CMMC Knowledge Base
Plain-English answers for defense contractors and the people who have to make compliance actually work. How to build an SPRS score you can defend, what the DFARS and FAR clauses in your contract really require, how to handle CUI without rebuilding your whole network, which federal frameworks apply to you, and how to keep the company secure while you get there.
If you cannot find information about a compliance topic, please contact us for free support.
Policies & Procedures
5- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
SPRS & Self-Assessment
5CMMC Fundamentals
6Contract Clauses & Flowdown
9- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
Trigger Events & Urgent Situations
10- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
CMMC Levels & Requirements
6The 14 Control Families
14- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
Implementation Roadmaps
5Industry-Specific Guides
5CMMC Documentation & Evidence
5CMMC Costs & Budgeting
3Technology & Tools
6CMMC Training & Awareness
5Supply Chain & Third-Party Risk
3Incident Response & Breach Reporting
3Common Mistakes & Failures
3Advanced Topics & Level 2
4Updates & Regulatory Changes
3Artificial Intelligence (AI)
1Comparisons & Alternatives
11- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
Featured Articles
- How to Calculate Your SPRS Score: NIST 800-171 Scoring Guide for DoD Contractors (Updated Aug 2026)
- How Much Does CMMC Certification Cost? [Updated July 2026]
- CMMC Level 1 Self-Assessment Guide
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- Backup and Disaster Recovery for CMMC Compliance
- CMMC Level 2 Self-Assessment Requirements
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Can You Use AI and CUI?
- Physical Protection (PE)
- 72-Hour DoD Breach Notification: DFARS Reporting Requirements
- Access Control (AC)
- Personnel Security (PS)
- What is CMMC Compliance?
- What is CMMC Level 2?
- What Happens if You Don't Get CMMC Certified?
- Build vs Buy Enclave: What In House Actually Costs
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Azure Government vs AWS GovCloud for CUI Workloads
- CMMC Compliance Software for Small Manufacturers
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Platform vs Consultant vs Doing It In House
- PreVeil vs GCC High for Small Defense Contractors
- Enclave vs Full Remediation: Which CMMC Path Fits
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- CMMC Trigger Events: A Triage Guide for Contractors
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Compliant MSP? How to Verify What Yours Claims
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- Build vs Buy Enclave: What In House Actually Costs
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Azure Government vs AWS GovCloud for CUI Workloads
- CMMC Compliance Software for Small Manufacturers
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Platform vs Consultant vs Doing It In House
- PreVeil vs GCC High for Small Defense Contractors
- Enclave vs Full Remediation: Which CMMC Path Fits
- CMMC Compliance Options: Enclave, Environment or Service
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Trigger Events: A Triage Guide for Contractors
- 90 Days to CMMC Compliance: What Is Really Possible
- Dropped Without CMMC? What a Prime Can Actually Do
Frequently Asked Questions
Short Answer: Certification audits are suspended as of July 13, 2026 — but if you have DoD contracts or subcontracts involving Controlled Unclassified Information (CUI), you absolutely still need the underlying compliance, and you need a self-assessed CMMC status in SPRS.
Full Answer: Here's the current state:
What you still need:
- NIST SP 800-171 implementation — DFARS 252.204-7012 has required all 110 controls since 2017, and both July 13 memos state it remains fully in effect
- CMMC Level 1 (Self) or Level 2 (Self) — Phase 1 self-assessment requirements remain in force; these are the only CMMC designations contracts may currently include
- A current SPRS score and annual affirmation — this is now the government's primary enforcement surface
- 72-hour cyber incident reporting under DFARS 7012
What's suspended:
- CMMC Level 2 (C3PAO) third-party certification — cannot be required in any solicitation or contract during the review
- Level 3 (DIBCAC) assessments and all later rollout phases
- Existing contract requirements for third-party assessment (being removed by modification)
You still don't need any of it if:
- You only handle publicly available information (no CUI, no FCI)
- You work exclusively with non-DoD federal agencies (they have different requirements)
- You provide only commercial off-the-shelf (COTS) products with no customization
What CUI includes: Technical data, engineering drawings, specifications, export-controlled data, certain performance and operational information — generally anything marked CUI or that would previously have been "For Official Use Only."
