Subcontractor CMMC Tracker

What changed on 13 July 2026, and what did not

Third-party CMMC certification was suspended on 13 July 2026 pending a review; the self-assessment, the SPRS score and the DFARS 252.204-7012 duties it rests on remain in force, and the register is built on those. As at 27 Sep 2026.

Still in force

Suspended

During the suspension, requiring activities designate only CMMC Level 1 (Self) or CMMC Level 2 (Self); the third-party assessment and Level 3 designations are not used, and contracting officers remove them from existing contracts before the next option or at the next scheduled administrative modification.

Renumbered, not repealed

DFARS 252.204-7020 is replaced in Department of War (DoD) contracts by 252.240-7997 under Class Deviation 2026-O0025 from 1 February 2026; 252.204-7012 (MAY 2024) and 252.204-7021 (NOV 2025) are kept. The eCFR still codifies 7019, 7020 and 7021. Confirm which deviation your contracting officer's agency has adopted.

Not final

The government-wide CUI rule (FAR Case 2017-016) is still a proposed rule, folded into the FAR overhaul proposal of 23 June 2026 (FR 2026-12559), which would require NIST SP 800-171 Revision 3 and 72-hour incident reporting outside DoD; comments closed on 23 July 2026 and no final rule has been published. DoW stays on Revision 2.

The DoW CIO announced a 60-day review; the Task Force report due on 11 September 2026 has not been published as of 27 September 2026, and further guidance is to follow the review.

The sentences, from the source

DoW CIO memorandum, 13 Jul 2026, Attachment 1memorandum, cleared for open publication 13 Jul 2026

Per the attached CIO memorandum, during this suspension the Department will enforce baseline compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and CMMC Level 2 self-assessment and select Government-led assessments. The cybersecurity requirements outlined in the clause at DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, remain in effect.

Threshold read: self-assessment and DFARS 252.204-7012 stay in force during the suspension. Source
DoW CIO memorandum, 13 Jul 2026, Attachment 1memorandum, cleared for open publication 13 Jul 2026

Program Managers and requiring activities may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period. The allowed designations are CMMC Level 1 (Self) or CMMC Level 2 (Self).

Threshold read: only Level 1 (Self) or Level 2 (Self) designated during the suspension. Source
DFARS 252.204-7020(g)(2)codified text, eCFR current to 24 Sep 2026; replaced in DoD contracts by 252.240-7997 under Class Deviation 2026-O0025, effective 1 Feb 2026

The Contractor shall not award a subcontract or other contractual instrument, that is subject to the implementation of NIST SP 800-171 security requirements, in accordance with DFARS clause 252.204-7012 of this contract, unless the subcontractor has completed, within the last 3 years, at least a Basic NIST SP 800-171 DoD Assessment

Threshold read: no subcontract award without an assessment completed within the last 3 years. Source
DFARS 252.240-7997(g) (DEVIATION 2026-O0025)Class Deviation 2026-O0025, effective 1 Feb 2026

The Contractor shall insert the substance of this clause, including this paragraph (g), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services (excluding commercially available off-the-shelf items).

Threshold read: the deviation clause flows down; it carries no award sentence or age of its own. Source
DFARS 252.204-7021(f)(2)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026

Prior to awarding a subcontract or other contractual instrument, ensure that the subcontractor has a current CMMC certificate or current CMMC status at the CMMC level that is appropriate for the information that is being flowed down to the subcontractor based on the requirements at 32 CFR 170.23.

Threshold read: before a subcontract award: a current CMMC status at the level the information flowed down calls for. Source

DFARS 252.204-7012, paragraph by paragraph

still in force

The clause a prime flows down to every subcontractor whose work involves covered defense information, as we state each paragraph, with the evidence an assessor or contracting officer asks for.

DFARS 252.204-7012 (b)Security on covered systems: implement NIST SP 800-171

The Contractor shall provide adequate security on all covered contractor information systems; for systems that are not part of an IT service or system operated on behalf of the Government, this means implementing the security requirements in NIST SP 800-171 in effect at the time the solicitation is issued (or as authorised by the Contracting Officer).

What an assessor asks to see: A System Security Plan (SSP) describing how each NIST SP 800-171 requirement is met; An SPRS self-assessment score; Implementation evidence for the 110 NIST SP 800-171 security requirements
Where subcontractors usually fall short: Missing or stale SSP; No SPRS score submitted; Claiming full implementation without supporting artefacts
Source: DFARS 252.204-7012
DFARS 252.204-7012 (b)(2)(ii)(D)Cloud and external service provider security

Cloud computing services provided as part of an IT service operated on behalf of the Government are subject to clause 252.239-7010; where the Contractor uses an external cloud service provider to store, process or transmit covered defense information, the Contractor shall require the provider to meet security requirements equivalent to the FedRAMP Moderate baseline and to comply with paragraphs (c) through (g) of this clause.

What an assessor asks to see: Evidence the external cloud service provider meets a FedRAMP Moderate-equivalent baseline; Contractual flowdown of paragraphs (c)-(g) to the cloud provider
Where subcontractors usually fall short: Using a cloud provider with no FedRAMP Moderate equivalency; No flowdown of incident-reporting obligations to the provider
Source: DFARS 252.204-7012
DFARS 252.204-7012 (b)(2)(ii)(B)Variance requests and alternative measures

The Contractor may submit requests to vary from NIST SP 800-171 in writing to the Contracting Officer for consideration by the DoD CIO, and may propose to use alternative but equally effective security measures; the Contracting Officer documents adjudication of any such requests.

