Home
Training & Education
CMMC Phase I Requirements During the Phase II Pause: What Defense Contractors Must Still Do
CMMC Phase I Requirements During the Phase II Pause: What Defense Contractors Must Still Do
Updated August 4, 2026
The transition to CMMC Phase II has been suspended, but CMMC Phase I requirements remain firmly in place.
That is the most important distinction defense contractors need to understand following the Department of War’s July 13, 2026 announcement.
The Department suspended the Phase II implementation milestones that were scheduled to begin on November 10, 2026. It did not cancel CMMC, eliminate Phase I self-assessments, or remove contractors’ existing obligations to protect Federal Contract Information and Controlled Unclassified Information.
According to the Department’s official announcement, all Phase I self-assessment requirements remain active while the Department conducts its review of the program. The Department also plans to continue cybersecurity enforcement through NIST SP 800-171 Revision 2 self-assessments and selected government-led assessments.
What CMMC Phase I requirements still apply?
CMMC Phase I requirements may require a contractor to complete either a CMMC Level 1 Self or CMMC Level 2 Self assessment, depending on the information processed, stored, or transmitted during contract performance.
Level 1 Self assessment generally applies when a contractor information system handles Federal Contract Information. Level 2 Self assessment generally applies when a contractor-owned information system handles Controlled Unclassified Information.
Applicable contractors must establish the correct assessment scope, complete the required self-assessment, submit results in the Supplier Performance Risk System, maintain the required CMMC status, and submit affirmations of continuous compliance. Existing FAR, DFARS, NIST SP 800-171, CUI safeguarding, incident-reporting, and subcontract flowdown obligations may also continue to apply.
CMMC Phase I is not the same as CMMC Level 1
The terms sound similar, but they describe two different parts of the CMMC program.
CMMC Phase I refers to the first stage of the Department’s contractual implementation schedule.
CMMC Level 1 refers to the cybersecurity level associated with basic safeguarding of Federal Contract Information.
CMMC Phase I began on November 10, 2025. The Department is currently paused within that implementation phase while it reviews the program. During this period, applicable procurements may use CMMC Level 1 Self-assessment or CMMC Level 2 Self-assessment requirements rather than the Phase II third-party assessment requirements that were scheduled to expand in November 2026.
Understanding that difference prevents two common mistakes:
- Assuming Phase I applies only to CMMC Level 1.
- Assuming the Phase II pause also suspended CMMC Level 2 requirements.
Under the current official guidance, CMMC Phase I requirements can include either Level 1 Self-assessment or Level 2 Self-assessment, depending on whether the contractor system will handle FCI or CUI.
Which CMMC Phase I requirements apply to your company?
The required CMMC level should be identified in the applicable solicitation and resulting contract.
During Phase I, the Department’s stated intent is to use:
- CMMC Level 1 Self-assessment when only FCI will be processed, stored, or transmitted.
- CMMC Level 2 Self-assessment when CUI will be processed, stored, or transmitted in contractor-owned information systems.
The Department’s current FAQ makes clear that a company handling only FCI does not need an independent assessment but may require a Level 1 self-assessment. When CUI is handled in contractor-owned systems, the applicable Phase I requirement is intended to be Level 2 Self rather than an independent C3PAO assessment.
Contractors should not determine their required level from assumptions, marketing materials, or the general sensitivity of a project.
Review:
- The solicitation
- The prime contract
- The subcontract
- Applicable FAR and DFARS clauses
- Statements of work
- Data requirements
- Prime-contractor flowdowns
- The information systems that will perform the work
- Whether those systems will process, store, or transmit FCI or CUI
The presence of CUI in one program does not necessarily place every company system within the same CMMC scope. The required CMMC status and assessment scope must correspond to the systems actually used for contract performance.
CMMC Phase I requirements at a glance
Level 1 Self-assessment
Protected information: Federal Contract Information
Security standard: 15 requirements from FAR 52.204-21
Assessment frequency: Annually
Affirmation: After the assessment and annually
Results submitted to: SPRS
POA&Ms: Not permitted
Level 2 Self-assessment
Protected information: Controlled Unclassified Information
Security standard: 110 requirements from NIST SP 800-171 Revision 2
Assessment frequency: Every three years
Affirmation: After the assessment and annually thereafter
Results submitted to: SPRS
POA&Ms: Permitted only under limited conditions and subject to a 180-day closeout period
These distinctions are summarized on the official Department of War CMMC overview and established in 32 CFR Part 170.
