The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Independent research · precise status responses

How to Respond to the CMMC RFI

Last updated:

Last verified: against primary regulatory, acquisition, and program sources.

Status check, August 15, 2026: If you came here for the Department of War's CMMC Reform Task Force RFI, that response window closed at 12:00 p.m. Eastern on Friday, August 14, 2026. It is not open. The rest of this page covers the CMMC information requests that are still landing on contractors' desks — and exactly what you're allowed to say in them.

By The Defense Compliance Report Editorial Team Published: August 15, 2026 · Last reviewed: August 2026 · Last verified: August 15, 2026

Editorial research — not formally reviewed by a CMMC Subject Matter Advisor. This article is educational and is not legal, contractual, or compliance advice. Confirm scope and applicability with a CMMC Registered Practitioner (RP/RPO) or a qualified federal-contracts attorney before acting.


Here's how to respond to the CMMC RFI in one sentence: answer the question actually asked with your exact, current CMMC Status — not with whether you're "compliant."

There are seven defined CMMC Statuses — Final Level 1 (Self), Conditional and Final Level 2 (Self), Conditional and Final Level 2 (C3PAO), and Conditional and Final Level 3 (DIBCAC). Those names come straight from DFARS 204.7501. If the request asks for your status, give the exact status name, status date, CMMC unique identifier, and affirmation date. If you hold none of the seven, say so plainly. Give a separate NIST SP 800-171 DoD Assessment score only if the requester asks for it and you have a current score posted in SPRS.

That's the answer. Now the part almost nobody gets right.

Four completely different documents get called "the CMMC RFI," and the correct response is different for each one. One is an award solicitation carrying DFARS 252.204-7025. One is a government sources-sought notice doing market research. One is a prime contractor questionnaire managing flow-down risk. And one was a policy comment window that shut yesterday.

Get the sender wrong and you'll write a response that answers a question nobody asked. Get the wording wrong and you'll write a sentence that a Justice Department attorney can read out loud in four years. In June 2026, a contractor agreed to pay $507,144 to resolve False Claims Act liability after a self-assessed score of 110 became central evidence and a later government assessment returned −170. The allegations also included security requirements the contractor had not implemented.

Let's make sure yours is the right answer.

Go straight to the response you need: government solicitation · sources-sought notice · prime questionnaire · four copy-ready templates


How to respond to the CMMC RFI you actually received

Answer capsule: Four different documents are routinely called "the CMMC RFI." A solicitation carrying DFARS 252.204-7025 uses your CMMC Status to determine award eligibility. A sources-sought notice asks about present capability for market research and does not itself award a contract. A prime contractor questionnaire manages subcontract and supplier risk. The Department of War's CMMC Reform Task Force RFI was a policy comment window that closed at noon Eastern on August 14, 2026. Each requires a different response.

Start here. Two minutes of sorting saves you from writing the wrong document.

Document — What it looks like — What the sender is deciding — What your answer must do
DocumentWhat it looks likeWhat the sender is decidingWhat your answer must do
1. Government solicitation carrying DFARS 252.204-7025A solicitation, task-order request, or delivery-order request that states one of four CMMC level and assessment-type designationsWhether you are eligible for awardSupply the exact current Status and CMMC UID for every in-scope contractor information system; make the written answer match SPRS
2. Government sources-sought notice or market-research RFIA SAM.gov sources-sought synopsis, capability inquiry, or RFI that is not an award solicitationWhether capable sources exist and how an acquisition may be structuredState current posture accurately, distinguish current facts from targets, and answer the capability question; do not pretend the notice itself creates award eligibility
3. Prime contractor questionnaireAn email, portal task, supplier-registration form, the CCRA, or a custom supplier questionnaireWhether and on what terms to place or keep you in the supply chainGive the exact current record, identify the applicable scope, and ask for the underlying clause, assessment type, and date when the request is vague
4. Department of War CMMC Reform Task Force RFISAM.gov Notice ID 89ef9bfb0834473791e991c712698d94, titled "Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base"Federal policy inputNothing now; the response window is closed unless an official amendment or replacement notice creates a new one

The first two both come from government, but they are not interchangeable. A sources-sought notice is market research. A solicitation carrying DFARS 252.204-7025 is an award instrument with a mechanical SPRS check. That distinction changes the answer.

If you came for the Department of War's CMMC Reform RFI

We'll be straight with you, because you'd find out in about ninety seconds anyway: you missed it, and we can't get you in.

The Department of War posted the RFI on July 13, 2026, the same day it announced the immediate suspension of CMMC Phase II. It asked the defense industrial base seven questions about what CMMC and NIST SP 800-171 Revision 2 compliance actually costs, which security requirements deliver real risk reduction, which requirements impose burden out of proportion to benefit, what commercial cybersecurity capabilities the Department could recognize, how Phase I self-assessment could be streamlined, what reforms would lower barriers for small and non-traditional companies, and how to improve real operational resilience.

The official SAM.gov notice directed email submission rather than a Regulations.gov docket. The response body was capped at ten pages, with an optional one-page cover letter. The window closed at 12:00 p.m. Eastern on Friday, August 14, 2026, and the notice stated that late submissions would not be considered.

We are not going to invent a workaround. There isn't one we can source. An old mailbox that still accepts mail is not a reopened response window, and a consultant's LinkedIn post is not an amendment.

Here's the part that actually matters, and it's better news than it sounds. The Task Force was directed to deliver its report to the Department CIO within 60 days of the July 13 suspension — which points to roughly mid-September 2026. Delivery to the CIO is not a promise of public release on that date, and the report itself will not rewrite your contract.

Any recommendation has to travel through an instrument before it reaches you: a memorandum, a class deviation, a DFARS change, a rulemaking action, a solicitation amendment, or a contract or subcontract modification. A proposed rule would carry a public comment process. A memorandum or class deviation may not. No new formal comment window was open as of August 15, 2026.

Preserve the cost figures, labor hours, and control-outcome evidence you assembled for this one. It'll be worth more the second time, because you'll already have it dated and organized while everyone else starts from zero.

Meanwhile, nothing you did or didn't file changed a single obligation already in your solicitation, contract, or subcontract.

What Phase 1 means on August 15, 2026

The dates and the suspension are both real. They describe different layers.

Layer — What it says — What that means today
LayerWhat it saysWhat that means today
Codified phase scheduleThe CMMC acquisition final rule took effect November 10, 2025. Phase 1 runs from November 10, 2025 through November 9, 2026; the rule's original schedule would have started Phase 2 on November 10, 2026.Phase 1 is the controlling rollout phase on August 15, 2026.
July 13, 2026 operational directionThe Department announced the immediate suspension of Phase II and stated that all Phase I self-assessment requirements remain in place.Do not treat the suspension as cancellation of CMMC or relief from Phase I.
New procurement designations during the reviewThe implementing direction limits new CMMC designations to Level 1 (Self) and Level 2 (Self) while the review is underway.A new post-suspension procurement action designating Level 2 (C3PAO) or Level 3 (DIBCAC) deserves a written clarification and review of the actual instrument.
Existing cybersecurity obligationsDFARS 252.204-7012, applicable NIST SP 800-171 duties, incident-reporting duties, existing contract terms, SPRS records, and current Phase I requirements were not erased.Read the instrument you actually hold. A headline does not amend it.