The Reality: Contractors are hearing "CMMC is suspended" and concluding "compliance is optional." Those are very different statements. The audit is gone; the legal obligation — and the False Claims Act liability attached to the score you affirm — isn't. A 60-day task force will recommend what comes next, and every plausible outcome is built on the same 110 controls you're contractually required to implement today.
Short Answer: Level 1 = 15 basic safeguarding requirements for FCI, self-assessed annually. Level 2 = all 110 NIST 800-171 controls for CUI — self-assessed during the suspension, previously headed for third-party audit. Your contract tells you which; handling CUI generally means Level 2.
Full Answer:
CMMC Level 1:
- 15 basic safeguarding requirements (from FAR 52.204-21)
- Self-assessment, entered in SPRS, with an annual senior-official affirmation
- For contracts with Federal Contract Information (FCI) only — contract performance info, pricing, delivery schedules
- Cost: $3,000–$15,000 for most small contractors (Greypike's fixed-fee Level 1 packages run $3,500–$9,500)
- Timeline: 60–90 days typically
- Never required a third-party audit — nothing about Level 1 changed on July 13
CMMC Level 2:
- All 110 NIST SP 800-171 Rev 2 controls
- Currently: self-assessment only. The C3PAO third-party requirement is suspended; contracts may only include Level 2 (Self)
- For contracts with CUI — technical data, drawings, export-controlled information
- Cost: implementation typically $50,000–$150,000+ depending on maturity and scope; see our full cost breakdown — a tightly scoped enclave changes this math dramatically
- Timeline: 4–6 months to a defensible posture, longer with significant gaps
- Self-assessments must stay current within three years, with annual affirmation
How to know which you need:
- Check your contract — it states the CMMC level and (during the suspension) will only say "Self"
- Check whether you handle CUI — if yes, you're a Level 2 shop
- Ask your contracting officer or prime
The trend: Most contractors doing anything beyond basic supplies or non-technical services handle CUI somewhere and should plan for Level 2 requirements — under whatever verification model the reform task force produces.
Short Answer: Level 1: $3,000-$8,000. Level 2: $15,000-$50,000+. Depends on your current security posture and company size.
Full Answer:
CMMC Level 1 Costs:
- Technology/Tools: $1,500-$3,000 (MFA, EDR, encrypted email, password manager, backups)
- Consultant/Implementation: $2,000-$5,000 (if you hire help)
- Internal labor: $1,000-$2,000 (your time configuring and documenting)
- Total: $3,000-$8,000 for most small contractors
CMMC Level 2 Costs:
- Gap assessment: $2,000-$5,000
- Technology/Tools: $5,000-$15,000 (more advanced security tools)
- Implementation consultant: $10,000-$30,000
- Documentation/Policies: $3,000-$8,000 (if done for you)
- C3PAO assessment fee: $5,000-$25,000 (depends on scope)
- Internal labor: $5,000-$15,000 (your staff's time)
- Total: $15,000-$50,000+ for small-medium contractors
What drives costs up:
- Multiple locations or networks
- Complex IT environments
- Poor current security posture (lots of gaps)
- Large scope (many systems handling CUI)
- Needing to replace old hardware/software
What drives costs down:
- Good existing security practices
- Small, simple network environment
- Cloud-based operations (AWS GovCloud, Azure Government)
- Doing some work yourself vs. full outsource
- Already have MFA, EDR, encrypted communications
Hidden costs people forget:
- Annual maintenance (ongoing monitoring, updates, training)
- Recertification every 3 years (Level 2)
- Staff time for evidence collection
- Potential downtime during implementation
ROI Perspective: If you have $500K-$2M+ in DoD contracts, spending $15K-$50K to protect them is a no-brainer. The cost of NOT certifying = losing all DoD revenue.
Short Answer: Level 1: 60–90 days on average. Level 2: 4–6 months to a defensible posture. The November 2026 audit deadline is gone — but that's a reason to do it right, not a reason to stop.
