Skip to content
CMMCPulsarby Federal Bid Partners

CMMC overview

Understand the requirement before building the packet.

CMMCPulsar organizes scope, practices, evidence, architecture, remediation, and exports around the work an organization must complete before an assessment.

Last updated: August 1, 2026

Current implementation status

On July 13, 2026, the Department of War announced an immediate suspension of CMMC Phase II requirements. Phase I self-assessment requirements remain in place. CMMCPulsar reflects public guidance available on August 1, 2026; always confirm the clauses and assessment level in the current solicitation or contract.

CMMC at a glance

Level 115 basic safeguarding requirements derived from FAR 52.204-21, assessed annually through a self-assessment and annual affirmation.
Level 2110 security requirements from NIST SP 800-171 Revision 2. Assessment type and cadence depend on the applicable contract and current phase.
POA&M rules differLevel 1 does not permit a POA&M. Level 2 permits only limited closeout use under applicable rules and deadlines.
Affirmation mattersAn affirming official must submit the required affirmation after an assessment and annually thereafter when applicable.

CMMC Level 1

Level 1 is intended for contractors and subcontractors that handle Federal Contract Information but not Controlled Unclassified Information. It focuses on basic safeguarding practices such as access control, authentication, physical protection, media handling, and system integrity.

  • Complete and score the self-assessment every year.
  • Enter the result in the Supplier Performance Risk System.
  • Submit an affirmation by an affirming official every year.
  • Implement every required practice because POA&Ms are not allowed.
  • Retain policies, evidence, scope decisions, and supporting records.

CMMC Level 2

Level 2 applies when an organization processes, stores, or transmits CUI in systems covered by a contract. The current CMMC model maps Level 2 to all 110 requirements in NIST SP 800-171 Revision 2. Some procurements call for a self-assessment and others call for a C3PAO assessment, subject to current implementation rules.

  • Define the CUI environment and document system boundaries.
  • Map every applicable requirement to implementation statements and evidence.
  • Maintain a system security plan that matches the actual environment.
  • Track only eligible deficiencies in a time-bound POA&M.
  • Prepare personnel, providers, policies, and evidence for assessor review.

What CMMCPulsar helps organize

ScopeEnvironment, assets, users, providers, and CUI boundaries.
ImplementationPractice status, policy text, owners, and operating details.
EvidenceFiles, descriptions, freshness, and linked controls.
ArchitectureNetwork map, data flows, trust boundaries, and protections.
RemediationFindings, due dates, owners, and eligible POA&M items.
ExportsReview packets with integrity metadata and assessment context.

Verify against the official sources

Readiness software, not certification

CMMCPulsar helps users prepare and organize documentation. It does not perform a CMMC assessment, provide legal advice, guarantee a score, or represent an assessor's certification decision.