The current Department CMMC page states the operational position. The codified structure remains in 32 CFR 170.3(e), and the acquisition final rule's effective date is in the September 10, 2025 Federal Register notice.

What would actually reopen a closed federal RFI

Contractors ask this constantly, usually phrased as "can I just send it anyway." Here's the honest sorting table.

Signal you might see — Does it reopen the response window?
Signal you might seeDoes it reopen the response window?
A consultant, association, or LinkedIn post saying "there's still time"No. Third parties do not control federal notice deadlines.
The government mailbox still accepts mailNo. A mailbox that does not bounce is not an open window.
Another company says it submitted lateNo. And it is not evidence the submission was considered.
An official amendment or replacement notice on SAM.govPossibly. Follow the new notice's instructions and deadline — not the old ones.
An official Department CIO announcement pointing to a new filing channelPossibly. Verify its terms and deadline at the source.
A proposed rule published in the Federal RegisterA different, formal channel. Follow the docket, scope, and deadline in that rulemaking notice.

Only an official government instrument changes the answer. Check the Department CMMC page, the SAM.gov notice, the Federal Register, and Acquisition.gov — not a vendor's countdown.


What can you truthfully say if you're not CMMC certified?

Answer capsule: You can say you do not hold a CMMC certification or CMMC Status. That answer is not automatically disqualifying in market research or a supplier survey. It is disqualifying for an award when the solicitation requires a current CMMC Status you do not hold. Under DFARS 204.7501 there are exactly seven CMMC Statuses, and three of them are self-assessment statuses that produce no Certificate of CMMC Status.

This is the fear underneath the search, so let's dismantle it directly.

A vendor-commissioned 2025 Defense Industrial Base survey reported a median SPRS score of 60 out of 110 and 17% negative scores. It also reported that 42% had submitted SPRS scores, meaning 58% had not. That is a CyberSheath survey figure, not a government statistic, but it is a useful reality check: the market contains a lot of contractors with unfinished records.

Saying "we're not certified" costs you a bid when the instrument requires a status you don't have. Saying "we're certified" when you aren't costs you something considerably worse.

The seven CMMC Statuses — and exactly what each one lets you write

This is our CMMC Answer Card. We built it from the status definitions in DFARS 204.7501, the award rule in DFARS 204.7502, and the assessment paths in 32 CFR Part 170.

DCR original framework · Version 1.1 · Last verified August 15, 2026

Exact status name — How you earn it — Status-age limit — Affirmation — Award use for the same assessment scope — What you may truthfully write
Exact status nameHow you earn itStatus-age limitAffirmationAward use for the same assessment scopeWhat you may truthfully write
Final Level 1 (Self)Annual self-assessment with all 15 Level 1 safeguarding requirements MET; no POA&M permittedNot older than 1 yearMust be current; Level 1 is reassessed and affirmed annuallySatisfies a Level 1 (Self) requirement"We hold Final Level 1 (Self), CMMC Status date [date], CMMC UID [UID], with an affirmation current as of [date]."
Conditional Level 2 (Self)Level 2 self-assessment score of at least 88 out of 110, with a POA&M that meets § 170.21 restrictionsNot older than 180 daysRequiredSatisfies Level 2 (Self) or lower while current"We hold Conditional Level 2 (Self), CMMC Status date [date], CMMC UID [UID]. POA&M closeout is due no later than [date]. Affirmation date: [date]."
Final Level 2 (Self)Level 2 self-assessment with all 110 NIST SP 800-171 Rev. 2 requirements MET, either initially or after valid POA&M closeoutNot older than 3 yearsAnnualSatisfies Level 2 (Self) or lower while current"We hold Final Level 2 (Self), CMMC Status date [date], CMMC UID [UID], affirmation current as of [date]."
Conditional Level 2 (C3PAO)Level 2 certification assessment by an authorized or accredited C3PAO, score of at least 88 out of 110, and an eligible POA&MNot older than 180 daysRequiredSatisfies Level 2 (C3PAO) or lower while current"We hold Conditional Level 2 (C3PAO), CMMC Status date [date], CMMC UID [UID], assessed by [C3PAO]. POA&M closeout is due no later than [date]."
Final Level 2 (C3PAO)Level 2 certification assessment with all 110 requirements MET, initially or after valid POA&M closeoutNot older than 3 yearsAnnualSatisfies Level 2 (C3PAO) or lower while current"We hold Final Level 2 (C3PAO), CMMC Status date [date], CMMC UID [UID], assessed by [C3PAO], affirmation current as of [date]."
Conditional Level 3 (DIBCAC)Final Level 2 (C3PAO) prerequisite, followed by a DCMA DIBCAC Level 3 assessment with at least 80% of the 24 selected NIST SP 800-172 requirements MET and an eligible POA&MNot older than 180 daysRequired for Level 3; the underlying Level 2 affirmation also remains relevantSatisfies Level 3 or lower while current"We hold Conditional Level 3 (DIBCAC), CMMC Status date [date], CMMC UID [UID]. POA&M closeout is due no later than [date]."
Final Level 3 (DIBCAC)Final Level 2 (C3PAO) prerequisite plus all 24 selected NIST SP 800-172 requirements MET in a DCMA DIBCAC assessmentNot older than 3 yearsAnnual for Level 3 and the underlying Level 2 (C3PAO) statusSatisfies Level 3 or lower while current"We hold Final Level 3 (DIBCAC), CMMC Status date [date], CMMC UID [UID], affirmation current as of [date]."
No CMMC Status yetNot eligible when the solicitation requires a CMMC Status"We do not currently hold a CMMC Status under 32 CFR Part 170. [If requested and applicable: Our current NIST SP 800-171 DoD Assessment score is [X], dated [date], posted in SPRS.] Our [scheduled/target] assessment date is [date]."

Definitions, first use: C3PAO — CMMC Third-Party Assessment Organization, the exact expansion used in 32 CFR Part 170. DIBCAC — the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center. SPRS — the Supplier Performance Risk System. POA&M — Plan of Action and Milestones. CMMC UID — the 10-character alphanumeric identifier assigned to each CMMC assessment and reflected in SPRS for each contractor information system.

The age limit is not the whole definition of "current." DFARS 204.7501 also requires no change in compliance since the CMMC Status date and the corresponding current affirmation. A status can be young enough on the calendar and still not be current.

Three things fall out of that table. All three change what you write.

One: "Conditional" is a winning answer at Level 2 and Level 3, and a losing one at Level 1.

DFARS 204.7502(b)(2) permits award with a Conditional Level 2 or Level 3 status for not more than 180 days from the status date. Level 1 requires Final. Conditional Level 1 does not exist.

Read that twice if you're a Level 1 shop. A Level 2 contractor with a valid, rule-compliant POA&M can be award-eligible. A Level 1 contractor with anything unfinished cannot point to a Conditional status, because there isn't one.

Two: you have two clocks, and the shorter one expires first.

A Final Level 2 or Final Level 3 CMMC Status can remain within its three-year age limit while its affirmation is already stale. A two-year-old Final Level 2 status paired with an affirmation that is fourteen months old is not "current" under the definition. When you write your response, give both dates.

