CMMC FAQs
CMMC Frequently Asked Questions for Business Leaders
Last Updated: August 2026
The Cybersecurity Maturity Model Certification (CMMC) program can quickly become complicated. For business leaders, the most important questions are often much simpler:
- Does CMMC apply to us?
- What information are we protecting?
- What level do we need?
- And where do we start?
The following answers are designed to provide executives with a practical understanding of CMMC and the decisions their organizations should be making now.
1. Is CMMC paused in 2026?
CMMC Phase II implementation is suspended. The underlying cybersecurity requirements are not.
On July 13, 2026, the Department of War suspended implementation of CMMC Phase II, which had been scheduled to begin November 10, 2026, while it conducts a broader review of the program. Phase I remains in effect.
The suspension changes the timing of when certain CMMC certification requirements will be implemented through the phased rollout. It does not mean defense contractors can stop protecting Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) or stop meeting cybersecurity requirements that already apply through their contracts.
Many of the cybersecurity requirements CMMC is designed to verify existed before CMMC. For organizations handling CUI, that includes applicable requirements to implement NIST SP 800-171. The Department has also stated that applicable Phase I self-assessment requirements remain in place.
A useful way for business leaders to think about the announcement is:
The government has paused part of the process for verifying CMMC compliance. It has not paused the cybersecurity requirements CMMC is intended to verify.
Executive takeaway: Do not pause your cybersecurity or CMMC readiness work. Use this time to understand what requirements apply to your organization, identify your gaps, define your scope, and build a roadmap toward readiness.
2. What is still required during the CMMC Phase II suspension?
Phase I remains in effect, and existing contractual cybersecurity obligations have not disappeared.
The Department has stated that applicable Phase I self-assessment requirements remain in place. It also continues to enforce applicable requirements for protecting sensitive government information through existing contractual requirements, self-assessments, and selected government-led assessments.
For organizations subject to existing defense-contract cybersecurity requirements, obligations involving NIST SP 800-171 and the NIST SP 800-171 DoD Assessment process may also continue to apply independently of the CMMC Phase II suspension.
Executive takeaway: The way the government verifies compliance may evolve. The responsibility to protect government information has not.
3. Does CMMC apply to my company?
It depends primarily on your contract and the information your organization will process, store, or transmit while performing the work.
CMMC is designed to protect two primary categories of information:
- Federal Contract Information (FCI), which generally drives Level 1 requirements.
- Controlled Unclassified Information (CUI), which generally drives Level 2 requirements and, for certain higher-priority programs, may require Level 3.
CMMC requirements can apply to both prime contractors and subcontractors when applicable government information and contractual requirements are involved.
Executive takeaway: Do not determine CMMC applicability simply by your company's size or the fact that you sell to the government. Start with your contracts and your information.
4. What is Federal Contract Information?
Federal Contract Information (FCI) is non-public information provided by or generated for the government under a contract to develop or deliver a product or service.
Importantly, the federal definition excludes information the government has made public and simple transactional information, such as information necessary to process payments.
Executive takeaway: Not every piece of information associated with a government sale is automatically FCI.
5. What is Controlled Unclassified Information (CUI)?
Controlled Unclassified Information is government information that is not classified but requires safeguarding or controls on how it is shared under applicable law, regulation, or government-wide policy.
Examples can include certain technical, engineering, export-controlled, critical infrastructure, privacy, procurement, or other information when it falls within an authorized CUI category.
The federal CUI Registry maintained by the National Archives and Records Administration is the government's authoritative resource for CUI categories.
Executive takeaway: CUI is not simply "important information" or anything associated with a defense contract. It is a defined category of government information subject to specific safeguarding or dissemination requirements.
6. What is the difference between CMMC Level 1 and Level 2?
At the executive level, the distinction is straightforward.
Level 1 focuses on protecting Federal Contract Information (FCI).
Level 1 includes 15 basic safeguarding requirements. Organizations subject to Level 1 must complete the applicable self-assessment and an annual affirmation of continuous compliance. Level 1 does not permit the use of a Plan of Action and Milestones (POA&M) to obtain the required final status.
Level 2 focuses on protecting Controlled Unclassified Information (CUI).
Level 2 incorporates the 110 security requirements from NIST Special Publication 800-171 Revision 2. Depending on the applicable requirement, Level 2 may involve a self-assessment or certification assessment. A Level 2 self-assessment is generally valid for three years, with an affirmation of continuous compliance required annually.
During the current Phase I implementation, applicable Level 2 self-assessment requirements remain in effect.
Executive takeaway: One of the first questions leadership should answer is not "How do we become Level 2?" It is "What information do we actually have, and what level does our contract require?"
