DRAFT PREVIEW — NOT PUBLISHED — PUBLICATION DATE PENDING

The Defense Compliance Report — Research & Data

CMMC Statistics 2026: Certification Counts, Costs, Small Business Impact & Enforcement Data

By The Defense Compliance Report editorial team · Published · Dataset compiled October 3, 2026 · Draft preview: public update date pending · Latest certification snapshot:

The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance. Our /research section publishes reference data with a source on every claim.


The original CMMC rulemaking models projected the program’s population and estimated the cost of assessment and affirmation; those are planning estimates, not a current contractor census or a guaranteed price. For the current certification snapshot, the Cyber AB’s September 29, 2026 primary deck reports 2,362 final Level 2 Certificates of CMMC Status, 71 conditional certificates, 151 assessments in progress and 117 Authorized or Accredited C3PAOs. These are system-scope certificate counts and ecosystem headcounts, not a compliance rate or measured booking backlog. The July 13 suspension remains a separate issue: it halted the later procurement-phase milestones, while Phase I and existing safeguarding obligations continue. The tables below keep each number tied to its source period and definition.

Every number on this page is graded, dated, and linked to its source — including the popular ones we refused to publish.

Key CMMC statistics at a glance

Table 1 — Headline CMMC statistics. Historical figures retain their stated source dates. The July 13, 2026 suspension entry was checked October 3, 2026.
StatisticFigureGradeSource
Original DFARS-rule projection: entities subject to CMMC by Year 4337,968ADFARS final rule, Sept. 10, 2025
Original DFARS-rule projection: small entities among them229,818 (68%)ADFARS final rule
Original DFARS-rule projection: entities projected to need Level 2 (C3PAO) certification118,289ADFARS final rule
2024 program-rule modeled small-entity Level 2 assessment-and-affirmation estimate$104,670 over 3 years — implementation excludedACMMC Program final rule, Oct. 15, 2024
Final Level 2 Certificates of CMMC Status2,362, as of September 29, 2026BCyber AB September 29, 2026 primary deck, p. 19
Authorized or Accredited C3PAOs117, as of September 29, 2026BCyber AB September 29, 2026 primary deck, p. 20
Defense-related cybersecurity FCA settlements since 2022$39.0 million across 10 resolutions (Historical selected-case snapshot, July 2, 2026; see the live ledger for later cases.)TDCRDOJ press releases (Table 8)
Phase 2 (original date) — suspended July 13, 2026; no replacement date announced (original; suspended)ADoD CIO; July 13, 2026 implementing procedures

Source: Compiled by The Defense Compliance Report from the Federal Register, DoD CIO, Cyber AB Town Halls, and Department of Justice press releases. Per-row sources, grades, and calculations appear in the sections below.

What this shows — and what it doesn’t

The population and cost numbers describe original rulemaking assumptions. The certification figures describe the September 29, 2026 snapshot. DoD’s modeled cost is not a minimum market price, and it excludes implementation and remediation. Dividing a system-scope certificate count by a projected entity count provides a scale comparison, not a measured compliance rate. The historical $39.0 million defense-related enforcement snapshot remains labeled July 2; use the separate settlements tracker for its expanded dated dataset.

These figures do not show a compliance rate or total compliance cost. DoD’s modeled cost excludes implementation and remediation. Public aggregate counts also lack the ready-applicant queue, regional or industry fit, assessment scope, team availability, conflicts and calendar data needed to infer a booking backlog.

How we built this page

We read both CMMC rules in the Federal Register — the program rule (32 CFR Part 170) and the acquisition rule amending the Defense Federal Acquisition Regulation Supplement (DFARS) — along with the current clause text on Acquisition.gov, DoD’s published reports and CIO guidance, the class deviation memo, Department of Justice settlement announcements, Cyber AB Town Hall disclosures, and original reporting from Reuters and Federal News Network. We recomputed every number independently and checked it against its stated source.