Three: CMMC Status, a CMMC assessment score, and a NIST SP 800-171 DoD Assessment score are not the same record.

Record — What it tells the reader — Typical result
RecordWhat it tells the readerTypical result
CMMC StatusWhether the minimum score and other conditions for a named assessment path were metOne of the seven exact statuses
CMMC Level 1 resultWhether all 15 Level 1 requirements were METFinal Level 1 (Self) or no Level 1 status
CMMC Level 2 assessment scoreThe scored result under the CMMC Level 2 methodologyUp to 110; 88 is the minimum score component for a Conditional path, subject to POA&M restrictions
CMMC Level 3 assessment scoreHow many of the 24 selected NIST SP 800-172 requirements were MET, after the Final Level 2 (C3PAO) prerequisiteUp to 24; at least 80% is required for a Conditional path, subject to POA&M restrictions
NIST SP 800-171 DoD Assessment scoreA separate Basic, Medium, or High assessment record under the NIST SP 800-171 DoD Assessment methodology−203 to 110, separately posted in SPRS

The practical rule is simple: name the record before you give the number. Never write "our CMMC score is 104" when what you mean is a legacy or codified NIST SP 800-171 DoD Basic Assessment score. Never let a numeric score stand in for the exact CMMC Status required for award.

Does CMMC use NIST SP 800-171 Rev. 2 or Rev. 3?

For CMMC today, Revision 2 controls.

32 CFR 170.2 incorporates NIST SP 800-171 Revision 2, February 2020 with updates through January 28, 2021. CMMC Level 2 uses its 110 requirements across 14 families. CMMC Level 3 adds 24 selected requirements from NIST SP 800-172, February 2021.

NIST published SP 800-171 Revision 3 in May 2024 and later publications superseded earlier NIST versions in NIST's own publication lifecycle. That does not silently amend 32 CFR Part 170 or your contract. Until DoD changes the controlling rule or contractual instrument, do not build a CMMC answer as though Rev. 3 were the CMMC control set.

Who puts each CMMC record into SPRS?

Assessment path — How the result reaches the government system — Who handles the affirmation
Assessment pathHow the result reaches the government systemWho handles the affirmation
Level 1 (Self)The organization submits the self-assessment result in SPRSThe affirming official submits the affirmation in SPRS at assessment and annually
Level 2 (Self)The organization submits the Level 2 self-assessment result and score in SPRSThe affirming official submits the affirmation in SPRS at assessment and annually
Level 2 (C3PAO)The C3PAO uploads the certification-assessment result to the CMMC instance of eMASS, which transmits it to SPRSThe organization's affirming official submits the affirmation in SPRS at assessment and annually
Level 3 (DIBCAC)DCMA DIBCAC uploads the Level 3 result to the CMMC instance of eMASS, which transmits it to SPRSThe affirming official submits the Level 3 affirmation and maintains the separate underlying Level 2 (C3PAO) affirmation
NIST SP 800-171 DoD AssessmentThe posting path depends on the clause version in the instrument. Codified 252.204-7020 includes Basic, Medium, and High records; deviation clause 252.240-7997 removes the old Basic mechanics and addresses government Medium and High assessments.Not a substitute for a CMMC affirmation

That last row is why an old instruction saying "upload your Basic score" can be right for one instrument and wrong for another. Read the clause version before you answer.

You just found out which status you actually hold. The next question is which one your contract requires.

Those are different questions, and the second one drives every dollar you're about to spend. Start with our CMMC Levels guide and CMMC Level 2 Cost guide, or tell the Find My CMMC Path tool your required level, whether you handle FCI or CUI, your assessment type, your cloud environment, and your timeline.

Map my required CMMC level

Free. Two minutes. No CUI required — do not submit CUI, drawings, or sensitive contract details.


What the CMMC RFI is actually asking — and how to translate it

Answer capsule: Most CMMC questions in RFIs and supplier questionnaires are written imprecisely. There is no NIST-issued "NIST SP 800-171 certification." A CMMC Level 2 or Level 3 assessment can produce a score, but award eligibility turns on the exact CMMC Status and assessment type required by the instrument. Translate the question into the defined record, then answer that record precisely.

This is the section we'd keep if we could only keep one. Below is our Question Translator — the sloppy questions we see most often, what's wrong with each one, and the answer that's both responsive and true.

DCR original framework · Version 1.1 · Last verified August 15, 2026

What the RFI or questionnaire asks — Why you cannot safely answer it as written — What to write instead
What the RFI or questionnaire asksWhy you cannot safely answer it as writtenWhat to write instead
"Are you CMMC certified?""Certified" does not tell you the level or assessment type. Three of the seven statuses are self-assessment statuses and do not produce a Certificate of CMMC Status.Name the exact Status, assessment type, status date, CMMC UID, and affirmation date. If you hold none, say so.
"Are you NIST 800-171 certified?"NIST publishes requirements; it does not certify organizations against SP 800-171."NIST does not issue an SP 800-171 certification. Our [Basic/Medium/High] NIST SP 800-171 DoD Assessment score is [X], dated [date], posted in SPRS."
"What is your CMMC score?"Level 2 and Level 3 CMMC assessments can produce scores, but the number alone does not identify the assessment type or award-eligible Status. The requester may instead mean the separate NIST SP 800-171 DoD Assessment score."Our CMMC Status is [exact status], dated [date]. The corresponding [Level 2/Level 3] CMMC assessment score is [X]. Separately, our NIST SP 800-171 DoD Assessment score is [X], dated [date], if requested."
"Are you CMMC compliant?""CMMC compliant" is not one of the seven defined statuses and does not identify the clause, level, scope, or assessment type."For [system/scope], the required designation is [level/type]. We hold [Status], status date [date], CMMC UID [UID], affirmation current as of [date]."
"Will you be certified by [date]?"This converts a status question into a forward-looking commitment. Assessment readiness, evidence review, scheduling, and closeout can move.State only what is actually scheduled or targeted. Use "scheduled" or "targeted," not "will be." Name the dependency.
"Provide a copy of your CMMC certificate."Level 2 C3PAO and Level 3 DIBCAC assessment paths can produce Certificates of CMMC Status. Self-assessment paths do not.State the path. For a self-assessment, provide the exact SPRS status information or an appropriate SPRS screenshot if the requester has a legitimate need. For a certification assessment, provide the certificate through an appropriate channel.
"Is your cloud FedRAMP certified?"Your organization is not made FedRAMP Authorized because it buys a cloud product. The cloud service offering may have a FedRAMP authorization, or may be evaluated for equivalence under applicable DoD policy.Name the CSP and service offering, its authorization status and package identifier where applicable, and the customer responsibility matrix.
"Do you flow CMMC down to your subcontractors?"A yes/no answer is a contract-administration representation. The applicable level depends on whether the subcontractor handles FCI or CUI and on the prime-contract designation.Describe your actual process under 32 CFR 170.23 and DFARS 252.204-7021: identify the applicable subcontract requirement, verify the subcontractor's evidence before award, require the current affirmation, and retain the record.

The pattern is the same every time. The question is imprecise. Your answer should not be. Precision is not pedantry here — it's the difference between a defensible record and a quotable one.


