August 18, 2026 status: CMMC Phase II is suspended. Only Level 1 (Self) and Level 2 (Self) may be designated in new procurement requirements during the suspension. DFARS 252.204-7012 safeguarding duties are unchanged. → What the suspension actually changed
By The Defense Compliance Report Editorial Team · Last reviewed: August 2026 · Last verified: August 18, 2026 · Methodology · Editorial standards · Corrections policy · Independent research — not legal, contractual, cybersecurity, or compliance advice
Bottom line: CMMC for cleared defense contractors follows the contract, the information, and the unclassified system boundary — not the facility clearance. Your FCL does not cover CMMC, and CMMC does not assess classified assets. The CMMC Program Rule applies only where a contractor will process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on unclassified contractor information systems (32 CFR § 170.3(c)). Your SIPRNet or JWICS terminal and your Cognizant Security Agency–authorized classified information system sit outside CMMC. A SCIF or closed area is not automatically outside scope if it contains unclassified assets that handle FCI or CUI. Your unclassified network — proposals, drawings, ERP, email — is where CUI may live and where CMMC lands.
Here's the part almost nobody tells cleared contractors: there is zero status reciprocity between the two programs. Your Facility Clearance (FCL), your DD Form 254, your NISPOM program, and your government Authorization to Operate produce no CMMC status and no NIST SP 800-171 DoD Assessment score. Not partial credit. None.
That sounds like bad news. It's actually the opposite, and we'll show you why in the next two minutes — along with the one paragraph in the NISPOM, written for cleared defense contractors and nobody else, that quietly draws this exact boundary and has been sitting there since 2021.
What changes the answer for you: whether any DoD contract or subcontract puts FCI or CUI on your unclassified systems, which CMMC status the current instrument requires, and whether an unclassified DoD opportunity exceeds $5 million — because a separate proposed FOCI rule would create another gate if finalized.
Start here: which cleared contractor are you?
| Your situation | What CMMC does | Jump to |
|---|---|---|
| Classified performance only, at a government site, with no FCI or CUI on your own contractor systems | May not apply to you at all | The honest part |
| Classified work plus unclassified DoD contracts carrying CUI | Applies to the unclassified side only | Which systems are in scope |
| One contract with both classified access and CUI in performance | May apply — and your DD Form 254 cannot tell you the CMMC status by itself | Why your DD 254 cannot answer this |
| An unclassified DoD opportunity above $5 million | A separate FOCI gate has been proposed, but is not current law | The proposed FOCI gate |
| You're a prime deciding what to flow down to a cleared subcontractor | Two separate contractual paths, not one | Flow-down |
The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every regulatory claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they make an expensive provider decision.
When does CMMC for cleared defense contractors apply?
Sometimes — but holding a clearance is not what triggers it. The Cybersecurity Maturity Model Certification (CMMC) Program follows the contract and the data: it applies when a DoD contract or flow-down requires a contractor to process, store, or transmit FCI or CUI on unclassified contractor information systems (32 CFR § 170.3(c)). Cleared status neither creates nor satisfies a CMMC requirement.
We can put that more sharply than anyone has, because we went looking for the term itself.
We checked three relevant parts of Title 32. “Cleared defense contractor” is defined in Parts 117 and 236. In the part that governs CMMC, Part 170, the term does not appear.
| Where | How it is defined or treated | What that part governs |
|---|---|---|
| 32 CFR § 117.3 (NISPOM) | “CDC means a subset of contractors cleared under the NISP who have classified contracts with the DoD.” | Protection of classified information |
| 32 CFR § 236.2 (DIB Cybersecurity Program) | A private entity granted clearance by DoD to access, receive, or store classified information for bidding or work supporting a DoD program | Voluntary cyber threat-information sharing |
| 32 CFR Part 170 (CMMC Program Rule) | The term does not appear. | CMMC levels, scoping, assessment, affirmation |
Verified against eCFR text, August 18, 2026.
That is the whole page in one table. Two federal cyber programs know exactly what a cleared defense contractor is and write rules specifically for them. The CMMC Program Rule doesn't use the concept. It sorts contractors by information type and system, not by clearance status.
So when a prime's supplier portal asks a Top Secret–cleared company for an SPRS score and the FSO forwards it to IT and it dies there — that's not a process failure. It's two organizations correctly operating in two systems that were never designed to talk to each other.
The three questions that actually decide it
- What does the contract say? Is there a CMMC requirement in the latest solicitation, award, modification, or prime flow-down — and has it been amended since July 13, 2026?
- What information do you handle? FCI, CUI, classified, or some combination.
- Where does it live? Specifically: which of your unclassified systems process, store, or transmit it.
Nothing on that list is answered by your FCL.
One piece of good news you already own
Within the DIB Cybersecurity Program, clearance status unlocks one distinct lane worth knowing about. Under 32 CFR § 236.7(b), receiving classified cyber threat information electronically requires an active FCL at Secret or above, a COMSEC account, approved safeguarding at Secret, and access to the secure transmission systems supporting the program.
DoD deliberately widened the program outside that classified lane. A final rule published at 89 FR 17741, effective April 11, 2024, removed the cleared-contractor prerequisite from general DIB Cybersecurity Program participation. DoD estimated that roughly 68,000 additional contractors could become eligible.
The direction of travel is clear. Federal cyber programs are moving away from clearance status as an organizing principle, not toward it.
Does a facility clearance satisfy CMMC?
No, and the reverse is equally true. An FCL is an administrative determination that an entity is eligible for access to classified information at a given level (32 CFR § 117.3) — it does not by itself even convey authority to store classified information. A CMMC status is tied to a specified OSA information system and defined assessment scope. Neither status substitutes for the other, and no rule grants credit across them.
Here's our damaging admission, and we'll take the hit for it
There is no status reciprocity between your cleared program and CMMC. None.
Not your FCL. Not your CSA Authorization to Operate. Not a clean NISP security review. Not ten years of satisfactory ratings. Not your insider threat program. None of it produces a CMMC status, a CMMC Unique Identifier, or a NIST SP 800-171 DoD Assessment score in SPRS.
If you've suspected you're being asked to pay twice for overlapping security, you're not paranoid. You're reading the regulations correctly. And the NISPOM itself says redundancy is a problem: 32 CFR § 117.4(b) states that national security requires the industrial security program to promote U.S. economic and technological interests, and that "redundant, overlapping, or unnecessary requirements impede those interests."
Now the pivot, because the good news is bigger than the bad
Zero reciprocity cuts both ways — and the direction that helps you is much larger.
Your classified assets are outside CMMC scope. Every dollar you've spent on a classified information system, classified network authorization, or classified workstation earns no CMMC credit, and those classified assets are not assessed for CMMC either. The DoD CMMC Level 2 Scoping Guide states that classified assets are excluded from the CMMC Assessment Scope even when they contain applicable CUI.
