CMMC Calendar

The CMMC Calendar tracks the dates that matter for CMMC compliance in Hawaii and Guam: CMMC Level 1 and Level 2 assessment windows, DFARS rule milestones and history, and changes affecting CUI and C3PAO scheduling. It also lists Intech Pacific webinars and live events, built for compliance officers and CMMC consultants planning around real deadlines.

CMMC did not appear overnight, and it did not appear in a vacuum. It is the product of more than two decades of federal cybersecurity policy, a slow tightening of DFARS rules, and a hard-earned recognition that self-reported cybersecurity compliance was not protecting Controlled Unclassified Information (CUI) or Federal Contract Information (FCI) as intended. This timeline walks through every major milestone, from the earliest federal information security laws through the CMMC program's projected full implementation in 2028, so Hawaii and Guam contractors, subcontractors, and CMMC providers can see exactly how today's CMMC Level 1, CMMC Level 2, and CMMC Level 3 requirements came to be.

CMMC Program Timeline

2002

FISMA and the Cybersecurity Research and Development Act Lay the Groundwork

Two federal actions in 2002 set the stage for the compliance framework Hawaii and Guam defense contractors follow today. The Federal Information Security Management Act (FISMA) required every federal agency to build, document, and continuously assess a formal information security program, establishing that cybersecurity was a matter of ongoing management, not a one-time checkbox. That same year, the Cybersecurity Research and Development Act directed new funding to the National Institute of Standards and Technology (NIST) and the National Science Foundation for network security research.

Neither action mentioned CMMC by name, since the program did not exist for another 17 years, but both created the research base and legal precedent that federal cybersecurity requirements eventually built into DFARS, NIST SP 800-171, and the CMMC framework contractors comply with now. For a CMMC provider explaining program history to a new client, 2002 is the year cybersecurity compliance first became a documented, agency-wide federal obligation rather than an informal best practice.

For Hawaii and Guam organizations working defense contracts today, 2002 is a useful answer to the question of why an IT provider needs to document everything rather than just fix problems as they arise. FISMA-style documentation requirements are the ancestor of the System Security Plan and Plan of Action and Milestones every CMMC Level 2 contractor now maintains.

2003

NIST Builds the Risk Management Framework

In 2003, NIST's Risk Management Framework effort, sometimes called the FISMA Project, began publishing the standards documents that still underpin CMMC assessment criteria: FIPS 199 for security categorization, FIPS 200 for minimum security requirements, and the first version of NIST Special Publication 800-53 for security and privacy controls on federal systems.

These publications established the control-based approach to cybersecurity that NIST later adapted for nonfederal systems in NIST SP 800-171, the standard that defines CMMC Level 2 requirements today. For contractors seeking a CMMC gap assessment now, these decades-old federal control families are the direct ancestor of the 110 security requirements they must implement, and the same control-family structure still shapes how a CMMC consultant organizes a remediation roadmap.

Contractors preparing for a CMMC Level 2 assessment often ask why NIST 800-171 controls feel so granular and interrelated rather than a simple checklist. The answer traces back to the control-family structure NIST built in 2003, which every subsequent NIST publication, including 800-171, inherited almost intact.

2010

Executive Order 13556 Creates the CUI Program

President Obama signed Executive Order 13556 in November 2010, establishing the Controlled Unclassified Information (CUI) program and rescinding the patchwork of agency-specific "sensitive but unclassified" designations that came before it. EO 13556 created a single, government-wide framework for identifying, marking, and safeguarding CUI, the category of information that now defines CMMC Level 2 scope.

Without this order, there would be no consistent legal basis for the CUI protections written into DFARS clause 252.204-7012 or the 110 controls in NIST SP 800-171. For Hawaii and Guam contractors handling Controlled Unclassified Information today, CMMC scoping still starts with the same question EO 13556 first forced federal agencies to answer: what is CUI, and where does it live in your environment? Answering that question correctly is still the first step in any CMMC gap assessment, and getting it wrong is one of the most common reasons contractors either over-scope their CMMC Enclave boundary or miss CUI entirely.