How to respond to a CMMC RFI inside a government solicitation

Answer capsule: When a DoD solicitation carries DFARS 252.204-7025, the contracting officer inserts one of exactly four CMMC level and assessment-type designations. The offeror must provide CMMC UIDs in the proposal for each contractor information system that will process, store, or transmit FCI or CUI during performance. The contracting officer checks SPRS against those identifiers before award. The written answer must match SPRS exactly.

This is the version with real teeth, because the person reading it has a prescribed government verification step.

The four values a contracting officer can insert

DFARS 252.204-7025, Notice of Cybersecurity Maturity Model Certification Level Requirements (NOV 2025), contains a blank the contracting officer fills in. The four permitted entries are:

  • CMMC Level 1 (Self)
  • CMMC Level 2 (Self)
  • CMMC Level 2 (C3PAO)
  • CMMC Level 3 (DIBCAC)

That's the whole universe for the provision. If the solicitation says only "CMMC compliant," "CMMC ready," or "Level 2 certified" without identifying the assessment type, the requirement is ambiguous. Ask the contracting officer in writing before the question deadline. We'd rather you spend twenty minutes on a clarification request than assume you need a C3PAO assessment you were never required to buy.

One dated note matters right now: since the July 13, 2026 Phase II suspension, Department program managers and contracting personnel have been directed to use only CMMC Level 1 (Self) or CMMC Level 2 (Self) for new procurement actions during the review. If a post-suspension action designates Level 2 (C3PAO) or Level 3 (DIBCAC), ask about the implementing direction in writing. Our full breakdown is in what the 2026 CMMC suspension actually changed.

Why your CMMC UIDs matter more than your prose

Paragraph (d) of DFARS 252.204-7025 requires the offeror to provide, in the proposal, the CMMC UIDs for each contractor information system that will process, store, or transmit FCI or CUI during performance.

Then DFARS 204.7503(b) tells the contracting officer to check SPRS and not award to an offeror that lacks a current CMMC Status at the required level, or higher, for each CMMC UID the offeror provides. New UIDs used during performance trigger another check.

So the evaluation is mechanical. UID by UID. Not narrative by narrative.

Which produces the most common self-inflicted wound on these responses: a contractor writes three beautiful paragraphs about its security program and omits the identifiers. There is nothing for the contracting officer to check. Lead with the identifiers. Put the prose underneath them, if you write prose at all.

And note the scope logic hiding in that sentence: the requirement attaches to each contractor information system that will process, store, or transmit FCI or CUI in performance. If you have one assessed enclave and one general network outside that assessment scope, the answer is not one company-wide adjective — it is a system-to-UID mapping. Our CMMC scoping guide walks that boundary question in full.

When your SPRS record and the solicitation disagree

Don't reconcile it in the narrative. Ask.

If the solicitation requires Level 2 (C3PAO) and your SPRS record shows Final Level 2 (Self), a paragraph explaining why you believe self-assessment should suffice is not a qualifying status. Submit a written question identifying the discrepancy and asking which designation is required for award. Keep the answer and any amendment.

Same rule if your record is right and the solicitation looks stale. Ask in writing. Get the amendment.

One trap: codified clauses and class-deviation clauses can coexist

Acquisition.gov still publishes the codified DFARS provision and clause at 252.204-7019 and 252.204-7020. Separately, the Revolutionary FAR Overhaul Part 240 class deviation, effective February 1, 2026, changed the package used in affected deviation-based acquisitions: 252.204-7019 is omitted, and 252.240-7997 replaces 252.204-7020 for the deviation.

The new 252.240-7997 text is not just a new number for the old clause. It addresses government-performed Medium and High NIST SP 800-171 assessments and removes the old Basic self-assessment mechanics. That does not eliminate a CMMC Level 2 (Self) assessment when a solicitation requires that CMMC path; the CMMC self-assessment comes from 32 CFR Part 170 and DFARS 252.204-7021/7025.

And it is not a universal declaration that 7019 and 7020 vanished from every contract. Existing contracts, older solicitations, and acquisitions not using the deviation may still carry the codified numbers. Read the instrument in front of you. Do not silently substitute a clause number because a secondary source told you the old one was "renamed."

DFARS 252.204-7012, 252.204-7021, and 252.204-7025 remain central to the analysis. Check current codified text at Acquisition.gov and the official DFARS Revolutionary FAR Overhaul class-deviation index, then answer the clause actually incorporated into the solicitation or contract.

How to answer a government sources-sought notice

A sources-sought notice is not the 252.204-7025 award check unless the notice expressly carries or previews that requirement.

Answer the market-research question:

  1. State the CMMC Status you hold today, with the status date and assessment type.
  2. State which systems or proposed performance environment that Status covers.
  3. Distinguish a scheduled assessment from a target.
  4. Identify the level and assessment type you could support by the anticipated award date, with the dependency stated.
  5. Ask whether the eventual solicitation is expected to carry Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), or Level 3 (DIBCAC).

Do not call yourself award-eligible before there is an award instrument. Do not send CUI, an SSP, a POA&M, network diagrams, or vulnerability details to prove capability.


How to respond when a prime contractor sends a CMMC questionnaire

Answer capsule: A prime contractor has to manage CMMC flow-down before subcontract award, but it does not perform the contracting officer's DFARS 204.7503 SPRS check on your behalf. Primes therefore collect evidence directly from suppliers: the exact Status, status date, assessment type, CMMC UID, current affirmation, a suitable SPRS screenshot, and a Certificate of CMMC Status where one exists. The written answer matters, but it does not have to be unsupported.

This is the version most contractors actually receive, and it's the version where people get hurt.

Why the prime has to ask you at all

Here's the mechanism nobody explains, and once you see it the whole dynamic makes sense.

The Government's award check is between the contracting officer and SPRS. The prime still has its own duty to place the correct requirement in the subcontract and ensure the subcontractor completes the required affirmation before subcontract award. The 2025 acquisition final rule expressly contemplated subcontractors taking screenshots of their CMMC Status and affirmation responses in SPRS to share as they deem necessary.

That means the prime's evidence path is usually direct: it asks you.

A defensible prime-side evidence package can include:

Evidence — What it proves — What it does not prove
EvidenceWhat it provesWhat it does not prove
Exact CMMC Status, status date, and assessment typeThe record you claim to holdThat the scope covers this subcontract
CMMC UID for the proposed in-scope systemWhich assessment record maps to the systemThat every system you might use is covered
Current affirmation dateWhether the annual affirmation clock is currentThat nothing material has changed since the affirmation
Appropriate SPRS screenshotA point-in-time view of the status and affirmation fieldsA government guarantee of future compliance
Certificate of CMMC Status, where one existsThe Level 2 C3PAO or Level 3 DIBCAC certificate recordA self-assessment certificate — because no such certificate exists
Short assessment-scope descriptionHow the proposed work maps to the assessed environmentThe SSP, POA&M, or technical evidence behind the assessment

The absence of the contracting officer's direct lookup does not lower the stakes. It changes the evidence path. The form that feels easiest to round up is the one most likely to survive until an audit, government assessment, or whistleblower compares it with the underlying record.

