Teramis Blog | CUI Discovery & Safeguarding Insights

CMMC in 2026: What Defense Contractors Need to Know

Written by Teramis | Sep 17, 2026, 10:04:47 AM

For most of its existence, the Cybersecurity Maturity Model Certification (CMMC) program lived in the future tense: something defense contractors would eventually need to address. That changed on November 10, 2025, when the Department of Defense began including CMMC requirements in contracts.

CMMC is now operational. Enforcement mechanisms are active, and a March 2026 federal watchdog report provides a candid assessment of where implementation could still face pressure. The message for defense contractors is not to panic. It is to prepare before a certification requirement appears in a solicitation.

CMMC's Phased Rollout Is Already Changing Contract Awards

The DoD is implementing CMMC through a four-phase rollout spanning roughly three years. Each phase expands the set of contracts that carry an assessment or certification requirement.

Phase 1: Self-Assessments and SPRS Affirmations

Phase 1 began on November 10, 2025. It introduced Level 1 and Level 2 self-assessment requirements, along with required affirmations in the Supplier Performance Risk System (SPRS), into applicable solicitations and contracts.

During this phase, contracting officers began identifying contracts that require a specific CMMC status as a condition of award. Contractors should expect their self-assessment scores and affirmations to be treated as material representations to the government.

Phase 2: Third-Party Level 2 Assessments

Phase 2 begins on November 10, 2026. It expands the use of accredited CMMC Third-Party Assessment Organizations (C3PAOs) for many Level 2 contracts involving Controlled Unclassified Information (CUI).

This is the critical shift for organizations that handle CUI:

  • Self-attestation gives way to independent verification.
  • Assessment evidence must support claimed control implementation.
  • The CUI boundary must be accurate, current, and defensible.
  • Assessment scheduling becomes a business-development dependency.

Phases 3 and 4: Broader and Higher-Level Requirements

Phase 3 is expected to introduce Level 3 assessments conducted by the Defense Industrial Base Cybersecurity Assessment Center and broaden certification conditions. Phase 4, expected on or after November 10, 2028, represents full implementation across applicable DoD solicitations and contracts above the micro-purchase threshold involving Federal Contract Information or CUI, excluding commercial off-the-shelf purchases.

The practical takeaway is that CMMC does not arrive on one universal deadline. It reaches contractors one contract at a time, based on the opportunities they pursue and the requirements attached to those awards.

CMMC Verification Raises False Claims Act Exposure

CMMC did not create the underlying obligation to protect CUI. Contractors have been required to implement the 110 controls in NIST SP 800-171 Revision 2 through DFARS clause 252.204-7012 for years. CMMC adds verification, and verification changes the enforcement calculus by making compliance representations easier to test.

The Department of Justice has used the False Claims Act (FCA) to pursue cybersecurity misrepresentations. Two 2025 settlements illustrate the risk.

MORSECORP: An Inaccurate SPRS Score Became Material

In March 2025, MORSECORP agreed to pay $4.6 million to resolve FCA allegations tied to its work for the Army and Air Force. According to the DOJ, the company submitted an SPRS score of 104 in early 2021, while a later third-party gap analysis calculated a score of negative 142. The government alleged that the company did not promptly correct the score after learning it was inaccurate.

The matter also originated with a whistleblower: the company's former head of security. The case demonstrates that an SPRS score is not a static filing. Contractors must keep it aligned with the actual condition of their environment.

Aero Turbine: Liability Extended Beyond the Contractor

In July 2025, Aero Turbine and its private equity owner, Gallant Capital Partners, agreed to pay $1.75 million to resolve alleged cybersecurity noncompliance on an Air Force contract. The settlement was reported as the first FCA cybersecurity matter to name a private equity firm as a party.

Across these cases, the enforcement pattern is consistent:

  • Compliance representations and annual affirmations are material statements.
  • Known or uncorrected inaccuracies can create FCA exposure.
  • Whistleblowers may have direct visibility into evidence gaps.
  • Consequences can include treble damages, suspension, or debarment.

The GAO Identifies Four Risks to CMMC Execution

On March 12, 2026, the Government Accountability Office published Defense Contractor Cybersecurity: DOD Should Address External Factors That Could Impede Program Implementation (GAO-26-107955). The audit found that DoD had addressed six of seven key elements of a comprehensive implementation strategy, including goals, responsibilities, milestones, and resources.

The GAO's central criticism was narrower: DoD had not systematically assessed and documented external factors that could impede the rollout. Four issues matter directly to contractors.

1. Assessor Capacity

CMMC relies on a private-sector ecosystem, overseen by Cyber AB, to provide enough C3PAOs and certified assessors. As of December 2025, approximately 92 C3PAOs had been authorized to serve a defense industrial base of roughly 200,000 companies. Tens of thousands are expected to require Level 2 certification.

That mismatch creates a foreseeable risk of assessment backlogs and longer lead times.

2. Contractor Attrition

The GAO warned that certification cost and complexity could push some companies, especially small businesses, out of the defense market. For contractors, delayed preparation can make compliance costs more disruptive by compressing technical work, documentation, and assessment scheduling into the proposal window.

3. Reliance on Waivers

DoD officials indicated that assessment requirements could be waived when capacity is constrained. The GAO cautioned that overreliance on waivers could weaken the program's purpose: verifying that contractors meet federal cybersecurity requirements.

A potential waiver is not a sound readiness strategy.

4. Evolving Standards

CMMC is currently anchored to the 2021 edition of NIST SP 800-171 Revision 2, although NIST published a newer revision in 2024. A future standards transition would affect requirements, assessor training, and exam materials, adding another moving part for contractors to manage.

What Defense Contractors Should Do Now

The work that reduces CMMC risk begins before an assessor arrives. Defense contractors should prioritize the following actions:

  • Identify where CUI actually resides. Map CUI across Microsoft 365, file shares, endpoints, scanned documents, images, engineering files, and CAD repositories.
  • Define and minimize the CUI boundary. Include systems that process, store, or transmit CUI while avoiding unsupported assumptions that expand scope and cost.
  • Maintain current assessment evidence. Build repeatable documentation that connects implemented controls to verifiable evidence.
  • Keep SPRS representations aligned with reality. Reassess scores when the environment, controls, or known gaps change.
  • Engage a C3PAO early. Treat assessment capacity as a scheduling constraint, not a last-minute procurement task.

Accurate CUI identification drives every downstream decision: the assessment boundary, required controls, evidence collection, licensing costs, and the SPRS score an executive affirms. Over-scoping increases cost. Under-scoping leaves gaps that may surface during an assessment or enforcement inquiry.

Build a Defensible CUI Evidence Base

Maintaining an accurate CUI footprint is difficult when sensitive information accumulates across cloud platforms, shared drives, endpoints, images, and technical file formats. Manual inventories and assumptions quickly become stale.

Teramis helps organizations identify and continuously monitor CUI across complex repositories. That evidence can support more accurate self-assessments, tighter CUI boundaries, and better-informed remediation priorities. Technology is only one input; process discipline, documentation, and qualified assessment guidance remain essential.

Conclusion: Prepare Before CMMC Reaches Your Contract

CMMC has moved from anticipated to operational. The rollout is phased, SPRS affirmations and contract clauses create enforceable representations, and the GAO has identified real capacity and readiness pressures.

The contractors best positioned to compete will know where their CUI resides, scope accurately, document thoroughly, keep affirmations current, and enter the assessment queue before a contract forces the issue.

Use Teramis to identify CUI at scale, strengthen the evidence behind your compliance posture, and focus remediation where it matters most.

Request a Teramis Demo

Sources