Defense Contracting

CMMC Timelines Keep Shifting. NIST 800-171 Readiness Still Matters.

Published July 27, 2026

CMMC implementation timelines and enforcement dates have shifted more than once, and they can change again. What has not changed is the underlying obligation to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Self-assessment expectations remain, NIST SP 800-171 Rev. 2 remains the operative standard behind the DFARS 252.204-7012 safeguarding clause, and contract-specific requirements are still driven by each solicitation. Treat schedule movement as timing, not as a policy reversal.

Verify the current requirement, every time

Because the program schedule has moved, the only reliable source for what applies to a given award is the official program material and the contract itself. Consult the CMMC program information maintained by the DoD CIO at dodcio.defense.gov/CMMC and read the clauses in each solicitation. Do not make compliance decisions from news coverage or secondhand summaries, and do not carry assumptions from one contract to another.

Self-assessment obligations remain

Schedule changes do not remove self-assessment obligations. Level 1 centers on an annual self-assessment against the 15 basic safeguarding requirements for FCI derived from FAR 52.204-21. Level 2 self-assessment continues to map to the 110 security requirements in NIST SP 800-171 Rev. 2, with an SSP, evidence, an SPRS score, a POA&M where allowed, and an annual affirmation by a senior official.

Level 1: FCI safeguarding

Level 1 is the baseline: annual self-assessment against the 15 FCI-focused safeguards. These cover fundamentals like access control, media protection, physical protection, system and information integrity, and identification and authentication for federal contract information. Contractors that only handle FCI can meet Phase I with a documented, credible self-assessment and an SPRS submission.

Level 2: NIST SP 800-171 Rev. 2

Level 2 self-assessment is tied to the 110 security requirements in NIST SP 800-171 Rev. 2. Contractors handling CUI need:

  • A current, defensible System Security Plan (SSP) describing how each 800-171 requirement is met.
  • Evidence backing each control, logs, configurations, policies, tickets, screenshots, organized so someone else can find it quickly.
  • An SPRS score that reflects the environment as it actually exists today, not a legacy snapshot.
  • A Plan of Action & Milestones (POA&M) for the controls where remediation is permissible, with realistic dates and owners.
  • An annual affirmation of compliance signed by a senior official.

A stale SSP or an SPRS score that no longer matches production is a common finding during prime-contractor due diligence, and it does not become less risky when program timelines slip, if anything, it is more visible then.

Why 800-171 readiness still matters

Shifting dates change the validation timeline, not the substance. DFARS 252.204-7012 continues to require adequate security measures aligned to NIST SP 800-171, prime contractors continue to ask subcontractors about their posture, and the underlying risks to FCI and CUI, spearphishing, credential theft, misconfigured cloud storage, unmanaged endpoints , do not wait for the program. Contractors that continue to close gaps now will be in substantially better shape whenever third-party validation requirements firm up, and they remain competitive for solicitations that reference 800-171 today.

What to do right now

  1. Refresh the SSP against the current 800-171 Rev. 2 requirements and how the environment operates today.
  2. Re-score SPRS honestly and submit updates when the score changes materially.
  3. Continue closing POA&M items on schedule; do not let schedule uncertainty become an excuse to slow remediation.
  4. Run the annual affirmation process on time with the appropriate senior official.
  5. Read every new solicitation for contract-specific security requirements, assumptions from one contract do not carry to another.
  6. Monitor official DoD sources for changes to CMMC timing and scope.
Need a fresh readiness view?

Need help validating your NIST 800-171 or CMMC readiness posture? Book a readiness call.

Do not conclude certification is gone for good

The most dangerous interpretation of a shifting schedule is that certification is permanently unnecessary. It is not. Obligations to protect FCI and CUI remain, and contract-specific validation requirements are still driven by the solicitations that appear each week. Treat any breathing room as time to strengthen the underlying 800-171 posture, not a reason to unwind it.

Related ControlSolid resources

Authoritative sources