Official sources and practical guidance

Make cybersecurity decisions from current, authoritative information.

This page separates official requirements from SURELINC guidance and links directly to primary government and standards sources.

!

Current CMMC program status

Phase II requirements are suspended; Phase I self-assessments remain in effect.

Use official program and contract sources for each opportunity. SURELINC does not recommend relying on old implementation charts or undated summaries.

Open the official CMMC site

Primary sources

Start here before interpreting a requirement.

SURELINC guidance

How to use the rules without turning the business into a paperwork project.

Scope before tools

Know where FCI or CUI actually flows.

Technology decisions made before the scope is understood can increase cost and expand the assessment boundary.

Evidence during operation

Capture proof as work occurs.

Evidence is more reliable when it is produced and retained through routine security and operational processes.

Separate status from detail

Give each audience what it needs.

Executives need risk and decisions. Implementers need actions. Assessors need supportable evidence. Primes need supplier status and exceptions.

Maintain after submission

Readiness changes when the environment changes.

New systems, providers, users, data flows, and contract terms can change scope and invalidate old assumptions.

Frequently asked questions

Readiness questions customers ask first.

Is CMMC cancelled?

No. As of July 2026, the Department has suspended Phase II implementation requirements and is reviewing the program. Phase I self-assessment requirements remain in place, and existing obligations to protect FCI and CUI remain.

Can a company self-assess for CMMC Level 2?

During the current Phase I pause, the official program states that Level 2 may require a self-assessment every three years with annual affirmation. The exact requirement must be confirmed from the applicable solicitation, contract, and current program direction.

Can a self-assessed company still face government review?

Yes. The current program describes selected government-led assessments, and NIST SP 800-171A recognizes government-sponsored assessments as one assessment method. A company should be able to support its submitted conclusions.

Does a good SPRS score prove the company is secure?

A score is a reported assessment result. It does not replace secure operation, ongoing evidence, incident readiness, or the need to update conclusions when the environment changes.

What should a prime contractor ask from a subcontractor?

The answer depends on the information and requirements being flowed down. A practical program typically needs current status, scope, responsible ownership, material exceptions, remediation timing, and enough evidence to support the prime's business decision without collecting unnecessary sensitive detail.

Does the Readiness Platform certify compliance?

No. The platform supports readiness, evidence, workflow, analysis, and reporting. It does not replace a required authorized assessment, government decision, contracting officer determination, or legal advice.

Apply the source to your situation

Official language still requires technical interpretation and business judgment.

SURELINC can help connect contract requirements, system scope, architecture, evidence, and the next practical action.