7. Does selling to the Department of War automatically mean we have CUI?
No. Selling a product or service to the Department does not, by itself, make all information associated with that transaction CUI.
Likewise, selling to a defense prime does not automatically make all information received from that prime CUI.
Organizations need to understand what information they actually receive or create in performing the contract, how that information is identified, and what contractual requirements apply to it.
Executive takeaway: Follow the information, not simply the customer.
8. We sell COTS products. Does that mean CMMC does not apply to us?
Not necessarily.
Commercially available off-the-shelf (COTS) items receive an important exception under current defense acquisition rules. CMMC requirements generally do not apply to a contract solely for the acquisition of COTS items.
The important word is “solely.”
A company that sells COTS products can still perform other work that is subject to CMMC.
For example, imagine a manufacturer sells a standard commercial component available from its normal catalog. A defense prime purchases that component in exactly the same form in which it is sold commercially. If the subcontract is solely for that COTS item, the COTS exception may apply.
Now imagine the same manufacturer receives a separate defense subcontract to produce a specialized component. To perform that work, the prime provides technical drawings or other information that is CUI. The fact that the manufacturer also sells COTS products does not automatically exempt this separate work from CMMC. The organization must evaluate the information it receives, the work being performed, and the requirements of that particular contract or subcontract.
A company can therefore have COTS work and CMMC-covered work at the same time.
Executive takeaway: Do not ask only, “Do we sell COTS products?” Ask, “Is this particular contract solely for COTS items, and are we receiving, creating, processing, storing, or transmitting FCI or CUI as part of other defense work?”
9. Does CMMC apply to our subcontractors and suppliers?
Yes, it can, and understanding your supply chain is an important part of CMMC readiness.
CMMC does not necessarily stop with the prime contractor. If your organization provides FCI or CUI to subcontractors or suppliers so they can perform their work, you need to understand where that information is going and what requirements apply.
For example, a manufacturer may receive CUI from a defense prime and then provide a portion of that information to another company manufacturing a specialized component. If that subcontractor needs the CUI to perform its work, applicable cybersecurity and contractual requirements must be addressed throughout that supply chain.
Organizations should understand which third parties receive FCI or CUI, what information they actually need, what requirements must be flowed down, and whether applicable CMMC and contractual requirements have been satisfied before FCI or CUI is provided to a subcontractor or supplier.
External service providers and cloud service providers may also affect CMMC scope and requirements when they process, store, transmit, or provide security protection for applicable information or systems.
At the same time, organizations should not assume every vendor requires CMMC. The analysis depends on the services being provided, the information and systems involved, and the applicable contractual requirements.
Executive takeaway: Know where your sensitive government information goes. CMMC readiness includes understanding not only how your organization protects FCI and CUI, but who you share it with, why they need it, and what requirements apply before you give them access.
10. Does our entire company have to be inside our CMMC environment?
Not necessarily.
CMMC scoping focuses on the systems and assets that process, store, or transmit the information being protected, along with other applicable assets that provide security protection or otherwise fall within the applicable scoping rules.
For many organizations, understanding where FCI or CUI actually flows can significantly affect the size and complexity of the CMMC environment.
Thoughtful architecture and information handling can help organizations appropriately limit scope, but scope must ultimately reflect where FCI or CUI is actually processed, stored, transmitted, or protected.
Executive takeaway: Understand your information flows and scope before you start buying technology or redesigning your entire enterprise.
11. Who should own CMMC inside our organization?
CMMC should have a program owner, not simply an IT owner.
Technology is an important part of CMMC, but achieving and sustaining readiness can involve leadership, IT, contracts, legal, procurement, operations, human resources, physical security, third-party providers, policies, training, incident response, disaster recovery, and documentation.
Organizations that approach CMMC one requirement at a time can quickly end up managing dozens of disconnected projects. One provider addresses a technical requirement. Another develops a policy. Another evaluates vendors. Another prepares employees. Each may be doing good work, but without an overarching strategy, organizations can duplicate efforts, create gaps between requirements, or spend money solving problems that could have been addressed more efficiently as part of a coordinated program.
Leadership should designate someone to own the CMMC strategy and roadmap. That person does not need to personally implement every requirement. Their role is to understand where the organization is today, where it needs to be, and how the different workstreams fit together. They can coordinate internal departments and outside specialists, identify dependencies, establish priorities, track remediation and evidence, and help leadership make informed decisions about resources, risk, and timing.
This program-level approach can also create efficiencies. A policy decision may affect a technical requirement. Properly defining where CUI flows may reduce the number of systems within scope. Training or an incident response exercise may support evidence across multiple requirements. A coordinated vendor-management process may address several supply-chain considerations.