Scope reduction is the single most valuable thing any contractor can buy in a CMMC program. Companies build CUI enclaves for exactly this reason: to shrink the assessment boundary. You already have a major scope carve-out as a byproduct of work you did for other reasons.
The uncleared machine shop down the road may have one flat network and every asset on it may become a scoping problem. You already have a hard, government-authorized boundary and a security staff that thinks in terms of boundaries. That's not a disadvantage. That's a head start most contractors would pay for.
What you have to do is draw the second boundary — the unclassified one — with the same discipline you already apply to the first.
What each status actually establishes
| Question | Facility Clearance (FCL) | CMMC status |
|---|---|---|
| What it means | Entity is eligible for access to classified information at a stated level (§ 117.3) | A specified OSA information system achieved a stated CMMC status for a defined assessment scope |
| What it does not convey | Authority to store classified information (§ 117.3); a safeguarding-capability determination, which is separate (§ 117.9(a)(3)) | Any authority to access, process, or store classified information |
| Who decides | The Cognizant Security Agency — DCSA for most DoD-cleared DIB companies | The OSA for a self-assessment, a C3PAO for Level 2 certification, or DCMA DIBCAC for Level 3 |
| Where it is recorded | NISS for facility-clearance and entity-vetting records | SPRS for CMMC status, UID, and affirmations |
| Neither one establishes | That every system is in scope; that every cleared company needs Level 2; that a specific cloud tenant is required; or protection from contractual or cyber risk | Same |
▸ Your next step
You now know which rulebook governs which half of your company. The expensive mistakes from here are scoping mistakes — pulling classified assets into a CMMC boundary where the rule excludes them, or missing unclassified CUI because the security office was watching the other network.
Map your situation with Find My CMMC Path → Tell us your level, scope, and timeline. We'll point you to the right provider category before you request a single quote. It routes to a category, never to a named provider.
⚠️ Do not submit CUI, classified information, drawings, contract numbers, program names, credentials, or system diagrams.
Where NISPOM ends and CMMC begins
NISPOM does not set the safeguarding requirements for unclassified contractor systems that handle CUI; your contract does. The direct information-system rule says so in one sentence at 32 CFR § 117.18(f): “While outside the requirements of the NISPOM, contractors will comply with contract requirements regarding contractor information systems that process, store, or transmit CUI.”
That is the direct NISPOM system-security handoff for unclassified CUI systems. One sentence that amounts to not our system-security standard — read your contract.
The NISPOM mentions CUI elsewhere — including training, contract provisions, incident reporting, and the limited conditions under which a CSA may assess CUI alongside a NISP review. But it does not turn your FSO's classified-security rulebook into a CMMC implementation guide.
The Two-Rulebook Register
We built this by reading both rules side by side. Every cell is sourced.
| Question | Classified side (NISP) | Unclassified side (CMMC) |
|---|---|---|
| Governing rule | 32 CFR Part 117 (NISPOM), effective Feb. 24, 2021 | 32 CFR Part 170, effective Dec. 16, 2024 |
| Contract instrument | DD Form 254 and classified-security provisions when classified access is required | DFARS 252.204-7025 in the solicitation and 252.204-7021 in the award, as applicable |
| Technical standard | CSA guidance using RMF concepts, CNSSI 1253, and NIST SP 800-53 under § 117.18 | NIST SP 800-171 Rev. 2 — 110 requirements in 14 families — at Level 2; FAR 52.204-21's 15 requirements at Level 1 |
| What drives the level | Classification guidance and the authorized classified-system categorization | The contract-selected CMMC status: FCI generally maps to Level 1; CUI to at least Level 2 |
| Who authorizes or assesses | The CSA authorizes the classified system before use | The OSA self-assesses, a C3PAO assesses Level 2 certification, or DCMA DIBCAC assesses Level 3 |
| Program oversight | The applicable CSA; DCSA for most DoD-cleared DIB companies | DoD CMMC PMO, DCMA DIBCAC, and a Cyber AB–authorized or accredited C3PAO when applicable |
| What the obligation attaches to | Entity eligibility, classified contracts, facilities, personnel, and authorized classified systems | The contract sets the required status; the CMMC record attaches to a defined assessment scope and OSA information system |
| System of record | NISS for facility/entity records; DISS for personnel | SPRS |
| Named accountable role | SMO, FSO, ITPSO, and ISSM under § 117.7 | Affirming Official under § 170.22 |
| Recurring check | Formal self-inspection at least annually, certified in writing to the CSA by the Senior Management Official | Assessment at the rule-set cadence plus affirmation after each assessment, after POA&M closeout, and annually thereafter |
| Failure mode | Adverse CSA finding and possible entity-eligibility consequences | Award, option, or extension ineligibility where a current required status is absent; potential False Claims Act exposure for knowingly false representations |
| Produces credit in the other lane? | No status credit | No clearance credit |
All citations verified at eCFR, August 18, 2026.
The detail that makes the "we're paying twice" argument mostly wrong
Look at the technical-standard row again. Your classified systems are authorized through a government RMF process using standards and guidance that include NIST SP 800-53. CMMC Level 2 is assessed against NIST SP 800-171 Rev. 2, through a self-assessment or C3PAO certification assessment depending on the required CMMC status.
Those two publications are related — 800-171 was derived from the moderate baseline of 800-53 — so a well-run classified program has genuinely built muscles that transfer at the practice level. Access control is access control. Audit logging is audit logging.
But the two programs share no authorization mechanism, assessor, system of record, or status reciprocity. That distinction is the difference between “we can reuse some evidence” (often true) and “our ATO should count” (not supported). We come back to exactly what does and does not transfer further down.
Do not confuse the two SPRS records
Cleared contractors are often told to “get the SPRS score” as though SPRS contains one universal cyber credential. It does not.
| SPRS record | What creates it | What it contains | What your FCL contributes |
|---|---|---|---|
| NIST SP 800-171 DoD Assessment record | The Basic, Medium, or High Assessment process in DFARS 252.204-7019 and 252.204-7020 | A summary score and assessment metadata tied to the relevant SSP, systems, and CAGE codes | Nothing |
| CMMC record | A CMMC assessment under 32 CFR Part 170 and DFARS 252.204-7021 | CMMC status, scope/system identification, CMMC UID, status dates, and annual affirmation | Nothing |
The records can concern the same unclassified environment and the same 110 Revision 2 requirements, but they are not the same record.
The posting duty is different in each lane. Under DFARS 252.204-7019, an offeror required to implement NIST SP 800-171 must verify before award that a current summary-level assessment is posted in SPRS for each relevant covered contractor information system; if none is posted, the offeror may conduct and submit a Basic Assessment. Medium and High Assessment results are posted by DoD under DFARS 252.204-7020. Under DFARS 252.204-7021, the contractor submits the applicable CMMC UID to the contracting officer, enters self-assessment results in SPRS when they are not covered by a C3PAO or DIBCAC assessment, and keeps the required affirmations current in SPRS — after assessment, after POA&M closeout, and annually thereafter.
