Planning guide
How CMMC requirements connect.
CMMC planning becomes easier when each part has a clear job. Use this guide to understand the current program distinction, trace the workflow, and find the authorities behind each requirement.
Reviewed September 2, 2026. Recheck authoritative sources and the applicable contract before making a program decision.
On this pageRequirements
One connected path
Four questions. Four authorities.
No single product, document, or questionnaire answers all four. A sound operating plan connects them without collapsing their roles.
Current program snapshot
NIST and CMMC differ.
NIST SP 800-171 Revision 3 superseded Revision 2 in May 2024. Current CMMC Level 2 program material still maps assessment to the 110 requirements in Revision 2. These tracks should be planned separately until authoritative program and contract language changes.
The CMMC program page states that Phase I began November 10, 2025 and remains in place. Phase II was suspended on July 13, 2026. The suspension does not remove existing safeguarding duties in applicable contracts.
Affected systems
Trace CUI before scoping.
The official Level 2 scoping guide addresses CUI assets, security protection assets, contractor risk managed assets, and specialized assets. Specialized assets can include operational technology, industrial IoT, government-furnished equipment, restricted systems, and test equipment.
Questions to carry into planning
- Which contracts, solicitations, or customer requirements create the obligation?
- Where is CUI received, created, processed, stored, transmitted, or protected?
- Which people, identities, endpoints, applications, production systems, and service providers touch that path?
- Which security protection assets and specialized assets support the path?
- Who owns each policy, authorization, exception, incident, affirmation, evidence, and operating decision?
Rules, contracts, and verification
How CUI and CMMC connect
CUI, safeguard requirements, contract clauses, and CMMC play different roles. Keeping them separate makes the planning conversation clearer.
Regulatory reviewSeptember 2, 2026
2010
A common CUI program
Executive Order 13556 established a government-wide program for Controlled Unclassified Information. The goal was a consistent way to identify and handle sensitive unclassified information across agencies.
National Archives CUI program (opens in a new tab)2015 to 2016
CUI safeguards take shape
NIST first published SP 800-171 for protecting CUI in nonfederal systems. The federal CUI rule in 32 CFR Part 2002 then established program requirements for executive branch agencies.
NIST Protecting CUI project (opens in a new tab)Federal CUI implementing regulation (opens in a new tab)Acquisition context
Defense contracts add safeguards
DFARS 252.204-7012 applies safeguarding and cyber incident reporting duties when it appears in a covered contract. The applicable solicitation and contract language remains the authority for a specific organization and engagement.
Acquisition.gov DFARS 252.204-7012 (opens in a new tab)2024
NIST and CMMC change separately
NIST published SP 800-171 Revision 3 in May 2024, superseding Revision 2 as the current NIST publication. The CMMC program rule became effective in December 2024, while current CMMC Level 2 program material continues to map assessment to the 110 Revision 2 requirements.
NIST SP 800-171 Revision 3 (opens in a new tab)Current CMMC program mapping (opens in a new tab)Federal Register CMMC program rule (opens in a new tab)2025 to 2026
Phase II rollout pauses
Phase I began November 10, 2025. The CMMC program page states that Phase II was suspended on July 13, 2026, while Phase I self-assessment requirements and existing contract safeguarding duties remain in place.
Current CMMC program status (opens in a new tab)
Before you decide
Review the official sources.
Each source opens on the publishing organization's site. The current-status sources should be checked again before an organization-specific program or contract decision.
- CMMC program overview and current phase status (opens in a new tab)
- CMMC resources and documentation (opens in a new tab)
- CMMC Level 2 scoping guide (opens in a new tab)
- NIST SP 800-171 Revision 3 (opens in a new tab)
- NIST small business cybersecurity primer (opens in a new tab)
- DFARS 252.204-7012 (opens in a new tab)
Apply the context
Take the next planning step.
Use the CMMC planning wizard to prepare a non-sensitive conversation profile, or review the SecureEnclave™ operating model for the product architecture.
SecureEnclave™ can support implementation of applicable CMMC Level 2 technical and operational requirements through managed state, safeguards, technical evidence, and scoped recovery. The organization retains policy, authorization, risk, exception, incident, affirmation, and operating responsibilities; the applicable assessor determines the assessment conclusion.
This guide is not a legal opinion, contract interpretation, gap assessment, readiness score, or assessment result. Verify current sources and seek qualified advice for organization-specific decisions.