Hawaii and Guam subcontractors that receive CUI-marked deliverables from a prime contractor are seeing EO 13556's labeling framework in action every day. Getting CUI identification right at the subcontractor level is one of the most common gaps Intech Pacific finds during a CMMC gap assessment.

2011

DFARS Case 2011-D039 Proposes the First Safeguarding Rule

The Department of Defense proposed DFARS Case 2011-D039 in 2011, introducing rule 252.204-7000 to require contractors to safeguard unclassified DoD information related to fundamental research. It was a narrow rule focused on research contracts, but it marked the first time DFARS explicitly required contractors to protect sensitive unclassified information on their own systems rather than only inside government networks.

This proposed rule opened the door to the much broader safeguarding requirements that followed later in the decade, and it remains a useful reference point for understanding how DFARS cybersecurity requirements evolved from narrow, contract-specific clauses into the sweeping CMMC framework in place today. It is also a reminder that CMMC compliance obligations have always started as proposed rules with a public comment period, the same process the CMMC Program itself went through more than a decade later.

This early, narrow rule is a reminder that CMMC obligations rarely arrive all at once. Contractors that build a habit of monitoring DFARS case numbers each year tend to be far better positioned to anticipate change than those who wait for a prime contractor to forward a new clause after the fact.

2013

DFARS 252.204-7000 Takes Effect

DFARS clause 252.204-7000 became effective in 2013, formally requiring contractors to protect sensitive unclassified defense information on non-federal systems. While the clause applied to a limited set of contracts, its effect on the defense industrial base (DIB) was significant: contractors could no longer treat cybersecurity as optional or assume that government-owned networks were the only systems that needed protecting.

This rule is a direct predecessor to today's CMMC Level 1 and CMMC Level 2 requirements, and it is often the starting point Intech Pacific uses when explaining to new clients why CMMC compliance is not a sudden new burden, but the latest step in a rule set defense contractors have been building toward for over a decade. Contractors who trace their compliance obligations back to this rule tend to have an easier time understanding why CMMC cost is proportional to scope, not an arbitrary fee tied to a new certification.

Contractors who signed defense contracts after 2013 have likely carried DFARS 252.204-7000 obligations for over a decade without realizing how directly they connect to today's CMMC Level 1 requirements. A CMMC gap assessment often uncovers these long-standing but neglected obligations hiding in plain sight.

2015

NIST SP 800-171 Publishes the CMMC Level 2 Control Set

NIST published Special Publication 800-171, "Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations," in 2015. This publication remains the single most important document in the entire CMMC ecosystem: its 110 security requirements, organized into 14 control families, are the backbone of CMMC Level 2 today.

Every CMMC gap assessment Intech Pacific performs for Hawaii and Guam contractors ultimately measures posture against this document. Understanding NIST SP 800-171 is not optional for any organization that wants to work with a CMMC consultant, pursue CMMC certification, or prepare for a C3PAO assessment; it is the foundation the entire CMMC Level 2 model was built on, and it is the document a CMMC Assessor will reference line by line during a certification assessment.

Any organization asking a CMMC MSP for a CMMC cost estimate should expect that estimate to be driven primarily by how many of the 110 NIST SP 800-171 controls from this 2015 publication are already in place, and how many still need to be built, documented, and operated continuously.

2016

DFARS 252.204-7012 Makes Self-Assessment Mandatory

DFARS clause 252.204-7012 took effect in 2016, and it remains one of the most consequential rules in defense contracting history. The clause required all DoD contractors handling covered defense information to implement the 110 security requirements in NIST SP 800-171, report cyber incidents within 72 hours, and flow the same requirements down to subcontractors.

