A Fractional CTO for Government Contractors: CMMC, NIST 800-171 and the Phase 2 Pause
The Pentagon paused the November 2026 CMMC deadline, but the security rules behind it never moved. Here's what federal work actually asks of your technology, in plain English, and how to get ready without overbuying.
For most of the past year, November 10, 2026 was the date circled on every defense supplier's calendar. That was when Phase 2 of CMMC was due to start, and with it, the requirement that many contractors handling sensitive defense information hold a third-party certification before they could win the work.
Then, on July 13, the Department of War's Chief Information Officer suspended Phase 2. A lot of owners I talk to heard "CMMC is off" and quietly moved it down the list.
That's the wrong read. The deadline moved. The requirements didn't. If you're winning federal work, or chasing it, this pause is the best window you'll get to do this properly instead of in a panic.
This is general information for business owners, not legal advice. Questions about what a specific contract requires, or whether you're eligible for an award, belong with your counsel and your contracting officer.
What changed in July, and what didn't
A quick timeline, because the headlines have blurred it.
- December 16, 2024. The CMMC program rule (32 CFR part 170) took effect. It defines the levels, the assessments and the rules for fixing gaps.
- November 10, 2025. The companion acquisition rule took effect, which lets contracting officers put CMMC requirements into contracts through DFARS clause 252.204-7021. That started Phase 1, which mostly relies on self-assessments.
- July 13, 2026. The suspension memo paused the move to Phase 2 and put Phases 3 and 4 on hold. A reform task force was stood up and a public request for information drew more than 1,100 responses.
- September 3, 2026. A revised class deviation told contracting officers to remove third-party CMMC requirements from new and existing contracts, allow Level 1 and Level 2 self-assessments, and keep NIST SP 800-171 Revision 2 as the baseline.
The task force's findings went to the CIO in September but haven't been published, and the department has said the program could be narrowed, restructured or expanded.
Here's what is still fully in force:
- DFARS 252.204-7012. In defense contracts since 2017. If you handle covered defense information, you must protect it to the NIST SP 800-171 standard and report cyber incidents to the DoD within 72 hours of discovery.
- Basic safeguarding. The 15 basic requirements for any system that holds federal contract information (long known as FAR 52.204-21).
- Self-assessments and affirmations. Where a contract calls for CMMC Level 1 or Level 2 (Self), you still assess, post results to the Supplier Performance Risk System (SPRS), and a senior official affirms compliance every year.
- Government assessments. The DoD's own assessors (DIBCAC) can still review you.
- The False Claims Act. More on this below, but it's the part that should keep owners honest.
One more source of confusion: the government is rewriting the FAR, and clause numbers are moving. FAR 52.204-21 is becoming 52.240-93, and the old NIST assessment clause 252.204-7020 now appears as 252.240-7997. The obligations are the same. Don't let a new number convince anyone that a requirement went away.
FCI, CUI and the three levels, in plain English
Almost everything turns on what kind of information you hold.
- Federal contract information (FCI) is information the government provides or you create under a contract that isn't meant for the public. Pricing, delivery schedules, a purchase order with requirements attached. Most contractors have some.
- Controlled unclassified information (CUI) is more sensitive: information the government requires you to safeguard even though it isn't classified. For defense suppliers, it's often technical drawings, specifications and engineering data marked as CUI. In DoD contracts it's called covered defense information.
The level you need follows the information:
- Level 1 covers FCI. Fifteen basic requirements, a self-assessment every year, and no partial credit: every requirement must be met.
- Level 2 covers CUI. The 110 requirements in NIST SP 800-171 Revision 2. Depending on the contract, it's a self-assessment or a certification by an accredited third-party assessor (a C3PAO), every three years, with an annual affirmation.
- Level 3 is for a smaller set of programs with the most sensitive CUI. It requires Level 2 certification first, plus 24 enhanced requirements from NIST SP 800-172, assessed by the government.
At Level 2, you can pass conditionally with a plan of action and milestones (a POA&M) for some gaps, but only if you score at least 80 percent, only for lower-weighted requirements, and you must close every item within 180 days. Some requirements can never be deferred, including having a system security plan at all.
