the step that would have added Level 2 (C3PAO) requirements. No new date has been set.

Contracts

Being revised

DFARS Class Deviation 2026-O0025 (Revision 3, September 3, 2026) directs contracting officers to remove or revise CMMC requirements in new and existing solicitations and contracts. Contracts can still require CMMC Level 1 (Self) or Level 2 (Self). Existing contracts are changed at the next option period or administrative modification.

Your obligations

Still in force

If you handle CUI, DFARS 252.204-7012 still requires NIST SP 800-171 Rev. 2, and DoD can still run Medium or High assessments whose scores are posted in SPRS. If you handle FCI, the FAR basic safeguarding clause (now 52.240-93, formerly 52.204-21) still applies. If your contract includes a Level 1 (Self) or Level 2 (Self) requirement, you still post a current self-assessment in SPRS, and an affirming official still signs an affirmation every year.

What it means

The pause changes who checks your work, not the work itself. Contractors who use this window to close gaps will be ready whenever third-party assessments return, and they're on firmer ground for the affirmations they sign today.

We update this page as guidance changes. Primary sources: DFARS class deviations · FAR Overhaul Part 40

CMMC Timeline

  1. Phase 1 begins

    The CMMC contract clause (DFARS 252.204-7021) takes effect. Solicitations can require Level 1 (Self) or Level 2 (Self).

  2. Phase 2 suspended

    The Department of War CIO pauses the Phase 2 transition and later rollout milestones while a Reform Task Force reviews the program.

  3. Contracts revised

    Class Deviation 2026-O0025, Revision 3, directs contracting officers to remove or revise CMMC requirements. Level 1 (Self) and Level 2 (Self) remain allowed.

  4. Original Phase 2 date

    Level 2 (C3PAO) requirements were set to begin. On hold, with no new date.

Why CMMC Compliance Matters for All — Large and Small

Too often, malicious actors target the weakest link in the supply chain. In today's threat landscape, supply chain compromise has become one of the most exploited vectors in national security breaches. Cyber adversaries, including nation-state actors, deliberately target small and mid-sized businesses that may lack mature cybersecurity programs — knowing that they often have trusted access to larger primes or sensitive government data.

"One vulnerable subcontractor can jeopardize an entire defense program."

This is why every member of the defense supply chain must demonstrate cybersecurity maturity — not just the big players.

What Does CMMC Require?

CMMC has three levels. Which one applies depends on the information you handle and the level your contract specifies:

Level 1

Self-assessment

Protects
Federal Contract Information (FCI)
Requirements
The 15 basic safeguarding requirements in FAR 52.240-93 (formerly 52.204-21)
Assessment
Self-assessment every year, posted in SPRS, with an annual affirmation. Every requirement must be met; no POA&Ms.
Right now
Unchanged
Contracts can still require Level 1 (Self).

Level 2

Self or C3PAO assessment

Protects
Controlled Unclassified Information (CUI)
Requirements
The 110 requirements in NIST SP 800-171 Rev. 2
Assessment
Self-assessment or C3PAO assessment, per contract, every 3 years, with an annual affirmation. Limited POA&Ms allowed for up to 180 days.
Right now
Self only
Only Level 2 (Self) while the Phase 2 suspension stands. C3PAO requirements are being removed from contracts.

Level 3

Government assessment

Protects
CUI in the Department's highest-priority programs
Requirements
Level 2 plus 24 selected requirements from NIST SP 800-172
Assessment
Government assessment by DCMA's DIBCAC every 3 years, after a final Level 2 (C3PAO) status. Annual affirmation.
Right now
Not yet in contracts
Later rollout milestones are also on hold.

Regardless of your size, if your organization receives, processes, stores or transmits CUI as a prime or a subcontractor, you must protect it under DFARS 252.204-7012 and NIST SP 800-171 Rev. 2, whether or not your contract names a CMMC level.

The Risks of Non-Compliance

  • Loss of Contract EligibilityIf your contract requires a CMMC level, you can't be awarded it, or have an option exercised, without a current CMMC status at that level posted in SPRS.
  • Legal and Financial ExposureAn inaccurate SPRS score or affirmation can create False Claims Act liability, and breaches tied to non-compliance can lead to contract penalties, lawsuits and lost business.
  • Damaged ReputationTrust is a key currency in the defense ecosystem — non-compliance undermines your credibility with partners and customers.
  • National Security ImpactInadequate cybersecurity controls put not just your organization, but the mission and the warfighter at risk.

Why Start Now?

Getting ready for CMMC isn't a quick checkbox exercise. It requires:

  • A thorough assessment of your current cybersecurity posture
  • Remediation of control gaps against NIST SP 800-171 Rev. 2 or the FAR basic safeguarding requirements
  • Policy and procedure development
  • Evidence collection for self-assessments, annual affirmations and future third-party assessments
  • Establishing a culture of cyber readiness

Starting now means you're ready when a CMMC level shows up in your next contract or when third-party assessments resume, not scrambling after a security incident forces the issue.

How We Help

We assist both prime and subcontractor organizations across the DIB in achieving and sustaining CMMC readiness. Our services include:

  • Readiness Assessments aligned with NIST SP 800-171 and CMMC requirements
  • Gap Analysis & Remediation Planning
  • Policy & Procedure Development
  • Security Control Implementation
  • Assessment Support and Continuous Compliance Monitoring

See service packages and timelines

Secure the Mission. Protect the Supply Chain.

CMMC isn't just about compliance — it's about trust, resilience, and protecting national defense information. Whether you're building missile systems or providing IT support, your role in the defense supply chain is critical. Let's ensure you're ready.

"Cybersecurity is not a size issue — it's a mission-critical responsibility."

Schedule a Complimentary Scoping Call

Or reach a practitioner directly: (907) 229-5222 · consultations@vigilantcybersecurity.net