CMMC Phase I requirements for Level 1 Self
CMMC Level 1 Self-assessment is designed to verify basic safeguarding of FCI.
Federal Contract Information generally includes nonpublic information provided by or generated for the Government under a contract to develop or deliver a product or service. It does not include information that the Government has made public or simple transactional information used to process payments.
The official definition and safeguarding requirements are contained in FAR 52.204-21.
1. Implement all 15 FAR safeguarding requirements
CMMC Phase I requirements for Level 1 are based on the 15 safeguarding requirements contained in FAR 52.204-21.
These requirements address areas such as:
- Limiting system access to authorized users
- Restricting users to permitted transactions and functions
- Controlling connections to external systems
- Controlling information posted to public systems
- Identifying and authenticating users and devices
- Sanitizing or destroying media containing FCI
- Protecting communications at system boundaries
- Correcting system flaws
- Maintaining malicious-code protection
- Updating malicious-code protection mechanisms
- Performing system scans
A contractor cannot obtain Final Level 1 Self status while leaving one or more requirements unresolved.
2. Define the Level 1 assessment scope
Before completing the assessment, the contractor must identify the systems that process, store, or transmit FCI.
The Level 1 scope should consider the relevant people, technology, facilities, and external service providers within the company’s environment. Systems that do not process, store, or transmit FCI may be outside the Level 1 scope.
The scope should be based on how FCI actually moves through the business—not simply on a list of computers owned by the company.
3. Complete the Level 1 self-assessment annually
The contractor evaluates its own implementation of the Level 1 requirements.
Every applicable requirement must receive a MET result. CMMC Level 1 does not use a partial numerical score in the same way as Level 2. The organization must satisfy all applicable Level 1 requirements to achieve Final Level 1 Self status.
4. Submit the assessment results in SPRS
The results of the Level 1 self-assessment must be submitted to the Supplier Performance Risk System (SPRS).
SPRS is also used by the Department to verify the company’s CMMC status and assessment information for applicable procurements.
5. Submit the required affirmation
An affirming official must attest to the organization’s continuing compliance after the Level 1 assessment and annually thereafter.
The affirmation should not be treated as a routine administrative signature. The affirming official is representing that the organization continues to satisfy the applicable security requirements.
6. Do not rely on a POA&M
Plans of Action and Milestones are not permitted for CMMC Level 1.
A company cannot obtain a Level 1 CMMC status by identifying incomplete requirements and promising to correct them later. All 15 requirements must be satisfied.
CMMC Phase I requirements for Level 2 Self-assessment
CMMC Level 2 Self-assessment is intended for applicable contractor systems that process, store, or transmit CUI.
During the current Phase II pause, the Department states that Level 2 Self may be required when CUI will be handled in contractor-owned information systems.
1. Implement the 110 NIST SP 800-171 Revision 2 requirements
Level 2 is based on the 110 security requirements in NIST SP 800-171 Revision 2.
These requirements cover 14 security families:
- Access Control
- Awareness and Training
- Audit and Accountability
- Configuration Management
- Identification and Authentication
- Incident Response
- Maintenance
- Media Protection
- Personnel Security
- Physical Protection
- Risk Assessment
- Security Assessment
- System and Communications Protection
- System and Information Integrity
The Department’s current FAQ confirms that Revision 2 remains the assessment standard during the interim period while Revision 3 awaits future incorporation through rulemaking.
2. Define the CMMC Level 2 scope
CMMC Phase I requirements do not apply automatically to every asset owned by the company.
The contractor must identify and categorize the assets within the Level 2 assessment environment.
The official scoping rule identifies categories including:
- CUI assets
- Security protection assets (SPAs)
- Contractor risk-managed assets (CRMAs)
- Specialized assets
- Out-of-scope assets
CUI assets process, store, or transmit CUI. Security protection assets provide security functions or capabilities to the CMMC environment. Other asset categories have separate documentation and assessment treatment.
The organization should document its asset inventory, network diagram, System Security Plan, external service providers, and the systems used to protect CUI.
3. Complete the Level 2 self-assessment
The organization must conduct its Level 2 self-assessment using the applicable CMMC procedures and scoring methodology.
