Where CMMC Stands Today

DFARS 252.204-7012 still requires contractors that handle CUI to implement the 110 security requirements in NIST SP 800-171 and to report cyber incidents to the Department of Defense within 72 hours.

CMMC Phase 1 began on November 10, 2025. Contracts can require a CMMC Level 1 or Level 2 self-assessment, with results posted in the Supplier Performance Risk System (SPRS).

On July 13, 2026, the Department of War suspended Phase 2, which would have required third-party Level 2 certifications starting November 10, 2026. Phase 1 self-assessments and the NIST SP 800-171 obligations remain in place.

Inaccurate SPRS scores carry False Claims Act risk, so a self-assessment should reflect what is actually implemented. The program is under review, so check the official CMMC page for the latest status.

Last reviewed September 2026.

How Computer Ties Supports Defense Suppliers

Finding Where CUI Lives

We help identify where FCI and CUI are stored and shared, such as email, file shares, engineering workstations and backups, so protections focus on the right systems.

Microsoft 365 Government Cloud

We plan and support Microsoft 365 government tenants, including GCC High, for organizations that keep CUI in email and files.

Access Control & MFA

MFA, least-privilege accounts, session locks and prompt offboarding cover many of the access control and authentication requirements.

Logging, Backups & Incident Response

Centralized logging, monitored backups and a documented incident process support audit requirements and the 72-hour reporting window.

Wide view of the CTi Tech Plaza conference room table and chairs

The Documentation Assessors Expect

A System Security Plan (SSP) and a Plan of Action and Milestones (POA&M) are the core documents for NIST SP 800-171 and CMMC Level 2.

Computer Ties can document your network, devices, accounts and security settings, track open items, and keep the technical details in your SSP accurate as systems change.

We are not a Certified Third-Party Assessment Organization (C3PAO) and do not issue certifications. Your company remains responsible for its SPRS score and affirmations.

Frequently Asked Questions

Is CMMC still required?

Yes, in part. Phase 1 self-assessment requirements have applied since November 10, 2025, and DFARS 252.204-7012 still requires NIST SP 800-171. Phase 2 third-party certification was suspended on July 13, 2026 while the program is reviewed.

What is the difference between FCI and CUI?

Federal Contract Information is information provided to or created for the government under a contract that is not meant for public release; it falls under CMMC Level 1. Controlled Unclassified Information is more sensitive and requires NIST SP 800-171 protections at CMMC Level 2.

Can Computer Ties certify us?

No. Only accredited C3PAOs and the government perform certification assessments. We help you implement and document the controls so you are ready for a self-assessment or an outside assessment.

Do we need Microsoft 365 GCC High?

Not always. It depends on whether you store CUI or export-controlled data in Microsoft 365 and on your contract terms. We can review how CUI moves through your systems and explain the options before you commit to a migration.

Computer Ties circular red and blue emblem

Get Ready for Your Next Assessment

Talk with Computer Ties about where CUI lives in your environment and which NIST SP 800-171 requirements still need work. We will recommend practical next steps.