Which rules apply to you
Most owners don't need every framework, just the right ones. This is a starting map, not a verdict.
| If your company... | You're likely looking at |
|---|---|
| Sells to the government but only handles FCI (commercial parts, services, no controlled drawings) | Basic safeguarding and CMMC Level 1 |
| Receives drawings, specs or data marked CUI from a prime or the DoD | DFARS 252.204-7012, NIST SP 800-171 Rev 2, CMMC Level 2, 72-hour incident reporting |
| Makes defense or aerospace articles with export-controlled technical data | All of the above, plus ITAR or EAR access rules, and usually a US-sovereign cloud |
| Is an aerospace manufacturer in the supply chain | AS9100 for quality management, alongside whatever the data requires |
| Sells a cloud or SaaS product to federal agencies | FedRAMP authorization |
| Supports a high-priority program with the most sensitive CUI | CMMC Level 3 and NIST SP 800-172 |
A few of those deserve a sentence each.
ITAR and EAR control who may access defense and dual-use technical data, not just where it sits. Sharing ITAR technical data with a foreign person, including an offshore IT contractor or a support engineer at a vendor, can be an export that needs a license. That rule drives which cloud you use, which vendors can touch your systems and who you can hire into which roles.
Microsoft 365 GCC and GCC High are Microsoft's government clouds. GCC High is built for US-person-only access and is the usual choice when you handle ITAR or export-controlled CUI. GCC can support many CUI environments without export-controlled data, with more work on your side to show it. Neither is required by CMMC itself, and GCC High costs noticeably more, so this is a decision to make on purpose, not by default.
FedRAMP applies if you sell cloud services to federal agencies. It's in the middle of its biggest overhaul in years: the "20x" program moved from pilots to formal rules in 2026, and the older authorization paths are expected to be retired over the next year or so. Plan against the current rules, not a 2024 blog post.
Civilian agencies are catching up: a proposed FAR rule would extend CUI safeguarding to contractors across the government. It isn't final yet.
NIST 800-171: which revision counts
NIST published Revision 3 of SP 800-171 in May 2024. It reorganized the requirements into 97, added families for planning, supply chain risk management and system acquisition, and lets agencies set specific parameters. The DoD, however, has kept contractors on Revision 2 through a class deviation, and CMMC Level 2 is still assessed against Revision 2's 110 requirements.
My advice: build to Revision 2 today, because that's what you'll be assessed on, but design with Revision 3 in mind so you don't build everything twice.
One practical note on encryption. CUI must be protected with FIPS-validated cryptography, and on September 21, 2026, NIST moved all remaining FIPS 140-2 certificates to historical status. Existing systems can keep running, but when you buy something new, ask vendors for their FIPS 140-3 validation.
What Level 2 actually takes
The requirements read like an IT checklist. Meeting them is a business project that touches people, process, technology and paperwork.
- Scoping. The most important decision, and the biggest cost lever. You can bring the whole company into scope, or build a smaller, well-defined enclave where CUI lives and keep everything else out. A tight enclave often cuts cost and effort dramatically. A sloppy one fails the assessment.
- Technology. Multi-factor authentication, managed and encrypted devices, logging and monitoring, controlled remote access, backups, vulnerability management, and a cloud environment that fits your data.
- Process. Access reviews, incident response that can hit the 72-hour reporting window, change management, visitor controls and training that people actually complete.
- Documentation. A system security plan (SSP) that describes how every requirement is met, a POA&M for anything still open, and the evidence behind both. Assessors test what you wrote against what you do.
What it costs
Honest ranges, labeled as ranges:
- The DoD's own estimate for a small company's Level 2 certification is about $104,670 over three years, covering the assessment and affirmations. A Level 2 self-assessment cycle is estimated at about $37,000. Those figures assume you've already implemented the requirements, which the rules have required for years.
- Implementation is the bigger number. Industry estimates for a small company's first cycle, including gap assessment, remediation and certification, commonly run from about $75,000 to $300,000 or more, depending on size, scope and how much is already in place.
- Government cloud licensing adds up. Microsoft 365 GCC High commonly lands somewhere around $60 to $90 or more per user per month once security add-ons are included.
- Time. Small companies commonly need six to eighteen months to get from a first gap assessment to genuinely assessment-ready.
The range is wide because scope is everything. A 40-person shop that keeps CUI in a 12-person enclave has a very different project from one where controlled drawings flow through every inbox.
Using AI when you handle CUI or ITAR data
Your team is already using AI. The question is whether it's using it somewhere your contracts allow.