Every statistic carries one of three evidence grades, or a calculation label:

Table 2 — Evidence grades used on this page
GradeMeaning
AOfficial primary source: Federal Register, eCFR, Acquisition.gov, DoD, NIST, DOJ documents
BOfficial program data stated in official venues or official dynamic sources, verified as of a date (Cyber AB Town Halls)
CNamed industry surveys, analyses, or original reporting by major news organizations with disclosed sourcing or methodology; sponsor identified where applicable
TDCROur arithmetic from A- or B-grade inputs, with the formula shown

Source: The Defense Compliance Report methodology, .

Claims that fail all four categories — no source, no denominator, no methodology — do not appear as facts anywhere on this page. They appear in one place only: the “claims we could not verify” section near the end.

Two related references in this section update on their own schedules: our CMMC certification tracker (monthly, after each Cyber AB Town Hall) and our cybersecurity enforcement ledger (event-driven, as DOJ announces resolutions). Figures on this page are snapshots from those datasets as of the verification date above.

How to cite this page

The Defense Compliance Report. “CMMC Statistics 2026: Certification Counts, Costs, Small Business Impact & Enforcement Data.” thedefensecompliancereport.com/research/cmmc-statistics/. Dataset compiled October 3, 2026; public update date pending.

The October 3, 2026 dataset, with source, evidence grade and retained row-level verification dates, is available as a CSV at /research/cmmc-statistics/cmmc-statistics-ledger-2026-10-03.csv and through the stable cmmc-statistics-ledger.csv URL — no email required.


How many companies need CMMC?

DoD estimates 337,968 unique entities — prime contractors and subcontractors combined — will be subject to CMMC requirements by Year 4 of the phased rollout, according to the DFARS final rule published . Of those, 229,818 (68%) are small entities. The requirement applies to any contractor whose information systems process, store, or transmit federal contract information (FCI) or controlled unclassified information (CUI) under a DoD contract, with a carve-out for contracts solely for commercially available off-the-shelf (COTS) items.

Table 3 — Projected CMMC population by level at full implementation
CMMC levelShareEntity countGrade
Level 1 (Self) — FCI only62%209,540 *A / TDCR
Level 2 (Self) — lower-risk CUI2%6,759 *A / TDCR
Level 2 (C3PAO) — most CUI35%118,289A
Level 3 (DIBCAC) — most sensitive CUI1%3,380 *A / TDCR
Total100%337,968A

Source: DFARS final rule, 90 FR 43560 (). Distribution percentages and the 337,968 and 118,289 figures are DoD’s; entity counts marked * are TDCR calculations applying the rule’s distribution to the 337,968 total. Last verified .

How DoD counted.The department doesn’t actually track unique offerors, and it has no contractual relationship with subcontractors at all. So the rule’s analysis works from assumptions: roughly 28,164 annual solicitations, an assumed average of two offerors each (56,328 prime offerors), and an assumed five subcontractors per prime proposal. Multiply through and you reach 337,968 unique entities. That means the headline number is a model output, not a census — a distinction that matters when extrapolating.

The phase-in is deliberately back-loaded for small businesses. The rule projects 1,104 small entities affected in Year 1, 5,565 in Year 2, 18,554 in Year 3, and the full 229,818 by Year 4 and beyond.

One precision note writers routinely miss: CMMC certifies information systems, not companies. Each assessed system receives a CMMC unique identifier (UID) in SPRS, DoD’s contractor-performance database, and a single company can hold several. The Cyber AB reinforced this at its Town Hall in guidance on joint ventures, which must identify every UID used in contract performance. “Companies certified” and “certificates issued” are close approximations, not identical measures.

How many companies need CMMC Level 2 certification?

The DFARS final rule projects 118,289 entities will require Level 2 certification by a Certified Third-Party Assessment Organization (C3PAO) — an independent assessor authorized by the Cyber AB — by Year 4 of implementation. That is 35% of all impacted entities. A much smaller group, about 6,759 entities (2%), will be allowed to self-assess at Level 2 for lower-risk CUI. The two paths are frequently collapsed into one “Level 2” number; they shouldn’t be.

