A practical guide for aerospace and defence suppliers
Your required CMMC level is determined by the solicitation or contract and the information your systems will process, store or transmit. It is not determined by company size, industry reputation or informal guidance.
Current position — July 30, 2026
Phase I remains active. During the Phase II suspension, procurement requirements may designate only Level 1 (Self) or Level 2 (Self). Level 2 C3PAO and Level 3 DIBCAC requirements may not currently be designated.
Start with the solicitation and contract
FAR 52.204-21 and DFARS 252.204-7012 establish safeguarding obligations for FCI and CUI, but they do not, by themselves, identify the exact CMMC assessment path. The required CMMC level should be stated in the solicitation through DFARS 252.204-7025 and incorporated into the resulting contract through DFARS 252.204-7021.
If those provisions are missing, incomplete or inconsistent with the information being exchanged, raise the issue with the contracting officer or prime contractor before making major security investments.
Match the information to the level
CMMC level
Information protected
Current assessment position
Level 1 (Self)
Federal Contract Information (FCI)
Annual self-assessment and annual affirmation against the 15 FAR 52.204-21 safeguards.
Level 2
Controlled Unclassified Information (CUI)
During the suspension, contracts may require Level 2 (Self). C3PAO assessments remain available voluntarily, but may not currently be designated as a contract requirement.
Level 3
CUI requiring protection against advanced persistent threats
Government-led DIBCAC assessment. New Level 3 requirements may not currently be designated during the suspension.
Important: CUI does not automatically mean a C3PAO assessment. The solicitation specifies whether Level 2 is Self or C3PAO. Under the current suspension, only Level 2 (Self) may be designated.
Markings help, but they are not the whole answer
CUI markings, contract data requirements, security guidance, and prime-contractor flow-downs are key indicators. However, the absence of a marking does not always clarify the issue. Suppliers should not relabel information or assume unmarked technical data is out of scope. Any ambiguity should be documented and referred to the contracting authority or prime contractor.
Subcontracts require their own decision
A subcontractor does not automatically inherit/assume the prime contractor’s CMMC level. The required level depends on whether FCI or CUI will be processed, stored, or transmitted under the subcontract. The prime contractor must communicate the applicable requirements and verify the subcontractor’s current CMMC status before award, when necessary.
What the Phase II suspension changes and what it does not change
The July 2026 suspension changes which CMMC assessment types may be imposed in procurement requirements. It does not remove the underlying duty to protect government information. FAR 52.204-21, DFARS 252.204-7012, incident-reporting obligations, NIST SP 800-171 Rev. 2 implementation and applicable subcontractor flow-downs remain in force.
Existing solicitations and contracts containing Level 2 C3PAO or Level 3 DIBCAC requirements are expected to be amended or modified in accordance with government direction. Suppliers should confirm the status of each procurement rather than relying on the suspension announcement alone.
A short applicability review before you invest
1
Read the complete procurement package
Locate the CMMC notice and clause, not only the general cybersecurity provisions.
Identify the information
Document whether each workstream involves FCI, CUI or publicly available information.
3
Map the flow
Identify the systems, users, locations, cloud services and subcontractors that will handle the information.
4
Confirm uncertainties
Obtain written clarification from the contracting officer or prime contractor where the level or data status is unclear.
5
Maintain the record
Keep the applicability decision, assessment results, SPRS entries and annual affirmations current.
The practical conclusion
Selecting the appropriate CMMC level depends on contract requirements and information flow. Over-scoping increases unnecessary cost and complexity, while under-scoping may jeopardize contract awards or create compliance risks. Conduct a concise, documented applicability and scoping review before making architecture changes, purchasing tools, or scheduling assessments.
SAOG Cyber helps aerospace and defence suppliers define the assessment boundary and prepare a proportionate readiness plan.