Most importantly, CMMC should produce more than a successful assessment. Defense contractors are entrusted with information that foreign adversaries actively seek. The goal should be a connected cybersecurity program that protects that information and strengthens the organization's ability to prevent, respond to, and recover from cyber incidents.
Executive takeaway: Don't manage CMMC as 110 separate problems. Establish an owner for the strategy and roadmap who can bring leadership, internal teams, and specialized partners together into one coordinated program. Done well, CMMC readiness can reduce unnecessary spending while building something far more valuable than compliance: organizational resilience.
12. Do we need one CMMC provider to do everything?
No. CMMC often requires several different areas of specialized expertise.
An organization may need technical implementation, legal and contractual guidance, governance and policy development, employee training, vendor management, incident response and recovery planning, cloud or managed services, and assessment expertise. Organizations should not assume that one provider will necessarily be equally strong in every discipline.
Be cautious of solutions that make CMMC sound like a one-time project, a technology purchase, or a package that one provider can simply complete on the organization's behalf. CMMC readiness involves technology, but it also involves people, processes, documentation, evidence, third parties, and cybersecurity practices that must be sustained over time.
And do not automatically view it as a weakness when a provider recommends another specialist. It can be a very good sign.
An MSP may have deep expertise in configuring and securing the technical environment but recommend another provider for governance, legal interpretation, policy development, incident response exercises, or another specialized discipline. Likewise, legal, governance, and compliance professionals should recognize when specialized technical expertise is required.
A provider that understands its strengths, recognizes the limits of its expertise, and collaborates effectively with qualified specialists demonstrates something important: they understand the complexity of CMMC.
The challenge is making sure those specialists are not operating independently.
A business-focused CMMC program strategist or coordinator can provide that connection. Their role is not to replace the MSP, attorney, technical specialist, or assessor. It is to understand the organization's business, contracts, information flows, risks, operations, and CMMC requirements well enough to develop the overall roadmap and coordinate the different workstreams against it.
Executive takeaway: Be cautious of anyone who makes CMMC sound like a one-and-done solution. You do not necessarily need one provider that does everything. You need one coordinated strategy supported by the right specialists. A provider confident enough to identify its strengths and recommend qualified expertise for other parts of the journey may be demonstrating exactly the kind of collaboration a successful CMMC program requires.
13. How much does CMMC certification cost?
There is no single price for becoming CMMC ready, and organizations should be cautious of estimates provided before their environment and requirements are understood.
The investment can vary significantly based on the CMMC level required, the organization's existing cybersecurity maturity, how and where FCI or CUI is handled, the systems and locations within scope, existing technology and service providers, remediation needs, and applicable assessment requirements.
Scope is often an important cost driver. An organization that allows CUI to move broadly across its enterprise may have a much larger environment to protect and assess than an organization that can appropriately limit where CUI is processed, stored, and transmitted. Understanding information flows and developing a strategy should therefore happen before major technology investments.
Cost is also more than technology. Organizations may need to address policies and procedures, employee training, vendor management, incident response and recovery planning, documentation and evidence, technical remediation, and assessment preparation.
A coordinated roadmap can help leadership understand what already exists, identify work that may support multiple requirements, prioritize remediation, and avoid unnecessary duplication.
Executive takeaway: Don't start with “How much does CMMC cost?” Start with “What applies to us, what is actually in scope, where are our gaps, and what is the most efficient roadmap for closing them?” Those answers will drive the real investment.
14. Can we wait until CMMC appears in our next contract?
For many organizations, waiting is not a sound strategy. Cybersecurity and assessment obligations may already apply today.
CMMC did not create the underlying responsibility to protect FCI and CUI. It provides the government greater assurance that contractors and subcontractors are implementing applicable cybersecurity requirements.
Organizations should also understand that CMMC and the NIST SP 800-171 DoD Assessment process are related but distinct requirements.
For contractors subject to applicable existing DFARS requirements, a current NIST SP 800-171 DoD Assessment may already be required, with the assessment score maintained in the Supplier Performance Risk System (SPRS).
Separately, during the current CMMC Phase I implementation, applicable Level 1 and Level 2 self-assessment requirements remain in effect. When an applicable solicitation requires a CMMC level, the organization must have the required current CMMC status and affirmation.
This has an important business consequence: CMMC readiness can determine whether your organization is eligible to receive an award, not merely what you must do after receiving one.
Organizations should also take self-assessments and affirmations seriously. These are representations about the organization's actual implementation of cybersecurity requirements, not paperwork that should be completed based on what the organization intends to implement later.
Executive takeaway: Don't wait for the next RFP to begin asking whether you're ready. Determine what requirements apply today, understand what you are currently assessing and affirming, make sure those representations are supportable, and build the roadmap for what comes next. By the time CMMC becomes an award requirement for an opportunity you want, you may need to demonstrate readiness, not promise to achieve it later.