About that “80,000” figure you keep seeing.A claim that “roughly 80,000 contractors need Level 2 certification” circulates widely. We could not pin that exact figure to current rule text. What we canreproduce: apply the rule’s 35% Level 2 (C3PAO) share to the 229,818 small entities and you get 80,436 small entities in the certification population (TDCR calculation) — almost certainly the origin of the ~80,000 shorthand. The correct all-entity figure is 118,289.

How many companies are CMMC certified right now?

The Cyber AB’s September 29, 2026 primary deck reports 2,362 final Level 2 Certificates of CMMC Status, 71 conditional certificates and 151 assessments in progress. A certificate covers an assessed information-system scope; the deck does not provide a unique-company total. Source: September deck, p. 19.

Table 4 — Recent final Level 2 certificate snapshots
SnapshotFinal certificatesNet change from preceding snapshotSource
1,666+275Retained tracker value, originally chart-read; qualification preserved in the full tracker
1,866+200Cyber AB July primary deck, p. 8
2,105+239Cyber AB August primary deck, p. 12
2,362+257Cyber AB September primary deck, p. 19

Sources are linked per row. The June value is retained from the tracker and was originally chart-read; July through September values are from the linked Cyber AB primary decks.

The latest three snapshot changes average 232 final certificates per month: (200 + 239 + 257) ÷ 3. The full tracker preserves earlier monthly records, source definitions and restatements. These point-in-time counts do not measure booking availability or the number of assessment-ready organizations.

Conditional certificates account for about 2.9% of final-plus-conditional certificates in the September snapshot: 71 ÷ (2,362 + 71). This is a certificate-status share, not a share of unique companies.

What are the official CMMC cost statistics?

DoD’s official estimate for a small entity’s Level 2 certification is $101,752 initially and $104,670 over the full three-year cycle — and that figure covers only assessment, certification, and affirmation activity. It excludes implementation and remediation entirely. Both numbers come from the CMMC Program final rule’s regulatory analysis.

Table 5 — DoD’s official CMMC cost estimates, by level and entity size
Assessment pathInitial estimateThree-year estimate
Level 1 self-assessment (small entity)$5,977+ $560 per annual reaffirmation
Level 2 self-assessment (small entity)$34,277$37,196
Level 2 self-assessment (other-than-small)$43,403$48,827
Level 2 C3PAO certification (small entity)$101,752$104,670
Level 2 C3PAO certification (other-than-small)$112,345$117,768
Level 3 assessment + affirmations (small entity)—$12,802 (atop Level 2, excl. engineering)

Source: CMMC Program final rule, 89 FR 83092 (), regulatory impact analysis; docket DOD-2023-OS-0063. Evidence grade: A for every row. Compiled by The Defense Compliance Report; last verified .

What DoD’s $104,670 estimate does not include

The rule states that implementation costs are not attributed to CMMC because the underlying requirements already exist: the basic safeguarding clause at FAR 52.204-21 has applied since , and DFARS 252.204-7012 required full implementation of NIST SP 800-171 — the 110-requirement federal standard for protecting CUI — by . In DoD’s accounting, a contractor handling CUI should have absorbed those costs years ago. CMMC merely charges you to prove it.

The proof that this was a choice, not an oversight: at Level 3, where the rule adds genuinely new requirements drawn from NIST SP 800-172, DoD did count engineering costs — an estimated $2.7 million in nonrecurring and $490,000 in recurring engineering costs for a small entity. The department costs implementation when requirements are new and excludes it when they’re preexisting. That accounting boundary is the single most useful thing to understand about every CMMC cost figure in circulation.

The gap between the certification paths is itself instructive: a small entity’s three-year Level 2 certification estimate runs $67,474 more than the self-assessment path($104,670 − $37,196; TDCR calculation). For scale, the rule’s own analysis puts the DFARS acquisition rule’s total cost at $344.9 million in present value over ten years at a 3% discount rate ($329.1 million public, $15.8 million government).

What contractors actually budget is a different question — and a different grade of evidence. In a PreVeil survey of more than 2,000 defense contractors (sponsor: PreVeil, a compliance platform vendor), 70% had budgeted less than the DoD estimate for Level 2 certification. The 2025 Merrill Research survey commissioned by CyberSheath, a CMMC managed services provider, found annual compliance budgets averaging nearly $50,000. We publish these as what they are — named surveys with disclosed sponsors (C) — not as official figures.

