Overview
CMMC checks that defence contractors actually meet the security requirements that are already written into their contracts, instead of relying on the contractor's word alone. Level 1 covers the 15 basic safeguarding requirements in FAR 52.204-21 for Federal Contract Information. Level 2 covers the 110 requirements of NIST SP 800-171 Rev. 2 for Controlled Unclassified Information. Level 3 adds 24 enhanced requirements selected from NIST SP 800-172 for the most sensitive programs.
The program rule came first. Codified at 32 CFR part 170, it took effect on December 16, 2024, and it sets the levels, the assessment methods, the rules for plans of action and milestones (POA&Ms), and the roles of the Cyber AB, C3PAOs, and the Defense Contract Management Agency's DIBCAC. The acquisition rule, which adds clause DFARS 252.204-7021 to contracts, was published on September 10, 2025 and took effect on November 10, 2025. That date started Phase 1, in which contracts ask mainly for self-assessments posted in the Supplier Performance Risk System (SPRS) along with an annual affirmation by a senior official.
The rollout changed in 2026. On July 13, 2026, the Department suspended Phase 2, which would have made Level 2 certification by a C3PAO a condition of award in many contracts from November 10, 2026. It also set up a CMMC Reform Task Force for a 60-day review. Phase 1 self-assessment requirements, DFARS 252.204-7012, and NIST SP 800-171 Rev. 2 stay in place. C3PAOs can still perform voluntary Level 2 certifications. As of October 11, 2026, the task force report had been delivered internally but not published, and no new Phase 2 date had been set.
Who it applies to in Canada
Companies anywhere in the U.S. defence supply chain that process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on their own systems. Contracts solely for commercially available off-the-shelf items are excluded.
Canadian manufacturers, engineering firms, and software suppliers that work on U.S. defence programs, directly or as subcontractors to U.S. primes, receive CMMC requirements through contract flowdown. The rule applies to foreign and domestic contractors alike, and Canada's own CPCSC uses similar controls but is not recognized as a substitute.
Controls at a glance
CMMC is organized by level, with each level drawing its requirements from an existing federal source.
Level 1: 15 requirements (FAR 52.204-21)
- Limit system access to authorized users and devices
- Identify and authenticate users before access
- Sanitize media before disposal or reuse
- Control physical access and escort visitors
- Monitor and protect system boundaries
- Patch flaws and use malicious code protection
Annual self-assessment, all 15 must be met, no POA&M allowed.
Level 2: 110 requirements (NIST SP 800-171 Rev. 2)
- Access control, awareness, and audit logging
- Configuration management and identification
- Incident response and maintenance
- Media, personnel, and physical protection
- Risk assessment and security assessment
- System, communications, and information integrity
14 domains. Self-assessment or C3PAO certification every 3 years, with annual affirmation.
Level 3: 24 requirements (NIST SP 800-172)
- Security operations centre and incident response team
- Threat-informed risk assessment and threat hunting
- Supply chain risk plans and responses
- Penetration testing and specialized asset security
- Requires a final Level 2 C3PAO certification first
Assessed by DCMA DIBCAC every 3 years, with annual affirmation.
POA&M and affirmation rules (32 CFR 170.21, 170.22)
- No POA&M at Level 1
- Level 2 needs a score of at least 80 percent
- Only 1-point requirements can go on a POA&M
- Some requirements, such as the security plan, can never be deferred
- POA&Ms must be closed within 180 days
- Senior official affirms compliance each year in SPRS
Certification and assessment
Results are entered in SPRS, or in the CMMC eMASS system for C3PAO and DIBCAC assessments, and each assessed system receives a CMMC unique identifier. A senior affirming official confirms continuing compliance. Contracting officers check the required status before award, option exercise, or extension.
Dates to know
- 2024-12-16
- CMMC Program rule (32 CFR part 170) takes effect
- 2025-09-10
- DFARS acquisition rule published in the Federal Register (90 FR 43560)
- 2025-11-10
- DFARS rule takes effect and Phase 1 begins
- 2026-07-13
- Department announces suspension of Phase 2 and a 60-day CMMC Reform Task Force review
- 2026-11-10
- Original Phase 2 start date, now suspended
In this hub
CMMC levels and assessment types
What each CMMC level requires, who assesses it, and how scoring and POA&Ms work.
CMMC rollout timeline and the Phase 2 suspension
How the CMMC phased rollout was designed, what started on November 10, 2025, and what changed when Phase 2 was suspended in July 2026.
C3PAOs and the Cyber AB
Who runs CMMC assessments, how C3PAOs are authorized, and how to use the CMMC Marketplace.
CMMC for Canadian suppliers
How CMMC reaches Canadian companies in the U.S. defence supply chain, and how it relates to Canada's CPCSC.
Resources
Official texts and free tools for CMMC. Links open the publisher’s site.
- 32 CFR part 170, CMMC Program (current text), Electronic Code of Federal Regulations
- DFARS 252.204-7021, Contractor Compliance with the CMMC Level Requirements, Electronic Code of Federal Regulations
- DFARS CMMC final rule, 90 FR 43560 (September 10, 2025), Federal Register via govinfo.gov
- NIST SP 800-171 Rev. 2, NIST
- CMMC Marketplace, The Cyber ABtool
- Canadian Program for Cyber Security Certification overview, Public Services and Procurement Canadaguidance
Need help? Browse the directory or read the guides.
References
- CMMC Program final rule, 89 FR 83092 (October 15, 2024), Federal Register via govinfo.gov
- DFARS CMMC final rule, 90 FR 43560 (September 10, 2025), Federal Register via govinfo.gov
- Statement on the Department of War's suspension of CMMC Phase II requirements (July 15, 2026), The Cyber AB
- CMMC Reform Task Force updates, September 2026, Covington & Burling, Inside Government Contracts
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.