CMMC Program Update
Last updated September 9, 2026.
The Department of War has suspended CMMC Phase II requirements until further notice. CMMC remains in Phase I, and applicable Level 1 and Level 2 self-assessment requirements remain in effect.
Organizations should continue meeting applicable cybersecurity requirements, including NIST SP 800-171 requirements under DFARS 252.204-7012.
CMMC Support for Defense Contractors
CMMC can affect a defense contractor’s eligibility for certain Department of War contracts and subcontracts. The required level and assessment type depend on the information the organization handles and the terms of the contract.
CISO Global helps contractors determine where they stand, define the assessment boundary, close security and documentation gaps, and prepare for applicable self-assessment requirements or a voluntary independent Level 2 certification assessment.
Organizations that handle CUI generally fall under Level 2. During the Phase II suspension, procurement requirements may include Level 2 (Self), but Level 2 C3PAO certification assessments may not be designated as procurement requirements.
Level 1
Level 2
Level 3
Current CMMC Assessment Status
During the Phase II suspension, procurement documents may require only Level 1 Self or Level 2 Self assessments. Level 2 C3PAO and Level 3 DIBCAC assessments may not be designated as contract requirements during the review. However, C3PAO Level 2 certification assessments remain operational and available to organizations that choose to pursue certification voluntarily.
CMMC Services
CISO Global provides CMMC readiness, advisory, and ongoing compliance support. TalaTek LLC, a wholly owned subsidiary of CISO Global and a Cyber AB-authorized C3PAO, conducts voluntary independent CMMC Level 2 certification assessments. Engagements are structured to follow applicable independence and conflict-of-interest requirements.
Readiness and Advisory Services
CMMC Gap
Assessment
Compare your current program against CMMC and NIST SP 800-171 requirements to identify gaps, priorities, and next steps.
Readiness and
Advisory Support
Prepare for assessment with support for SSPs, POA&Ms, policies, evidence collection, and remediation planning.
Mock CMMC
Assessment
Test readiness before the official assessment by reviewing documentation, evidence, and likely assessor questions.
CMMC Assessment
Support
Organize documentation, respond to evidence requests, and coordinate internal teams during an assessment conducted by an independent C3PAO.
Independent Level 2
Assessment
TalaTek LLC, a wholly owned subsidiary of CISO Global and a Cyber AB-authorized C3PAO, conducts voluntary independent CMMC Level 2 certification assessments in accordance with applicable program and independence requirements.
Ongoing CMMC
Readiness
Keep controls, documentation, evidence, and remediation work current between assessments and annual affirmations.
When CMMC Services Are the Right Fit
- A solicitation or contract includes a CMMC requirement
- Your organization handles FCI or CUI
- The CUI boundary or assessment scope is unclear
- Your SSP, POA&M, SPRS score, policies, or evidence need work
- A Level 1 or Level 2 self-assessment is approaching
- Voluntary Level 2 certification would support a customer or supply-chain requirement
Choose Your CMMC Starting Point
Start with the support that matches your current position, whether you are defining scope, preparing for an assessment, pursuing independent certification, or maintaining readiness.
Determine Your Current Status
Define your scope and compare your program against CMMC and NIST SP 800-171 requirements.
Prepare for Assessment
Close priority gaps and organize the policies, procedures, documentation, and evidence assessors will review.
Complete an Independent Level 2 Assessment
Organizations may continue to pursue voluntary Level 2 certification during the Phase II suspension. TalaTek conducts CMMC Level 2 certification assessments as a Cyber AB-authorized C3PAO in accordance with applicable CMMC and Cyber AB conflict-of-interest requirements.
Maintain Ongoing Readiness
Keep required safeguards, documentation, evidence, affirmations, and remediation work current as systems and contract requirements change.
Maintain Readiness Between Assessments
Cybersecurity responsibilities continue after assessment results are submitted. Contractors must keep required controls operating, update their SSP and evidence as systems change, complete applicable affirmations, and prepare for future contract or assessment requirements.
CISO Global helps organizations manage this work through ongoing control tracking, evidence management, reporting, and remediation support.
Prepare for Your CMMC Requirements
Understand your current requirements, address gaps, and move forward with a clear CMMC plan.
Frequently Asked Questions
What is CMMC?
The Cybersecurity Maturity Model Certification (CMMC) is a federal program for assessing how defense contractors protect Federal Contract Information and Controlled Unclassified Information. The required level and assessment method depend on the terms of the applicable contract.
What CMMC level applies to my organization?
The required CMMC level depends on the information your organization handles and the requirements in the applicable defense contract.
- Level 1: Applies to organizations handling Federal Contract Information (FCI) and is validated through self-assessment.
- Level 2: Applies to organizations handling Controlled Unclassified Information (CUI) and is based on NIST SP 800-171 Rev. 2.
During the current Phase II suspension, Level 1 (Self) and Level 2 (Self) assessments may be included in procurement requirements.
What is a C3PAO?
A Certified Third-Party Assessment Organization (C3PAO) is authorized to conduct formal CMMC assessments. TalaTek LLC, a wholly owned subsidiary of CISO Global, is a Cyber AB-authorized C3PAO.
When is a C3PAO assessment required?
Under the CMMC program, certain Level 2 requirements may require certification through a C3PAO assessment. During the current Phase II suspension, Level 2 C3PAO assessments are not being designated as procurement requirements. Organizations may still choose to pursue a Level 2 certification assessment voluntarily.
How is CMMC different from NIST SP 800-171?
NIST SP 800-171 defines the security requirements for protecting CUI. CMMC uses those requirements and adds an assessment and certification process to verify that the required practices are implemented.
Can CISO Global help before the official assessment?
Yes. CISO Global can help with gap assessments, readiness planning, documentation, evidence collection, mock assessments, remediation guidance, and assessment support before a formal C3PAO assessment.
How often must organizations maintain CMMC compliance?
Level 1 requires an annual self-assessment and affirmation. Level 2 (Self) requires a self-assessment every three years and an annual affirmation. Contractors must continue maintaining the safeguards and documentation required by their applicable contracts between assessments.
What does the CMMC Phase II suspension mean for contractors?
The suspension pauses the CMMC Phase II requirements that were scheduled to begin November 10, 2026. CMMC remains in Phase I, and applicable Level 1 and Level 2 self-assessment requirements remain in effect. Contractors should continue meeting the cybersecurity requirements that apply to their contracts, including NIST SP 800-171 requirements under DFARS 252.204-7012.