In July 2026 the DoD paused CMMC Phase 2 — the rollout that would have made third-party (C3PAO) assessments mandatory in solicitations — pending a program review. The obligations underneath did not move: contractors and subcontractors must still implement NIST SP 800-171 and complete annual Level 1 and Level 2 self-assessments posted to SPRS. Pistos builds and maintains that evidence record continuously — and now guides subcontractors through their self-assessments.
Defense contractors operate under the most rigorous cybersecurity requirements in any commercial sector. The framework is not optional — it is baked into contract language.
Cybersecurity Maturity Model Certification — DoD
Level 1 (17 practices) applies to FCI — Federal Contract Information. Level 2 (110 practices) applies to CUI — Controlled Unclassified Information. With Phase 2 paused, Level 2 is met today through self-assessment posted to SPRS; third-party (C3PAO) assessment resumes when the DoD lifts the pause. Pistos supports both paths, built around the Level 2 practice set derived from NIST SP 800-171 Rev 2 and Rev 3.
Protecting CUI in Nonfederal Systems
The technical foundation for CMMC Level 2. 110 security requirements across 14 families — access control, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, system and information integrity, and awareness and training.
Defense Federal Acquisition Regulation Supplement
Requires contractors to implement NIST SP 800-171 security requirements, report cyber incidents to DoD within 72 hours, provide access to systems for damage assessment, and maintain a current System Security Plan and Plan of Action and Milestones.
PCS maps all 110 CMMC Level 2 practices to CIS Controls v8.1 safeguards. Skopein reads the technical configuration state. Mathisi satisfies the training domain. Every practice carries a control record, a dated evidence status, and a remediation path.
22 practices. User access, remote access, mobile device management, CUI access limitations.
3 practices. Security awareness, role-based training, insider threat awareness.
9 practices. Audit log creation, review, retention, and protection.
4 practices. System assessment, plan of action, continuous monitoring, internal system connections.
9 practices. Baseline configurations, system change control, least functionality, unauthorized software.
11 practices. User identification, MFA, password management, replay-resistant authentication.
3 practices. Incident response capability, reporting, and testing.
6 practices. System maintenance controls, maintenance tools, remote maintenance.
9 practices. Media access, marking, storage, transport, sanitization, and disposal.
2 practices. Personnel screening and termination procedures.
6 practices. Physical access authorization, monitoring, and visitor control.
3 practices. Risk assessment, vulnerability scanning, and risk response.
16 practices. Boundary protection, encryption in transit, network segmentation, CUI in public cloud.
7 practices. Malware protection, security alerts, software and firmware integrity, security architecture.
With third-party assessments paused, the annual self-assessment is what the DoD is actually looking for — and for most subcontractors it always was. Pistos runs it end to end, so your SPRS score is current, defensible, and ready the day a prime or a contracting officer asks.
Federal Contract Information (FCI)
The 17-practice annual self-assessment and affirmation. We implement the controls, gather the evidence, and post the result to SPRS — then keep it current year over year.
Controlled Unclassified Information (CUI)
The 110-practice NIST SP 800-171 self-assessment: a scored System Security Plan, a Plan of Action & Milestones, and the SPRS submission — maintained between reviews, not rebuilt each year.
When Phase 2 returns
The same evidence record that satisfies your self-assessment is what a C3PAO will ask to see. Build it once with Pistos and you are ready either way.
Request a briefing and we will walk you through PCS against the CMMC Level 2 practice set for your organization.
Request a defense briefing