Do I Still Need CMMC? Yes. Here’s Exactly What’s Required Right Now
Nick Sally · Certified CMMC Registered Practitioner · July 25, 2026
Since July 13 I’ve gotten a dozen versions of the same call. An owner or a multi-hat IT manager, half relieved and half suspicious, asking: so do we still need to do CMMC?
Fair question. Here’s the answer I give them, with receipts.
If you only handle Federal Contract Information (FCI)
You’re at CMMC Level 1. That’s the 15 basic safeguarding requirements of FAR 52.204-21, a self-assessment, a score in SPRS, and an annual affirmation. Light lift. Do it honestly and move on.
If you touch CUI
You’re at Level 2, and the pause changed less than you’d hope. DFARS 252.204-7012 has required all 110 controls of NIST SP 800-171 Rev 2 since 2017, and the suspension memo reaffirms it by name.
New solicitations still carry CMMC. The memo instructs program offices that they “must only include the need for CMMC Level 1 (Self) or Level 2 (Self) assessments.” Self is the operative word. The requirement to assess yourself against the full control set, post the score, and affirm it annually is alive and enforced.
The part folks miss: your prime doesn’t care about the pause
I hold paper from my customers’ primes demanding compliance documentation now. One put it plainly: if you’re going to stay our sub, we want your paper today. Primes can’t demand a C3PAO certificate that no longer exists, so they’re back to demanding your SPRS score and your questionnaire answers.
The requirement doesn’t arrive on a calendar date. It arrives through a flowdown, and you can’t predict when. Win a CUI-bearing contract next month and you need all of this next month.
Do I need GCC High for it?
No regulation names a cloud. Plenty of contractors satisfy 800-171 elsewhere. If you handle export-controlled data (ITAR/EAR) or want the boring, defensible answer for CUI in Microsoft 365, GCC High is that answer, and it’s where my own customers land.
The government told you what to do next
Straight from the department’s own post-suspension FAQ:
“The best way that company can prepare for CMMC is by carefully conducting a self-assessment of their contractor-owned information system(s) to make sure they have implemented the necessary cybersecurity measures . . . If the self-assessment identifies any unmet requirements, companies should take corrective action to address those gaps.”
That’s the clearest the government has ever been about your homework. Do the self-assessment. Fix what it finds. Sign it with a straight face.