The CCRA, and what "green" actually means

If your prime routes you through Exostar, you may be looking at the Cybersecurity Compliance and Risk Assessment (CCRA) — a common supplier questionnaire developed through the Defense Industrial Base Sector Coordinating Council.

The current CCRA contains a maximum of 60 questions. Its risk section uses a subset of NIST SP 800-171 Revision 2 requirements, and the format is designed so a supplier can validate and export responses for reuse across requesting organizations. Exostar's Onboarding Module is one electronic implementation.

Two things to hold onto:

  1. The CCRA is not a CMMC assessment. It does not create a CMMC Status, and the DIB SCC says completing it does not waive or substitute for a DoD-required assessment.
  2. A prime's "green," "approved," or minimum-rating threshold is that prime's business rule unless the prime ties it to a specific contract requirement. It is not a status defined in 32 CFR Part 170.

We break down the portal-versus-questionnaire-versus-product distinction in our Exostar CMMC review.

When the prime asks for a level your contract doesn't require

Ask for the clause. In writing. Politely, and early.

32 CFR 170.23 gives a more precise flow-down map than "everyone needs whatever the prime has."

What the subcontractor will handle — Regulatory minimum described in § 170.23
What the subcontractor will handleRegulatory minimum described in § 170.23
FCI only, not CUILevel 1 (Self)
CUI, when the associated prime contract does not require Level 2 (C3PAO) or Level 3Level 2 (Self)
CUI, when the associated prime contract requires Level 2 (C3PAO)Level 2 (C3PAO)
CUI, when the associated prime contract requires Level 3 (DIBCAC)Level 2 (C3PAO) minimum for the subcontractor, unless specific procurement guidance establishes more

A prime can impose a stricter supplier standard as a business decision. That may still be enforceable as a commercial term, but it is not the same thing as saying the federal rule itself required that higher level for your subcontract.

The question to send back is short:

Which prime-contract clause or subcontract flow-down establishes this requirement, what exact CMMC level and assessment type does it require, which information and systems place us in scope, and by what date must the Status be current?

If the answer is "our supplier policy," you're negotiating commercial terms. If the answer is a clause, you're administering a requirement. That changes what you're willing to spend and when. Our CMMC requirements for subcontractors guide covers the full analysis.

One more dated note, because it is causing real confusion right now: the July 13, 2026 suspension direction binds Department personnel. It does not automatically rewrite an existing subcontract. Relief at the government level reaches you only when the relevant prime-contract and subcontract instruments are changed.

The forward-looking promise trap

"We will be Level 2 certified by Q1."

Do not write that sentence. Not on a questionnaire, not in an email, not in a capability statement.

A status answer describes what is true today. A schedule answer is a commitment, and commitments get compared against outcomes. Assessment readiness, C3PAO availability, evidence review, POA&M eligibility, and closeout timing can move.

Write this instead:

"Our Level 2 certification assessment is scheduled with an authorized C3PAO for [month, year]. That schedule depends on completion of [specific dependency]. We will provide an updated status if the scheduled date changes."

Same information. Accurate. No guarantee you do not control.

The response just showed you exactly where your gap is.

That's the useful part of filling out one of these — you can't answer honestly without seeing what's missing. Our CMMC Readiness Checklist maps 32 checkpoints to the 14 NIST SP 800-171 Revision 2 families, plus scoping, SSP and POA&M baselines, and the SPRS posting steps.

Download the CMMC Readiness Checklist

No CUI, drawings, system diagrams, or contract details — this is a self-assessment aid, not an intake for sensitive material.


What happens if you overstate your CMMC status

Answer capsule: A CMMC or NIST SP 800-171 representation is a legally significant statement, not an administrative formality. In June 2026, LOGZONE agreed to pay $507,144 after a self-assessed NIST SP 800-171 score of 110 was compared with a later DCMA score of −170; DOJ's allegations also included security requirements the company had not implemented. In March 2025, MORSECORP agreed to pay $4.6 million and admitted facts including a score of 104 left uncorrected after a consultant calculated −142, incomplete controls, an inadequate SSP, and a noncompliant email-hosting arrangement.

We are not including this section to frighten you. We're including it because it is the single best argument for the honest answer — and because it makes the honest answer feel like the safe choice instead of the weak one.

Here is our Overstatement Ledger: two DOJ cyber–False Claims Act matters mapped to the written representation and the control failures behind it.

DCR original framework · Version 1.1 · Last verified August 15, 2026 · Sourced to Department of Justice releases and settlement records

Matter — Announced — Amount — What the public record says — What it changes in your response
MatterAnnouncedAmountWhat the public record saysWhat it changes in your response
LOGZONE, Inc.June 18, 2026$507,144, including $253,572 identified as restitution in the settlement agreementLOGZONE submitted a NIST SP 800-171 self-assessment score of 110 in October 2021. A later DCMA assessment returned −170. DOJ alleged the company knowingly failed to comply with cybersecurity requirements, including requirements it had not implemented, while submitting claims under two Navy contracts. The matter settled without a trial determination on the allegations.A score is not harmless paperwork. But the case was not only about the number — the number exposed a mismatch with the underlying environment.
MORSECORP, Inc.March 26, 2025$4.6 millionMORSE admitted that it submitted a score of 104 in January 2021; a third-party consultant calculated −142 in July 2022; and MORSE did not update SPRS until June 2023. MORSE also admitted incomplete implementation, lack of a consolidated SSP during part of the period, and an email-hosting arrangement that did not meet required protections.Failing to correct a known-inaccurate score is not passive. The surrounding controls, SSP, and service-provider facts still matter.

Three practical takeaways change how you write:

  1. The statement and the security posture travel together. The representation is dangerous because it can be compared with the environment, evidence, and later assessment.
  2. Failing to correct can become its own fact pattern. A number you know is wrong does not become safer because you leave it untouched.
  3. A breach is not required for the representation to matter. Neither public resolution depended on DOJ first proving a successful intrusion.

Under 32 CFR Part 170, DoD also retains the right to conduct a DCMA DIBCAC assessment. If a later government assessment shows the required status was not achieved or maintained, the government result takes precedence over the pre-existing CMMC Status in SPRS.

If you're worried about a score or status you already posted, the sequence is: reassess accurately, preserve the evidence, correct the appropriate record, document what changed and when, and involve qualified counsel before making a disclosure with legal consequence. Our CMMC non-compliance penalties guide covers the wider enforcement landscape.


What to attach to your response — and what to keep back

Answer capsule: Send only what substantiates the record claimed and what the requester legitimately needs: exact CMMC Status, status date, assessment type, CMMC UID, affirmation date, and an appropriate SPRS screenshot or certificate where applicable. Do not casually attach an SSP, POA&M, network diagram, vulnerability list, CUI, or export-controlled material.

More responses are over-attached than under-attached. Generosity with documents feels like transparency. It usually isn't.