One current-document warning matters here: DoD is operating under acquisition class deviations that can change prescriptions or clause numbering in live instruments. The codified DFARS clauses remain essential authorities, but your actual solicitation, award, amendment, modification, and prime flow-down are the documents you must read.
The NISPOM incident paragraph written only for cleared defense contractors
32 CFR § 117.8(f) applies only to cleared defense contractors, and it splits cyber incident reporting into two separate lanes: an immediate classified-system lane and an unclassified lane whose trigger, recipient, and clock come from the contract. It also cross-references DFARS clause 252.204-7012 by number. It is one unusually direct place where the classified rulebook and the unclassified contract regime touch.
Most cleared contractors have never read it. It is the single most useful paragraph on this topic, so here is what it does.
The paragraph opens by stating that it applies only to CDCs and sets out reporting requirements pursuant to 10 U.S.C. 391 and 393 and DFARS clause 252.204-7012. Then it forks:
| Question | § 117.8(f)(1) — classified lane | § 117.8(f)(2) — unclassified lane |
|---|---|---|
| Applies to | A classified covered information system approved by the designated DoD Cognizant Security Office to process classified information | Non-federal, unclassified information systems |
| When to report | Immediately | “In accordance with contract requirements” |
| Report to | The designated DoD CSO — DCSA when DCSA is the applicable CSO | Whatever the contract says; under DFARS 252.204-7012, DIBNet within 72 hours of discovery |
| Minimum content | Technique or method; malicious-software sample if isolated; summary of any DoD program information potentially compromised | Set by the clause, not by the NISPOM |
Section 117.8(f)(3) then permits DoD personnel to request access to additional equipment or information for forensic analysis after a reportable incident. It is not limited to only one lane above.
Source: 32 CFR § 117.8(f), verified August 18, 2026.
"Classified covered information system" is itself defined at § 117.3 as a system owned or operated by or for a cleared defense contractor that processes, stores, or transmits information created by or for DoD requiring enhanced protection.
Why this matters more than it looks
Read § 117.8(f)(2) again: for cyber incidents on unclassified systems, the NISPOM's instruction to a cleared defense contractor is go read your contract. It does not set a clock. It does not name a recipient. It hands you off.
That handoff is where cleared companies get hurt. The FSO knows the classified reporting path cold — it is immediate, it goes to the designated CSO, and it has been drilled. The unclassified path may run on a different clock, to a different portal, under a clause the security office may never have read. When ransomware hits the engineering file share at 4 p.m. on a Friday, the muscle memory in the building points at the classified lane. Meanwhile a 72-hour DFARS clock may already be running toward DIBNet.
Practical takeaway: if you hold an FCL and you also have any contract carrying DFARS 252.204-7012, your incident response plan needs both lanes written into it, by name, with the trigger, clock, recipient, and evidence-preservation duties for each. That is a one-page fix and it is probably the highest-value thing on this page.
Two more things worth knowing while we're in § 117.8:
- § 117.8(c)(7)(v) requires you to report material changes in foreign ownership, control, or influence by submitting an updated SF 328. Hold that thought — it becomes important below.
- § 117.8(g)(1) gives you a right almost nobody uses: contractors may report instances of redundant or duplicative security review and audit activity by the CSAs to the Director of the Information Security Oversight Office (ISOO) for resolution. The contact information is published in the rule itself, in Table 2 to § 117.7(o). If you genuinely believe you're being reviewed twice for the same thing, that channel exists and it is in the regulation.
Why your DD Form 254 can't tell you your CMMC level
The DD Form 254 has two CUI items, and both may only be used on a contract that requires access to classified information. The official instructions state that the NISPOM provides no guidance on CUI protection and hand the question to the Government Contracting Activity to answer in free text. Across all twelve pages of those instructions, CMMC, NIST SP 800-171, DFARS 252.204-7012, and SPRS are never mentioned.
We read the whole thing. The document is Instructions for Completing DD Form 254, Department of Defense Contract Security Classification Specification, April 2018, as updated July 11, 2025, published by the Washington Headquarters Services Executive Services Directorate. Twelve pages, eighteen items. Here's what we found.
Item 10.j — Controlled Unclassified Information (CUI). The instruction says not to select the item unless a contract requiring access to classified information also includes a requirement for access to CUI. Then, in the government's own words: "The NISPOM, DoDM 5220.22, does not provide guidance concerning CUI so the GCA must provide guidance on protection procedures in Item 13." DoD components are pointed to DoDI 5200.48.
Item 11.l — Receive, Store, or Generate CUI. The instruction opens with an explicit prohibition: do not select this item for a contract that only requires receipt, storage, or generation of CUI. It may be checked only when Item 10.j is checked and the contract requires classified access for performance. The instructions then confirm that Items 10.j and 11.l "only pertain for the protection of any CUI required in the performance of this specific classified contract."
The gap, stated plainly
| What the DD Form 254 does | What it does not do | Where the answer actually lives |
|---|---|---|
| Tells you a contract involves classified access, at what level, and where | Tell you your CMMC level or assessment type | The current solicitation, award, modification, or flow-down — including the applicable CMMC notice or clause |
| Flags that CUI is present on a classified contract (Item 10.j) | Apply to an unclassified CUI-only contract — no DD 254 is issued for one | The contract or subcontract instrument itself |
| Points to DoDI 5200.48 for CUI protection | Reference NIST SP 800-171, DFARS 252.204-7012, SPRS, or CMMC anywhere in twelve pages | 32 CFR Part 170, the DFARS, and the live instrument |
| Routes CUI handling instructions to GCA free text in Item 13 | Guarantee that Item 13 states a CMMC status or supplies complete cyber guidance | Ask the contracting officer or prime in writing |
Source: DD Form 254 Instructions, April 2018 (updated 20250711), esd.whs.mil. Read in full and verified August 18, 2026.
This is not an oversight by your FSO, and it is not proof of sloppiness by your contracting officer. The form is a classified-contract instrument. It can flag CUI and route protection guidance to Item 13, but it was not built to state your CMMC status. If your company's security governance runs through the FSO and the DD 254 — and in most cleared companies it does — then your CMMC obligation can be structurally invisible to your own process.
Free tool: the four questions that close the gap
Copy this into an email to your contracting officer or prime. It takes them five minutes and it resolves most of what this page is about. No form, no email capture, no catch.
Subject: Cybersecurity requirement clarification — [Contract/Solicitation No.]
We hold a facility clearance and are reviewing our obligations under this effort. To scope correctly, we need four things confirmed in writing:
- Does performance of this contract require us to process, store, or transmit FCI or CUI on our unclassified contractor information systems?
- If yes, what CMMC level and assessment type applies, and under which clause or flow-down?
- Is CUI handling for this effort addressed anywhere other than Item 13 of the DD Form 254?
