CMMC Phase 1 requirements: what applies to defense contractors in 2026
Phase 1 of CMMC started on 10 November 2025 and is still in force after Phase 2 was suspended. Here is what contracting officers can require now and how to prove it.
CMMC, NIST SP 800-171 and FedRAMP for defense contractors and cloud providers selling to US agencies, plus NYDFS 500 and SOX ITGC.
Phase 1 of CMMC started on 10 November 2025 and is still in force after Phase 2 was suspended. Here is what contracting officers can require now and how to prove it.
NIST SP 800-171 is the set of security requirements; CMMC is the Department of War program that checks you meet them. Here is how they relate and what the Phase 2 suspension means.
FedRAMP 20x moves from long narrative packages to automated evidence and certification classes. Here is how it compares with the Rev5 path and what existing providers need to do.