Send in the response when requested — Offer under an appropriate channel and terms — Do not send through an ordinary RFI, email, portal, or web form
Send in the response when requestedOffer under an appropriate channel and termsDo not send through an ordinary RFI, email, portal, or web form
Exact CMMC Status nameCertificate of CMMC Status, where one existsYour System Security Plan
CMMC Status dateAppropriate SPRS status/affirmation screenshotYour POA&M or list of unmet requirements
Assessment typeHigh-level assessment-scope summaryNetwork or architecture diagrams
CMMC UID for each proposed in-scope information systemWritten assessment-boundary summaryIP addresses, hostnames, credentials, or configuration detail
Affirmation dateCustomer responsibility matrix, where relevantKnown vulnerabilities or open findings
Separately labeled NIST SP 800-171 DoD Assessment score and date, only if requested and applicableName of the assessing C3PAO or DCMA DIBCAC, as applicableIncident reports or detailed incident facts
Point of contactSecure follow-up processCUI, controlled technical data, drawings, export-controlled content, or source selection information

The right-hand column is not paranoia. A POA&M is a curated list of unmet security requirements. Emailed into a supplier portal, it becomes a roadmap sitting in someone else's environment with retention and access rules you may not control.

If a legitimate requester needs that level of detail, the next question is not "which attachment button?" It is: what authority requires it, who will have access, what secure channel will be used, how will it be retained, and under what terms?

A note for any future policy comment window: policy submissions may be summarized, quoted, retained, released, or handled under notice-specific rules. Read the actual notice before including proprietary information. When the notice does not give you enough certainty, use ranges, categories, and redacted descriptions instead of raw technical or commercial details you cannot afford to see outside your company.


Four CMMC RFI response templates you can copy

Answer capsule: A defensible CMMC response is usually short: identify the requirement, exact Status, status date, assessment type, CMMC UID for each in-scope system, current affirmation date, and point of contact. Narrative length does not improve a 252.204-7025 eligibility check.

Use these as structure, not as text to send unread. Open SPRS first and copy the values from the record. Every bracket below is a field you verify, not a field you estimate.

Template 1 — You hold a Final status, responding to a government solicitation

CMMC Status Response — [Solicitation Number]

[Company Name], CAGE [CAGE Code], holds [Final Level 1 (Self) / Final Level 2 (Self) / Final Level 2 (C3PAO) / Final Level 3 (DIBCAC)] for the contractor information systems that will process, store, or transmit FCI or CUI in performance of this requirement.

CMMC Status date: [date] Assessment type: [Self / C3PAO / DIBCAC] CMMC UID(s): [UID] — [system name or short description]; [UID] — [system name or short description] Affirmation of continuous compliance date: [date]

[If applicable: Assessing organization: [authorized C3PAO name / DCMA DIBCAC]. Certificate of CMMC Status: [reference or secure-delivery statement].]

These values were confirmed against SPRS on [date]. Point of contact: [name, title, email, phone].

Template 2 — You hold a Conditional status, responding to a government solicitation

CMMC Status Response — [Solicitation Number]

[Company Name], CAGE [CAGE Code], holds [Conditional Level 2 (Self) / Conditional Level 2 (C3PAO) / Conditional Level 3 (DIBCAC)] for the contractor information systems in scope for this requirement.

CMMC Status date: [date] Assessment type: [Self / C3PAO / DIBCAC] CMMC UID(s): [UID] — [system name or short description] POA&M closeout deadline: [date, no later than 180 days after the Conditional Status date] Affirmation of continuous compliance date: [date]

The Conditional Status and affirmation were confirmed against SPRS on [date]. We will provide updated CMMC UID and Status information as required by the solicitation or resulting contract. Point of contact: [name, title, email, phone].

Before you send this one: confirm the required designation is Level 2 or Level 3 and that the Status is still current. Conditional Level 1 does not exist.

Template 3 — You hold no CMMC Status, responding to a prime's questionnaire

CMMC Status — Supplier Response

[Company Name], CAGE [CAGE Code], does not currently hold a CMMC Status under 32 CFR Part 170.

[If requested and applicable: Our current NIST SP 800-171 DoD Assessment is a [Basic/Medium/High] assessment with a score of [X], dated [date], posted in SPRS. This is a separate NIST SP 800-171 DoD Assessment record and is not a CMMC Status.]

[If actually scheduled: Our [Level 2 self-assessment / Level 2 certification assessment] is scheduled for [month, year], subject to [specific dependency].]

To confirm the requirement applicable to our scope of supply, please provide written confirmation of: (1) the prime-contract clause or supplier-policy source, (2) the exact CMMC level and assessment type, (3) the FCI or CUI expected under our subcontract, and (4) the date by which the Status must be current.

Point of contact: [name, title, email, phone].

That closing paragraph does two jobs. It's responsive, and it puts the burden of specificity back where it belongs — without a word of pushback.

Template 4 — The prime is asking for a level you do not believe applies

Re: CMMC Requirement — Request for Clarification

Thank you for the CMMC requirement notice dated [date]. We want to respond accurately, so please confirm the following in writing:

  1. Source of the requirement. Is the specified CMMC designation flowed down from a prime-contract requirement, or is it [Prime]'s supplier standard?
  2. Level and assessment type. Which designation applies — Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), or Level 3 (DIBCAC)?
  3. Information and scope. Will our subcontract require us to process, store, or transmit FCI, CUI, or both, and which systems are expected to support that work?
  4. Timing. By what date must the required CMMC Status be current — quote, subcontract award, start of performance, option exercise, or another stated milestone?

Our current posture is [exact Status, or no Status plus separately labeled NIST SP 800-171 DoD Assessment score if requested], dated [date]. We are prepared to act once the requirement is confirmed.

Point of contact: [name, title, email, phone].

Ask before you buy.

You've got your answer written. Now fix the thing the answer exposed.

Almost nobody finishes one of these feeling great about the environment. The next decision is which category of help you need — and it is usually not an assessor first.

Start with Who to Hire First for CMMC and our CMMC Provider Categories guide. Then tell us your level, scope, environment, and timeline, and we'll match you with source-checked provider options in the categories that fit.

Get matched with source-checked provider options

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. Do not submit CUI, drawings, export-controlled content, or sensitive contract details — this intake is for provider-category routing only.

Which category fits — and which doesn't

No names here, because the right answer depends entirely on your situation and we're not going to pretend otherwise. Categories only, with what to ask before you hire.

Provider category — Fits when — Does not fit when — Ask before you hire
Provider categoryFits whenDoes not fit whenAsk before you hire
RPO / RP — Registered Provider Organization / Registered PractitionerYou need scoping, readiness planning, SSP and POA&M work, or help reading the requirementYou need the formal Level 2 certification assessment; an RP is not a C3PAOCurrent Cyber AB status, named deliverables, boundaries around legal advice, and how conflicts will be handled
MSSP / MSP / vCISOYou need implementation: identity, logging, endpoint security, monitoring, incident response, administration, and evidenceYou want to outsource the affirming official's accountabilityCMMC-specific experience, CUI handling, service-provider scope, customer responsibilities, and the evidence delivered back to you
GRC platformYou need evidence workflow, control mapping, task ownership, and SSP/POA&M trackingYou believe software alone satisfies CMMCWhether exports are assessment-ready and whether the mapping is to NIST SP 800-171 Rev. 2, the current CMMC Level 2 control set
CUI enclaveContaining CUI in a smaller environment would genuinely shrink the assessment scopeYou expect an enclave to erase every connected asset, user, service, and CUI path from scopeCSP and ESP responsibilities, the responsibility matrix, endpoints, identity, administration, every CUI entry and exit point, and the residual on-premises scope
C3PAOYou are assessment-ready or the instrument requires Level 2 (C3PAO)You need the assessor to remediate the same environment it will assessCurrent authorized or accredited status in the Cyber AB Marketplace, scope, availability, assessment team, price assumptions, and written conflict-of-interest analysis

The independence rule is narrower and more exact than "a C3PAO can never assess a company it helped."