Is there enough C3PAO capacity — and is there a backlog?

The September 29, 2026 Cyber AB primary deck reports 117 Authorized or Accredited C3PAOs, 1,179 Certified CMMC Assessors and 681 Lead CCAs. These counts do not establish current booking availability or a national assessment backlog. Obtain scope-specific availability from the assessor you are considering. The comparisons below are historical model illustrations, not a measurement of spare capacity or a finding that contractor readiness is the sole national constraint. Source: September deck, p. 20.

Table 6 — Historical model comparisons — May/March 2026 inputs; not current backlog measurements
MeasureFigureGradeSource
Entities projected to need Level 2 (C3PAO) certification118,289ADFARS final rule
Final Level 2 certificates issued1,391BCyber AB May 2026 Town Hall (PDF)
Authorized C3PAOs104BCyber AB May 2026 Town Hall (PDF)

Source: Federal Register projection data combined with Cyber AB May 2026 Town Hall snapshot data by The Defense Compliance Report; last verified .

Table 7 — Historical ecosystem headcounts and September 2026 snapshot
DateC3PAOsCCAsCCPsLead CCAsGradeSource
976881,459425BCyber AB Jan. 2026 recap
987481,494452BCyber AB Feb. 2026 recap
103759——BMarch 2026 Town Hall via Secureframe
104+15% Apr→May——BCyber AB May 2026 Town Hall (PDF)
1171,179—681BCyber AB September primary deck (pp. 19–20)

Sources are linked per row. Historical rows retain their source dates; the September snapshot was checked October 3, 2026.

The historical monthly ecosystem series retains its original snapshot dates and definitions. For the latest reported values, use the September 29, 2026 source snapshot and the dated rows in the full certification tracker.

Historical population projections and earlier ecosystem headcounts can be compared only with their assumptions and units kept explicit. These comparisons do not describe current appointment supply or establish a backlog.

Historical headcounts and hypothetical throughput calculations cannot resolve today’s scheduling question. Public aggregate counts lack the ready-applicant queue, regional or industry fit, assessment scope, team availability, conflicts and calendar data needed to infer a booking backlog. The current certificate and headcount snapshots are available in the full tracker; direct written assessor availability is the useful evidence for an actual purchase.

How does CMMC affect small businesses?

DoD’s original rulemaking projected that small entities would represent 68% of the CMMC population: 229,818 entities, including prime contractors and subcontractors. Applying the modeled 35% Level 2 (C3PAO) share to that small-entity count gives about 80,436 as a TDCR calculation. These are planning estimates, not a current supplier census or a measured effect of CMMC.

DoD’s February 2022 State of Competition report found that the small-business population in the defense industrial base had shrunk by more than 40% over the preceding decade. That historical trend predates CMMC and does not measure exits caused by certification requirements. The report’s supplier-loss projection is also historical. CMMC’s 2024 rulemaking cost model is an estimate of assessment and affirmation activity, not a six-figure minimum quote or a current requirement for every supplier; implementation cost and the written procurement requirement must be evaluated separately.

The early evidence on how suppliers are responding is journalistic, and we grade it accordingly (grade C: original reporting, attributed). Reuters reported on that the new rules are leading some small suppliers to rethink military work: three aerospace companies each told Reuters they have suppliers who will not undergo the CMMC audit; the president of one U.S. firm said half of its suppliers had not indicated whether they will comply; and one Canadian supplier executive put his combined EU/US compliance cost at about C$500,000 (roughly US$365,000). The Aerospace Industries Association told Reuters that accumulating regulatory costs are forcing some member firms to “reconsider — if not exit” the defense marketplace. Reuters also cited 2022 House Small Business Subcommittee data that 88% of aerospace firms are small businesses. These are documented examples and on-record statements — not an exit rate. No verified exit-rate statistic exists (see the unverified-claims section).