The assessment results submitted to SPRS include information such as:
- CMMC level
- CMMC status date
- Assessment scope
- Associated CAGE codes
- Overall assessment score
- POA&M use and compliance status, when applicable
Level 2 self-assessments are generally valid for three years, but the organization must also complete the required annual affirmations.
4. Maintain an accurate System Security Plan
The System Security Plan is central to Level 2 readiness.
It should accurately describe:
- The systems included in the assessment scope
- The environment’s boundaries
- How the security requirements are implemented
- Connections to external systems
- Cloud services
- External service providers
- Security responsibilities
- Network architecture
- CUI flows
- Changes to the environment
The Department’s current FAQ warns that the absence of an up-to-date SSP can result in the assessment being incomplete and the organization receiving no CMMC score.
5. Use POA&Ms only where permitted
Unlike Level 1, Level 2 can allow limited use of a POA&M.
However, not every requirement is eligible. Certain critical requirements cannot be placed on a POA&M, and the assessment must meet the applicable minimum conditions for a Conditional Level 2 Self status.
When conditional status is obtained, all eligible unresolved items must be remediated and successfully closed within 180 days. If the POA&M is not closed within the required period, the conditional status expires.
6. Submit the assessment and affirmation in SPRS
To support contract eligibility where Level 2 Self is required, the contractor must have the appropriate current CMMC status and affirmation in SPRS.
Affirmation is required at the time of the assessment and annually thereafter.
A three-year assessment cycle does not mean the organization can ignore compliance for three years. Annual affirmation requires the company to confirm that it continues to satisfy the applicable requirements.
CMMC Phase I requirements and contract eligibility
The CMMC requirement should appear in the solicitation.
DFARS 252.204-7025 allows the solicitation to identify the required level as:
- CMMC Level 1 Self
- CMMC Level 2 Self
- CMMC Level 2 C3PAO
- CMMC Level 3 DIBCAC
During the current Phase II pause, the Department has limited implementation to the self-assessment levels.
When a CMMC requirement is included, the applicable status is required before award for each contractor information system that will process, store, or transmit FCI or CUI during contract performance.
The offeror must have:
- The required current CMMC status in SPRS
- A current affirmation of continuous compliance
- The appropriate CMMC Unique Identifier for each system used to perform the contract
The contracting officer can use those identifiers to verify that the systems proposed for contract performance are covered by the appropriate CMMC status.
Existing FAR and DFARS obligations remain important
CMMC Phase I requirements do not replace the underlying contract clauses that require contractors to safeguard federal information.
FAR 52.204-21
FAR 52.204-21 requires basic safeguarding of covered contractor information systems that process, store, or transmit FCI.
These obligations can apply independently of the timing of a CMMC assessment.
DFARS 252.204-7012
DFARS 252.204-7012 establishes safeguarding, cloud-service, cyber-incident reporting, evidence-preservation, and subcontract flowdown obligations for covered defense information.
The Department’s CMMC guidance specifically states that the Phase II pause does not eliminate companies’ responsibilities under DFARS 252.204-7012.
DFARS 252.204-7019 and 252.204-7020
DFARS 252.204-7019 can require an offeror to have a current NIST SP 800-171 DoD Assessment score in SPRS.
DFARS 252.204-7020 addresses Government access for Medium or High assessments and includes requirements involving applicable subcontractors.
Contractors should not assume that the CMMC Phase II pause removed these separate contract requirements.
CMMC Phase I requirements still include physical CUI protection
CMMC readiness is not limited to networks, cloud systems, and cybersecurity software.
CUI can also exist in:
- Printed drawings
- Manufacturing travelers
- Inspection documents
- Shipping records
- Removable media
- Production workstations
- Quality-control areas
- Storage cabinets
- Conference rooms
- Printer and scanner stations
Organizations must protect hard-copy CUI even when the CMMC assessment requirement is focused on contractor information systems.
The Department’s current FAQ states that organizations handling only hard-copy CUI may not require a third-party assessment, but they remain obligated to safeguard that information when applicable contract clauses are included and flowed down. It specifically points contractors to NIST SP 800-171 and DoDI 5200.48 for applicable protection and handling requirements.
Physical implementation may include:
- Marking and cover-sheet procedures
- Restricted-area identification
- Visitor escort procedures
- Access logs
- Secure storage
- Printer and scanner controls
- Shipping procedures
- Media protection
- Authorized destruction methods
- Employee training
CUI Supply offers CUI Compliance Packs, CUI signs, and CUI labels that can support documented marking and physical-handling procedures.
