← All news
CMMC·August 12, 2026·6 min read

CMMC Phase 1 is live: what it means for defense contractors

Phase 1 self-assessment requirements have been in force since November 2025, and they survived the summer's program shake-up untouched. If you sell into the defense supply chain, the obligation is already on your contracts — not on a future calendar.

The CMMC Program rule took effect on November 10, 2025, and with it the first phase of the phased rollout. From that date, most new Department of Defense solicitations began carrying a CMMC Level 1 or Level 2 (Self) requirement as a condition of award. The Department estimated the Phase 1 requirements would touch roughly two thirds of the defense industrial base — tens of thousands of companies, the overwhelming majority of them small.

Ten months on, the most common misconception we hear from prospective clients is that CMMC is still something coming. It isn't. Phase 1 is the live, enforceable floor, and the summer suspension of the later phases did nothing to change it.

What Phase 1 actually requires

Three obligations, and they compound:

A current self-assessment

Level 1 covers the 15 basic safeguarding requirements for Federal Contract Information. Level 2 (Self) covers all 110 NIST SP 800-171 Rev 2 controls. The assessment has to reflect your environment as it is, not as you intend it to be.

A score posted in SPRS

Your Level 2 score goes into the Supplier Performance Risk System, where contracting officers and primes can see it. A stale or missing score is a bid-eligibility problem long before it's a security problem.

An annual affirmation by a senior official

A named executive attests to continued compliance each year. That signature is the part contractors underestimate: it moves the assertion out of the IT department and onto someone personally accountable for it.

DFARS 252.204-7012 sits underneath all of it and hasn't moved. Neither has your flow-down obligation to subcontractors.

Self-assessment is not the easy option

Because Phase 1 doesn't require a third-party assessor, a lot of contractors treat it as a paperwork exercise. That reading gets the risk backwards. With no C3PAO in the loop, there is no external party validating the claim — which means the full weight of the assertion lands on the affirming official and, by extension, on the False Claims Act exposure that comes with a materially inaccurate representation to the government.

The practical implication: a self-assessment needs the same evidentiary discipline as a certified one. Every control claim should trace to a policy, an implementation record, and something that shows the control is operating — not just that it was written down eighteen months ago.

Where contractors are getting stuck

Across the client work we see through our partners, the same four failure modes recur:

  • Scope drift. CUI turns out to live in three systems nobody enumerated — a shared drive, an estimator's laptop, an email archive. Scope defined loosely at the start invalidates everything built on top of it.
  • Policies with no operating evidence. A complete policy set and an empty evidence folder is the single most common state we encounter.
  • POA&Ms treated as permanent. A plan of action is a schedule, not a shelter. Open items with no closure date are the ones that surface at exactly the wrong moment.
  • A score that ages out. The SPRS entry was accurate when it was posted. Then the environment changed and nobody re-ran the math.

What service providers are doing about it

The providers handling this well have stopped treating each client as a fresh project. They define a baseline once — the shared policies, the inherited controls, the recurring activities that a managed environment satisfies on the client's behalf — and push it across the client base. What remains client-specific is genuinely client-specific: scope, evidence, exceptions.

That's the difference between servicing five defense clients and servicing fifty. It's also what makes the annual affirmation defensible: when the underlying record is continuously maintained rather than reconstructed each year, the executive signing it is signing something real. That inherited-baseline model is what COPA.cloud is built around — see how CMMC compliance delivery works for service providers.

The short version

Phase 1 is in force, it applies to most new DoD contracts, and the suspension of the later phases changed none of it. If your SPRS score is older than your last infrastructure change, that's the thing to fix this quarter.

Talk to us about CMMC readiness ← All news