It also introduced the compliance mechanism CMMC would later formalize: contractors were expected to self-assess and attest to their own security posture, without independent verification. That gap between self-attestation and actual, verified compliance is precisely the problem CMMC was created to solve three years later. Any CMMC MSP working with legacy defense contractors today will recognize DFARS 7012 language embedded in decade-old contracts that are still active.

DFARS 252.204-7012 flow-down language is still active in current subcontracts throughout the defense industrial base. CMMC subcontractors in Hawaii and Guam that assume their prime contractor's certification covers them are often surprised to learn this 2016 flow-down obligation still applies directly to their own systems.

2017

Self-Assessment Becomes Standard Practice Across the DIB

By 2017, self-assessment against NIST SP 800-171 was a standing requirement for every DoD contractor and subcontractor handling covered defense information, per the terms of DFARS 252.204-7012. In practice, enforcement was inconsistent.

Many primes and subcontractors submitted System Security Plans (SSPs) and scores to the Supplier Performance Risk System (SPRS) that overstated their actual security posture, whether from misunderstanding the requirements or simply underinvesting in cybersecurity. This enforcement gap, combined with a wave of publicized breaches in the defense supply chain, became the direct catalyst for the Department of Defense's decision to build an independently verified certification model instead of relying on contractor self-attestation. This is the year the industry-wide credibility problem CMMC was built to solve became impossible to ignore.

The enforcement gap that defined 2017 is exactly why CMMC assessment now requires independent verification rather than self-attestation for CMMC Level 2 certification. Contractors who still carry a self-assessment mindset from this era are often the ones most likely to struggle on their first C3PAO assessment.

2019

DoD Announces the Creation of CMMC

In 2019, the Department of Defense announced the creation of the Cybersecurity Maturity Model Certification program, developed in partnership with Carnegie Mellon University's Software Engineering Institute and the Johns Hopkins University Applied Physics Laboratory. The announcement followed a string of high-profile breaches across the defense industrial base, including intrusions that compromised sensitive program data through subcontractor networks.

CMMC was designed to close the self-attestation gap exposed by years of inconsistent NIST SP 800-171 compliance: instead of contractors grading their own homework, a formal certification model would require independent verification by a CMMC Third-Party Assessment Organization (C3PAO) for higher-risk contracts. This is the year CMMC, as a named program, was born, and the year the terms CMMC readiness, CMMC certification, and CMMC consultant first entered the defense contracting vocabulary.

For Hawaii and Guam contractors, 2019 marks the year CMMC readiness became a real planning category, distinct from general IT compliance work. Organizations that started building toward CMMC readiness in 2019 or 2020 are generally far ahead today of those only beginning the process now.

2020

The Interim Rule and the First Pathfinder Contracts

2020 was the year CMMC moved from concept to contract language. On September 29, DoD published the DFARS interim rule (Case 2019-D041) in the Federal Register, formally authorizing CMMC requirements to appear in DoD solicitations; the rule took effect on November 30.

On December 8, the CMMC Accreditation Body and DoD released an updated implementation timeline projecting full rollout by September 2021, and the Department announced seven pathfinder contracts to pilot the model, requiring contractors on those specific awards to complete a third-party assessment. Days later, on December 31, the General Services Administration signaled that CMMC's reach would extend beyond the DoD alone, noting in its Polaris IT services solicitation that all government contractors, civilian and military, should prepare for similar requirements.

The pace set in 2020 proved far more ambitious than what actually followed, but it marked the first time CMMC had real regulatory teeth, and the first time contractors and CMMC providers had to plan around an actual effective date rather than a policy announcement.

Contractors who won one of the seven original pathfinder contracts in 2020 remain some of the most experienced organizations in the country at completing a full C3PAO assessment, and lessons learned from that pilot still shape how CMMC Overwatch and CMMC Command engagements are scoped today.

