home / frameworks / cmmc

// U.S. frameworks that reach Canada

Cybersecurity Maturity Model Certification (CMMC) 2.0

CMMC is the U.S. Department of Defense program that verifies whether defence contractors protect FCI and CUI. It has 3 levels, with self-assessment, third-party C3PAO, or government assessment, and is being phased into contracts since November 10, 2025.

United States

Overview

CMMC checks that defence contractors actually meet the security requirements that are already written into their contracts, instead of relying on the contractor's word alone. Level 1 covers the 15 basic safeguarding requirements in FAR 52.204-21 for Federal Contract Information. Level 2 covers the 110 requirements of NIST SP 800-171 Rev. 2 for Controlled Unclassified Information. Level 3 adds 24 enhanced requirements selected from NIST SP 800-172 for the most sensitive programs.

The program rule came first. Codified at 32 CFR part 170, it took effect on December 16, 2024, and it sets the levels, the assessment methods, the rules for plans of action and milestones (POA&Ms), and the roles of the Cyber AB, C3PAOs, and the Defense Contract Management Agency's DIBCAC. The acquisition rule, which adds clause DFARS 252.204-7021 to contracts, was published on September 10, 2025 and took effect on November 10, 2025. That date started Phase 1, in which contracts ask mainly for self-assessments posted in the Supplier Performance Risk System (SPRS) along with an annual affirmation by a senior official.

The rollout changed in 2026. On July 13, 2026, the Department suspended Phase 2, which would have made Level 2 certification by a C3PAO a condition of award in many contracts from November 10, 2026. It also set up a CMMC Reform Task Force for a 60-day review. Phase 1 self-assessment requirements, DFARS 252.204-7012, and NIST SP 800-171 Rev. 2 stay in place. C3PAOs can still perform voluntary Level 2 certifications. As of October 11, 2026, the task force report had been delivered internally but not published, and no new Phase 2 date had been set.

Who it applies to in Canada

Companies anywhere in the U.S. defence supply chain that process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on their own systems. Contracts solely for commercially available off-the-shelf items are excluded.

Canadian manufacturers, engineering firms, and software suppliers that work on U.S. defence programs, directly or as subcontractors to U.S. primes, receive CMMC requirements through contract flowdown. The rule applies to foreign and domestic contractors alike, and Canada's own CPCSC uses similar controls but is not recognized as a substitute.

Controls at a glance

CMMC is organized by level, with each level drawing its requirements from an existing federal source.

Level 1: 15 requirements (FAR 52.204-21)

  • Limit system access to authorized users and devices
  • Identify and authenticate users before access
  • Sanitize media before disposal or reuse
  • Control physical access and escort visitors
  • Monitor and protect system boundaries
  • Patch flaws and use malicious code protection

Annual self-assessment, all 15 must be met, no POA&M allowed.

Level 2: 110 requirements (NIST SP 800-171 Rev. 2)

  • Access control, awareness, and audit logging
  • Configuration management and identification
  • Incident response and maintenance
  • Media, personnel, and physical protection
  • Risk assessment and security assessment
  • System, communications, and information integrity

14 domains. Self-assessment or C3PAO certification every 3 years, with annual affirmation.

Level 3: 24 requirements (NIST SP 800-172)

  • Security operations centre and incident response team
  • Threat-informed risk assessment and threat hunting
  • Supply chain risk plans and responses
  • Penetration testing and specialized asset security
  • Requires a final Level 2 C3PAO certification first

Assessed by DCMA DIBCAC every 3 years, with annual affirmation.

POA&M and affirmation rules (32 CFR 170.21, 170.22)

  • No POA&M at Level 1
  • Level 2 needs a score of at least 80 percent
  • Only 1-point requirements can go on a POA&M
  • Some requirements, such as the security plan, can never be deferred
  • POA&Ms must be closed within 180 days
  • Senior official affirms compliance each year in SPRS

Certification and assessment

Results are entered in SPRS, or in the CMMC eMASS system for C3PAO and DIBCAC assessments, and each assessed system receives a CMMC unique identifier. A senior affirming official confirms continuing compliance. Contracting officers check the required status before award, option exercise, or extension.

Dates to know

2024-12-16
CMMC Program rule (32 CFR part 170) takes effect
2025-09-10
DFARS acquisition rule published in the Federal Register (90 FR 43560)
2025-11-10
DFARS rule takes effect and Phase 1 begins
2026-07-13
Department announces suspension of Phase 2 and a 60-day CMMC Reform Task Force review
2026-11-10
Original Phase 2 start date, now suspended

In this hub

Resources

Official texts and free tools for CMMC. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. CMMC Program final rule, 89 FR 83092 (October 15, 2024), Federal Register via govinfo.gov
  2. DFARS CMMC final rule, 90 FR 43560 (September 10, 2025), Federal Register via govinfo.gov
  3. Statement on the Department of War's suspension of CMMC Phase II requirements (July 15, 2026), The Cyber AB
  4. CMMC Reform Task Force updates, September 2026, Covington & Burling, Inside Government Contracts