Clear, technical resources for Defense Industrial Base contractors processing Controlled Unclassified Information. If your organization handles CUI — as a prime or subcontractor — safeguarding obligations under DFARS 252.204-7012 and NIST SP 800-171 remain a current requirement, even with third-party CMMC certification now paused.
Updated July 2026: With Phase 2 suspended, Level 2 self-assessment is the operative path right now — no C3PAO certification is currently required for contract award. That said, the program as designed makes third-party assessment the default for any contract involving CUI, and it may return following the DoD's 60-day review. Building your architecture and documentation toward that standard remains the safe assumption.
DoD estimates approximately 80,000 contractors across the Defense Industrial Base will require Level 2 third-party (C3PAO) certification — effectively any organization that stores, processes, or transmits CUI under a DoD contract.
Don't stand down — the certification is suspended, the standard is not. Keep preparing your architecture and documentation to the full 800-171 bar: it keeps you eligible for award today and ready if third-party certification returns after the review.
The phased rollout is active. Compliance is a current requirement for winning and maintaining defense contracts.
The DoD is inserting Level 2 Self-Assessment requirements into new solicitations. Contractors must have an active SPRS score prior to contract award. If you have not submitted a score, you are already at risk.
The mandatory Level 2 third-party (C3PAO) certification milestone — originally set for November 10, 2026 — was suspended on July 13, 2026 pending a 60-day DoD reform review, citing compliance cost and assessor-capacity concerns. Third-party certification is not currently a condition of contract award. The underlying NIST SP 800-171 standard and your self-assessment obligations are unchanged, so continuing to prepare your SSP and SPRS score is the prudent hedge while the review is underway. Accredited assessors remain listed in the Cyber AB Marketplace.
C3PAO requirements expand to cover all applicable new contracts across the DIB, regardless of CUI classification tier.
C3PAO requirements apply to option periods on existing contracts, completing the transition to universal implementation across the defense supply chain.
Technical guidance on building, documenting, and maintaining a CMMC 2.0 Level 2 compliance posture — without decoding regulatory jargon.
Practical, plain-English breakdowns of the 14 security requirement families and all 110 individual controls — what each requires, how to implement it, and what evidence an assessor will look for.
Browse control family guides →Guides on structuring your System Security Plan and Plan of Action & Milestones — how to map control inheritance, document your environment accurately, and produce artifacts that hold up under C3PAO scrutiny.
Browse SSP & documentation guides →Using JSON, XML, and OSCAL (Open Security Controls Assessment Language) to move away from static spreadsheets toward machine-readable, continuous compliance tracking.
Browse automation resources →Certalo is our AI CMMC assistant — it drafts your SSP from real environment evidence, scores SPRS in real time, builds your POA&M, and prepares the policy and procedure documentation an assessor expects.
To help Defense Industrial Base organizations reduce the cost and time of CMMC assessments while measurably improving their security posture — through plain-language guidance today and agentic tooling soon.
Free, technical resources covering the 110 NIST SP 800-171 controls, SSP and POA&M architecture, scoping decisions, C3PAO selection, and the assessment lifecycle — written for practitioners, not auditors.
AI agents that draft your SSP from real environment evidence, score gaps against SPRS, and keep your POA&M current as your environment changes — built to compress months of manual assessment work into days. Explore Certalo →