2021

CMMC 2.0 Streamlines the Model

Facing sustained industry criticism over cost, complexity, and an unrealistic assessor pipeline, the Department of Defense announced CMMC 2.0 on November 4, 2021. The revised model eliminated two of the original five maturity levels and removed CMMC-unique practices that didn't map directly to NIST SP 800-171, leaving three levels: CMMC Level 1 for Federal Contract Information (FCI), CMMC Level 2 for Controlled Unclassified Information (CUI) aligned entirely to the 110 NIST SP 800-171 controls, and CMMC Level 3 for the highest-risk programs, layering in select NIST SP 800-172 enhanced requirements.

CMMC 2.0 also expanded the use of annual self-assessment for a subset of Level 2 contracts, rather than requiring a C3PAO assessment for every one. This is the version of CMMC that exists today, and it is the model Intech Pacific's CMMC Overwatch, CMMC Sentry, CMMC Command, and CMMC Enclave services are built around. Every CMMC Level referenced anywhere on this site, and everywhere else in the industry, refers to this 2021 restructuring.

CMMC 2.0's three-level structure is the direct reason Intech Pacific organizes its service menu around CMMC Overwatch, CMMC Sentry, CMMC Command, and CMMC Enclave: each service model maps to a different combination of CMMC Level and internal IT capability defined by this 2021 restructuring.

2022

The Assessor and Training Ecosystem Takes Shape

With the CMMC 2.0 model set, 2022 became the year the assessor and training ecosystem caught up. In September, the Cyber AB, the official accreditation body for the CMMC ecosystem, established the Cybersecurity Assessor and Instructor Certification Organization (CAICO) to manage training and certification for CMMC Certified Professionals (CCPs) and CMMC Certified Assessors (CCAs).

The following month, CAICO launched the Certified CMMC Professional exam, giving individuals a formal path to earn the CCP credential that now defines who is qualified to guide contractors through CMMC readiness. This is the year the credentials behind terms like CMMC consultant and CMMC provider started to mean something specific and verifiable, rather than a marketing claim. When Intech Pacific describes its team as certified CCPs and CCAs, this is the credentialing structure that claim refers to.

When evaluating a CMMC consultant or CMMC provider, confirming that its staff hold active CCP or CCA credentials created in 2022 is one of the fastest ways to separate genuine CMMC expertise from general IT marketing language.

2023

The First Assessments and the Proposed Rule

2023 delivered two milestones that moved CMMC from policy to practice. In January, CMMC third-party assessor RedSpin completed the first successful assessment under the Joint Surveillance Voluntary Assessment Program (JSVAP), an early, voluntary trial run of the formal C3PAO assessment process later required under CMMC 2.0.

Then, on December 26, the Department of Defense published the CMMC Program proposed rule in the Federal Register, formally proposing to codify the CMMC 2.0 model as 32 CFR Part 170. This rule opened a public comment period and set the stage for the finalized program requirements that followed the next year, giving contractors, C3PAOs, and CMMC consultants their first detailed look at exactly how the finalized certification and assessment requirements would function in practice.

The JSVAP assessments conducted in 2023 gave early C3PAOs and CMMC Assessors real-world experience before the final rule made certification assessments mandatory, which is part of why assessment quality and consistency have improved industry-wide since the rule took effect.

2024

The CMMC Program Final Rule Publishes

On October 15, 2024, the Department of Defense published the CMMC Program final rule in the Federal Register, formally establishing the CMMC Program under 32 CFR Part 170. The final rule confirmed the three-level structure introduced in CMMC 2.0, detailed the assessment and affirmation requirements for each level, and set out how Plans of Action and Milestones (POA&Ms) could be used to close narrow, non-critical gaps after an assessment.

This rule answered the question defense contractors, subcontractors, and CMMC consultants had been asking since 2019: what, exactly, will CMMC require, and how will it be enforced. With 32 CFR Part 170 finalized, the only remaining step was giving DoD contracting officers the contractual authority to actually require it, which arrived the following year.