15. Can we use a POA&M for requirements we have not completed yet?
Sometimes, but a Plan of Action and Milestones (POA&M) is not a blanket permission to postpone CMMC requirements.
For CMMC Level 1, POA&Ms are not permitted to achieve the required final status. The applicable requirements must be met.
For Level 2, limited use of a POA&M may be permitted under the CMMC rules when specific conditions are satisfied. Certain requirements cannot be placed on a POA&M, minimum scoring thresholds apply, and outstanding items must be closed within the required timeframe.
For a conditional Level 2 status, outstanding POA&M items generally must be successfully closed within 180 days to achieve final status. Failure to close the required items can cause the conditional status to expire and affect eligibility for future awards requiring that status.
Executive takeaway: A POA&M is a controlled remediation mechanism, not a substitute for compliance. Leadership should understand exactly which gaps remain, whether they are eligible for a POA&M, who owns remediation, and when they must be closed.
16. What happens if our self-assessment is not completely accurate?
Treat your self-assessment and affirmation seriously. They are representations to the federal government about your organization's cybersecurity posture.
A self-assessment is not the place to give your organization the benefit of the doubt. If a requirement is not fully implemented, the assessment should reflect what is actually in place, and the organization should follow the applicable process for documenting and addressing deficiencies.
An identified cybersecurity gap is not the same thing as misrepresenting your cybersecurity posture. An error, disagreement, or identified deficiency is also not automatically fraud. Legal exposure depends on the facts and applicable legal standards, including issues such as knowledge and materiality.
The greater risk arises when an organization knowingly reports a score or affirms compliance that it cannot support, ignores information showing that a previous assessment is materially inaccurate, or continues representing compliance despite known deficiencies.
The Department of Justice has pursued False Claims Act matters involving government contractors that allegedly failed to meet contractual cybersecurity requirements or submitted inaccurate cybersecurity assessment information. These matters have resulted in settlements ranging from hundreds of thousands to millions of dollars.
This is another reason CMMC readiness should include governance and executive oversight. Leadership should understand who conducted the assessment, what evidence supports the answers, what gaps were identified, what remediation remains, and exactly what an authorized affirming official is being asked to affirm.
Executive takeaway: Do not guess, round up, or give yourself credit for something you intend to implement later. Assess what is actually in place, document the evidence supporting it, identify gaps honestly, and build a roadmap for addressing them. An honest gap can be managed. An unsupported representation to the federal government can become a much larger business and legal problem.
17. Where should our organization start?
Start with your business, not a list of CMMC controls.
CMMC can feel overwhelming because it brings together cybersecurity, contracts, technology, people, vendors, operations, documentation, and federal requirements. The first step should be finding someone who can understand those different pieces, translate the complexity for leadership, and help develop a practical roadmap for the organization.
At a high level, that roadmap should answer four questions:
- What applies to us?
- What is actually in scope?
- Where are we today, and where do we need to be?
- What is our roadmap to readiness?
This is why CMMC readiness benefits from someone who can look across the entire program. That person does not need to personally implement every technical requirement or provide every specialized service. They should, however, understand the business, technology, contractual and legal considerations, and complexity of CMMC well enough to coordinate leadership, internal departments, and outside specialists around one strategy.
The right technical providers can focus on technical implementation. Legal professionals can address contractual and legal issues. Governance and resilience specialists can address policies, vendors, training, incident response, and recovery. Assessors can independently perform their appropriate role. But everyone should be working toward the same destination.
Executive takeaway: Don't begin CMMC by asking, “Which control should we implement first?” Begin by asking, “Who understands our business well enough to help us determine what applies, where we are, where we need to be, and build the roadmap to get us there?”
CMMC requires specialized expertise. Your organization needs a strategy that connects it.
CMMC Services at Ice Miller
Ice Miller brings together a multidisciplinary team of government contracts, regulatory and compliance attorneys, along with cybersecurity and CMMC program strategy experience, to help organizations navigate CMMC as a coordinated business program. The team includes Senior Cybersecurity Advisor Chetrice Romero, a non-lawyer professional focused on CMMC program strategy who works with leadership to understand the organization's business and cybersecurity environment, determine where it is today, and develop a practical roadmap toward readiness.
Working alongside Ice Miller attorneys and other specialists, we help clients address contractual and regulatory requirements, governance and policy development, vendor and supply-chain risk, incident response and disaster recovery, training and exercises, and overall program coordination. When additional specialized technical or assessment expertise is needed, we can work collaboratively with qualified outside providers so clients have the right disciplines working from one connected strategy designed to support both CMMC readiness and long-term cybersecurity resilience.