These products support the execution of a compliance program but do not independently create CMMC status or satisfy every security requirement.
CMMC Phase I requirements for cloud and external service providers
Contractors must evaluate cloud providers, managed service providers, managed security service providers, and other external organizations that support the CMMC environment.
When a cloud service provider processes, stores, or transmits CUI, DFARS 252.204-7012 requires the contractor to ensure the service meets the applicable FedRAMP Moderate requirements or approved equivalency conditions.
The Department’s official FAQ also explains that MSPs and MSSPs can be within an organization’s assessment scope when they process CUI or provide security functions for the environment, even when the provider does not need a separate CMMC certification of its own.
Contractors should document:
- The service being provided
- Whether the provider accesses CUI
- Whether the provider handles security protection data
- The systems and assets involved
- Shared security responsibilities
- Contractual security requirements
- Evidence available for the assessment
- Incident-reporting procedures
- Data return and destruction procedures
Outsourcing IT does not outsource the contractor’s responsibility for meeting applicable CMMC Phase I requirements.
What changed under the Phase II pause?
The pause affected the expansion of independent certification requirements.
During the announced suspension, program managers and requiring activities are permitted to use Level 1 Self or Level 2 Self requirements. They may not designate Level 2 C3PAO or Level 3 DIBCAC assessment requirements during the suspension period.
The Department is also conducting a review intended to examine program burden, scalability, assessment consistency, implementation, and support for small and nontraditional businesses.
What did not change?
The following did not automatically disappear:
- CMMC Phase I requirements
- Level 1 and Level 2 self-assessments
- Annual affirmations
- SPRS submissions
- Contract-specific CMMC status requirements
- FAR 52.204-21 safeguarding obligations
- DFARS 252.204-7012 obligations
- NIST SP 800-171 requirements
- NIST SP 800-171 DoD Assessment requirements
- CUI safeguarding and handling
- Cyber-incident reporting
- Subcontractor flowdowns
- Responsibility for cloud and external service providers
Contractors should continue reviewing each solicitation, contract, and subcontract individually rather than relying on a generalized interpretation of the pause.
CMMC Phase I requirements checklist
Defense contractors can use this checklist to evaluate their current position:
- Identify which contracts involve FCI
- Identify which contracts involve CUI
- Review each solicitation and contract for its required CMMC level
- Confirm every system that will process, store, or transmit FCI or CUI
- Establish the correct CMMC assessment scope
- Complete the appropriate Level 1 or Level 2 self-assessment
- Confirm that assessment results are entered correctly in SPRS
- Verify that every applicable environment has a CMMC UID
- Submit the required affirmation
- Update the System Security Plan
- Review asset inventories and network diagrams
- Review POA&M eligibility and closeout deadlines
- Confirm cloud-provider requirements
- Document MSP and MSSP responsibilities
- Review subcontractor flowdowns
- Test physical CUI-handling procedures
- Organize evidence supporting each implemented requirement
- Train employees on their specific responsibilities
The official CMMC FAQ recommends that businesses prepare by carefully self-assessing their contractor-owned systems, identifying unmet requirements, correcting gaps, and fully implementing the necessary security measures.
The Phase II pause is not permission to ignore Phase I
The Department’s announcement provides contractors with additional time before the wider expansion of third-party certification requirements.
It does not provide permission to stop protecting FCI or CUI.
CMMC Phase I requirements remain part of applicable procurement and contract decisions. Contractors may still need current self-assessment results, accurate assessment scopes, SPRS records, CMMC UIDs, annual affirmations, and evidence that security requirements are implemented.
The companies in the strongest position will be those that use the pause to improve accuracy rather than simply delay activity.
That means knowing:
- Which information requires protection
- Which systems handle it
- Which assessment applies
- Which security requirements are complete
- Which gaps remain
- Which suppliers and service providers are involved
- Which evidence proves that controls are operating
The deadline may have changed. The responsibility to safeguard federal information has not.
Frequently Asked Questions
Are CMMC Phase I requirements still active?
Yes. The Department of War has explicitly stated that all Phase I self-assessment requirements remain firmly in place during the Phase II suspension.
What assessments can be required during CMMC Phase I?