A June 2026 report described a Senate FY2027 NDAA proposal for a CMMC assessment grant program. That is a historical proposal, not an available grant or enacted funding entitlement. This update has not established its October 2026 legislative status. Do not budget for or apply for funding based on that proposal summary; check the current bill text and any enacted program or official application notice before relying on it. The historical NCODE award figures and separate proposed tax-credit discussion also retain their original source periods.

What CMMC enforcement actions have happened?

This historical July 2, 2026 selected-case table contains 13 cybersecurity-related FCA resolutions totaling $60,393,500, including 10 defense-related resolutions totaling $38,986,778. It is not the complete or current enforcement ledger. For the expanded dataset and its current totals, use the cybersecurity FCA settlements tracker.

Selected DOJ cybersecurity-related FCA resolutions — historical July 2, 2026 snapshot
YearCaseAmountContract contextDefense?
2022Comprehensive Health Services$930,000State Dept. & Air Force medical facilitiesYes
2022Aerojet Rocketdyne$9,000,000Misrepresented cyber compliance on federal contractsYes
2024Guidehouse / Nan McKay$11,300,000Federally funded state programNo
2024ASRC Federal Data Solutions$306,722Medicare beneficiary dataNo
2024Penn State$1,250,00015 DoD/NASA contracts; NIST SP 800-171 failuresYes
2025MORSECORP Inc.$4,600,000Army and Air Force contracts; NIST SP 800-171 requirementsYes
2025Health Net / Centene$11,253,400DoD TRICARE cybersecurity certificationsYes
2025Raytheon / Nightwing$8,400,000~30 DoD contracts; noncompliant internal systemYes
2025Illumina$9,800,000Product cybersecurity vulnerabilitiesNo
2025Aero Turbine / Gallant Capital$1,750,000Air Force contract; NIST SP 800-171 requirementsYes
2025Georgia Tech Research Corp.$875,000Air Force & DARPA contractsYes
2025Swiss Automation$421,234DoD prime and subcontractor; NIST SP 800-171Yes
2026LOGZONE Inc.$507,144Two Navy contracts; NIST SP 800-171 failuresYes

Source: Department of Justice press releases, linked where shown; evidence grade A (DOJ-published amounts) for every row. Full documentation for every resolution is maintained in our enforcement ledger. Totals are The Defense Compliance Report’s calculations from DOJ-published amounts, not official DOJ aggregate statistics. “Defense-related” means the resolution involved DoD-funded contracts, subcontracts, or DoD program certifications. Last verified .

Historical selected-table calculation: 13 resolutions, $60,393,500 total; defense-related subset, 10 resolutions, $38,986,778. These figures describe the rows above, not every publicly announced cyber FCA resolution.

September 1, 2026 update: DOJ announced that Honeywell Aerospace Inc. agreed to pay $2,042,518 to resolve allegations of NIST SP 800-171 noncompliance under a DoD contract. The alleged conduct ran from April 2020 through December 2023. The stated whistleblower share was $375,823. The settlement resolved allegations; DOJ reported no determination of liability.

Source: S10.

The case that explains why third-party verification exists. On , DOJ announced that LOGZONE Inc., a Huntsville, Alabama defense contractor, agreed to pay $507,144 over two Navy contracts spanning to . The company had assessed itself a perfect 110 in SPRS. When the Defense Contract Management Agency assessed the same environment, it scored −170— near the bottom of the −203-to-110 scale. Half the settlement, $253,572, is restitution. A 280-point gap between self-report and government assessment, in one sentence, is the entire argument for CMMC.

Two more patterns worth a writer’s attention. The Raytheon/Nightwing resolution held Nightwing liable as successorfor conduct predating its acquisition of Raytheon’s cyber business — acquirers now inherit cyber-FCA exposure. And the Georgia Tech resolution paid whistleblowers $201,250 of the $875,000 recovery, a reminder of where these cases originate. Separately, the Administrative False Claims Act () now lets agencies pursue smaller cyber misrepresentations directly, without a DOJ suit.

How ready is the defense industrial base?

