CMMC Phase 1 Is Active: What Must the Solicitation and SPRS Record Show?
Map a CMMC request to the live implementation phase, solicitation clause, required level, assessment scope, SPRS status and affirmation before proposing assessment work.

Signals to watch
- A named DoD solicitation or subcontract identifies the CMMC level and the contractor information systems that will process, store or transmit FCI or CUI
- The required self-assessment, C3PAO assessment or DIBCAC assessment route is tied to a current SPRS status rather than inferred from a phase date
- A proposal or option decision has a date, but the CMMC UID, status currency, assessment scope or annual affirmation is missing or disputed
On August 13, 2026, the Cybersecurity Maturity Model Certification (CMMC) program is in Phase 1. That date does not tell an assessment provider what to quote. The controlling evidence is the actual solicitation or subcontract: required CMMC level, applicable Defense Federal Acquisition Regulation Supplement (DFARS) provision and clause, contractor information systems in scope, and the current status and affirmation recorded in the Supplier Performance Risk System (SPRS).
This distinction matters to a CMMC assessment provider’s business-development lead following authorised defense-industrial-base, government-contracting and supplier-compliance Telegram groups. A post saying “our prime needs CMMC this quarter” may point to a real award gate, an option exercise, an early readiness review or a future-phase assumption. If the BD sees the supporting solicitation after another provider has mapped the scope, it may be too late to enter the assessment schedule. If the BD quotes from the phase date alone, it may sell the wrong assessment.
The evidence map is: decision date → procurement text → information handled → required CMMC status → assessment scope and UID → current SPRS status and affirmation. A break in that chain defines the next review; the phrase “needs CMMC” does not.
Definition: phased implementation changes procurement coverage, not the named requirement
CMMC is DoD’s framework for assessing whether a contractor has implemented the information-security protections required for Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on unclassified contractor systems. FCI is non-public information provided by or generated for the Government under a contract. CUI is information subject to safeguarding or dissemination controls under law, regulation or Government-wide policy.
The program generally reaches DoD solicitations and contracts above the micro-purchase threshold when contractor systems will process, store or transmit FCI or CUI, including commercial items but excluding awards exclusively for commercially available off-the-shelf items. It does not apply to Federal information systems that contractors operate for the Government. Phase-in rules and approved waivers can narrow that general boundary.
32 CFR 170.3 establishes four implementation phases. The complementary DFARS acquisition final rule became effective on November 10, 2025, which started Phase 1. The resulting dates are:
- Phase 1: November 10, 2025–November 9, 2026. DoD intends to include Level 1 (Self) or Level 2 (Self) for applicable awards and may require Level 2 (C3PAO) at its discretion.
- Phase 2: November 10, 2026–November 9, 2027. Level 2 (C3PAO) is added for applicable solicitations and contracts; DoD may require Level 3 (DIBCAC).
- Phase 3: November 10, 2027–November 9, 2028. Level 2 (C3PAO) expands across applicable awards and specified option exercises, while Level 3 applies to its applicable awards.
- Phase 4: from November 10, 2028. Full implementation reaches all applicable solicitations and contracts, including relevant option periods on older contracts.
These are planned coverage dates, not substitutes for the procurement text. Phase 1 still permits DoD to require Level 2 (C3PAO) at its discretion.
Read the procurement record before classifying the assessment
The strongest request contains a solicitation number or subcontract record, a proposal or option date, and the CMMC text. DFARS 252.204-7025 gives the solicitation a fill-in for Level 1 (Self), Level 2 (Self), Level 2 (C3PAO) or Level 3 (DIBCAC). DFARS 252.204-7021 carries the selected level into contract performance.
The provider should preserve five fields from that record:
- solicitation, contract or subcontract identifier and relevant date;
- exact required CMMC level and assessment route;
- whether the affected system will process, store or transmit FCI or CUI;
- each contractor information system and its CMMC unique identifier (UID); and
- whether the decision is award, subcontract award, option exercise or period extension.
This prevents a common mistake: converting “we handle CUI” directly into “book a C3PAO.” The program office or requiring activity selects the status for the procurement. During phase-in, its determination and the document language remain decisive.
For an adjacent voluntary-framework problem, the NIST CSF 2.0 Current Profile assessment explains why a desired security profile is not the same object as a federal contract eligibility status.
Match the level to the correct evidence owner
The three CMMC levels do not produce one interchangeable certificate.
- Level 1 (Self) covers 15 safeguarding requirements. The organization performs the assessment annually, records the result in SPRS and must meet every requirement; no plan of action and milestones (POA&M) is allowed.
- Level 2 covers the 110 requirements from NIST SP 800-171 Revision 2 incorporated by 32 CFR Part 170. A procurement may require Level 2 (Self) or a certification assessment by an authorised or accredited CMMC Third-Party Assessment Organization (C3PAO).
- Level 3 (DIBCAC) adds 24 selected requirements from NIST SP 800-172 and is assessed by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). A Final Level 2 (C3PAO) status for the Level 3 scope is a prerequisite.
For Level 2, the phrase “we already have an 800-171 score” is not enough. Ask whether SPRS shows Level 2 (Self) or C3PAO, whether it is Conditional or Final, which system scope and Commercial and Government Entity (CAGE) codes it covers, and its CMMC Status Date. A readiness review, a NIST assessment and a C3PAO certification assessment may examine related controls but do not create the same contracting record.
Status, affirmation and scope must remain connected
Award eligibility is more than a PDF certificate. Under DFARS 204.7503, the contracting officer checks SPRS for a current status at the required level or higher for every UID the offeror identifies. The UID is a ten-character identifier assigned to a CMMC assessment for a contractor information system. The corresponding affirmation of continuous compliance must also be current.
