Last updated: August 1, 2026
Current implementation status
On July 13, 2026, the Department of War announced an immediate suspension of CMMC Phase II requirements. Phase I self-assessment requirements remain in place. CMMCPulsar reflects public guidance available on August 1, 2026; always confirm the clauses and assessment level in the current solicitation or contract.
CMMC at a glance
CMMC Level 1
Level 1 is intended for contractors and subcontractors that handle Federal Contract Information but not Controlled Unclassified Information. It focuses on basic safeguarding practices such as access control, authentication, physical protection, media handling, and system integrity.
- Complete and score the self-assessment every year.
- Enter the result in the Supplier Performance Risk System.
- Submit an affirmation by an affirming official every year.
- Implement every required practice because POA&Ms are not allowed.
- Retain policies, evidence, scope decisions, and supporting records.
CMMC Level 2
Level 2 applies when an organization processes, stores, or transmits CUI in systems covered by a contract. The current CMMC model maps Level 2 to all 110 requirements in NIST SP 800-171 Revision 2. Some procurements call for a self-assessment and others call for a C3PAO assessment, subject to current implementation rules.
- Define the CUI environment and document system boundaries.
- Map every applicable requirement to implementation statements and evidence.
- Maintain a system security plan that matches the actual environment.
- Track only eligible deficiencies in a time-bound POA&M.
- Prepare personnel, providers, policies, and evidence for assessor review.
What CMMCPulsar helps organize
Verify against the official sources
Readiness software, not certification
CMMCPulsar helps users prepare and organize documentation. It does not perform a CMMC assessment, provide legal advice, guarantee a score, or represent an assessor's certification decision.