Subcontractor CMMC Tracker

Every threshold the register reads, with its source sentence

23 rule sentences, each with the period or number the register reads from it, the status of the text as at 27 Sep 2026 and a link to the source. Confirm which deviation your contracting officer's agency has adopted.

How the date tests are written

32 CFR 170.16(a)(1)codified text, eCFR current to 24 Sep 2026

To maintain compliance with the requirements for a CMMC Status of Level 2 (Self), the OSA must conduct a Level 2 self-assessment every three years and submit the results in SPRS, within three years of the CMMC Status Date associated with the Conditional Level 2 (Self).

Threshold read: Level 2 (Self) assessment: every three years. Source
DFARS 252.204-7021, "current" (2)(ii)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026

Not older than 3 years for Final Level 2 (Self) assessments and Final Level 2 (C3PAO) assessments, with (A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.16 and 170.17); and (B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official

Threshold read: Final Level 2: not older than 3 years, affirmation not older than 1 year. Source
DFARS 252.204-7020(g)(2)codified text, eCFR current to 24 Sep 2026; replaced in Department of War (DoD) contracts by 252.240-7997 under Class Deviation 2026-O0025, effective 1 Feb 2026

The Contractor shall not award a subcontract or other contractual instrument, that is subject to the implementation of NIST SP 800-171 security requirements, in accordance with DFARS clause 252.204-7012 of this contract, unless the subcontractor has completed, within the last 3 years, at least a Basic NIST SP 800-171 DoD Assessment

Threshold read: no subcontract award without an assessment completed within the last 3 years. Source
DFARS 252.240-7997(g) (DEVIATION 2026-O0025)Class Deviation 2026-O0025, effective 1 Feb 2026

The Contractor shall insert the substance of this clause, including this paragraph (g), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services (excluding commercially available off-the-shelf items).

Threshold read: the deviation clause flows down; it carries no award sentence or age of its own. Source
DFARS 252.204-7021(f)(2)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026

Prior to awarding a subcontract or other contractual instrument, ensure that the subcontractor has a current CMMC certificate or current CMMC status at the CMMC level that is appropriate for the information that is being flowed down to the subcontractor based on the requirements at 32 CFR 170.23.

Threshold read: before a subcontract award: a current CMMC status at the level the information flowed down calls for. Source
32 CFR 170.15(a)(1)codified text, eCFR current to 24 Sep 2026

To maintain compliance with the requirements for the CMMC Status of Final Level 1 (Self), the OSA must conduct a Level 1 self-assessment on an annual basis and submit the results in SPRS, or its successor capability.

Threshold read: Level 1 (Self) assessment: annual. Source
DFARS 252.204-7021, "current" (2)(i)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026

Not older than 1 year for Final Level 1 (Self), with (A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.15); and (B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official

Threshold read: Final Level 1: not older than 1 year. Source
32 CFR 170.22(a)codified text, eCFR current to 24 Sep 2026

An Affirming Official from each OSA, whether a prime or subcontractor, must affirm the continuing compliance of their respective organizations with the specified security requirement after every assessment, including POA&M closeout, and annually thereafter.

Threshold read: affirmation after every assessment and annually thereafter. Source
32 CFR 170.21(a)(2)(i)codified text, eCFR current to 24 Sep 2026

The assessment score divided by the total number of CMMC Level 2 security requirements is greater than or equal to 0.8;

Threshold read: conditional status only with a score of at least 0.8 of 110, which is 88. Source
32 CFR 170.21(b)codified text, eCFR current to 24 Sep 2026

The closing of a POA&M must be confirmed by a POA&M closeout assessment within 180-days of the Conditional CMMC Status Date. If the POA&M is not successfully closed out within the 180-day timeframe, the Conditional CMMC Status for the information system will expire.

Threshold read: POA&M closeout within 180 days of the Conditional CMMC Status Date. Source
DFARS 252.204-7021, "current" (1)(i)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026

Not older than 180 days for Conditional Level 2 (Self) assessments and Conditional Level 2 (certified third-party assessment organization (C3PAO)) assessments

Threshold read: Conditional Level 2: not older than 180 days. Source
32 CFR 170.21(a)(1)codified text, eCFR current to 24 Sep 2026

A POA&M is not permitted at any time for Level 1 self-assessments.