The most complete public multi-year readiness series we found — Merrill Research’s annual survey commissioned by CyberSheath, a CMMC managed services provider — found only 1% of surveyed contractors felt fully prepared for CMMC assessments in 2025, down from 8% in 2023 and 4% in 2024. Over the same series, the median self-reported SPRS score rose from 20 in 2022 to 60 in 2025. This is self-reported survey data with a commercial sponsor, and we grade it accordingly. We publish it anyway because it is the only multi-year readiness series with a named research firm and disclosed methodology.

Table 9 — Readiness survey provenance
FieldDetail
SeriesState of the DIB Report, annual waves 2022–2025
Research firmMerrill Research
SponsorCyberSheath, a CMMC managed services provider (disclosed in every release)
Published methodology2022 wave: 300 US-based DoD contractors, tested at a 95% confidence level; later-wave sample sizes are not stated in the public releases
Evidence gradeC
Key limitationSelf-reported readiness; commercially sponsored

Source: Merrill Research / CyberSheath State of the DIB releases, 2022–2025; 2025 wave released . Compiled by The Defense Compliance Report; last verified .

The 2025 wave’s other findings, per the release: 69% of contractors claim DFARS compliance through self-assessment, but only 30% have completed medium or high validated assessments; just 42% have submitted SPRS scores at all; 17% still report negative scores (110 is the maximum); 89% report having suffered financial, business, or reputational losses from cyber incidents(57% financial, 56% business, 46% reputational); more than 70% call achieving and maintaining compliance “very difficult”; and eight in ten expect to undergo a C3PAO audit by winter 2026.

These are dated survey responses from a commercially sponsored wave, not a direct assessment of every contractor or proof of current booking constraints. Keep survey findings separate from primary-source certificate counts and from an organization’s own assessment-readiness decision.

What is the CMMC timeline?

The CMMC Program rule became effective . The DFARS acquisition rule became effective , starting Phase 1, which remains active. The suspension halted the Phase II transition; new Level 2 (C3PAO) and Level 3 designations are suspended with no replacement date announced. The original 32 CFR phased schedule is preserved in the historical milestone table below.

Table 10 — CMMC milestones, 2010–2028
DateMilestone
Executive Order 13556 establishes the CUI program
DoD announces CMMC
Interim DFARS rule (85 FR 61505)
CMMC 2.0 announced; model cut from five levels to three
Proposed program rule (88 FR 89058)
Proposed DFARS rule (89 FR 66327); draws 97 public comments
CMMC Program final rule published (89 FR 83092)
Program rule effective; Level 2 assessments begin Jan. 2025
DFARS final rule published (90 FR 43560)
DFARS rule effective — Phase 1 begins (remains active after July 13, 2026 suspension)
Class Deviation 2026-O0025 issued / takes effect: new DFARS Part 240; deviation clause 252.240-7997 prescribed (see Table 11)
Department suspends Phase II transition and all pending/future implementation milestones; Phase 1 continues; no replacement date announced
Phase 2 (original 32 CFR schedule — suspended July 13, 2026): Level 2 (C3PAO) in applicable solicitations
Phase 3 (original schedule — suspended): option-period conditions and Level 3 (DIBCAC)
Phase 4 (original schedule — suspended): full implementation across applicable contracts

Source: Federal Register documents as cited; DoD CIO CMMC page (dodcio.defense.gov/cmmc/About/); DoD Class Deviation 2026-O0025. Evidence grade: Afor every row. Historical figures retain their stated source dates. The July 13, 2026 suspension entry was checked against the Department’s memoranda on September 14, 2026.

Two details from that table that writers get wrong constantly. First, the elapsed time: six years from announcement to enforceable contract clause (2019 to ). Second, the clause numbers. Since , DoD has used Class Deviation 2026-O0025 — part of the Revolutionary FAR Overhaul — to route NIST SP 800-171 assessment mechanics through deviation clause 252.240-7997 in covered solicitations, removing the old -7019 provision from those packages. But class deviations don’t rewrite the codified regulations: current Acquisition.gov DFARS text still lists 252.204-7019 and 252.204-7020 pending formal rulemaking. The operative clause is the one printed in your solicitation or contract.