What an assessor asks to see: Written variance/deviation requests and the DoD CIO adjudication; Documentation of any alternative-but-equally-effective measures accepted
Where subcontractors usually fall short: Deviating from 800-171 without an approved variance; Undocumented compensating controls
Source: DFARS 252.204-7012
DFARS 252.204-7012 (c)Cyber incident reporting (72-hour rapid report)

When the Contractor discovers a cyber incident affecting a covered contractor information system, the covered defense information residing therein, or its ability to perform operationally critical support, it shall conduct a review for evidence of compromise and rapidly report the incident (within 72 hours of discovery) to DoD at https://dibnet.dod.mil, including the required report content, and shall have or acquire a DoD-approved medium assurance certificate to make the report.

What an assessor asks to see: Incident review records evidencing the compromise assessment; The cyber incident report submitted via dibnet.dod.mil within 72 hours; A DoD-approved medium assurance certificate
Where subcontractors usually fall short: Reporting later than 72 hours after discovery; No medium assurance certificate in place; Incomplete incident report content
Source: DFARS 252.204-7012
DFARS 252.204-7012 (d)Malicious software submission to DC3

When the Contractor or a subcontractor discovers and isolates malicious software in connection with a reported cyber incident, it shall submit the malicious software to the DoD Cyber Crime Center (DC3) in accordance with DC3 or Contracting Officer instructions, and shall not send malicious software to the Contracting Officer.

What an assessor asks to see: Records of malicious software isolated and submitted to DC3; DC3 submission instructions followed
Where subcontractors usually fall short: Sending malware to the Contracting Officer; Not submitting isolated malware to DC3
Source: DFARS 252.204-7012
DFARS 252.204-7012 (e)Media preservation and protection (90 days)

The Contractor shall preserve and protect images of all known affected information systems identified in the incident review and all relevant monitoring/packet-capture data for at least 90 days from submission of the cyber incident report, to allow DoD to request the media or decline interest.

What an assessor asks to see: Forensic images of affected systems retained at least 90 days; Retained monitoring/packet-capture data with chain of custody
Where subcontractors usually fall short: Wiping or re-imaging affected systems before 90 days; No packet-capture/monitoring data retained
Source: DFARS 252.204-7012
DFARS 252.204-7012 (f)Access to additional information or equipment for forensic analysis

Upon request, the Contractor shall provide DoD with access to additional information or equipment necessary to conduct a forensic analysis of a reported cyber incident.

What an assessor asks to see: A process to provide DoD access to systems/data/equipment for forensic analysis; Records of access provided on request
Where subcontractors usually fall short: Refusing or delaying forensic access requests; No procedure to support DoD forensic analysis
Source: DFARS 252.204-7012
DFARS 252.204-7012 (g)Cyber incident damage assessment activities

If DoD elects to conduct a damage assessment, the Contracting Officer will request that the Contractor provide all of the damage assessment information gathered in accordance with the media preservation paragraph.

What an assessor asks to see: Damage assessment information packaged from preserved media on request; Support to the DoD damage assessment process
Where subcontractors usually fall short: Unable to produce damage assessment information from preserved media
Source: DFARS 252.204-7012
DFARS 252.204-7012 (h) to (k)DoD safeguarding and use of contractor attributional/proprietary information

Information shared by the Contractor under this clause that qualifies as contractor attributional/proprietary information is safeguarded and used by DoD subject to restrictions on use and release (whether or not created by or for DoD), and all activities under the clause are conducted in accordance with applicable law and regulation.

What an assessor asks to see: Markings on attributional/proprietary information provided to DoD; Awareness of the use/release protections that apply to reported information
Where subcontractors usually fall short: Not marking proprietary information when reporting; Assuming reported data carries no protection
Source: DFARS 252.204-7012
DFARS 252.204-7012 (l)Other safeguarding or reporting requirements

The safeguarding and cyber incident reporting required by this clause are in addition to, and do not abrogate, any other safeguarding or reporting requirements imposed by law or by other provisions of the contract.

What an assessor asks to see: Register of other applicable safeguarding/reporting obligations in the contract; Evidence those obligations are met alongside 7012
Where subcontractors usually fall short: Treating 7012 as the only applicable cyber requirement
Source: DFARS 252.204-7012
DFARS 252.204-7012 (m)Subcontract flowdown

The Contractor shall include this clause, without alteration except to identify the parties, in subcontracts (including for commercial products or services) for operationally critical support or whose performance will involve covered defense information, determine whether information retains its identity as covered defense information, and require subcontractors to report cyber incidents to the prime (or next higher-tier subcontractor) and to DoD via dibnet.

What an assessor asks to see: Subcontracts containing clause 252.204-7012 unaltered; Determination of which subcontracts involve covered defense information; Subcontractor incident-reporting obligations to the prime and DoD
Where subcontractors usually fall short: Omitting the clause from in-scope subcontracts; No mechanism for subcontractor incident reporting to the prime
Source: DFARS 252.204-7012

Read on the DoW CIO CMMC page, in the memorandum and in the class deviation. The register reads each subcontractor against the rules still in force and never says certification is required now.