Skip to main content
—
Framework library
Framework module · cmmc-2-0

CMMC

The DoD program that applies contract-specified safeguards and assessment requirements to contractor systems processing Federal Contract Information or Controlled Unclassified Information. The required level and assessment path may involve self-assessment, a C3PAO, or DIBCAC.

32 CFR Part 170; DFARS 252.204-7021 (Nov. 2025) · DoD CMMC Program · published 2025-09-10

Standing today
Directory entry

00Answer

from the registry record
What is CMMC?
The DoD program that applies contract-specified safeguards and assessment requirements to contractor systems processing Federal Contract Information or Controlled Unclassified Information. The required level and assessment path may involve self-assessment, a C3PAO, or DIBCAC.
Who does CMMC apply to?
CMMC applies to defense industrial base, US, per DoD CMMC Program.
What is the current version of CMMC?
The current edition is 32 CFR Part 170; DFARS 252.204-7021 (Nov. 2025), issued by DoD CMMC Program and published 2025-09-10. Source: https://business.defense.gov/Programs/Cyber-Security-Resources/CMMC-20/.
What does an assessment under CMMC require?
No control catalog has been ingested for CMMC yet — the registry tracks it as roadmap (Modeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

CMMC is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Freely published; model not ingested as a control catalog.

02Registry record

checked 2026-08-30
Registry status
Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Level 1 — Foundational · Level 2 — Advanced · Level 3 — Expert
Applies to
defense industrial base · US
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-30
Pending change
On 2026-07-13 the Department suspended Phase II and all pending and future CMMC implementation milestones while a reform review proceeds. Phase I self-assessment requirements remain in place, and the Department states that interim enforcement uses NIST SP 800-171 Rev. 2 self-assessments plus selected government-led assessments.Expected: Phase II timing unannounced; program review in progress

03Version ledger

2 editions
1.0Superseded2020-01-31
32 CFR Part 170; DFARS 252.204-7021 (Nov. 2025)Current edition · supersedes 1.02025-09-10

03aCoexisting versions

1 other version in force
  1. Phase II (C3PAO third-party certification)

    Applies to: Would apply to the Level 2/3 third-party certification population once resumed; every pending and future implementation milestone is currently suspended

    No scheduled end date — Suspended 2026-07-13 pending the Reform Task Force review; no resumption date has been set.

    Source (opens in a new tab)

05Change history

06Related frameworks

scored from registry facts
  1. Also applies to defense industrial base · NIST's current recommended security requirements for Controlled Unclassified Information in non-federal systems. Contractual applicability is agreement-specific; CMMC Phase I continues to use Rev. 2 rather than automatically inheriting Rev. 3.

  2. Also applies to defense industrial base · Enhanced security requirements for protecting controlled unclassified information tied to critical programs and high-value assets against advanced threats. It supplements SP 800-171 and does not apply to every CUI environment by default.

  3. TX-RAMPProgram Manual 4.0

    Same framework family · Texas's risk and authorization management program for cloud services used by state agencies and public higher education. Level 1, Level 2, and Provisional are service-offering certifications—not company-wide certifications.

  4. CSA STARSTAR Level 1 and Level 2

    Commonly assessed together · The Cloud Security Alliance's cloud-assurance program and public registry. Level 1 is a CCM/CAIQ self-assessment; Level 2 is a third-party certification or attestation path. Tracking STAR does not place ControlFrame or any customer on the registry.

CMMC | ControlFrame