The date rules make a useful evidence ledger:
- Final Level 1 (Self) is current for no more than one year.
- Final Level 2 (Self), Final Level 2 (C3PAO) and Final Level 3 (DIBCAC) can be current for no more than three years.
- The affirmation for continuing compliance is no more than one year old and is renewed annually.
- Conditional Level 2 or Level 3 is limited to 180 days. Any permitted POA&M must be closed within that window to reach Final status.
- Assessment artifacts are retained for six years from the CMMC Status Date; Level 2 and Level 3 certification artifacts are hashed under Part 170.
An Affirming Official is a senior representative inside the organization with responsibility and authority to attest that applicable requirements remain implemented across the assessment scope. A consultant can identify missing evidence or help prepare the organization, but cannot make that affirmation for the contractor.
The same identity discipline applies to software-supply-chain evidence: the dependency and lockfile evidence article shows why a current file has to be tied to the exact product and decision, rather than accepted by filename alone.
Example: “Level 2 by October” still leaves three different projects
Consider an illustrative fragment created for this article, not a customer message:
“Prime says Level 2 by Oct. We put a score in SPRS last year. Need someone to check it.”
On August 13, 2026, October is still in Phase 1. But the phase does not settle the route. Three bounded possibilities remain:
- The subcontract handles only FCI and the prime has not yet provided the required clause or level. This needs document and information-flow clarification before assessment pricing.
- The subcontract handles CUI and requires Level 2 (Self). The project may be a scope, evidence and current-SPRS-status review, not a C3PAO engagement.
- The solicitation or prime flowdown expressly requires Level 2 (C3PAO). The provider must confirm the assessment scope, CAGE codes, system UID readiness, assessment timing and whether a Conditional or Final status is required by the decision date.
Still unknown are the solicitation language, systems holding CUI, status type, status date, annual affirmation and authority of the poster. Those unknowns prevent a confident quotation; they do not make the post useless.
When the group mention becomes a reviewable project
A reviewable CMMC opportunity has a dated procurement decision and at least one broken connection in the evidence map. Useful examples include a solicitation naming Level 2 (C3PAO) while the supplier can show only Level 2 (Self), an option exercise approaching while the annual affirmation is stale, or a new system entering the contract without a mapped UID and assessment scope.
TOP Prospect can find and group those incomplete discussions only in Telegram groups a user intentionally connects and is authorised to access. It can preserve the original message, source, time and related context, remove duplicates and rank the candidate for human review. It cannot determine which clause legally applies, inspect SPRS, perform a CMMC assessment, issue a status, make the contractor’s affirmation or contact the poster. Pricing and access options cover the discovery layer; qualified assessment and contracting personnel own the evidence decision.
FAQ
Which CMMC implementation phase is active on August 13, 2026?
Phase 1 is active. It began when the complementary DFARS acquisition rule took effect on November 10, 2025. Phase 2 begins on November 10, 2026, so its broader Level 2 C3PAO treatment is not yet current.
Does Phase 1 mean every DoD supplier needs a C3PAO assessment?
No. Phase 1 centres on applicable Level 1 (Self) and Level 2 (Self) requirements, while DoD may require Level 2 (C3PAO) at its discretion. Read the actual solicitation, contract or flowdown.
Is a CMMC certificate enough to prove award eligibility?
No. The contracting officer checks the current SPRS status and affirmation for every UID associated with systems that will process, store or transmit FCI or CUI. The level, scope and procurement requirement must match.
How long do CMMC statuses and affirmations remain current?
Final Level 1 (Self) is annual. Final Level 2 and Level 3 statuses can remain current for three years, with annual affirmations. A Conditional Level 2 or Level 3 status is limited to 180 days while an allowed POA&M is closed.
The calendar is the first coordinate. Procurement text, required status, system UID, scope and affirmation identify the actual work.
Frequently asked questions
Which CMMC implementation phase is active on August 13, 2026?
Phase 1 is active. It began when the complementary DFARS acquisition rule took effect on November 10, 2025. Phase 2 begins one calendar year later, on November 10, 2026, so its broader Level 2 C3PAO treatment is not yet the current phase.
Does Phase 1 mean every DoD supplier needs a C3PAO assessment?
No. Phase 1 focuses on applicable Level 1 Self and Level 2 Self requirements, although DoD may require Level 2 C3PAO at its discretion. The solicitation and contract language, not the calendar alone, identify the required status.
Is a CMMC certificate enough to prove award eligibility?
Not by itself. The contracting officer checks the current status and affirmation in SPRS for every CMMC UID tied to an information system that will process, store or transmit FCI or CUI under the award. The level and assessment scope must match the solicitation.
How long do CMMC statuses and affirmations remain current?
Final Level 1 Self is annual. Final Level 2 Self, Final Level 2 C3PAO and Final Level 3 DIBCAC statuses can remain current for three years, but their affirmations must remain current annually. Conditional Level 2 or 3 status is limited to 180 days while an allowed POA&M is closed.
Sources and further reading
- 32 CFR Part 170, Cybersecurity Maturity Model Certification Program, current through 11 August 2026, accessed 13 August 2026
- Federal Register: CMMC Program final rule, 89 FR 83092, 15 October 2024
- Federal Register: DFARS Case 2019-D041 final rule, 90 FR 43554, 10 September 2025
- Acquisition.gov: DFARS 252.204-7021, Contractor Compliance with CMMC Level Requirements, accessed 13 August 2026
How a Signal worth attention is found
See how Top Prospect finds and organizes Signals worth checking, keeps the original Telegram context, removes duplicates, and helps you decide what to review first. You decide whether to follow up and what to do next.