- Which contractor systems and CAGE codes does the Government or prime expect the requirement to cover?
We are asking so that we scope our environment accurately rather than over- or under-applying requirements. Thank you.
If the answer to Question 1 is a documented no, you may be one of the companies that doesn't need CMMC right now. That's a legitimate outcome, and it's worth having in writing before you spend anything.
Are classified systems included in a CMMC assessment?
No. The CMMC Program Rule applies to FCI and CUI on unclassified contractor information systems (32 CFR § 170.3(c)), and DoD's Level 2 Scoping Guide states that classified assets are excluded from the CMMC Assessment Scope even when they contain applicable CUI. The qualifier that matters: authorized unclassified copies, endpoints, and supporting services remain separate scoping questions.
Two independent authorities land on the same answer, which is why we're confident stating it flatly.
The rule. Section 170.3(c) applies CMMC Program requirements to solicitations and contracts where a contractor "will process, store, or transmit FCI or CUI on unclassified contractor information systems," above the micro-purchase threshold, except for acquisitions exclusively of commercially available off-the-shelf items. Separately, § 170.3(b) states the part does not apply to federal information systems operated by contractors on the government's behalf — relevant if you run government-owned systems under contract.
The guide. DoD's CMMC Level 2 Scoping Guide adds the edge case directly: classified assets are outside the CMMC Program scope even when they contain applicable CUI.
The edge case cleared companies actually hit
CUI on a classified asset does not pull that classified asset into CMMC. But it also does not automatically exclude every unclassified destination or supporting service. Ask where else information from that program exists and what the authorized marking or classification decision says:
- A properly authorized unclassified derivative or separately provided CUI drawing on a shop-floor or manufacturing system
- An unclassified email or Teams message containing CUI
- A print station, scanner, or plotter that handled a CUI document
- A help-desk ticket containing CUI or security-protection data
- Backups, identity systems, and administrative workstations supporting the in-scope environment
- A file-transfer or collaboration service used to move CUI to a prime or subcontractor
Every one of those is an unclassified-asset question. The classified source asset's CMMC exclusion does not automatically exclude the unclassified destination. The copy's marking or classification determination, the contract, and its actual handling govern. If the copy remains classified, moving it to an unclassified system is a spillage incident — not a CMMC-scoping shortcut.
What "excluded" does not mean
It does not mean you have no CMMC requirement. It does not mean adjacent unclassified systems are excluded. It does not mean shared administrators and shared tools can be ignored. It does not mean a physical SCIF or closed area is itself a universal CMMC exclusion. And it does not make an unclassified copy safe merely because its source system was classified.
Which systems at a cleared facility are actually in scope?
Draw two boundaries, not one. Classified assets fall outside CMMC. On the unclassified side, 32 CFR § 170.19 sorts Level 2 assets into five categories — CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets — each with its own documentation and assessment treatment.
The five Level 2 asset categories
From Table 3 to § 170.19(c)(1):
| Category | What it is | How it is treated |
|---|---|---|
| CUI Assets | Assets that process, store, or transmit CUI | Asset inventory, SSP treatment, network diagram; assessed against all Level 2 requirements |
| Security Protection Assets | Assets that provide security functions or capabilities to the assessment scope | Asset inventory, SSP treatment, network diagram; assessed against Level 2 requirements relevant to the capabilities provided |
| Contractor Risk Managed Assets | Assets that can, but are not intended to, process, store, or transmit CUI because of documented policies, procedures, and practices | Asset inventory, SSP treatment, network diagram; SSP review first, with a limited check if documentation or findings raise questions |
| Specialized Assets | IoT, IIoT, Operational Technology, Government Furnished Equipment, Restricted Information Systems, and Test Equipment that can handle CUI but cannot be fully secured | Asset inventory, SSP treatment, risk-based management, network diagram; SSP review, not assessment against the other Level 2 requirements |
| Out-of-Scope Assets | Assets that cannot process, store, or transmit CUI, do not provide security protection for CUI Assets, and are physically or logically separated as required | Outside the assessment scope; the OSA must be able to justify the exclusion |
The Cleared-Facility Asset Split
This is our editorial classification, applied to assets a cleared facility may actually have. Your markings, architecture, and contract govern; confirm disputed cases with a qualified practitioner or provider that is not your assessor.
| Asset a cleared facility may have | Likely CMMC treatment | Authority or decision rule |
|---|---|---|
| SIPRNet drop or JWICS terminal processing classified information | Outside CMMC as a classified asset | § 170.3(c); DoD Level 2 Scoping Guide |
| Standalone classified information system under CSA authorization | Outside CMMC | § 170.3(c); NISPOM § 117.18 |
| Classified-only workstation inside a SCIF | Outside CMMC as an asset; the physical space is not the test | § 170.3(c); Scoping Guide |
| Federal information system operated on the government's behalf | Outside CMMC | § 170.3(b) |
| Unclassified email, file share, ERP, PLM, or CAD environment holding CUI | CUI Asset — fully assessed at Level 2 | § 170.19(c)(1), Table 3 |
| Unclassified proposal or business-development environment holding FCI but no CUI | Potential Level 1 scope when the contract requires Level 1 | § 170.19(b) |
| SIEM, identity provider, or managed security service protecting the Level 2 scope | Security Protection Asset to the extent it provides security functions or handles security-protection data | § 170.19(c)(1), Table 3 |
| Unclassified GFE that can handle CUI but cannot be fully secured | Specialized Asset at Level 2; excluded from Level 1 scope | § 170.4; § 170.19(b) and (c) |
| Unclassified test or calibration equipment that meets the regulatory Test Equipment definition | Specialized Asset at Level 2 | § 170.4; § 170.19(c)(1), Table 3 |
| NISS or DISS workstation | Depends — classify it by the information actually handled, the services it provides, and its connectivity; use of NISS or DISS alone does not decide the category | Editorial application of § 170.19 |
Our classification, built on primary sources cited. Last verified August 18, 2026.
The trap that hits cleared facilities hardest
Specialized Assets are treated differently at each level, and cleared facilities may have a meaningful number of them.
At Level 1, Specialized Assets are outside the Level 1 CMMC Assessment Scope and are not assessed against Level 1 requirements. At Level 2, those assets are inside the assessment scope: the asset inventory, SSP treatment, risk-based policies, and network diagram are required, even though the assets are not assessed against the other Level 2 requirements.
So a company that scoped a Level 1 self-assessment and later receives a Level 2 requirement does not simply add controls. It acquires a documentation obligation for a class of assets it was previously allowed to leave outside the Level 1 scope. GFE and test equipment are exactly where that can land.
One useful relief valve: 32 CFR § 170.4 defines an Enduring Exception as a circumstance or system where full compliance with a CMMC security requirement is not feasible, listing systems that replicate the configuration of fielded systems, test equipment, operational technology, and IoT as examples. An operational plan of action is not required for an Enduring Exception, but the circumstance and mitigation must be documented in the SSP.
