Know where FCI or CUI actually flows.
Technology decisions made before the scope is understood can increase cost and expand the assessment boundary.
Official sources and practical guidance
This page separates official requirements from SURELINC guidance and links directly to primary government and standards sources.
Current CMMC program status
Use official program and contract sources for each opportunity. SURELINC does not recommend relying on old implementation charts or undated summaries.
Open the official CMMC site ↗Primary sources
Current program status, implementation notices, resources, and assessment information.
Open source ↗ Acquisition.govCurrent CMMC policy and contracting officer procedures for award, options, and status checks.
Open source ↗ Acquisition.govContract clause covering current status, affirmations, system use, flowdown, and subcontract requirements.
Open source ↗ NISTCurrent NIST publication for protecting CUI in nonfederal systems. Confirm which revision applies to the contract.
Open source ↗ NISTAssessment procedures and methodology for evaluating CUI security requirements.
Open source ↗ NISTOutcome-based guidance for governing and managing enterprise cybersecurity risk.
Open source ↗SURELINC guidance
Technology decisions made before the scope is understood can increase cost and expand the assessment boundary.
Evidence is more reliable when it is produced and retained through routine security and operational processes.
Executives need risk and decisions. Implementers need actions. Assessors need supportable evidence. Primes need supplier status and exceptions.
New systems, providers, users, data flows, and contract terms can change scope and invalidate old assumptions.
Frequently asked questions
No. As of July 2026, the Department has suspended Phase II implementation requirements and is reviewing the program. Phase I self-assessment requirements remain in place, and existing obligations to protect FCI and CUI remain.
During the current Phase I pause, the official program states that Level 2 may require a self-assessment every three years with annual affirmation. The exact requirement must be confirmed from the applicable solicitation, contract, and current program direction.
Yes. The current program describes selected government-led assessments, and NIST SP 800-171A recognizes government-sponsored assessments as one assessment method. A company should be able to support its submitted conclusions.
A score is a reported assessment result. It does not replace secure operation, ongoing evidence, incident readiness, or the need to update conclusions when the environment changes.
The answer depends on the information and requirements being flowed down. A practical program typically needs current status, scope, responsible ownership, material exceptions, remediation timing, and enough evidence to support the prime's business decision without collecting unnecessary sensitive detail.
No. The platform supports readiness, evidence, workflow, analysis, and reporting. It does not replace a required authorized assessment, government decision, contracting officer determination, or legal advice.
Apply the source to your situation
SURELINC can help connect contract requirements, system scope, architecture, evidence, and the next practical action.