Threshold read: no POA&M at Level 1. Source
DFARS 252.204-7012(c)(3)codified text, eCFR current to 24 Sep 2026; 252.204-7012 (MAY 2024) is kept in Class Deviation 2026-O0025, effective 1 Feb 2026

In order to report cyber incidents in accordance with this clause, the Contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents.

Threshold read: a medium assurance certificate to report cyber incidents. Source
DFARS 252.204-7012(a), "rapidly report"codified text, eCFR current to 24 Sep 2026

Rapidly report means within 72 hours of discovery of any cyber incident.

Threshold read: 72 hours from discovery. Source
DFARS 252.204-7012(m)(1)codified text, eCFR current to 24 Sep 2026

Include this clause, including this paragraph (m), in subcontracts, or similar contractual instruments, for operationally critical support, or for which subcontract performance will involve covered defense information, including subcontracts for commercial products or commercial services, without alteration, except to identify the parties.

Threshold read: flows down where subcontract performance involves covered defense information. Source
32 CFR 170.23(a)(1)codified text, eCFR current to 24 Sep 2026

If a subcontractor will only process, store, or transmit FCI (and not CUI) in performance of the subcontract, then a CMMC Status of Level 1 (Self) is required for the subcontractor.

Threshold read: FCI only: Level 1 (Self). Source
32 CFR 170.23(a)(2)codified text, eCFR current to 24 Sep 2026

If a subcontractor will process, store, or transmit CUI in performance of the subcontract, then a CMMC Status of Level 2 (Self) is the minimum requirement for the subcontractor.

Threshold read: CUI: Level 2 (Self) at least. Source
32 CFR 170.16(a)(1)(i)(D)codified text, eCFR current to 24 Sep 2026

All industry CAGE code(s) associated with the information system(s) addressed by the CMMC Assessment Scope.

Threshold read: SPRS results carry every CAGE code in scope. Source
32 CFR 170.24(c)(2)codified text, eCFR current to 24 Sep 2026

For each requirement NOT MET, the associated value of the security requirement is subtracted from the maximum score, which may result in a negative score.

Threshold read: the score runs from -203 to 110 (the values in 170.24 add to 313). Source
DoW CIO memorandum, 13 Jul 2026, Attachment 1memorandum, cleared for open publication 13 Jul 2026

Per the attached CIO memorandum, during this suspension the Department will enforce baseline compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and CMMC Level 2 self-assessment and select Government-led assessments. The cybersecurity requirements outlined in the clause at DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, remain in effect.

Threshold read: self-assessment and DFARS 252.204-7012 stay in force during the suspension. Source
DoW CIO memorandum, 13 Jul 2026, Attachment 1memorandum, cleared for open publication 13 Jul 2026

Program Managers and requiring activities may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments during this period. The allowed designations are CMMC Level 1 (Self) or CMMC Level 2 (Self).

Threshold read: only Level 1 (Self) or Level 2 (Self) designated during the suspension. Source
DFARS 252.204-7021, "CMMC UID" and (d)(4)codified text, eCFR current to 24 Sep 2026; the same text is carried in Class Deviation 2026-O0025, effective 1 Feb 2026

Cybersecurity Maturity Model Certification unique identifier (CMMC UID) means 10 alpha-numeric characters assigned to each CMMC assessment and reflected in the Supplier Performance Risk System (SPRS) for each contractor information system.

Threshold read: a CMMC status belongs to each contractor information system, with its own CMMC UID; the affirmation is per system. Source
32 CFR 170.22(a)(1)codified text, eCFR current to 24 Sep 2026

The Affirming Official is the senior level representative from within each Organization Seeking Assessment (OSA) who is responsible for ensuring the OSA's compliance with the CMMC Program requirements and has the authority to affirm the OSA's continuing compliance with the specified security requirements for their respective organizations.

Threshold read: the affirmation is made by the affirming official. Source