Program status
What applies now, which revision to use, and what each CMMC level means.
Find your next step
RSS feed5 guides
- Program status
Do I still need CMMC after the Phase 2 pause?
Yes. The pause cancelled the November 2026 certificate deadline, not the security work. What stopped, what still applies, and how to spend money now.
- Program status
NIST SP 800-171 Rev. 2 vs. Rev. 3: which applies to your CMMC work?
CMMC Level 2 and DFARS 7012 still use Rev. 2's 110 controls. What Rev. 3 changed, why it doesn't apply yet, and the one thing worth doing now.
- Program status
CMMC Levels 1, 2, and 3: what is the difference?
Your level is set by the information your customer sends you, not your size. Level 1 is 15 safeguards, Level 2 is 110 requirements, Level 3 is rare.
- Program status
How do CMMC requirements, policies, and evidence fit together?
An assessor checks that four things agree: the requirement, your policy, the setting that enforces it, and the record that proves it ran. One worked example.
- Program status
Continuous monitoring is coming to CMMC: what it means for you
The DoD CIO and the Cyber AB both want CMMC to move past point-in-time checks. No rule or memo requires it yet. What was said, what's guesswork, and the ongoing duties you already have.




