Skip to content
Vendor-Neutral Advisory

CMMC Readiness for Government Contractors: Where to Start

Eric Anderson
Eric Anderson

Start with what's actually in effect right now — not what was planned

CMMC readiness advice dates quickly, and it's worth being precise about the current state as of this writing: Phase 1, effective November 10, 2025, introduced self-assessment requirements allowing contractors to attest to their own CMMC Level 1 and Level 2 compliance. Phase 2 — which was set to eliminate self-attestation for most Level 2 contracts involving Controlled Unclassified Information (CUI) in favor of mandatory third-party C3PAO assessments — was suspended by the Department of Defense on July 13, 2026, ahead of its planned November 10, 2026 start. Contractors should confirm the current status directly with their contracting officer or DoD guidance before making assumptions, since this kind of timeline has shifted before and can shift again.

Why "suspended" doesn't mean "ignore it"

A suspended mandatory third-party assessment requirement doesn't reduce the underlying security obligation — contractors handling CUI are still expected to meet NIST SP 800-171 controls and maintain an accurate Supplier Performance Risk System (SPRS) score under the current self-attestation framework. Treating the Phase 2 suspension as a reason to deprioritize CMMC work risks being caught unprepared whenever a firm third-party assessment requirement does take effect — and contractors already well-positioned for Level 2 self-assessment now will have a meaningfully shorter path if and when third-party assessment becomes mandatory again.

Where to actually start

1. Confirm which level applies to your contracts

CMMC level requirements are tied to the sensitivity of information handled under specific contracts — confirm this with your contracting officer rather than assuming based on company size or industry.

2. Build or update the System Security Plan (SSP)

The SSP documents how all 110 NIST SP 800-171 controls are implemented. This document is the foundation for both self-attestation and any future third-party assessment, so it's worth building it accurately now regardless of which assessment path ultimately applies.

3. Get an honest SPRS score

The Supplier Performance Risk System score should reflect actual security posture, not an optimistic estimate — an inflated score creates real contractual and legal exposure under the False Claims Act if it doesn't match reality.

4. Document a POA&M for any gaps

A Plan of Action and Milestones for unmet controls is expected as part of the current framework — gaps aren't disqualifying on their own, but undocumented gaps are.

5. Budget realistically for the timeline

Preparation typically takes six to twelve months depending on current security posture — a timeline that hasn't changed even as the third-party assessment deadline has shifted.

Where an outside review helps

Confirming SSP accuracy, SPRS scoring, and control implementation against a shifting compliance timeline is exactly the kind of independent review that catches gaps before a contracting officer does. Talk to an advisor about where your current CMMC posture actually stands.

Share this post