🛠 Free worksheet: the Cleared Facility Boundary Splitter
Use these eleven non-sensitive questions to create a first-pass boundary worksheet. Do not enter or attach CUI, classified information, program names, system diagrams, credentials, or vulnerability details.
- Are you a prime, subcontractor, or both?
- Do you hold an active FCL?
- Do you have DoD contracts that do not require classified access?
- Does any current instrument contain DFARS 252.204-7012?
- Does any current solicitation, award, modification, or flow-down contain a CMMC notice or clause?
- Does any unclassified contractor system hold FCI?
- Does any unclassified contractor system hold CUI?
- Is any applicable CUI held only on classified assets, or does an authorized unclassified copy exist elsewhere?
- Do you have GFE, OT, IoT/IIoT, Restricted Information Systems, or Test Equipment on the unclassified side?
- Which external service providers process CUI or security-protection data?
- Who is the senior internal representative authorized to submit CMMC affirmations in SPRS?
For each “yes” or “unsure,” record the contract source, information type, asset or service category, owner, CAGE code, and unresolved question. That produces a dated worksheet you can take to contracts, IT, your FSO, counsel, or a readiness provider without disclosing sensitive content.
▸ Your next step
Once you know your boundary, the work becomes concrete and finite. It is also the point where most cleared companies discover the gap isn't controls — it's evidence.
Use the CMMC Readiness Checklist → Organize the work across all 14 NIST SP 800-171 Revision 2 families. Free, no gate.
Can DCSA assess your CUI during a security review?
Only when DCSA is acting as the applicable Cognizant Security Agency and all three conditions in 32 CFR § 117.7(h)(1)(iii) are met. The rule says CUI compliance is outside the scope of the NISP and the NISPOM rule, but permits a CSA to conduct a CUI assessment alongside a NISP government review under three specific conditions.
This question gets asked constantly, and the answers circulating in FSO-facing content are mostly assertions without a citation. Here is the actual rule.
A CSA may assess CUI alongside a NISP review when all three of the following are true:
- You're in the NISP because you need classified access. The contractor is a participant in the NISP based on a requirement to access classified information.
- A classified contract carries CUI provisions. A classified contract under that CSA's cognizance includes provisions for access to, or protection or handling of, CUI.
- The CSA told you the rules first. The CSA has provided the contractor with specific guidance regarding the assessment criteria and methodology it will use for overseeing protection of the CUI being accessed, stored, or transmitted as part of the classified contract.
Source: 32 CFR § 117.7(h)(1)(iii), verified at eCFR, August 18, 2026.
Note the third condition carefully. The criteria and methodology must be provided in advance. That is not a courtesy; it is a precondition written into the rule. If a CUI question arrives during a review and you have not received that guidance, asking for it is a reasonable, rule-based response — not obstruction.
What to have ready if this comes up
- The contract provision that creates the CUI obligation
- Your CUI data-flow documentation and system boundary
- The System Security Plan covering the unclassified environment
- A clear map of which systems are classified and which are not
- The right people in the room: FSO, ISSM, IT, contracts, and whoever signs your affirmations
What this is not
A CUI assessment conducted alongside a NISP review is not a CMMC assessment and does not produce a CMMC status. CMMC statuses come from a self-assessment, a C3PAO certification assessment, or a DCMA DIBCAC assessment, depending on the status type, and are recorded in SPRS.
On the claim that a cyber incident jeopardizes your clearance
You'll see this asserted in marketing content aimed at FSOs. We went looking for the authority and did not find one that makes that causal link automatic.
What the regulations actually establish: § 117.8(c)(7) requires reporting changed conditions affecting entity eligibility, and § 117.8(d) requires reporting loss or compromise of classified information. A cyber incident on an unclassified system is reported under § 117.8(f)(2) in accordance with contract requirements. That is a contract-reporting channel, not an automatic clearance-revocation rule.
A serious incident can reveal separate facts or failures that matter under another contract, regulation, eligibility review, or enforcement theory. But “a CUI incident automatically threatens your FCL” is a claim we could not source, and we're not going to repeat it to sell you something. If you see that claim, ask which rule it cites.
Can you reuse NISPOM evidence for CMMC?
Sometimes at the artifact level — never at the status level. No rule grants CMMC status credit for an FCL, a satisfactory NISP security review, or a CSA authorization of a classified system. Individual artifacts from a mature cleared program can support CMMC requirements, but only after they are mapped to the specific requirement, the unclassified assessment scope, and the evidence the assessment objective calls for.
The distinction matters because it's where cleared companies waste the most time. Two different questions get collapsed into one:
- Status reciprocity — "our clearance should count." It doesn't. There is no mechanism.
- Evidence reuse — "we already do this, can we show it?" Often yes, with work.
What tends to transfer, and what doesn't
| Artifact you already have | Realistic CMMC value |
|---|---|
| Personnel access, onboarding, and termination records | Often adaptable. They must cover the people and unclassified systems inside the CMMC Assessment Scope, not only cleared personnel |
| Security awareness and role-based training records | Often adaptable. The evidence must cover the personnel and roles implicated by the Level 2 requirements |
| Physical access-control and entry records | Often adaptable, if the documented boundary includes the locations where CUI is handled |
| Incident-response roles, escalation, and after-action records | Adaptable, but the unclassified lane can have a different trigger, clock, recipient, and preservation duty — see § 117.8(f) |
| Configuration and change-management records | Adaptable if the process actually runs on the unclassified in-scope environment |
| Privileged-access and account-review records | Adaptable, under the same condition |
| Media handling, marking, and destruction procedures | Adaptable, though CUI marking and handling follow the applicable CUI authorities and contract, not classified marking rules |
| Self-inspection reports under § 117.7(h)(2) | Useful as a model, not automatic CMMC evidence. They assess a different program against different criteria |
| Your CSA authorization decision letter | No status transfer. Different standard, authority, and scope |
| A satisfactory NISP security review | No status transfer |
| Policies written only for the classified environment | No transfer until adapted to the unclassified CMMC Assessment Scope |
Editorial assessment based on the requirement sets and scoping rules cited on this page.
The honest version of "how much overlap?"
We're not going to give you a percentage. You'll see “80% overlap” and similar figures in vendor material; we have not found a published, transparent, control-by-control mapping that turns those percentages into a universal answer, and we're not going to invent one.
What we can say from the source documents is directional and useful: your practices may have real overlap, because SP 800-171 was derived from SP 800-53's moderate confidentiality baseline. Your evidence has partial overlap, gated by whether the artifact covers the unclassified in-scope environment and the applicable assessment objective. Your status has zero overlap.
Budget for the mapping work. Don't budget for the credit.
Who owns CMMC at a cleared company?
