CMMC
The DoD program that applies contract-specified safeguards and assessment requirements to contractor systems processing Federal Contract Information or Controlled Unclassified Information. The required level and assessment path may involve self-assessment, a C3PAO, or DIBCAC.
32 CFR Part 170; DFARS 252.204-7021 (Nov. 2025) · DoD CMMC Program · published 2025-09-10
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
CMMC is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Freely published; model not ingested as a control catalog.
02Registry record
- Registry status
- Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Level 1 — Foundational · Level 2 — Advanced · Level 3 — Expert
- Applies to
- defense industrial base · US
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-08-30
- Pending change
- On 2026-07-13 the Department suspended Phase II and all pending and future CMMC implementation milestones while a reform review proceeds. Phase I self-assessment requirements remain in place, and the Department states that interim enforcement uses NIST SP 800-171 Rev. 2 self-assessments plus selected government-led assessments.Expected: Phase II timing unannounced; program review in progress
03Version ledger
| 1.0 | Superseded | 2020-01-31 |
| 32 CFR Part 170; DFARS 252.204-7021 (Nov. 2025) | Current edition · supersedes 1.0 | 2025-09-10 |
03aCoexisting versions
- Phase II (C3PAO third-party certification)
Applies to: Would apply to the Level 2/3 third-party certification population once resumed; every pending and future implementation milestone is currently suspended
No scheduled end date — Suspended 2026-07-13 pending the Reform Task Force review; no resumption date has been set.
Source (opens in a new tab)
05Change history
06Related frameworks
- NIST SP 800-171Rev. 3
Also applies to defense industrial base · NIST's current recommended security requirements for Controlled Unclassified Information in non-federal systems. Contractual applicability is agreement-specific; CMMC Phase I continues to use Rev. 2 rather than automatically inheriting Rev. 3.
- NIST SP 800-172Rev. 3
Also applies to defense industrial base · Enhanced security requirements for protecting controlled unclassified information tied to critical programs and high-value assets against advanced threats. It supplements SP 800-171 and does not apply to every CUI environment by default.
- TX-RAMPProgram Manual 4.0
Same framework family · Texas's risk and authorization management program for cloud services used by state agencies and public higher education. Level 1, Level 2, and Provisional are service-offering certifications—not company-wide certifications.
- CSA STARSTAR Level 1 and Level 2
Commonly assessed together · The Cloud Security Alliance's cloud-assurance program and public registry. Level 1 is a CCM/CAIQ self-assessment; Level 2 is a third-party certification or attestation path. Tracking STAR does not place ControlFrame or any customer on the registry.