Updated CMMC Requirements

Updated CMMC Requirements

July 22, 2026

Continue Using CCRA - Compliance

On July 13, 2026, the Department of War (DoW) announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements (third-party assessments) pending a 60-day review period. Phase I self-assessment requirements remain in effect, and the DoW will continue to enforce the NIST SP 800-171 Rev 2 baseline through:

  • CMMC Level 1 & Level 2 Self-Assessments (DFARS 252.204-7021)
  • DFARS 252.204-7012 – Safeguarding Covered Defense Information and Cyber Incident Reporting, and
  • DFARS 252.204-7020 – NIST SP 800-171 DoD Assessment Requirements

As noted in the recent Update Supplier Cybersecurity Requirements in Exostar article, Lockheed Martin will continue using the CCRA – Compliance questionnaire to capture supplier’s status against the DFARS and CMMC self-assessment obligations.

What we need from our suppliers

Complete (or update) the CCRA – Compliance form and indicate:

  • Applicability of / compliance with cyber regulatory requirements (FAR 52.204-21 / DFARS 252.204-7012 / DFARS 252.204-7020)
  • Current CMMC status (None, Level 1 or Level 2).
  • Planned Future CMMC status

Take immediate action to verify a current and accurate submission.

Why this matters

  • The suspension of CMMC Phase II does not waive the contractual obligation to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
  • Prime Contractors remain obligated to verify current subcontractor compliance with DoW Supplier Performance Risk System (SPRS) reported assessment status – assessments and affirmations must be kept current per regulatory requirements.
  • Maintaining an up-to-date compliance status enables uninterrupted participation in current and future Lockheed Martin procurements.

Need Help?

  • Lacking subject matter expertise? Consider leveraging Cyber AB Registered Practitioner Organizations (RPO) to assist with CMMC Level 2 Self-Assessment.
  • Leverage ND-ISAC and DIB SCC CyberAssist for best practices and self-help resources.
  • Utlize resource buttons below for additional assistance

Your prompt attention protects the Defense Industrial Base and ensures uninterrupted business with Lockheed Martin. Thank you for your partnership and commitment to cybersecurity excellence.