Contractors who used the roughly ten-month gap between the 2023 proposed rule and the 2024 final rule to complete a CMMC gap assessment entered Phase 1 implementation in 2025 with a substantial head start over competitors who waited for the rule to finalize before starting any remediation work.

2025

The Contract Clause Rule and Phase 1 Implementation

2025 delivered the final piece of the CMMC regulatory puzzle. On September 10, DoD published the companion 48 CFR contract clause rule, giving contracting officers the authority to write CMMC requirements directly into solicitations and contracts.

Two months later, on November 10, Phase 1 implementation officially began: eligible DoD solicitations started requiring CMMC Level 1 or CMMC Level 2 self-assessments, with results and annual affirmations submitted to the Supplier Performance Risk System (SPRS). For Hawaii and Guam contractors and subcontractors, this is the year CMMC readiness stopped being a future planning exercise and became an active condition of contract eligibility.

Hawaii and Guam contractors bidding on solicitations issued after November 2025 should expect CMMC Level 1 or Level 2 self-assessment requirements to appear directly in the solicitation language itself, not as a future condition mentioned only in passing.

2026

Phase 1 Continues, Phase 2 Approaches

Phase 1 implementation continues through November 9, 2026, meaning many DoD solicitations issued this year still rely on CMMC Level 1 and CMMC Level 2 self-assessment rather than independent C3PAO certification. That changes on November 10, 2026, when Phase 2 begins and DoD starts requiring CMMC Level 2 certification through a formal C3PAO assessment for applicable solicitations, rather than accepting self-assessment alone.

Contractors who have relied on self-assessment through Phase 1 face a narrowing runway: a CMMC gap assessment, remediation, and C3PAO scheduling all take months to complete, and C3PAO assessment slots are a finite, in-demand resource. This is the year Intech Pacific expects the sharpest increase in demand for CMMC Overwatch, CMMC Sentry, CMMC Command, and CMMC Enclave engagements, as contractors who delayed readiness work race to avoid losing contract eligibility when Phase 2 requirements take hold.

Organizations that have not yet completed a CMMC gap assessment should treat 2026 as the last full year to prepare before CMMC Level 2 certification becomes a hard, independently verified requirement rather than a self-assessed one.

July 13, 2026

DoW Suspends CMMC Phase II, Launches 60-Day Reform Review

The Department of War suspended CMMC Phase II requirements, originally set to take effect November 10, 2026, and launched a 60-day CMMC Reform Task Force to review the program's future. Phase I self-assessment requirements remain in place, and contractors are still contractually obligated to protect covered defense information under DFARS 252.204-7012 and NIST SP 800-171. The move aims to cut compliance costs for small and mid-sized defense contractors without lowering the security bar.

2027

Phase 3 Adds CMMC Level 3 Certification

Phase 3 begins November 10, 2027, extending certification requirements to CMMC Level 3 for the highest-risk DoD programs. Under the final rule, Level 3 certification requires a contractor to first hold a current CMMC Level 2 (C3PAO) certification, then undergo an additional assessment conducted directly by the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) against 24 enhanced security requirements drawn from NIST SP 800-172.

Relatively few Hawaii and Guam contractors will need Level 3, since it applies only to programs handling the most sensitive Controlled Unclassified Information against advanced persistent threats, but subcontractors flowing into prime contracts with Level 3 requirements should expect those obligations to cascade down through the supply chain.

Prime contractors managing Level 3 programs in 2027 will increasingly require their subcontractors to demonstrate at least CMMC Level 2 certification as a condition of continued subcontracting, even when a given subcontractor's own scope does not reach Level 3.

2028

Phase 4 Brings Full CMMC Implementation

Phase 4, full implementation of the CMMC Program, begins November 10, 2028, three years after Phase 1 launched. From this date forward, DoD contracting officers can include CMMC Level 1, Level 2, or Level 3 requirements in any applicable solicitation without the phase-in restrictions that limited enforcement from 2025 through 2027.

