Skip to content
complianceofficer

CMMC compliance software that tracks the 110 controls and the rule changes

CMMC compliance software helps a defense contractor prove it protects Controlled Unclassified Information: it maps the 110 NIST SP 800-171 controls to what you already run, tracks the evidence for a Level 2 self-assessment or a C3PAO audit, and keeps your System Security Plan and SPRS score current. Complianceofficer adds the part most CMMC tools skip. It watches the CMMC rule itself, so when something moves like the 13 July 2026 suspension of Phase 2, you hear it from the tool in plain language, not from a LinkedIn post three weeks later.

Scan your CMMC obligations now

Pick defense contracting and CMMC below. The scan returns the obligation register with the last 12 months of regulatory movement, sources linked. No signup, nothing stored.

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation
§ 15 What actually changed

CMMC Phase 2 was suspended on 13 July 2026

Here is the state of play, because most vendor pages still say third-party certification becomes mandatory in November 2026. It does not, at least not on that date.

On 13 July 2026 the Department of War announced the immediate suspension of CMMC Phase 2, the rollout that would have required most contractors handling Controlled Unclassified Information to pass a third-party assessment by an authorized C3PAO starting 10 November 2026. The Pentagon opened a 60-day review of the program and issued a Request for Information on cost and burden, with responses due 14 August 2026. Reporting from WilmerHale, Morgan Lewis and Federal News Network all confirm the same scope.

What did not change is the important part. Phase 1, which took effect on 10 November 2025 and requires a Level 1 or Level 2 self-assessment in applicable solicitations, stays in force. Every contractor's existing duty under DFARS 252.204-7012 to implement the 110 NIST SP 800-171 controls and report incidents within 72 hours is untouched. The 110 controls and the 320 assessment objectives did not move. Only the mandatory third-party verification method is paused. This is exactly the kind of fast-moving change a regulatory change management engine is meant to surface the day it happens.

The 110 controls, across 14 NIST 800-171 families

CMMC Level 2 is NIST SP 800-171 Rev. 2 in full: 110 requirements grouped into 14 control families and checked against 320 assessment objectives. The register below is what the scan builds for a contractor handling CUI, each line tied to the policy and technical control you already have.

  • § 01 Access control across systems and CUI AC
  • § 02 Awareness and training for staff AT
  • § 03 Audit and accountability, log review AU
  • § 04 Configuration management and baselines CM
  • § 05 Identification and authentication, including MFA IA
  • § 06 Incident response and 72-hour reporting IR
  • § 07 Maintenance of systems and tools MA
  • § 08 Media protection and sanitization MP
  • § 09 Personnel security and screening PS
  • § 10 Physical protection of facilities PE
  • § 11 Risk assessment and vulnerability scanning RA
  • § 12 Security assessment and the SSP CA
  • § 13 System and communications protection, encryption SC
  • § 14 System and information integrity, flaw remediation SI

Each family maps to policies, technical controls and the evidence an assessor samples, and it rolls up into the SPRS score you self-report. When the DoW revises the rule, changes a deadline, or updates the underlying NIST standard, the affected lines flag seal-red and the alert explains what moved. The loop is described on how it works.

§ 16 Which level applies

Which CMMC level and path applies to you

Your level depends on the data you handle. The verification method reflects the July 2026 suspension: the self-assessment path is fully active, the third-party path is paused.

Level Who it covers How you verify (July 2026)
Level 1 Contractors handling only Federal Contract Information (FCI) Annual self-assessment of 15 FAR 52.204-21 requirements, affirmed in SPRS
Level 2 (Self) Most contractors and subcontractors handling CUI Self-assessment of the 110 NIST 800-171 controls, SPRS score, annual affirmation
Level 2 (C3PAO) CUI contracts a contracting officer designates as higher priority Third-party certification by an authorized C3PAO, suspended since 13 July 2026
Level 3 The most sensitive CUI, against advanced persistent threats The 110 controls plus a subset of NIST SP 800-172, assessed by the government (DIBCAC)

Roughly 80,000 contractors in the defense supply chain fall under Level 2. If you also carry SOC 2 or ISO 27001, the control overlap with NIST 800-171 is large, and our SOC 2 compliance software and ISO 27001 compliance software pages explain how to reuse the same evidence across frameworks.

CMMC compliance software questions, answered

Is CMMC still required in 2026?

Yes, in part. On 13 July 2026 the Department of War suspended CMMC Phase 2, the mandatory third-party certification rollout scheduled for 10 November 2026, and opened a 60-day review. Phase 1 Level 2 self-assessments, in force since 10 November 2025, still apply, and every contractor's duty under DFARS 252.204-7012 to implement the 110 NIST 800-171 controls is untouched. The controls still apply; only mandatory third-party verification is paused.

What are the CMMC Level 2 requirements?

Level 2 requires a contractor handling CUI to implement all 110 security requirements of NIST SP 800-171 Rev. 2, grouped into 14 control families and validated against 320 assessment objectives. You document them in a System Security Plan, track open items in a POA&M, and report a score to SPRS. As of July 2026 you can meet Level 2 by self-assessment with an annual affirmation, because the C3PAO path is suspended pending the review.

What is the difference between CMMC and NIST 800-171?

NIST SP 800-171 is the underlying standard: 110 requirements for protecting CUI in nonfederal systems. CMMC is the Department of War program that verifies a contractor has actually implemented them. NIST 800-171 is the rulebook and CMMC Level 2 is the check that you follow it. The 110 controls are identical either way, which is why the July 2026 suspension changed the verification method but not a single control.

Can CMMC software make me compliant?

No product makes you CMMC compliant on its own, and no vendor can sell you a certification the DoW recognizes. Compliance comes from actually implementing the 110 controls and then either self-affirming in SPRS or passing an authorized assessment. What software does is cut the labor: it scopes your CUI environment, maps the controls, collects evidence, calculates the SPRS score, and keeps the SSP and POA&M current so verification is faster.

What is a C3PAO and do I still need one?

A C3PAO is a CMMC Third-Party Assessment Organization authorized by the Cyber AB to perform CMMC Level 2 certification assessments. Because Phase 2 was suspended on 13 July 2026, a contracting officer cannot currently mandate a C3PAO certification for most CUI contracts, and the self-assessment path is the active route. Contractors already in a C3PAO assessment can finish, but the requirement to obtain one is paused during the review.

Last updated July 2026. General regulatory information, not legal advice.

Run the compliance scan

§ 99 · Final entry

Get on the early-access list

Leave your work email, confirm the 6-digit code, and we will email you when your spot opens. Nothing is charged before launch.