Full Answer:
CMMC Level 1 Timeline:
- Weeks 1–2: Gap assessment against the 15 requirements, scope your FCI
- Weeks 3–6: Implement technology (MFA, endpoint protection, backups)
- Weeks 7–8: Write policies and procedures
- Weeks 9–10: Train staff, collect evidence
- Weeks 11–12: Self-assess, enter results, senior-official affirmation
- Total: 60–90 days for most companies
CMMC Level 2 Timeline:
- Month 1: Gap assessment and roadmap, boundary definition
- Months 2–3: Technology implementation, policy development
- Month 4: Training, evidence collection, internal testing
- Months 5–6: Validation pass, corrected SPRS scoring, affirmation
- Total: 4–6 months average — significant gaps or mixed on-prem environments run longer
What changed on July 13: The old timeline ended with "schedule your C3PAO 2–3 months out and pass the audit." The new timeline ends with "submit a score you can defend and affirm it." Same work, different finish line — and no more assessor scheduling bottleneck.
Fast-track is realistic if: you're cloud-based in a compliant environment, your scope is tight (an enclave compresses everything), you have executive buy-in, and someone experienced is driving. A bounded enclave deployment can stand up a compliant Level 2 environment in weeks rather than months.
Why it takes longer than expected: scope creep (finding more systems touching CUI than you thought), waiting on hardware or licensing, staff turnover mid-project, and treating documentation as an afterthought — the SSP isn't paperwork at the end; without it, no valid score exists at all.
Pro tip: The suspension removed the deadline, not the obligation. Contractors who use this window to build honestly will onboard to whatever the reform task force produces with minimal friction. Contractors who freeze will be starting from behind — again — when the replacement lands.
Short Answer: Level 1 — yes, if you're tech-savvy and small. Level 2 — possible but hard; 110 controls with evidence behind each is a serious lift, and post-suspension there's no auditor to catch honest mistakes before the government relies on your score.
Full Answer:
You CAN do it yourself if:
- You have IT experience or technical background
- Your company is small and simple — one location, few systems, tight CUI footprint
- You have realistic time to invest (expect 40–80+ hours for Level 1, far more for Level 2)
- You're comfortable working from NIST SP 800-171A assessment objectives, not just the control titles
- You're willing to use quality templates and tooling
You SHOULD hire help if:
- You have no IT department or technical staff
- Your environment is complex — multiple locations, cloud plus on-prem
- You're a Level 2 shop (110 controls, ~320 assessment objectives, evidence for each)
- You need it done fast or need it defensible on the first pass
- Your time is worth more than the consulting fee
Hybrid approach (best for many):
- Hire out: gap assessment, boundary/architecture design, score validation
- Do yourself: policy customization from templates, some tool rollout, training
- Typical savings: 30–40% versus full outsource, with far better odds than pure DIY
The DIY risk that changed on July 13: It used to be "fail your C3PAO audit and pay to remediate and reassess." Now it's subtler and worse: nobody fails you. You self-assess, misread a requirement, post an inflated score, and your Affirming Official signs it annually — until a government-led assessment, a prime's due diligence, or a whistleblower surfaces the gap. The most common DIY errors — confusing policy with implementation, misapplying the two partial-credit rules, missing systems in scope — all inflate scores. That's exactly the fact pattern the DOJ's Civil Cyber-Fraud Initiative pursues.
A sensible middle path: DIY the implementation if you're capable, then get independent eyes on the score before anyone affirms it. That validation engagement costs a flat $7,500–$15,000 — a fraction of the audit it replaces and of the exposure it insures against.
Short Answer: Two failure modes now. Don't implement and don't bid: you lose DoD eligibility as contracts require CMMC Self statuses. Don't implement but keep affirming a compliant score: you convert a compliance gap into False Claims Act exposure. The second is far worse.
Full Answer:
If you simply don't comply and don't submit:
- Contracts with CMMC Level 1 (Self) or Level 2 (Self) requirements — which remain fully in force — are off the table
- Contracts with DFARS 7019/7020 require a current SPRS score; no score, no award
- Primes will route around you — they own supply-chain risk regardless of what the certification program does, and with government verification suspended, many are leaning harder on their own supplier requirements
If you don't comply but affirm anyway (the dangerous one):
- Your annual SPRS affirmation is a personal attestation to the federal government by a named senior official
- A knowingly inaccurate score or affirmation sits squarely inside the False Claims Act: treble damages, per-claim penalties, and cases frequently initiated by whistleblowers — often a former IT employee who knows exactly which controls existed on paper only
- The DOJ's Civil Cyber-Fraud Initiative was created for precisely this, and has already produced multimillion-dollar settlements with defense contractors over misrepresented cybersecurity
- Contract termination and suspension/debarment are also on the table
What about POA&Ms?