Table 11 — Which clause should you cite? Status after
Clause / provisionStatusWhat to cite in practice
FAR 52.204-21 (basic safeguarding, 15 controls)Renumbered to FAR 52.240-93 in covered solicitations; title, text, and requirements unchanged; codified FAR still shows 52.204-21Both numbers refer to the same requirements; CMMC Level 1 documentation still references 52.204-21
DFARS 252.204-7012 (safeguarding + 72-hour incident reporting)UnchangedCite as-is — still the foundational clause
DFARS 252.204-7019 (notice of NIST SP 800-171 assessment)Removed from packages issued under the deviation; still appears in codified DFARS pending rulemakingLegacy contracts only; do not cite as a current requirement in new solicitations
DFARS 252.204-7020 (NIST SP 800-171 assessment requirements)Mechanics carried forward through 252.240-7997 in covered solicitations; codified text still lists 7020The clause in your contract controls — new packages use 252.240-7997
DFARS 252.240-7997 (NIST SP 800-171 DoD Assessment Requirements, deviation)New deviation clause; defines Medium and High government-performed assessments only — no “basic” self-assessmentThe operative assessment clause in solicitations issued on or after under the deviation
DFARS 252.204-7021 / 252.204-7025 (CMMC clause and solicitation provision)UnchangedThe contracting instruments for CMMC status requirements

Source: DoD Class Deviation 2026-O0025 and attachments (DARS class deviation index); current DFARS Part 252 text on Acquisition.gov. Evidence grade: A for every row. Compiled by The Defense Compliance Report; last verified .

Which circulating CMMC statistics could we not verify?

Several widely repeated CMMC numbers could not be traced to any primary source, reproducible denominator, or named methodology. We list them here — with what the verified data says instead — so they stop getting recycled. If you originated one of these figures and can share the underlying methodology, we will evaluate it and update this page.

Table 12 — Circulating claims we declined to publish as fact
Circulating claimWhy we could not verify itWhat the verified data says
“Only 8% of contractors requiring Level 2 are certified” (as of early 2026)No source, no denominator, no methodology on any page carrying itCyber AB data: 896 final certificates in Feb. 2026 ≈ 0.8% of the 118,289 projection. The real figure is an order of magnitude lower than the claim.
“A 24–30 month C3PAO assessment backlog by late 2026”Attributed only to unnamed “industry analysts”; no queue data exists from any primary sourceThe published certificate and assessor counts do not establish a national booking backlog or its cause. The cited March 2026 hypothetical ceiling is a model, not measured spare capacity.
“15–20% of small suppliers will exit the DIB because of CMMC”No survey or dataset produces this rangeVerified instead: a >40% small-business decline in the pre-CMMC decade (DoD, 2022) and Reuters-documented suppliers declining to comply (Feb. 2026). The direction is supported; the percentage is invented.
“~80,000 contractors need Level 2 certification”Not pinned to current rule textCite 118,289 (DFARS final rule). The ~80,000 shorthand likely traces to the derived small-entity figure of 80,436.
“All DoD contractors need CMMC”Contradicted by the rule itselfThe rule exempts contracts solely for COTS items and applies based on whether systems handle FCI or CUI.
“Cyber-related FCA cases rose 156% from 2024 to 2025”No DOJ statistic matches; DOJ does not publish a “cyber FCA” category this wayThe countable record is Table 8: publicly announced resolutions and amounts.
“Non-compliance costs $14.82M vs. $5.47M for compliance”Circulates without citation; we could not trace it to any CMMC- or DIB-specific datasetNo verified CMMC-specific cost-of-noncompliance figure exists. The verifiable consequences are contract ineligibility and FCA exposure (Table 8).

Source: The Defense Compliance Report review of circulating vendor statistics pages and sales collateral, –, checked against the primary sources cited throughout this page.

