Understand CMMC, the July 2026 suspension of third party certification, and what defense contractors must still do for compliance.
Section
CMMC and NIST 800-171
What the framework asks for, what changed in July 2026, and how to work out what applies to you.
All articles
10 piecesConfused about CMMC Level 2? Learn how to determine if Level 1 or Level 2 applies, based on whether you handle FCI or CUI, and what to do next.
Understand the difference between FCI and CUI, why CUI drives your compliance scope, and how correct marking under 32 CFR Part 2002 can save costs and risk.
Understand all 14 families of NIST 800-171 controls, including practice counts and what each family requires for Level 2 compliance.
Understand CMMC scoping with a focus on the five asset categories in 32 CFR 170.19(c)(1) Table 3 to avoid common mistakes and improve compliance.
Understand the four essential documents needed for a CMMC assessment: CUI Flow Diagram, Network Boundary Diagram, Physical Site Diagram, and Authorized User List.
Understand how your SPRS score is calculated, what a negative score means, and why the DIB average SPRS score lags behind the required 110.
Learn what a System Security Plan is, why CA.L2-3.12.4 mandates it for defense contractors, and the real consequences of failing to maintain one.
Learn what a POA&M is, how it works at Level 2 for CMMC and NIST SP 800-171, and why POA&Ms are not permitted at Level 3. Understand the 180 day rule.
The CMMC self-assessment process remains mandatory for defense contractors. Learn what requirements still apply after the suspension of third-party certification.