Not the FSO alone. The NISPOM assigns named responsibilities to the Senior Management Official, FSO, Insider Threat Program Senior Official, and ISSM for the classified-security program. CMMC requires an Affirming Official under 32 CFR § 170.22: a senior internal representative responsible for ensuring compliance and authorized to affirm continuing compliance in SPRS.
The same person may hold more than one role. The scopes do not merge merely because the names on the org chart do.
This is the seat most cleared companies leave empty, for an understandable reason: the security organization assumes it owns anything with “security” in the name, and the IT organization assumes anything the security organization touches is handled.
| Role | Created by | Accountable for | Primary record or package |
|---|---|---|---|
| Senior Management Official (SMO) | § 117.7(b)(2) | The facility's system of security controls; annual written certification of the self-inspection to the CSA | NISS and CSA-facing records, as applicable |
| FSO | § 117.7(b)(3) | Supervising and directing security measures implementing the NISPOM | NISS / DISS and facility records |
| ITPSO | § 117.7(b)(4) | Establishing and executing the insider threat program | Program records |
| ISSM | § 117.7(b)(5), § 117.18(c)(2) | The classified information-system security program and required CSA-facing certification that the SSP is implemented | CSA authorization package |
| Affirming Official | 32 CFR §§ 170.4 and 170.22 | Ensuring CMMC Program compliance and affirming continuing compliance for all systems in the relevant CMMC Assessment Scope | SPRS |
Three practical consequences:
One. Your ISSM's job title contains the words “information system security manager,” and their regulatory scope under § 117.18 is the classified-system program. Assigning them CMMC by default can be wrong on scope and capacity grounds even when the same individual is capable of doing the work.
Two. The Affirming Official makes a representation to the government about the unclassified assessment scope. DFARS 252.204-7021 requires maintenance of the applicable CMMC status for the contract's duration and current annual affirmation. A knowingly false representation can turn a compliance gap into False Claims Act exposure — a risk the Department of Justice has pursued in defense-contractor cybersecurity cases.
Three. Get the seat filled and get the person briefed. An Affirming Official who doesn't understand what they're affirming is the worst outcome available.
DCSA and DCMA DIBCAC are not the same agency
Worth stating flatly because we see them conflated constantly, including on otherwise careful sites:
- DCSA — Defense Counterintelligence and Security Agency. For most DoD-cleared DIB companies, it performs CSA functions for facility clearances, FOCI, NISP security reviews, and classified-system authorization.
- DCMA DIBCAC — the Defense Industrial Base Cybersecurity Assessment Center within the Defense Contract Management Agency. It performs government-led NIST SP 800-171 DoD Assessments and Level 3 CMMC certification assessments.
Different agencies. Different missions. Different people. If a DCSA representative raises CUI during a NISP review, refer back to the three-condition test.
Keep readiness and assessment roles separate
A readiness provider can help you scope, remediate, implement, and assemble evidence. A CMMC Third-Party Assessment Organization assesses a Level 2 certification scope when that assessment type is contractually relevant.
Before hiring a C3PAO:
- Verify the organization and current status in the Cyber AB Marketplace.
- Do not accept a guaranteed-certification promise. The Cyber AB Code of Professional Conduct prohibits C3PAOs from guaranteeing or promising an assessment or certification outcome.
- Do not use a C3PAO for the certification assessment if that C3PAO or an assessment-team member served as a consultant to prepare your organization for any CMMC assessment within the prior three years. The rule covers preparatory, advisory, and consulting activity; it also treats implementation templates or tools that guide remediation as advisory activity.
The rule is not “the C3PAO may never interact with you before the assessment.” The Code permits a true non-certification assessment under strict non-consultative conditions, including no remediation recommendations or advice. The clean decision rule is simpler: separate preparation that changes your implementation from the organization that certifies it.
That independence rule is not a reason to avoid readiness help. It is a reason to decide who prepares and who assesses before money changes hands.
▸ Your next step
Ownership sorted, the question becomes what you buy and in what order. The answer depends on which problem is actually unresolved — and for cleared contractors it's usually scoping, not tooling.
See who to hire first → Then compare provider categories and review the CMMC Level 2 cost guide before you request quotes. No rankings, no endorsements on this page.
What do you flow down to a cleared subcontractor?
Two separate contractual paths, not one. The DD Form 254 and related security provisions govern a subcontractor's access to classified information. CMMC requirements follow the FCI or CUI the subcontractor will process in performance and the status identified in the subcontract instrument. 32 CFR § 170.23 and DFARS 252.204-7021 require CMMC flow-down at the applicable level and assessment type; the DD Form 254 does not carry that status by itself.
A damaging admission for primes: calling a subcontractor “cleared” tells you nothing about what CMMC requirement to flow down. We've seen supplier programs treat an FCL as a proxy for cyber maturity. It isn't one, and the rule doesn't support it.
| Your subcontractor receives | Security instrument | The CMMC question you still have to answer |
|---|---|---|
| Classified information only | DD Form 254 and classified-security provisions | Does the subcontractor also process FCI or CUI on its own unclassified contractor systems in performance? |
| FCI only | Subcontract safeguarding and CMMC terms | Is Level 1 (Self) required for the relevant system and CAGE codes? |
| CUI | CUI, DFARS, and CMMC flow-down terms | Is Level 2 (Self) sufficient, or does the prime contract require a higher assessment type for this subcontract? |
| Classified information and CUI | Both paths, separately | Which systems handle each information type, and which instrument governs each lane? |
One nuance matters in the current suspension: the July 13, 2026 implementation memorandum directs government acquisition personnel. It does not automatically rewrite an existing prime-to-subcontractor purchase order or supplier agreement. If a private subcontract still requires a Level 2 certification assessment, relief on the government-procurement side does not automatically flow downhill. Read the subcontract, request written clarification, and document any amendment.
→ More detail: CMMC for subcontractors
Could FOCI screening reach unclassified DoD contracts over $5 million?
It isn't cyber — it's foreign ownership. A proposed DFARS rule published May 7, 2026, DFARS Case 2021-D011, would extend DCSA foreign ownership, control, or influence screening through NISS to certain unclassified DoD awards above $5 million. It would make an eligible NISS status a precondition for award, certain modifications, and option exercises, subject to the proposal's scope and exceptions.
Everyone expects the two worlds to merge through cybersecurity. Under this proposal, they would converge through the FOCI channel instead — and cleared contractors already know the system because they already live in NISS.
| Date | What happened | Primary source |
|---|---|---|
| May 1, 2025 | The updated SF 328 was approved | DCSA announcement |
| May 12, 2025 | The updated SF 328 was deployed in NISS; DCSA said companies did not need to resubmit solely because the form changed | DCSA announcement |
| May 7, 2026 | DFARS Case 2021-D011 proposed a FOCI screening regime for covered unclassified DoD acquisitions above $5 million, using NISS, SF 328, and beneficial-ownership information | 91 FR 24783 |
| July 6, 2026 | The proposal's public-comment period closed | Federal Register notice |
DoD's own regulatory analysis estimated 37,740 potentially affected offerors and subcontractors, including 21,511 small entities — 57% of the total. The proposal also includes an eligible NISS status before covered award actions, submission through NISS, flow-down at any tier when applicable, and a 90-calendar-day period for directed mitigation in the circumstances it describes.
