What CMMC Actually Changed, and What It Did Not
Quick answer: CMMC added no security controls. Level 2 requires the same 110 requirements contractors have owed since the end of 2017. What changed is how compliance is verified and how much evidence you have to produce. Getting this right matters, because a lot of the fear driving CMMC spending is aimed at the wrong thing.
Did CMMC add new security controls?
No. 32 CFR 170.14(c)(3) states it in one sentence: "the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2."
And the underlying obligation is old. DFARS 252.204-7012(b)(2)(ii)(A) has required contractors to implement NIST SP 800-171 "as soon as practical, but not later than December 31, 2017."
Same 110 requirements, same revision, obligation unchanged for years. If someone tells you CMMC introduced new controls, they have not read the rule.
What actually changed under CMMC?
Verification and evidence burden, in five specific ways.
- Third-party certification. 32 CFR 170.17(c)(1) provides that "an authorized or accredited C3PAO must perform a Level 2 certification assessment." Self-attestation is no longer the whole story at that level.
- POA&M discipline. 32 CFR 170.21 limits which requirements are POA&M eligible, sets a minimum score, imposes a 180-day closeout, and creates Conditional and Final statuses.
- Annual affirmation. 32 CFR 170.22 requires an affirmation in SPRS by a named Affirming Official. A person now attaches their name to the claim.
- Formalised scoping. 32 CFR 170.19 requires asset categories documented in an asset inventory, the SSP, and a network diagram.
- Explicit flowdown. DFARS 252.204-7021(f) requires flowdown where a subcontract involves FCI or CUI, and requires verifying the subcontractor status before award.
Notice the shape. Every item is about proof, not protection. The security bar did not move. The burden of demonstrating you cleared it did.
Does a DIBCAC assessment give you a certification?
As a general rule, no. A DoD High Assessment, conducted under what is now DFARS 252.240-7997, formerly 252.204-7020, produces a NIST SP 800-171 assessment score posted to SPRS. It is a Government assessment, not a CMMC certification, and only a C3PAO may perform a Level 2 certification assessment.
There is one exception, and it is closed. 32 CFR 170.20 covers organisations with a perfect score and no open POA&M from a DCMA DIBCAC High Assessment conducted before the rule's effective date. Those received a CMMC Status of Level 2 Final, valid for three years from the original assessment date. Assessments conducted with Joint Surveillance under DCMA Manual 2302-01 are included.
The effective date was December 16, 2024, so an assessment conducted today cannot convert. Anyone holding a converted status should note that the clock runs from the original assessment date, not from December 2024. The last of those lapse around the end of 2027.
What did the July 2026 suspension change?
Timing, not obligations. DoD CIO memo 26-P-1023 states that "the upcoming November 2026 transition to Phase 2 of CMMC implementation is suspended," pending a 60-day review, and also suspends waiver procedures.
The same memo is explicit that "the cybersecurity requirements outlined in the clause at DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, remain in effect."
Say suspended, not repealed. We found no evidence that 32 CFR Part 170 was rescinded or that DFARS 252.204-7021 was withdrawn. A reform task force was stood up alongside the suspension, and its request for information closed to comments on August 14, 2026. More detail in CMMC Phase 2 suspended.
What is still required today?
Everything that was required before the suspension, minus the Phase 2 timing.
- DFARS 252.204-7012 in full, including the 72-hour cyber incident reporting, media preservation, and malicious software submission obligations that CMMC never assessed in the first place.
- NIST SP 800-171 Revision 2, all 110 requirements. Revision 3 is not incorporated. We covered that in CMMC mandates a NIST standard NIST has withdrawn.
- Self-assessment and score posting to SPRS, plus annual affirmations, which arise from the CMMC program rule at 32 CFR 170 and, for SPRS entry, DFARS 252.240-7997. The 2026 DFARS overhaul deleted 252.204-7019 and renumbered 252.204-7020, but the obligations themselves were untouched by the memo.
- A System Security Plan under 3.12.4 and plans of action under 3.12.2. Those remain the only two documents named as required across all 110 requirements.
The suspension moved a deadline. It did not move the standard, and self-assessment scores posted to SPRS remain assertions the Government relies on.
Sources
- 32 CFR 170.14(c)(3), 170.17(c)(1), 170.19, 170.20, 170.21, 170.22
- DFARS 252.204-7012(b)(2)(ii)(A), 252.240-7997 (formerly 252.204-7020), 252.204-7021(f)
- DoD CIO memo 26-P-1023, July 2026
- NIST SP 800-171 Rev 2, requirements 3.12.2 and 3.12.4
Verified against primary sources on August 1, 2026. This is not legal advice.