Reference · last checked September 12, 2026
CMMC statistics, sourced and dated
16 figures, each with the document it came from and the date somebody last read that document. Quote any of them; the source is one click away.
Use these freely. No attribution is required, though a link is welcome. If you find one that has gone stale, tell us and it gets corrected — four figures on this site already have been.
The standard itself
These do not move with the programme's timetable. They are what a Level 2 assessment examines, and they have been stable through both 2026 changes.
-
110
security requirements
CMMC Level 2 is assessed against the 110 security requirements of NIST SP 800-171, across 14 families.
NIST SP 800-171 Rev. 2 · Current
-
320
assessment objectives
The 110 requirements decompose into 320 assessment objectives. An assessment examines objectives, not requirements, which is why "we meet the control" and "we can evidence it" are different claims.
NIST SP 800-171A · Current
-
14
requirement families
From Access Control at 22 requirements down to Personnel Security at 2. The distribution matters when scoping: the families are not equal in size or effort.
NIST SP 800-171 Rev. 2 · Current
-
74 / 25 / 11
provider / shared / customer
Of the 110 requirements, 74 can be substantially addressed by a managed provider's environment, 25 are shared, and 11 remain the contractor's regardless of who runs the infrastructure. The System Security Plan, the POA&M and the SPRS affirmation are in that last group.
Cloud Kings shared responsibility matrix · Current
The Phase II suspension
The part most published figures now get wrong. Two separate actions moved the programme in 2026, and the second one is the reason the first is binding.
-
13 July 2026
Phase II suspended
The Department of War suspended CMMC Phase II requirements, holding all pending and future implementation milestones in abeyance until further notice.
DoW memorandum 26-P-1023 · 13 July 2026
-
10 Nov 2026
the date it would have taken effect
Phase II had been scheduled to begin on 10 November 2026. The suspension arrived roughly four months ahead of it.
DoW memorandum 26-P-1023 · 13 July 2026
-
Cost and burden
the stated reason — not assessor capacity
The Department gave prohibitive compliance costs and bureaucratic burden on small business as the rationale. Assessment capacity is a real constraint, documented separately by GAO, but it is not the reason the memorandum gives. Pages asserting otherwise are repeating an inference.
DoW memorandum 26-P-1023 · 13 July 2026
-
3 Sept 2026
the class deviation that made it binding
A class deviation directed contracting officers to strip CMMC's third-party assessment requirements out of solicitations and contracts, converting a policy suspension into an enforceable instruction. Signed by the principal director for defense pricing, contracting and acquisition policy.
DARS class deviation 2026-O0025 Rev. 3 · 3 September 2026 not read directly — see method
-
Self-assessment
how compliance is enforced during the suspension
The release states that Phase I self-assessment requirements remain, and that enforcement will rely on self-assessments together with selected government-led assessments. Wider claims circulate — that only Level 1 (Self) and Level 2 (Self) may be designated, and that no waivers are available — but they are not in this release, and we have not read a document that states them.
DoW memorandum 26-P-1023 · Current
Capacity and scale
Two figures circulate here and they are not in conflict — they count different things at different times. Quoting either as though it refuted the other is the most common error on this subject.
-
92
authorized C3PAO organizations
GAO's count of authorized CMMC Third-Party Assessment ORGANIZATIONS, as of December 2025. SBA separately referred to "about 100 approved assessors" in July 2026 — a later date and a different unit. Ninety-two organizations and about a hundred assessors are compatible figures, not competing ones.
GAO report GAO-26-107955 · December 2025
-
120,000+
small businesses in the defense industrial base
SBA's figure for the small businesses that would have had to seek compliance had Phase II begun on schedule. Note what it does NOT say: SBA describes those firms as seeking either self-assessment or third-party assessment, so this population is not a C3PAO workload and dividing it by an assessor count produces a ratio no source supports.
SBA news release, 13 July 2026 · 13 July 2026
What it costs
Both figures come from the Small Business Administration's analysis, and both describe a small firm. Which one applies is set by the requirement in the contract, not by how a company is configured.
-
up to ~$593,800
per certification, third-party assessed
SBA's figure for a small firm requiring a third-party assessment. SBA states costs "can reach approximately" this amount, so treat it as an upper estimate rather than a price.
SBA news release, 13 July 2026 · 13 July 2026
-
~$388,600
per certification, self-assessed
SBA gives "about $388,600" for a small firm eligible to self-assess. Both figures are described as TOTAL compliance costs for firms in different assessment categories, so the gap between them is not an assessor's invoice — SBA does not break down what makes up the difference, and neither will we.
SBA news release, 13 July 2026 · 13 July 2026
What did not pause
The suspension is on the assessment, not the obligation. These sit in contracts already signed and are unaffected by either 2026 action.
-
72 hours
to report a cyber incident
DFARS 252.204-7012 requires a cyber incident affecting covered defense information to be reported rapidly — defined in the clause as within 72 hours of discovery — to DoD at dibnet.dod.mil.
DFARS 252.204-7012 · Current
-
Required
DoD-approved medium assurance certificate
The same clause requires a contractor to "have or acquire" a DoD-approved medium assurance certificate in order to report at all. The clause sets no issuance time, so treat obtaining one as something to settle before an incident rather than during — that is our operational advice, not a stated requirement.
DFARS 252.204-7012 · Current
-
Unchanged
the NIST SP 800-171 assessment in SPRS
A current NIST SP 800-171 assessment posted in SPRS remains a condition of award under DFARS 252.204-7019. The separate ANNUAL AFFIRMATION is a CMMC requirement living in DFARS 252.204-7021, and applies where that clause is in the contract. A task force report is advice: only a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170 changes what a contract obliges.
How these are checked
Every figure cites a primary document — NIST, GAO, the SBA, the Department of War, or the DFARS text itself — rather than another compilation, and all but the one marked below were read directly from that document. Where a figure is derived from our own published shared responsibility matrix, it says so.
One entry is marked not read directly. The Department publishes class deviations over DoD PKI, which ordinary clients will not verify; that document is identified by its DARS tracking number and can be read by anyone who trusts that certificate chain. It has not been read from here, and saying so is the point — a page that hid the difference between a checked source and an assumed one would not deserve to be quoted.
The programme is still moving. The reform task force reports to the Department CIO around 11 September 2026, with a public report expected later. A task force report is advice: only a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170 changes what a contract obliges. This page will be updated when one of those lands, and the date at the top will move with it.