Why these numbers matter right now

The September 29 source snapshot shows continued issuance of Level 2 certificates while the July 13 suspension keeps the original later-phase procurement milestones from acting as current deadlines. DFARS safeguarding and the applicable self-assessment obligations continue; the current written solicitation or contract determines the requirement for a particular organization. DOJ’s September 1 Honeywell announcement also shows that alleged failures under preexisting NIST SP 800-171 contract requirements remain relevant during the suspension. Historical rulemaking projections, sponsored survey results and a contractor’s own contract decision are different kinds of evidence; keep their dates and definitions visible.

Limitations: what this data does and doesn’t show

We publish the caveats because a statistic without its limits is just a slogan.

  • Cyber AB Town Hall figures are official statements at a point in time, not an auditable public registry; monthly deltas can reflect reporting timing as well as issuance.
  • DoD’s entity counts and cost figures are regulatory model outputs built on disclosed assumptions (two offerors per solicitation, five subcontractors per prime proposal, preexisting NIST SP 800-171 implementation) — they are the authoritative estimates, not measurements.
  • There is no public registry of which contractors must certify, so no true compliance rate can be computed by anyone.
  • Survey findings in the readiness section are self-reported and commercially sponsored; we identify the sponsor every time.
  • Our enforcement totals are aggregations of DOJ-published amounts under a stated scope definition, not DOJ statistics.
  • Clause status in Table 11 reflects a class deviation that remains in effect until rescinded or incorporated through rulemaking; the operative clause is always the one in the contract.
  • Derived figures marked as TDCR calculations inherit their inputs’ uncertainty and are rounded as shown.
  • Nothing here is legal, financial, or compliance advice — for obligations under a specific contract, read the clause and consult qualified counsel.

Frequently asked questions

How many companies need CMMC?

DoD estimates 337,968 unique prime and subcontractor entities will be subject to CMMC requirements by Year 4 of implementation, per the DFARS final rule published . Of those, 229,818 — 68% — are small entities.

How many companies need CMMC Level 2 certification?

The DFARS final rule projects 118,289 entities will require Level 2 certification by a C3PAO, or 35% of all impacted entities. A separate, much smaller group of about 6,759 entities will be permitted to self-assess at Level 2.

How many companies are CMMC certified right now?

The Cyber AB’s primary deck reports 2,362 final Level 2 Certificates of CMMC Status, 71 conditional certificates and 151 assessments in progress. A certificate covers an assessed information-system scope; the deck does not provide a unique-company total. See the full certification tracker.

How much does CMMC Level 2 certification cost a small business?

DoD’s official estimate is $101,752 initially and $104,670 over the three-year cycle. That covers assessment, certification, and affirmation activity only.

Does DoD's cost estimate include implementation?

No. The rule excludes implementation and remediation costs on the basis that FAR 52.204-21 (2016) and DFARS 252.204-7012 (2017) already required contractors to implement the underlying safeguards. At Level 3, where requirements are new, DoD did include engineering costs.

How many C3PAOs are there?

The Cyber AB’s September 29, 2026 primary deck reports 117 Authorized or Accredited C3PAOs, 1,179 Certified CMMC Assessors and 681 Lead CCAs. These are ecosystem headcounts, not appointment availability.

Is DOJ enforcing CMMC?

Not CMMC certification itself — no case has done that. DOJ enforces the preexisting cybersecurity obligations CMMC verifies: since 2022, defense-related False Claims Act resolutions total $39.0 million across 10 cases (Historical selected-case snapshot, July 2, 2026; see the live ledger for later cases), most recently LOGZONE’s $507,144 settlement in .

When did Phase 1 start, and what happened to Phase 2?

Phase 1 began and remains active. The suspension halted the Phase II transition; new Level 2 (C3PAO) and Level 3 designations are suspended with no replacement date announced. Confirm your solicitation’s specific designation with your contracting officer.

Is there a CMMC assessment backlog?

The public aggregate certificate and assessor counts do not establish a national booking backlog or its cause. The available data lack the ready-applicant queue, regional or industry fit, assessment scope, team availability, conflicts and calendar information needed to infer one. Ask the assessor about direct, scope-specific availability.

Primary sources

This page is educational reference material, produced independently. It is not legal, financial, or compliance advice.