What this means for you specifically
This is a proposed rule. It is not law. It may change materially, be delayed, or never be finalized. Treat it as planning information, not a current contract requirement.
But if it finalizes in something close to its proposed form, cleared contractors have a real operational head start. You already know NISS, SF 328, changed-condition reporting, and the basic logic of FOCI review. Tens of thousands of offerors and subcontractors would be learning that process for the first time.
Two practical moves worth making now, both cheap:
- Confirm your NISS access, entity data, and current SF 328 process are in order for the requirements you already have. DCSA expressly said the 2025 form update did not require a resubmission solely because the form changed.
- Add a proposal-monitoring check to your pre-bid process for unclassified DoD opportunities above $5 million: Has DFARS Case 2021-D011 been finalized, and does the live solicitation contain the resulting provision or clause?
- Add Question 4 from the letter above to your standard pre-bid checklist on any effort above $5 million.
What is required right now, in August 2026?
Phase I remains in effect and Phase II is suspended. The codified rollout established Phase I for November 10, 2025 through November 9, 2026. On July 13, 2026, the Department suspended Phase II before its scheduled November 10 start and paused the remaining implementation milestones. During the suspension, new procurement requirements may designate only Level 1 (Self) or Level 2 (Self); program managers and requiring activities may not designate Level 2 (C3PAO) or Level 3 (DIBCAC). DFARS 252.204-7012 safeguarding obligations are unchanged.
Nothing in the suspension is specific to cleared contractors, because clearance status was never a CMMC variable. What changed applies to everyone.
| CMMC status | Information protected | Requirement set | May it be newly designated during the suspension? |
|---|---|---|---|
| Level 1 (Self) | FCI | 15 basic safeguarding requirements | Yes |
| Level 2 (Self) | CUI | 110 NIST SP 800-171 Revision 2 requirements across 14 families | Yes |
| Level 2 (C3PAO) | CUI | The same 110 requirements, assessed by a CMMC Third-Party Assessment Organization | No for new procurement requirements during the suspension |
| Level 3 (DIBCAC) | CUI associated with a critical program or high-value asset | Final Level 2 (C3PAO) plus 24 selected NIST SP 800-172 Feb2021 requirements | No for new procurement requirements during the suspension |
What remains in force: Phase I self-assessment requirements; DFARS 252.204-7012 safeguarding and 72-hour cyber-incident reporting; contract-specific NIST SP 800-171 DoD Assessment requirements; CMMC annual affirmation where a CMMC status applies; flow-down duties in the current instrument; and every NISPOM obligation on the classified side.
If your paperwork still says Level 2 (C3PAO) or Level 3: do not assume the requirement evaporated, and do not assume it still operates exactly as originally issued. Check for a solicitation amendment or contract modification, ask the contracting officer or prime in writing, preserve the instrument history, and make the assessment decision from the current document — not from an old implementation slide.
CMMC still controls to Revision 2, even though NIST moved on
CMMC Level 2 assessments run against NIST SP 800-171 Revision 2 because 32 CFR § 170.14 incorporates that version. NIST published Revision 3 as the successor to Revision 2, but that does not silently rewrite the CMMC rule.
The same version problem now exists at Level 3. NIST withdrew the February 2021 edition of SP 800-172 on May 13, 2026 and superseded it with SP 800-172 Revision 3. CMMC still incorporates SP 800-172 Feb2021 and selects 24 requirements from that edition.
Contractors may implement newer practices where they make sense. But until DoD changes the incorporated versions through a controlling amendment or other valid acquisition action, the CMMC assessment baselines remain SP 800-171 Revision 2 and SP 800-172 Feb2021. Do not let a vendor blur NIST's current publication catalog with the versions currently incorporated into CMMC.
→ Full detail: What the Phase II suspension changed · NIST SP 800-171 Rev. 2 vs. Rev. 3 · Compare CMMC levels
What we actually verified
We publish this box on every decision page. It's more useful than a badge.
Read directly and verified August 18, 2026:
- 32 CFR § 170.3 — applicability, including “unclassified” in § 170.3(c) and the contractor-operated federal-system exclusion in § 170.3(b)
- 32 CFR § 170.4 — CMMC definitions, five Specialized Asset types, CMMC status, OSA, C3PAO, Affirming Official, and Enduring Exception
- 32 CFR § 170.14 — 15 Level 1, 110 Level 2, and 24 selected Level 3 requirements; SP 800-171 Revision 2 and SP 800-172 Feb2021
- 32 CFR § 170.19 — Level 1 and Level 2 scoping, including Table 3 asset categories and external-service-provider treatment
- 32 CFR §§ 170.22–170.23 — affirmation and subcontractor flow-down
- 32 CFR Part 117 — FCL and CDC definitions, security officials, CUI assessment conditions, reporting, entity eligibility, and classified-system security
- 32 CFR Part 236 — DIB Cybersecurity Program definition and eligibility
- DFARS 252.204-7012, 252.204-7019, 252.204-7020, 252.204-7021, and 252.204-7025
- NIST SP 800-171 Revision 2 and NIST SP 800-172 Feb2021 publication and successor status
- DD Form 254 Instructions, April 2018, updated 20250711 — all twelve pages read in full
- DoD CMMC Level 2 Scoping Guide — classified-asset exclusion and Level 2 categorization guidance, through the official DoD guidance register
- The July 13, 2026 CMMC suspension release and implementation materials
- Cyber AB CMMC Assessment Process v2.0 and Code of Professional Conduct v2.0, including Marketplace verification, outcome-promise restrictions, non-certification assessment boundaries, and conflict separation
- DCSA's updated SF 328 announcement
- 91 FR 24783 — DFARS Case 2021-D011 proposed rule, including the official affected-entity estimate
What we did not verify, and are not claiming:
- Private DCSA review trends or how often Industrial Security Representatives raise CUI in practice
- Whether a specific cyber incident affected a specific facility clearance
- Prime contractor internal supplier policies beyond the terms visible in an actual subcontract
- Any provider's claims, pricing, or outcomes — no named provider is recommended on this page
- Whether DFARS Case 2021-D011 will be finalized, when, or in what form
- That any physical room is automatically in or out of scope without analyzing the assets and information inside it
Correction on our own work: the three-condition CUI assessment test at § 117.7(h)(1)(iii) was surfaced during a second review of this article, not in our first research pass. We verified it against the eCFR before publishing. We'd rather tell you how the sausage is made than pretend we found everything first.
This guide is editorial research and has not been formally reviewed by a CMMC Subject Matter Advisor. No individual reviewer attribution is claimed.