32 CFR 170.8(b)(17)(ii)(G) requires the Cyber AB's Code of Professional Conduct to prohibit a CMMC Ecosystem member from participating in a Level 2 certification assessment when that member served as a consultant preparing the organization for any CMMC assessment within the previous three years. 32 CFR 170.9 also requires C3PAOs to follow Cyber AB conflict-of-interest policy.

The Cyber AB CMMC Assessment Process, Version 2.0 puts conflict identification, disclosure, and resolution into the assessment process and makes clear that assessment personnel cannot guarantee an outcome. If a provider proposes readiness work and a later assessment relationship, get the people, affiliates, services, dates, and conflict analysis in writing before you sign.


What happens after a CMMC RFI response window closes?

Answer capsule: A closed federal RFI produces information and recommendations, not obligations. The CMMC Reform Task Force was directed to deliver a report to the Department CIO within 60 days of the July 13, 2026 suspension. A recommendation does not change your duties until it reaches the relevant instrument.

This is where a lot of contractors get burned twice — first by missing a window, then by acting on a headline.

Read the instrument, not the headline

Use this hierarchy. It's the most useful thing on this page for anyone trying to decide whether something they read actually applies.

Source — What it can establish — What it cannot establish by itself
SourceWhat it can establishWhat it cannot establish by itself
Press releaseDepartment policy direction and public explanationWhat your solicitation, contract, or subcontract requires
CIO or acquisition memorandumInternal implementation direction to Department personnelThat your existing instrument has already changed
SAM.gov RFI or sources-sought noticeA market-research action, its questions, instructions, and deadlineA binding rule or award requirement
Federal Register / eCFRRule text, amendments, effective dates, and formal comment opportunitiesWhether a clause was incorporated into your contract
Acquisition.govCurrent codified FAR and DFARS textWhether a class deviation or your specific instrument uses different operative text
Class deviationWhich alternative provisions, clauses, or procedures contracting personnel are directed to useA universal rewrite of every existing contract or the codified CFR
Solicitation amendmentChanges to that solicitationChanges to any other procurement
Contract modificationChanges to your contractAn industry-wide rule
Prime contractor communication or subcontract amendmentA supplier expectation, commercial term, or flowed-down requirementA government-wide legal requirement on its own

The short version, and it's worth taping to a monitor: a press release explains direction, a memorandum directs implementation, and the solicitation, contract, subcontract, or formal amendment determines what applies to your company.

What should trigger you to re-check

Watch for these. Everything else is commentary.

  • An amendment or replacement notice on SAM.gov
  • Publication of the CMMC Reform Task Force report or an official summary
  • A new memorandum from the Department CIO or acquisition leadership
  • An update to the official Department CMMC page or FAQ
  • A Federal Register action affecting 32 CFR Part 170
  • A new DFARS change or class deviation
  • An amendment to a solicitation you are bidding
  • A modification to a contract you hold
  • A written change from your prime to the applicable subcontract or supplier requirement

Nothing on that list changes your instrument because a vendor blog publishes first.

If you drafted a response and never sent it

Don't throw it away. Freeze it as a dated internal record: the draft, the date, the source documents behind each figure, and a clear label on every number distinguishing actual from estimated from quoted. Note which question each section answered.

That file has three future uses. It's the input to your next budget conversation. It's the scoping brief you hand a provider so you stop paying to explain your own environment. And when the next legitimate comment channel opens, you'll be the company with dated cost and outcome evidence while everyone else reconstructs invoices from memory.

Keep the sensitive support separate from the summary. The summary should survive being read outside your company. The underlying evidence should not have to.


What we actually verified

We don't ask anyone to take our word for it. Here's what we checked directly on August 15, 2026, and what each source supports.

Primary or official source — What it supports on this page
Primary or official sourceWhat it supports on this page
32 CFR Part 170CMMC applicability, phase structure, assessment paths, 15 Level 1 requirements, 110 Level 2 Rev. 2 requirements, 24 selected Level 3 SP 800-172 requirements, scoring, POA&M rules, affirmations, flow-down, C3PAO and DIBCAC roles, and the three-year consultant-participation restriction
DFARS 204.7501Seven exact CMMC Statuses; definition of "current"; 180-day, one-year, and three-year age limits; annual affirmation; 10-character CMMC UID
DFARS 204.7502 and 204.7503Award policy; Conditional award eligibility for Levels 2 and 3; Final requirement for Level 1; contracting officer SPRS checks
DFARS 252.204-7025Four solicitation designations; current Status and affirmation before award; CMMC UIDs in the proposal for each in-scope system
DFARS 252.204-7012, 252.204-7019, 252.204-7020, and 252.204-7021Separate NIST SP 800-171 DoD Assessment records; contract cybersecurity duties; CMMC maintenance, affirmation, and flow-down requirements
CMMC acquisition final rule, 90 FR 43560November 10, 2025 effective date; final acquisition-rule rationale; UID and SPRS process; subcontractor sharing of SPRS screenshots
Official DFARS Revolutionary FAR Overhaul class-deviation indexThe Part 240 deviation package, including the affected use of 252.240-7997 and the distinction between deviation text and codified DFARS text
NIST SP 800-171 Rev. 2, Rev. 3, and SP 800-172NIST publication dates and lifecycle; the distinction between NIST's current publications and the versions incorporated into CMMC
Department CMMC page and linked July 13, 2026 memorandaImmediate Phase II suspension; Phase I remaining in place; current implementation direction
SAM.gov Notice ID 89ef9bfb0834473791e991c712698d94Reform RFI title, posting, instructions, questions, and noon Eastern August 14, 2026 deadline
Cyber AB CMMC Assessment Process v2.0 and Cyber AB MarketplaceLevel 2 certification-assessment process, conflicts, no-outcome-guarantee rule, and current C3PAO status verification
DIB SCC CCRA materialsCCRA origin, maximum question count, Rev. 2 subset, reuse/export, Exostar implementation, and the statement that CCRA does not replace a DoD-required assessment
DOJ LOGZONE release and settlement record$507,144 resolution; 110 versus −170 scores; alleged control failures; contract period and payment facts
DOJ MORSECORP release and settlement record$4.6 million resolution; admitted 104 versus −142 scoring facts; delayed correction; SSP, control, and service-provider admissions

What we could not establish

Just as important:

  • Whether any late Reform RFI submission was read. The notice said late submissions would not be considered.
  • Whether the notice will be reopened, amended, or replaced. No official reopening was found as of August 15, 2026.
  • The exact public release date for the Task Force report. Delivery to the CIO within 60 days is not a publication commitment.
  • Which reforms, if any, will be adopted. No final reform package exists.
  • Whether individual Reform RFI responses will be made public. The sources reviewed did not establish that.
  • Whether any specific solicitation, contract, or subcontract has been amended. That is instrument-specific.
  • A universal prime-contractor SPRS access matrix. The award-check rule is clear; prime-side evidence practices vary. This page therefore tells suppliers to provide supportable evidence rather than claiming that a written questionnaire is the only possible record.
  • Whether a class deviation governs your instrument. Read the solicitation or contract and the deviation authority it cites.

