Product context is educational relevance, not a feature-status or compliance claim.
What is CMMC (Level 1 vs Level 2)?
The Department’s cybersecurity assessment program for defense contractors and subcontractors handling FCI or CUI; implementation is currently paused in Phase 1.
Plain-English Summary
Why This Matters
Defense contractors still have to protect FCI and CUI under the applicable contract clauses even while Phase II is suspended. Current CMMC Phase I can make the relevant self-assessment status a condition of contract award, and the Department says it will continue enforcing NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments during the review.
Explanation Depth
Concept Explanation
CMMC is one way the Department checks whether defense contractors are protecting government information. Right now the rollout is paused in Phase 1. Level 1 and Level 2 self-assessments still matter, but the broader Phase II move to Level 2 third-party certification that had been scheduled for November 10, 2026 was suspended in July 2026. Always check the current contract and CMMC guidance instead of relying on the old timeline.When You'll See This in SecurePoint
SecurePoint Visitor can help document selected physical-access activities relevant to a customer’s visitor and physical-protection procedures, such as access history and configured escort workflows. Those records may support the customer’s evidence, but SecurePoint does not determine CMMC scope, grant CMMC status, perform the assessment, or replace the customer’s SSP and other required cybersecurity controls.
What You Should Do Next
Check the current CMMC phase and the exact clauses in your solicitations and contracts before planning an assessment. For FCI, review the Level 1 requirements derived from FAR 52.204-21. For CUI under the current Phase I posture, review the Level 2 self-assessment requirements based on NIST SP 800-171 Rev. 2. Do not schedule or market a C3PAO assessment as universally required based on the old November 10, 2026 rollout date; verify the current Department guidance first.
What Can Go Wrong
Sources & References
Related Terms
Need structured workflow compliance?
SecurePoint USA builds these checks, watchlists, approvals, and immutable logs directly into your daily operations.