By 2028, every active and prospective DoD contractor and subcontractor handling Federal Contract Information or Controlled Unclassified Information in Hawaii and Guam should expect CMMC compliance to be a standard, non-negotiable condition of contract award, not a future requirement to plan around. Phase dates reflect the Department of Defense's currently published implementation plan and are subject to change; Intech Pacific updates this calendar as DoD issues new guidance.

By the time Phase 4 arrives, Hawaii and Guam organizations without a CMMC certification appropriate to their contract's requirements should expect to be ineligible to bid on, or continue performing, applicable DoD work.

How This History Shapes Intech Pacific's CMMC Service Model

The three decades of policy covered in this timeline explain why Intech Pacific structures its CMMC services the way it does today. CMMC Overwatch exists because the Certified CMMC Professional credential became available in 2022 and because contractors need outsourced compliance leadership that speaks the language of NIST SP 800-171 without replacing their existing IT vendor. CMMC Sentry exists because DFARS 252.204-7012 in 2016 made continuous control implementation, not a one-time audit, the standard contractors must maintain, which requires an actively managed security tool stack rather than a point-in-time project.

CMMC Command exists because Phase 1 implementation in 2025 turned CMMC readiness into an active condition of contract eligibility for organizations with little or no internal IT, who need a single CMMC provider to own both day-to-day IT operations and compliance at the same time. CMMC Enclave exists because Executive Order 13556 in 2010 defined CUI as a distinct, identifiable category of information, one that can be isolated into a dedicated Azure GCC High boundary rather than protected everywhere across an organization's environment.

Reading this timeline alongside Intech Pacific's service menu makes the connection between CMMC history and CMMC IT strategy concrete: every phase of the program, from FISMA in 2002 through Phase 4 in 2028, narrowed the gap between what contractors claimed about their cybersecurity and what they could actually prove. Choosing the right CMMC MSP, CMMC consultant, or CMMC provider today means choosing a partner who understands not just the current rule, but the twenty-six years of policy that led to it.

Where We Are Now

As of August 2026, the CMMC program remains in Phase 1, with Level 1 and Level 2 self-assessments continuing to appear in DoD solicitations. On July 13, 2026, the Department of War suspended Phase 2's transition to formal C3PAO certification, originally scheduled for November 2026, along with the broader phase implementation timeline, while a CMMC Reform Task Force conducts a 60-day review of the program's future (a report to the DoW CIO is expected around mid-September 2026). Intech Pacific's CMMC Certified Professionals and CMMC Assessors are tracking the review as it unfolds and will post updates, webinars, and readiness workshops on this calendar as new milestones are announced.

The pause doesn't remove your existing obligations. Hawaii and Guam contractors are still required to self-assess against NIST SP 800-171 and to protect covered defense information under DFARS 252.204-7012, and that baseline isn't going anywhere regardless of how the reform review lands. A CMMC gap assessment is exactly how you measure where your organization stands against that baseline today, so if you haven't mapped your CUI footprint or scored your NIST SP 800-171 posture, this review period is the time to close that gap, not something to postpone until the next deadline is back on the calendar.

Common Misconceptions About CMMC History

Even organizations that have followed CMMC news for years sometimes carry assumptions inherited from an earlier phase of the program. Correcting them matters, because pursuing CMMC certification, CMMC readiness, or a CMMC gap assessment based on stale information can waste months of preparation time and misallocate a Hawaii or Guam contractor's compliance budget.

CMMC is a brand-new requirement invented in 2019.

In reality, CMMC formalized more than 15 years of existing DFARS and NIST obligations dating back to 2011. What changed in 2019 was the introduction of independent, third-party verification, not the underlying security requirements themselves.

1

Only large prime contractors need to worry about CMMC.

DFARS flow-down provisions dating to 2016 apply CMMC requirements to subcontractors of any size that handle FCI or CUI, regardless of contract value. Small and mid-size subcontractors in Hawaii and Guam are just as exposed as large primes.