Frequently asked questions

Is the CMMC RFI still open?

If you mean the Department of War's CMMC Reform Task Force RFI, no. The response window closed at 12:00 p.m. Eastern on Friday, August 14, 2026. Only an official amendment or replacement notice should be treated as reopening it.

Can I submit a CMMC RFI response after the deadline?

You can send an email, but the notice said late submissions would not be considered. That is not a filing strategy. Preserve the response as a dated internal record for the next legitimate channel.

Did responding to the CMMC Reform RFI create a CMMC Status?

No. A policy RFI response is input. A CMMC Status is created only through the assessment paths in 32 CFR Part 170 and recorded through the applicable SPRS/eMASS process.

What are the seven CMMC Statuses?

Final Level 1 (Self); Conditional Level 2 (Self); Final Level 2 (Self); Conditional Level 2 (C3PAO); Final Level 2 (C3PAO); Conditional Level 3 (DIBCAC); and Final Level 3 (DIBCAC).

Can I win a contract with a Conditional CMMC Status?

At Levels 2 and 3, yes, when the Conditional Status is current, the POA&M is eligible, the required assessment type is satisfied, and the affirmation is current. At Level 1, no — Level 1 requires Final.

How long does a CMMC Status stay current?

Conditional Level 2 and Level 3 statuses have a maximum 180-day window. Final Level 1 is not older than one year. Final Level 2 and Final Level 3 statuses are not older than three years. "Current" also requires no change in compliance since the Status date and the corresponding current affirmation.

What is a CMMC UID and why does the solicitation want it?

A CMMC UID is a 10-character alphanumeric identifier assigned to each CMMC assessment and reflected in SPRS for each contractor information system. DFARS 252.204-7025 requires the offeror to provide the relevant UIDs in the proposal so the contracting officer can check each in-scope system.

What do I say if I do not have a CMMC Status?

Say so directly. Then provide a separately labeled NIST SP 800-171 DoD Assessment score only if the requester asks for it and you have a current applicable record. Add an assessment date only when it is actually scheduled or clearly label it as a target.

Is "NIST 800-171 certified" a real thing?

Not as a certification issued by NIST. NIST publishes SP 800-171; it does not certify organizations. CMMC and the NIST SP 800-171 DoD Assessment methodology create different assessment records.

Does CMMC have a score?

Level 2 and Level 3 CMMC assessments do. Level 2 is scored against 110, and Level 3 against 24 selected SP 800-172 requirements after the Final Level 2 (C3PAO) prerequisite. But the score does not replace the exact CMMC Status and assessment type used for award eligibility.

Does CMMC use NIST SP 800-171 Rev. 2 or Rev. 3?

Revision 2. NIST published Revision 3, but 32 CFR Part 170 currently incorporates Revision 2 for CMMC Level 2. Do not switch the CMMC control set to Rev. 3 unless the governing rule or contractual instrument changes.

Why is my prime asking instead of using the contracting officer's SPRS check?

Because the contracting officer's DFARS 204.7503 verification is a government award step. The prime has its own flow-down and subcontract-award duties and typically collects evidence directly from the supplier, including status data, UIDs, affirmation dates, screenshots, and certificates where applicable.

Is the CCRA a CMMC assessment?

No. It is a common supplier questionnaire developed through the DIB Sector Coordinating Council. It can reduce duplicate supplier questionnaires, but it does not create a CMMC Status or replace a DoD-required assessment.

My prime is demanding a level my subcontract does not appear to require. What now?

Ask for the prime-contract clause or supplier-policy source, exact level and assessment type, information type, scope, and required date. A prime may impose a stricter commercial standard, but that is not the same as the minimum flow-down in 32 CFR 170.23.

Did the July 13, 2026 Phase II suspension remove Phase I requirements?

No. The Department stated that Phase I self-assessment requirements remain in place. The suspension stopped the planned Phase II progression and changed current implementation direction; it did not erase existing cybersecurity clauses, SPRS records, affirmations, or contract terms.

Should I attach my SSP or POA&M to an RFI response?

Generally, no. Neither is normally needed to substantiate the exact Status, UID, and affirmation. A POA&M reveals unmet requirements; an SSP contains sensitive system detail. Use an appropriate secure channel and defined terms when a legitimate authority requires deeper evidence.

Can I include CUI or proprietary information in a response?

Do not place CUI, controlled technical data, drawings, export-controlled material, credentials, vulnerability details, or source-selection information into an ordinary RFI response, supplier portal, or provider-routing form. For a policy notice, follow that notice's specific handling instructions.

When will the CMMC Reform Task Force report be released?

The Task Force was directed to deliver a report to the Department CIO within 60 days of July 13, 2026, pointing to roughly mid-September. No specific public release date was established by the sources reviewed.

Will the Task Force report change my contract automatically?

No. A recommendation must reach the relevant instrument through a memorandum, class deviation, rule, solicitation amendment, contract modification, or subcontract change before it alters what applies to you.

How often should I re-check this?

Re-check the official Department CMMC page and SAM.gov weekly during the current review and immediately before an expensive decision, proposal submission, subcontract award, or assessment commitment. Check SPRS before every response that represents your current record.


Before you send it

Run this list. It takes four minutes and catches almost everything that goes wrong.

  1. Identify the document. Solicitation, sources sought, prime questionnaire, or policy RFI.
  2. Open SPRS. Copy the Status name, status date, UIDs, and affirmation date from the record.
  3. Check whether the record is current. Age, affirmation, and no change in compliance all matter.
  4. Use one of the seven exact Status names. Not a paraphrase.
  5. For a 252.204-7025 solicitation, list every applicable UID.
  6. Map each UID to the system proposed for performance.
  7. Name every score before giving the number. CMMC Level 2, CMMC Level 3, or NIST SP 800-171 DoD Assessment.
  8. Keep CMMC on Rev. 2 unless the governing rule or instrument changes.
  9. Delete every forward-looking guarantee that is not within your control.
  10. Strip the attachments you were not asked for.
  11. Confirm the source, level, assessment type, scope, and date before committing money.
  12. Keep a dated copy of what you sent and the evidence behind it.

Need help deciding what type of CMMC provider you need?

Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.

Find My CMMC Path

Already know what you need? Request scoped quotes from matched provider categories. Free, no obligation.

Do not submit CUI, drawings, export-controlled content, or sensitive contract details. This intake is for provider-category routing only. Provider matching may generate referral or lead-routing compensation, disclosed at the point of recommendation.


The Defense Compliance Report is an independent trade publication on CMMC and Defense Industrial Base compliance. We are not affiliated with the Cyber AB, the Department of Defense or Department of War, DCMA DIBCAC, NIST, or any U.S. government agency. This article is educational research and is not legal, contractual, or compliance advice. Requirements vary by instrument, assessment scope, information type, and system architecture.

Research approach documented at Methodology and Editorial Standards. Found an error? See our Corrections policy — we publish them.