Every threshold the register reads, with its source sentence
23 rule sentences, each with the period or number the register reads from it, the status of the text as at 27 Sep 2026 and a link to the source. Confirm which deviation your contracting officer's agency has adopted.
How the date tests are written
- "Not older than 3 years": current through the third anniversary of the assessment date; the day after it, the finding fires.
- "Not older than 1 year": the same test on the first anniversary, for a Level 1 assessment and for an affirmation.
- "Within 180 days of the Conditional CMMC Status Date": current through the 180th day after the assessment date.
- The 90-day window of finding 7 is a window this register sets for chasing, not a legal deadline, and includes the 90th day.
- The lowest SPRS score is 110 less the values 32 CFR 170.24 gives the requirements: 313 when none is met, so -203.
32 CFR 170.16(a)(1)codified text, eCFR current to 24 Sep 2026To maintain compliance with the requirements for a CMMC Status of Level 2 (Self), the OSA must conduct a Level 2 self-assessment every three years and submit the results in SPRS, within three years of the CMMC Status Date associated with the Conditional Level 2 (Self).
DFARS 252.204-7021, "current" (2)(ii)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026Not older than 3 years for Final Level 2 (Self) assessments and Final Level 2 (C3PAO) assessments, with (A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.16 and 170.17); and (B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official
DFARS 252.204-7020(g)(2)codified text, eCFR current to 24 Sep 2026; replaced in Department of War (DoD) contracts by 252.240-7997 under Class Deviation 2026-O0025, effective 1 Feb 2026The Contractor shall not award a subcontract or other contractual instrument, that is subject to the implementation of NIST SP 800-171 security requirements, in accordance with DFARS clause 252.204-7012 of this contract, unless the subcontractor has completed, within the last 3 years, at least a Basic NIST SP 800-171 DoD Assessment
DFARS 252.240-7997(g) (DEVIATION 2026-O0025)Class Deviation 2026-O0025, effective 1 Feb 2026The Contractor shall insert the substance of this clause, including this paragraph (g), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services (excluding commercially available off-the-shelf items).
DFARS 252.204-7021(f)(2)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026Prior to awarding a subcontract or other contractual instrument, ensure that the subcontractor has a current CMMC certificate or current CMMC status at the CMMC level that is appropriate for the information that is being flowed down to the subcontractor based on the requirements at 32 CFR 170.23.
32 CFR 170.15(a)(1)codified text, eCFR current to 24 Sep 2026To maintain compliance with the requirements for the CMMC Status of Final Level 1 (Self), the OSA must conduct a Level 1 self-assessment on an annual basis and submit the results in SPRS, or its successor capability.
DFARS 252.204-7021, "current" (2)(i)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026Not older than 1 year for Final Level 1 (Self), with (A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.15); and (B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official
32 CFR 170.22(a)codified text, eCFR current to 24 Sep 2026An Affirming Official from each OSA, whether a prime or subcontractor, must affirm the continuing compliance of their respective organizations with the specified security requirement after every assessment, including POA&M closeout, and annually thereafter.
32 CFR 170.21(a)(2)(i)codified text, eCFR current to 24 Sep 2026The assessment score divided by the total number of CMMC Level 2 security requirements is greater than or equal to 0.8;
32 CFR 170.21(b)codified text, eCFR current to 24 Sep 2026The closing of a POA&M must be confirmed by a POA&M closeout assessment within 180-days of the Conditional CMMC Status Date. If the POA&M is not successfully closed out within the 180-day timeframe, the Conditional CMMC Status for the information system will expire.
DFARS 252.204-7021, "current" (1)(i)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026Not older than 180 days for Conditional Level 2 (Self) assessments and Conditional Level 2 (certified third-party assessment organization (C3PAO)) assessments
32 CFR 170.21(a)(1)codified text, eCFR current to 24 Sep 2026A POA&M is not permitted at any time for Level 1 self-assessments.
DFARS 252.204-7012(c)(3)codified text, eCFR current to 24 Sep 2026; 252.204-7012 (MAY 2024) is kept in Class Deviation 2026-O0025, effective 1 Feb 2026In order to report cyber incidents in accordance with this clause, the Contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents.
DFARS 252.204-7012(a), "rapidly report"codified text, eCFR current to 24 Sep 2026Rapidly report means within 72 hours of discovery of any cyber incident.
DFARS 252.204-7012(m)(1)codified text, eCFR current to 24 Sep 2026Include this clause, including this paragraph (m), in subcontracts, or similar contractual instruments, for operationally critical support, or for which subcontract performance will involve covered defense information, including subcontracts for commercial products or commercial services, without alteration, except to identify the parties.
32 CFR 170.23(a)(1)codified text, eCFR current to 24 Sep 2026If a subcontractor will only process, store, or transmit FCI (and not CUI) in performance of the subcontract, then a CMMC Status of Level 1 (Self) is required for the subcontractor.
32 CFR 170.23(a)(2)codified text, eCFR current to 24 Sep 2026If a subcontractor will process, store, or transmit CUI in performance of the subcontract, then a CMMC Status of Level 2 (Self) is the minimum requirement for the subcontractor.
32 CFR 170.16(a)(1)(i)(D)codified text, eCFR current to 24 Sep 2026All industry CAGE code(s) associated with the information system(s) addressed by the CMMC Assessment Scope.
32 CFR 170.24(c)(2)codified text, eCFR current to 24 Sep 2026For each requirement NOT MET, the associated value of the security requirement is subtracted from the maximum score, which may result in a negative score.
DoW CIO memorandum, 13 Jul 2026, Attachment 1memorandum, cleared for open publication 13 Jul 2026Per the attached CIO memorandum, during this suspension the Department will enforce baseline compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and CMMC Level 2 self-assessment and select Government-led assessments. The cybersecurity requirements outlined in the clause at DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, remain in effect.
DoW CIO memorandum, 13 Jul 2026, Attachment 1memorandum, cleared for open publication 13 Jul 2026Program Managers and requiring activities may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period. The allowed designations are CMMC Level 1 (Self) or CMMC Level 2 (Self).
DFARS 252.204-7021, "CMMC UID" and (d)(4)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026Cybersecurity Maturity Model Certification unique identifier (CMMC UID) means 10 alpha-numeric characters assigned to each CMMC assessment and reflected in the Supplier Performance Risk System (SPRS) for each contractor information system.
32 CFR 170.22(a)(1)codified text, eCFR current to 24 Sep 2026The Affirming Official is the senior level representative from within each Organization Seeking Assessment (OSA) who is responsible for ensuring the OSA's compliance with the CMMC Program requirements and has the authority to affirm the OSA's continuing compliance with the specified security requirements for their respective organizations.