2

A clean NIST SP 800-171 self-assessment score in SPRS is the same as CMMC certification.

Self-assessment, even an accurate one, does not satisfy CMMC Level 2 certification requirements once Phase 2 begins in November 2026. Only an independent assessment by an authorized C3PAO, or DIBCAC for Level 3, produces a valid CMMC certification.

3

CMMC 2.0 and the original CMMC model are functionally the same, just renamed.

CMMC 2.0, announced in November 2021, cut the model from five levels to three and removed CMMC-unique practices that did not map directly to NIST SP 800-171, changing both the scope and the cost of achieving CMMC Level 2 certification.

4

The CMMC pause means contractors have nothing to do until Phase 2 resumes.

The July 2026 suspension only paused Phase 2's C3PAO certification requirement; Phase 1 self-assessments for CMMC Level 1 and Level 2 are still appearing in solicitations, and NIST SP 800-171 and DFARS 252.204-7012 obligations remain in force.

5

Key CMMC Terms Referenced in This Timeline

CMMC history is easier to follow with a working definition of the acronyms that recur across every phase of the program. This glossary covers the terms Hawaii and Guam contractors encounter most often when working with a CMMC consultant, preparing for a CMMC assessment, or evaluating a CMMC MSP.

CMMC Levels

The tiered structure of the CMMC Program: CMMC Level 1 for Federal Contract Information, CMMC Level 2 for Controlled Unclassified Information, and CMMC Level 3 for the highest-risk programs. Every requirement in this timeline maps to one of these three levels.

1

NIST 800-171

The NIST Special Publication that defines the 110 security requirements behind CMMC Level 2, first published in 2015 and still the technical foundation of the program.

2

DFARS

The Defense Federal Acquisition Regulation Supplement, the set of contract clauses, including 252.204-7000 and 252.204-7012, that introduced cybersecurity safeguarding requirements years before CMMC existed.

3

CUI

Controlled Unclassified Information, the category of sensitive government data defined by Executive Order 13556 in 2010 that CMMC Level 2 and CMMC Level 3 are built to protect.

4

C3PAO

A CMMC Third-Party Assessment Organization, the accredited body authorized to conduct formal CMMC Level 2 certification assessments.

5

SPRS

The Supplier Performance Risk System, the DoD database where contractors submit NIST SP 800-171 self-assessment scores and CMMC affirmations

6

PIEE

Procurement Integrated Enterprise Environment, the DoD platform contractors use for a range of contract administration and reporting functions tied to federal acquisition compliance.

7

GCC High (GCCH)

Microsoft's government-community cloud environment, commonly used as the technical foundation for a CMMC Enclave because it meets the compliance baseline CUI handling requires.

8

CMMC Certified Professional / CMMC Assessor

The CCP and CCA credentials created by CAICO in 2022, which qualify individuals to guide CMMC readiness work or conduct official assessments.

9

FCI

Federal Contract Information, defined under FAR 4.1901, the category of information CMMC Level 1 is designed to protect. FCI is less sensitive than CUI but still subject to the 15 baseline safeguarding requirements in FAR clause 52.204-21.

10

CMMC Cost

The total investment required to reach and maintain a given CMMC Level, driven primarily by how many NIST SP 800-171 or FAR 52.204-21 controls an organization still needs to implement, not a flat certification fee.

11

CMMC IT

Shorthand for the IT operations, tooling, and documentation practices an organization must maintain to support ongoing CMMC compliance, whether delivered internally, through a CMMC MSP, or through a co-managed model.

12

Unmatched CMMC Expertise in Hawaii and Guam img

Terence Tang

CMMC Certified Assessor, CISSP

certification level2 last cta
CCA Logo White

Talk to a CMMC Certified Assessor Today!

Intech Pacific is the only CMMC Level 2 Certified MSP serving Hawaii and Guam, with CMMC Certified Professionals and Assessors on staff. Explore how we can help with our expert guidance on CMMC, IT, cybersecurity, IT compliance, and AI.