Frequently asked questions
Does CMMC apply to classified information? No. The CMMC Program Rule applies to FCI and CUI on unclassified contractor information systems (32 CFR § 170.3(c)). Classified information and classified assets are governed through the NISP and the applicable CSA. The same contractor's unclassified FCI or CUI systems can still be in CMMC scope.
Does a facility clearance satisfy CMMC? No. An FCL is an administrative determination that an entity is eligible for access to classified information (32 CFR § 117.3). It produces no CMMC status, no CMMC UID, and no NIST SP 800-171 DoD Assessment score. There is no status reciprocity in either direction.
Does every cleared company need CMMC Level 2? No. The level follows the contract requirement and the information handled. A cleared company whose unclassified systems process FCI but not CUI may face a Level 1 requirement. A cleared company with no FCI or CUI on its own contractor systems may face none.
Does a non-possessing facility clearance require Level 2? No. A favorable entity eligibility determination does not itself convey authority to store classified information, and it does not establish any CMMC level. Non-possessing status is a statement about classified storage, not about your unclassified environment.
Is my SCIF in CMMC scope? A physical SCIF is not the assessment unit. Classified assets inside it are outside the CMMC Assessment Scope. Any unclassified assets inside the same space are evaluated by the information they handle, the services they provide, and their connectivity.
What if CUI is stored on a classified system? The classified asset stays outside CMMC scope — DoD's Level 2 Scoping Guide addresses this directly. But authorized unclassified copies, derivatives, emails, printouts, or downstream handling are separate scoping questions. If the copy remains classified, placing it on an unclassified system is a spillage incident.
Is SIPRNet in CMMC scope? A SIPRNet terminal or connection processing classified information is a classified asset governed through the applicable classified-system authorization and falls outside the CMMC Assessment Scope.
Does NISPOM cover CUI? The NISPOM contains several CUI-related provisions, but § 117.18(f) sends the safeguarding of unclassified contractor systems that process, store, or transmit CUI back to the contract. It is not a CMMC implementation manual.
Can DCSA assess my CUI during a NISP security review? Only when DCSA is the applicable CSA and all three conditions in 32 CFR § 117.7(h)(1)(iii) are met: you're in the NISP because you need classified access; a classified contract under that CSA's cognizance includes CUI provisions; and the CSA has given you specific guidance on the criteria and methodology it will use. Such an assessment is not a CMMC assessment and produces no CMMC status.
Does DCSA assess CMMC? No. DCSA performs NISP and other security functions. Government-led CMMC and NIST SP 800-171 assessments are conducted by DCMA DIBCAC. Level 2 certification assessments are conducted by a CMMC Third-Party Assessment Organization (C3PAO).
Does my DD Form 254 tell me my CMMC level? No. The DD Form 254 is a classified-contract instrument. Its instructions state that the NISPOM provides no CUI protection guidance and route procedures to the Government Contracting Activity in Item 13. The instructions never reference CMMC, NIST SP 800-171, DFARS 252.204-7012, or SPRS. Your required status comes from the current contract instrument.
Do I get a DD Form 254 for an unclassified CUI contract? No. The DD Form 254 is issued for contracts requiring access to classified information. Its instructions specifically direct that Item 11.l not be selected for a contract that only requires receipt, storage, or generation of CUI.
Can my FSO be the Affirming Official? Nothing in the rule prohibits the same person from holding both roles, but the Affirming Official must be a senior internal representative responsible for ensuring CMMC compliance and authorized to affirm continuing compliance for the relevant assessment scope in SPRS.
Where do I report a cyber incident if I'm a cleared contractor? It depends which system. Under 32 CFR § 117.8(f)(1), an incident on a classified covered information system is reported immediately to the designated DoD Cognizant Security Office. Under § 117.8(f)(2), an incident on an unclassified system is reported in accordance with contract requirements — for a contract carrying DFARS 252.204-7012, that means DIBNet within 72 hours. Write both paths into your incident response plan.
Does a cyber incident on our unclassified network jeopardize our facility clearance? We could not find an authority establishing that as an automatic consequence. NISPOM reporting for changed conditions and loss of classified information is separate from unclassified incident reporting, which § 117.8(f)(2) routes through the contract. A serious incident may reveal separate facts relevant elsewhere, but the incident itself is not an automatic FCL-revocation rule.
Can we reuse our NISPOM evidence for CMMC? Individual artifacts, often. Your status, never. Reuse works only where the artifact covers the unclassified in-scope environment and maps to a specific CMMC requirement and assessment objective. Budget for the mapping work; don't budget for the credit.
Do cleared subcontractors need CMMC? They may. It depends on the FCI or CUI they process in performance and the requirement flowed down in the subcontract — not on whether they hold a facility clearance.
Did the July 2026 suspension exempt cleared contractors? No, and it never singled them out. The suspension paused Phase II and later milestones for everyone. Level 1 (Self) and Level 2 (Self) remain designatable in new procurement requirements; Level 2 (C3PAO) and Level 3 (DIBCAC) may not be newly designated during the suspension. DFARS 252.204-7012 is unchanged.
Is the SF 328 part of CMMC? No current rule makes SF 328 a CMMC assessment artifact. Separately, a proposed DFARS rule would extend FOCI disclosure through NISS to certain unclassified DoD contracts above $5 million. That is a proposed rule, not a current requirement.
Is GCC High required for cleared contractors? No blanket rule requires any specific cloud tenant because a company is cleared. The right environment depends on your information types, contract requirements, architecture, and any separate obligations such as export control.
Know which lane you're in before you hire anyone
You came here holding a clearance and a question nobody in your building could answer cleanly. The answer, in one line: your clearance and CMMC are two rulebooks that were never designed to meet, and the boundary between them runs straight through your server room.
Draw that boundary and the rest of this is a defined project. Skip it and you'll buy the wrong thing.
Need help deciding what type of CMMC provider you need? Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.
Find My CMMC Path →
Already know the category you need? Request quotes from source-checked provider options →
⚠️ Do not submit CUI, classified information, drawings, export-controlled technical data, contract numbers, program names, credentials, system diagrams, or vulnerability details.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. See our editorial and advertising policy.
Not legal advice. This page is educational research, not legal, contractual, cybersecurity, or compliance advice. The current contract instrument and your actual FCI/CUI handling govern — not a checklist, and not this article. Confirm scope and applicability with your contracting officer or prime, a qualified CMMC practitioner or provider that is not serving as your assessor, and a qualified federal-contracts attorney where appropriate.
Not affiliated. The Defense Compliance Report is not affiliated with the Cyber AB, the Department of War or Department of Defense, DCSA, DCMA DIBCAC, NIST, or any U.S. government agency.
Note on naming: 2026 Department issuances referenced on this page use “Department of War.” Earlier rules and clauses use “Department of Defense.” We cite each source as published.