Applicable procurements may require CMMC Level 1 Self or CMMC Level 2 Self assessments. During the current suspension, Level 2 C3PAO and Level 3 DIBCAC requirements may not be designated.
Does CMMC Level 1 apply to CUI?
No. Level 1 is designed around basic safeguarding of FCI. CUI handled in contractor-owned information systems generally aligns with CMMC Level 2 requirements.
How often is a CMMC Level 1 self-assessment required?
A Level 1 self-assessment is required annually, along with the required affirmation of continuous compliance.
How often is a CMMC Level 2 Self assessment required?
A Level 2 Self assessment is generally required every three years. An affirmation of compliance is required at the time of assessment and annually thereafter.
Are POA&Ms allowed during Phase I?
POA&Ms are not permitted for Level 1. Limited POA&M use is permitted for Level 2 when all applicable conditions are met, and successful closeout is required within 180 days.
Do contractors still need an SPRS score?
Applicable contractors may still need current NIST SP 800-171 DoD Assessment information under DFARS 252.204-7019 and 252.204-7020. Contractors subject to CMMC Phase I requirements must also submit the applicable CMMC self-assessment and affirmation information in SPRS.
Does the Phase II pause eliminate DFARS 252.204-7012?
No. The Department’s official CMMC guidance states that the pause does not eliminate the requirement to protect information in accordance with DFARS 252.204-7012.
Do hard-copy CUI documents still require protection?
Yes. Contractors and subcontractors remain responsible for protecting hard-copy CUI under applicable contract and safeguarding requirements, even when a particular paper-only environment does not require a third-party CMMC assessment.
Official sources
All external references below are official United States Government or military sources:
- Department of War announcement suspending CMMC Phase II requirements
- Department of War CMMC overview
- Official CMMC Frequently Asked Questions, Revision 6
- 32 CFR Part 170—CMMC Program
- 32 CFR 170.19—CMMC Scoping
- FAR 52.204-21—Basic Safeguarding
- DFARS 252.204-7012
- DFARS 252.204-7019
- DFARS 252.204-7020
- DFARS 252.204-7021
- DFARS 252.204-7025
- NIST SP 800-171 Revision 2
- National Archives CUI Registry
- DoDI 5200.48—Controlled Unclassified Information
This article is provided for general educational purposes and is not legal, contractual, cybersecurity, or certification advice.
- #32 CFR Part 170
- #32 CFR Part 2002
- #CDI
- #Cloud Service Providers
- #CMMC Annual Affirmation
- #CMMC Assessment
- #CMMC Assessment Scope
- #CMMC Compliance
- #CMMC Contract Requirements
- #CMMC Level 1
- #CMMC Level 1 Self Assessment
- #CMMC Level 2
- #CMMC Level 2 Self Assessment
- #CMMC Phase 1
- #CMMC Phase I
- #CMMC Phase I Requirements
- #CMMC Phase II Pause
- #CMMC Readiness
- #CMMC Requirements
- #CMMC Scoping
- #CMMC Self Assessment
- #CMMC SPRS Submission
- #Covered Defense Information
- #CUI
- #CUI Access Control
- #CUI Cover Sheets
- #CUI Data Flow
- #CUI Destruction
- #CUI Identification
- #CUI Labels
- #CUI Marking
- #CUI Physical Security
- #CUI Safeguarding
- #CUI Scoping
- #CUI Shipping
- #CUI Signs
- #CUI Subcontractors
- #CUI Supply Chain
- #CUI Visitor Management
- #Cybersecurity Compliance
- #Defense Contractor Compliance
- #Defense Contractors
- #Defense Industrial Base
- #DFARS 252.204-7012
- #DFARS 252.204-7019
- #DFARS 252.204-7020
- #DFARS 252.204-7021
- #DFARS 252.204-7025
- #DFARS Compliance
- #DIB Cybersecurity
- #DoD Contractors
- #DoDI 5200.48
- #FAR 52.204-21
- #FCI
- #FCI Protection
- #Federal Contract Information
- #Managed Service Providers
- #MSP Compliance
- #NIST 800-171 Compliance
- #NIST 800-171 Self Assessment
- #NIST SP 800-171
- #Physical Security
- #POA&M
- #POA&M Closeout
- #SPRS
- #SPRS Score
- #SSP
- #Subcontractor Compliance
- #Supplier Performance Risk System
- #System Security Plan
- #Visitor Control
Share

