What Does the Government Actually Require of You Today?

In this article
Is this page for you?
Start here if any of these sound familiar:
- You just won a defense contract, or you’re about to, and it has a cybersecurity clause you don’t fully understand.
- You’re pursuing a defense contract and want to know what you’ll be asked to show.
- You’re moving from commercial work into government contracting for the first time.
- You won a research or innovation award, and now someone is asking about compliance.
- You’ve heard “CMMC is on hold” and you’re not sure what that means for you.
You don’t need to know the acronyms yet. By the end of this page, you’ll know what applies to you today and where to start.
The short answer
Some headlines turned the July pause into “CMMC is dead.” It isn’t. And even if it were, most of what you owe never came from CMMC in the first place.
What changed in July 2026?
On July 13, 2026, the Department of War paused Phase 2 implementation of the Cybersecurity Maturity Model Certification program, known as CMMC. On November 10, 2025, Phase 1 was already implemented which slowly introduced the requirement for DIB contractors to be certified by CMMC Third-Party Assessment Organization (C3PAO) before winning contracts involving sensitive information. Phase 2, which merely expanded the scope of contractors required to be assessed at CMMC L2 by a C3PAO was scheduled to begin November 10, 2026 and has now been paused.
The Department also created a Reform Task Force to review the program and recommend changes. As of the date at the top of this page, its recommendations have not been made public.
What didn’t change?
Almost everything you owe today. These obligations come from your contract clauses, and they remain in force. CMMC did not go away, and the requirements are still applicable (Only the phase 2 portion is paused).
If you remember one thing: protect what the government gives you, and tell the truth about how you do it.
- Protecting basic contract information. If your contract involves Federal Contract Information (non-public information the government gives you, or that you create for it), you must meet 15 basic safeguarding requirements. (FAR 52.204-21)
- Protecting sensitive information. If you handle Controlled Unclassified Information (sensitive government information that requires protection), you must implement the 110 security requirements in NIST SP 800-171. You must also report cyber incidents to the Department within 72 hours and flow these requirements down to your subcontractors. (DFARS 252.204-7012)
- Assessing yourself and reporting your score. You post your results in the Supplier Performance Risk System (SPRS), the government’s database of contractor cybersecurity scores. That score is based on your System Security Plan, the document that describes how you protect sensitive information. (DFARS 252.204-7019, -7020, -7021)
- Signing an affirmation. Level 1 contractors self-assess and affirm every year. Level 2 self-assessments run every three years, with an affirmation every year. Each affirmation is a representation to the federal government by a named senior official at your company. (32 CFR Part 170)
Enforcement didn’t pause either. The Department of Justice has continued to resolve cybersecurity cases under the False Claims Act during the review. Civil Division | Fraud Section Press Releases | United States Department of Justice
What can a contracting officer put in a solicitation right now?
Current direction instructs contracting officers to remove third-party certification requirements from solicitations and contracts, and to allow self-assessment in their place. NIST SP 800-171 remains the baseline for protecting sensitive information and DFARS 252.204-7021 remains the requirement for assessing.
The certification requirement is paused. The security requirement and the self-assessment requirement are not.
What happens when the Task Force report comes out?
A task force report is advice. Your legal obligations change only through a formal action:
- a class deviation,
- a change to the defense acquisition rules (DFARS), or
- an amendment to the CMMC rule itself (32 CFR Part 170).
Same day of report release, we’ll cover what it recommends, what it actually changes, and what it can’t change without formal rulemaking. Our approach won’t change with it: readiness now, certification when it’s required.
Where to start
Cybersecurity is the journey. Compliance is the outcome. Wherever you are on the journey, these steps come in this order.
- Know what you owe.
- Read your contract clauses. Look for FAR 52.204-21 and DFARS 252.204-7012, -7019, -7020 and -7021. They tell you whether you handle basic contract information, sensitive information, or both.
- Find out where that information lives: which systems, people and locations touch it. That scope decides how much work you actually have.
- Check what you’ve said.
- Find out whether your company has posted an SPRS score, and whether it reflects what’s actually in place.
- Read your System Security Plan and ask whether it describes your environment or a generic one. A score that overstates reality is a risk, not an asset.
- Plan the next step.
- Write down the gaps and how you’ll close them. That’s what a plan of action is for.
- Keep the security work and the people doing it. If you pause “the CMMC project,” don’t pause the security underneath it. That work counts no matter what the report says.
Start with a conversation, not a contract.
Evidence Review
Thorough examination of your compliance evidence. We verify documentation completeness.
Don't miss these
No one wants to start from blank templates.
No one wants to start from
blank templates.
Stop starting from blank templates. Get documentation proven through actual CMMC Level 2 assessment.



























































