US federal compliance

CMMC Phase 1 requirements: what applies to defense contractors in 2026

Phase 1 of CMMC started on 10 November 2025 and is still in force after Phase 2 was suspended. Here is what contracting officers can require now and how to prove it.

Short answer

CMMC Phase 1 requirements are the self-assessments contracting officers can require since 10 November 2025: a Level 1 self-assessment for Federal Contract Information or a Level 2 self-assessment for CUI, each posted in SPRS with a senior official's affirmation. Phase 1 stayed in force when Phase 2 was suspended in July 2026.

Key takeaways

  • Phase 1 began on 10 November 2025 with the 48 CFR DFARS rule.
  • It covers Level 1 and Level 2 self-assessments, posted in SPRS.
  • A senior official affirms compliance after each assessment and every year.
  • The July 2026 suspension paused Phase 2 onwards, not Phase 1.

What Phase 1 requires

When a solicitation includes a CMMC requirement during Phase 1, the contractor must have a current self-assessment at the required level before award. Level 1 is for contractors handling only Federal Contract Information (FCI) and covers 15 safeguarding requirements from FAR 52.204-21. Level 2 self-assessment is for contractors handling Controlled Unclassified Information (CUI) and covers all 110 requirements of NIST SP 800-171 Rev 2.

Level 1 (self)Level 2 (self)
DataFederal Contract InformationControlled Unclassified Information
Requirements15 (FAR 52.204-21)110 (NIST SP 800-171 Rev 2)
AssessmentAnnual self-assessmentSelf-assessment every 3 years
RecordSPRS entry and annual affirmationSPRS score and annual affirmation
POA&MNot allowedAllowed for eligible requirements, closed within 180 days

Scores and affirmations

Results go into the Supplier Performance Risk System (SPRS). For Level 2 the score uses the DoD assessment methodology: start at 110 and subtract 1, 3 or 5 points for each unmet requirement. A senior official must affirm continuing compliance after each assessment and every year after; an affirmation that turns out to be false carries legal risk, so evidence should be current before anyone signs.

Phase 1 after the suspension

A Department of War memo of 13 July 2026 suspended Phase 2, which would have required C3PAO certification for most CUI contracts from 10 November 2026, and put Phases 3 and 4 on hold. Phase 1 self-assessments remain a condition of award where a solicitation includes them, and DFARS 252.204-7012 still requires NIST SP 800-171 and 72-hour incident reporting.

Checklist

Phase 1 readiness

0 of 6 done

Put this into practice on QULDEX

Frequently asked questions

When did CMMC Phase 1 start?

On 10 November 2025, when the 48 CFR DFARS rule took effect. Contracting officers can require Level 1 and Level 2 self-assessments from that date.

Is CMMC Phase 1 affected by the July 2026 suspension?

No. The memo suspended Phase 2 and put Phases 3 and 4 on hold; Phase 1 self-assessment requirements stay in place.

Can I use a POA&M for Level 1?

No. Level 1 requires all 15 requirements to be met. Level 2 allows a POA&M for eligible requirements if the minimum score is met, with items closed within 180 days.

Sources

  1. 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program, eCFR
  2. CMMC Program, DoW CIO
  3. DFARS class deviation 2026-O0025 (Revision 3), OUSD(A&S) DPCAP
  4. DFARS Case 2019-D041, Assessing Contractor Implementation of Cybersecurity Requirements (final rule), Federal Register