The practical rule is simple: CUI and export-controlled data don't go into consumer AI tools. A free chatbot account isn't inside your assessed boundary, you don't control where the data is processed or who can see it, and pasting ITAR technical data into a service with foreign-person access can be an unauthorized export. Any AI tool that touches CUI is part of your CUI environment and has to meet the same requirements as everything else in it.
That doesn't mean no AI. It means deliberate AI:
- Use government-cloud services where the data requires it. Azure OpenAI in Azure Government, for example, is authorized at FedRAMP High and DoD Impact Levels 4 and 5, and Microsoft has been bringing Copilot into its government clouds. Check what's available in your tenant today.
- Write an AI use policy that names approved tools and prohibited data, and enforce it on devices and the network rather than by memo.
- Use the NIST AI Risk Management Framework as your structure for thinking about AI risk. It's voluntary, practical and understood by government customers.
There's plenty of value in AI for the parts of the business outside the enclave. The scoping decision you make for CMMC is the same one that makes safe AI adoption possible.
Why this is a leadership problem, not an IT ticket
Every hard question here is a business decision wearing a technical costume. Which contracts are worth the compliance cost? Enclave or whole company? GCC or GCC High? Who may see export-controlled data, and what does that mean for hiring and vendors?
And someone has to sign. Affirmations are made by a senior official of your company, and the DOJ's Civil Cyber-Fraud Initiative uses the False Claims Act against contractors that misrepresent their cybersecurity. Settlements have run from hundreds of thousands to several million dollars, including against small companies, and 2025 was the busiest year so far. Several of those cases began with a whistleblower inside the company's own IT or security team. An honest score with a credible plan is defensible. An inflated one isn't.
It helps to be clear about who does what:
- Your MSP or MSSP runs the tools: devices, patching, monitoring, the help desk. Essential, but they operate what you decide.
- A C3PAO assesses you. By rule, an assessor can't take part in your certification if they consulted to prepare you in the past three years, so your assessor can't also be your builder.
- Counsel answers the legal questions: contract terms, export classification, disclosures.
- A CTO owns the architecture, the scope, the budget and the trade-offs, holds the vendors accountable and translates all of it into decisions an owner can make.
Most $5M to $35M contractors don't need that CTO full-time. They need one intensely for six to twelve months, then at a lighter cadence to keep the program honest. That's exactly the shape of work a fractional engagement fits, and I've written about what it typically costs and why the model has spread.
I've spent a lot of my career in businesses where a regulator had to sign off before we could operate. At Set Jet, a private aviation company I co-founded, that meant clearing FAA and DOT approvals. The lesson carries over directly: compliance goes well when it's designed into the operation, and badly when it's bolted on the week before the audit.
A practical 90-day starting plan
You won't be certification-ready in 90 days. You can have a defensible position and a real plan.
- Days 1 to 15: know your obligations. Pull your current contracts and subcontracts and list the clauses in them. Ask your primes what they expect. Find out whether you have an SPRS entry and what it says.
- Days 15 to 30: find the data. Map where FCI, CUI and any export-controlled data actually enters, lives and leaves the company: email, file shares, engineering tools, laptops, vendors. This is usually where the surprises are.
- Days 30 to 45: decide scope. Choose whole-company or enclave, and choose your cloud with ITAR and cost in view. This decision shapes everything that follows.
- Days 45 to 60: assess honestly. Run a gap assessment against the 110 requirements. Draft the system security plan and a POA&M with owners and dates.
- Days 60 to 75: take the quick wins. Multi-factor authentication everywhere, FIPS-validated encryption on devices, centralized logging, an AI use policy, and removal of stale accounts and unmanaged devices.
- Days 75 to 90: prepare for the bad day and set the budget. Write an incident response plan that can meet the 72-hour reporting rule, including getting the DoD-approved certificate you need to file a report. Then put a realistic remediation budget and timeline in front of leadership, and consider a mock assessment before a real one.
At the end of that, you'll know what you have, what you owe, what it will cost and what you're going to do about it.
The pause is the opportunity
The companies that treat July's suspension as a reprieve will be scrambling again when the recommendations turn into rules. The ones that use it will walk into the next phase with a tight scope and an honest score.
If you'd like a quick read on where your technology stands overall, the scorecard takes about five minutes. And if you're working through CMMC, ITAR or a first federal contract and want someone to own the technology side of it with you, let's talk.
Not sure what level of tech leadership you need?
Tell me where the business is and where it's headed. I'll tell you honestly whether you need a fractional CTO, a full-time hire, or neither yet.