Frequently Asked Questions About CMMC Program History

When did the CMMC program officially begin?

The Department of Defense announced the creation of CMMC in 2019, but the program's requirements build on federal cybersecurity policy dating back to 2002, with the Controlled Unclassified Information program established by Executive Order 13556 in 2010 and DFARS safeguarding clauses starting in 2011.

What is the difference between CMMC 1.0 and CMMC 2.0?

CMMC 1.0, introduced in 2019 and 2020, used five maturity levels with some CMMC-specific practices layered on top of NIST SP 800-171. CMMC 2.0, announced in November 2021, streamlined the model to three levels aligned directly to NIST SP 800-171 and NIST SP 800-172, and expanded the use of self-assessment for a subset of Level 2 contracts. CMMC 2.0 is the version in effect today.

What phase of CMMC implementation are we in right now?

As of Phase 1, which runs from November 10, 2025 through November 9, 2026, DoD solicitations require CMMC Level 1 or CMMC Level 2 self-assessments. Phase 2 begins November 10, 2026 and introduces CMMC Level 2 certification through a formal C3PAO assessment.

When will CMMC be fully implemented across all DoD contracts?

Based on the Department of Defense's published four-phase plan, full implementation, referred to as Phase 4, is scheduled to begin November 10, 2028. From that date, contracting officers can include CMMC Level 1, Level 2, or Level 3 requirements in any applicable solicitation.

Do I need a CMMC consultant to understand this timeline?

Understanding CMMC history helps explain why today's requirements exist, but applying that history to your specific environment, contracts, and CUI scope is where a CMMC consultant or CMMC MSP like Intech Pacific adds value. Certification outcomes depend on your organization's environment, evidence, and the findings of your assigned C3PAO or DIBCAC assessor.

What is the difference between CMMC Level 1 and CMMC Level 2?

CMMC Level 1 covers Federal Contract Information (FCI) and requires an annual self-assessment against the 15 security requirements in FAR clause 52.204-21. CMMC Level 2 covers Controlled Unclassified Information (CUI) and requires implementation of the 110 security requirements in NIST SP 800-171, verified through either self-assessment or a formal C3PAO certification assessment, depending on the contract.

Does CMMC apply to subcontractors, not just prime contractors?

Yes. CMMC requirements flow down through the supply chain under DFARS clause 252.204-7012, first effective in 2016. Any CMMC subcontractor handling FCI or CUI on behalf of a prime contractor is subject to the same CMMC Level requirements as the prime, regardless of the subcontractor's size or the value of its portion of the contract.

Is a CMMC Enclave using GCC High required for CMMC certification?

No single technology is required by the CMMC final rule. A CMMC Enclave built on Microsoft GCC High (GCCH) is one common strategy for isolating CUI and shrinking assessment scope, but organizations can also pursue CMMC Level 2 certification across their full environment without an enclave. The right approach depends on your CUI footprint, existing infrastructure, and CMMC cost tolerance, which is typically evaluated during a CMMC gap assessment.

Why does this DFARS and NIST history matter if my current contract doesn't mention CMMC yet?

Even if a current solicitation does not name CMMC directly, most active DoD contracts already carry DFARS clause 252.204-7012 obligations dating back to 2016, which require NIST SP 800-171 implementation regardless of whether a formal CMMC assessment has been scheduled. Waiting for a contract to explicitly require CMMC before starting a CMMC gap assessment often means starting compliance work years later than the underlying legal obligation actually began.

What happens if my organization misses a CMMC deadline tied to its phase?

Missing a required CMMC Level or assessment type tied to your phase can make your organization ineligible for contract award or continued performance on applicable solicitations. Because CMMC gap assessments, remediation, and C3PAO or DIBCAC scheduling all take months, Intech Pacific recommends starting readiness work well before your specific contract's CMMC requirement takes effect, not after.