Where CMMC Stands Today
DFARS 252.204-7012 still requires contractors that handle CUI to implement the 110 security requirements in NIST SP 800-171 and to report cyber incidents to the Department of Defense within 72 hours.
CMMC Phase 1 began on November 10, 2025. Contracts can require a CMMC Level 1 or Level 2 self-assessment, with results posted in the Supplier Performance Risk System (SPRS).
On July 13, 2026, the Department of War suspended Phase 2, which would have required third-party Level 2 certifications starting November 10, 2026. Phase 1 self-assessments and the NIST SP 800-171 obligations remain in place.
Inaccurate SPRS scores carry False Claims Act risk, so a self-assessment should reflect what is actually implemented. The program is under review, so check the official CMMC page for the latest status.
Last reviewed September 2026.
How Computer Ties Supports Defense Suppliers
Finding Where CUI Lives
We help identify where FCI and CUI are stored and shared, such as email, file shares, engineering workstations and backups, so protections focus on the right systems.
Microsoft 365 Government Cloud
We plan and support Microsoft 365 government tenants, including GCC High, for organizations that keep CUI in email and files.
Access Control & MFA
MFA, least-privilege accounts, session locks and prompt offboarding cover many of the access control and authentication requirements.
Logging, Backups & Incident Response
Centralized logging, monitored backups and a documented incident process support audit requirements and the 72-hour reporting window.

The Documentation Assessors Expect
A System Security Plan (SSP) and a Plan of Action and Milestones (POA&M) are the core documents for NIST SP 800-171 and CMMC Level 2.
Computer Ties can document your network, devices, accounts and security settings, track open items, and keep the technical details in your SSP accurate as systems change.
We are not a Certified Third-Party Assessment Organization (C3PAO) and do not issue certifications. Your company remains responsible for its SPRS score and affirmations.
Frequently Asked Questions
Yes, in part. Phase 1 self-assessment requirements have applied since November 10, 2025, and DFARS 252.204-7012 still requires NIST SP 800-171. Phase 2 third-party certification was suspended on July 13, 2026 while the program is reviewed.
Federal Contract Information is information provided to or created for the government under a contract that is not meant for public release; it falls under CMMC Level 1. Controlled Unclassified Information is more sensitive and requires NIST SP 800-171 protections at CMMC Level 2.
No. Only accredited C3PAOs and the government perform certification assessments. We help you implement and document the controls so you are ready for a self-assessment or an outside assessment.
Not always. It depends on whether you store CUI or export-controlled data in Microsoft 365 and on your contract terms. We can review how CUI moves through your systems and explain the options before you commit to a migration.

Get Ready for Your Next Assessment
Talk with Computer Ties about where CUI lives in your environment and which NIST SP 800-171 requirements still need work. We will recommend practical next steps.