Contrary to a common misconception, CMMC 2.0 does allow POA&Ms for Level 2 — within limits. Conditional status requires a minimum score of 88 out of 110, POA&M items must close within 180 days, and certain critical requirements can't be POA&M'd at all. An honest score with a real POA&M is a legitimate, defensible position. That's the whole point: the system is built to reward accuracy, not perfection.
Timeline of consequences (revised):
- Now: Phase 1 self-assessment requirements in force; SPRS score checked before award; FCA enforcement active
- ~September 2026: Reform task force reports; the replacement framework takes shape
- After: Whatever returns will be built on NIST SP 800-171 — contractors with an honest, current posture onboard easily; everyone else scrambles again
Bottom line: The suspension didn't make compliance optional. It changed who catches you — from an auditor you hired to a government you certified to.
Short Answer: Your SPRS score is your self-assessed NIST 800-171 compliance, reported to the government. CMMC was the program built to verify those self-reports with third-party audits. As of July 13, 2026, the verification layer is suspended — which makes your SPRS score not a historical footnote but the whole ballgame.
Full Answer:
SPRS (Supplier Performance Risk System):
- Your self-assessment score against the 110 NIST 800-171 Rev 2 controls, on a scale from -203 to 110
- Required by DFARS 252.204-7019/7020; entered via the PIEE portal; visible to contracting officers before award
- Affirmed annually by a named senior company official
- Not an honor system in any meaningful sense anymore: the affirmation is enforceable under the False Claims Act, and government-led (DIBCAC) assessments explicitly continue during the suspension
CMMC:
- The Department's program for verifying that self-reports match reality — self-assessment at Level 1 and (until July 13) third-party C3PAO audits at Level 2
- Phase 1 (Level 1 Self and Level 2 Self statuses, entered in SPRS with affirmations) remains fully in force
- Phase 2+ (third-party verification) is suspended pending the 60-day reform review
The relationship, corrected: CMMC was never "replacing" SPRS — SPRS is the system of record where CMMC statuses, scores, and affirmations live. They're not competitors; one is the database, the other was the verification regime. With the verification regime suspended, the database entry is the compliance record.
Why verification existed at all: DoD's own assessments repeatedly found large gaps between what contractors self-reported and what government assessors found on-site — that gap is the entire reason CMMC was created. The suspension didn't declare the gap fixed; it concluded the audit model was unaffordable. The government's remaining tools for the gap are select government-led assessments and the False Claims Act.
What to do right now:
- Submit an honest score, even if it's low — accuracy is the defensible position
- If you're below 88, you have real gaps against the conditional benchmark; prioritize the 5-point controls
- If your posted score is higher than your environment supports, correcting it is the most urgent compliance task you have
- Get independent validation before your Affirming Official signs the next annual affirmation
Bottom line, inverted from the old advice: CMMC certification was the test; it's postponed. Your SPRS score is the real deal now — it's what contracting officers see, what primes check, and what the Department of Justice can hold you to.
Who This CMMC Knowledge Base Is For
Every article here is written for the small and mid-sized supplier: the machine shop that just received CUI-marked drawings, the manufacturer whose prime sent a 400-row security questionnaire, the owner trying to work out whether a clause in an executed contract still binds them. Not a vendor pitch and not acronym soup: what the requirement says, what it means for your environment, and what to do about it this week.
Current as of the Phase 2 suspension. On July 13, 2026 the Department of War suspended CMMC Level 2 and Level 3 certification assessments. DFARS 252.204-7012, NIST SP 800-171, SPRS reporting and the annual senior-official affirmation are all still in force. Every article in this knowledge base reflects that split. Read the full breakdown →
New here? Start with What is CMMC Compliance? or What is Controlled Unclassified Information (CUI)? If you already know you need a number, the SPRS Score Calculator walks all 110 requirements and is free.
Browse by topic
Start here
What your contract requires
Scoring and proof
Building the controls
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs