The self-attestation era is over
For a decade, defense contractors could largely self-attest to their cybersecurity posture. That era is over. CMMC 2.0 replaces self-attestation with independently assessed evidence that Controlled Unclassified Information (CUI) is actually protected.
The program is also in flux. On July 13, 2026, the Department of War announced an immediate suspension of CMMC Phase 2, which had been scheduled for November 10, 2026. Pending and future implementation milestones are on hold during a program review, with task force recommendations due to the Department CIO by mid-September 2026.
Here is what the pause does not change. Phase 1 remains in full effect: self-assessment requirements, DFARS 252.204-7012, NIST SP 800-171 Rev. 2 compliance, SPRS score postings, and annual affirmations. Existing certifications retain their full value. During the suspension, contracting officers may only insert CMMC Level 1 (Self) or Level 2 (Self) requirements, and active solicitations and contracts carrying Level 2 (C3PAO) or Level 3 requirements are being amended to remove them.
So the obligations are live, and cryptography is one of the hardest parts to get right. This playbook shows how to align your PKI and cryptographic controls with CMMC and NIST SP 800-171. It also shows how to prove it when an assessor arrives.
What CMMC 2.0 and NIST SP 800-171 actually require
CMMC 2.0 is a DoW tiered verification program layered on NIST SP 800-171 Revision 2. NIST SP 800-171 defines the underlying security controls. CMMC is the mechanism that verifies you have implemented them.
Put simply: NIST SP 800-171 is the “what,” and CMMC is the “prove it.” The DFARS final rule took effect November 10, 2025, and rolls out in four phases through November 2028.
The three CMMC levels at a glance
- Level 1 (FCI only): self-assessment against 15 basic safeguarding practices.
- Level 2 (CUI): all 110 NIST SP 800-171 controls, most commonly verified by a C3PAO every three years.
- Level 3: adds 24 enhanced requirements from NIST SP 800-172, assessed directly by DoW’s DIBCAC for the most sensitive programs.
Who is in scope
- Primes and subcontractors handling FCI or CUI.
- Cloud and Managed Service Providers hosting CUI, expected to meet a FedRAMP Moderate equivalentunder DFARS 252.204-7012.
- C3PAOs and assessors accredited to conduct CMMC Level 2 assessments.
Why this matters now for the Defense Industrial Base
CMMC status is a condition of contract award. DFARS 252.204-7025 is the solicitation provision that makes CMMC status a condition of eligibility for award. DFARS 252.204-7021 is the contract clause, effective November 10, 2025.
Contracting officers can require a current CMMC status and an SPRS score before a bid is even considered. An affirming official must also complete an annual affirmation of continuous compliance in SPRS for each required assessment.
The scale is significant. DoW estimates well over 80,000 contractors and subcontractors will need Level 2 or Level 3 certification. For most of the Defense Industrial Base, cryptographic readiness is now directly tied to revenue.
FIPS validated, not merely FIPS compliant
This distinction fails more assessments than almost anything else in the cryptographic controls. SC.L2-3.13.11 is a 5-point requirement. Under 32 CFR 170.21(a)(2), it may go on a Plan of Action and Milestones (POA&M) at a 3-point cost only when encryption is employed but is not FIPS-validated. If no encryption is in place, the 5-point gap cannot be deferred and blocks Conditional Level 2 status. An algorithm can be FIPS-compliant, meaning it uses an approved algorithm. A cryptographic module is FIPS-validated only when it has been formally tested under NIST’s Cryptographic Module Validation Program (CMVP).
The §3.13 family (System and Communications Protection) carries the direct cryptographic obligations, and it is one of the hardest families to pass. Assessors distinguish sharply between the two, and they look for validation evidence, not a vendor’s marketing claim.
Timing adds urgency. FIPS 140-2 modules remain active for five years after validation, or until September 21, 2026, when FIPS 140-2 validations move to the CMVP historical list. After that date, FIPS 140-3 is the only active cryptographic module standard at CMVP. CMVP supports continued use of historical modules in existing systems, but guidance is that federal agencies should not include historical modules in new procurements.
How NIST SP 800-171 maps to cryptography and PKI
Most of the cryptographic obligations concentrate in two control families: §3.13 (System and Communications Protection) and §3.5 (Identification and Authentication). Here is how the specific controls translate into PKI and cryptographic practice.
FIPS validated cryptography for CUI confidentiality (§3.13.11)
Employ FIPS-validated cryptography when used to protect the confidentiality of CUI. In practice, that means certificates issued and managed by modules holding a FIPS 140-3 validation, verifiable on the CMVP active list.
Cryptographic key establishment and management (§3.13.10)
Key management is where documentation and reality often diverge. This control requires documented key generation, distribution, storage, and destruction across the full CUI environment. The lifecycle has to be defined and consistently followed, not improvised per system.
Protecting CUI in transit and at rest (§3.13.8, §3.13.16)
CUI must be protected both in transit and at rest. That translates to certificate-backed TLS for CUI moving across networks, and PKI-issued keys protecting stored CUI.
Device and user authentication (§3.5.1 to §3.5.2)
These controls cover identifying and authenticating users, processes, and devices. The strong path is certificate-based authentication that replaces shared passwords for access to CUI systems, giving each identity a unique, verifiable credential.
Remote access session protection (§3.1.13, §3.1.12)
Remote access into CUI environments needs protected sessions. That means mutually authenticated, certificate-backed VPN and remote session connections, so both ends of the connection prove their identity.
Cryptographic asset inventory for assessment evidence
You cannot prove what you cannot see. An inventory of the algorithms and libraries in use supports your System Security Plan (SSP) and POA&M for C3PAO review.
Getting audit ready for a CMMC Level 2 assessment
Level 2 assessors, whether self or C3PAO, focus on verified implementation of all 110 controls, not documentation alone. They want to see the control working in your environment. Treat the following as a practical readiness checklist.
The evidence assessors look for
- FIPS validation evidence: modules protecting CUI confidentiality that are formally FIPS 140-2 or 140-3 validated, not merely built on approved algorithms.
- Key management documentation: key generation, distribution, storage, and destruction documented and consistently followed per §3.13.10.
- CUI boundary encryption: CUI encrypted at rest and in transit across all boundaries, including cloud and remote endpoints.
- Device and user authentication evidence: unique, certificate-based credentials in place of shared passwords for CUI systems.
- SSP and POA&M accuracy: an SSP that accurately reflects implemented cryptographic controls, with gaps tracked in a current POA&M.
- Assessment-ready evidence package: organized, current evidence spanning all 110 controls.
Preparing for what comes next: post-quantum on the horizon
Cryptographic readiness is not static. In 2024, NIST finalized the first three post-quantum cryptographic standards. It also published a transition timeline deprecating RSA and elliptic curve algorithms by 2030, with full disallowance targeted for 2035. Those milestones sit in NIST IR 8547, which remains an Initial Public Draft. IR 8547’s 2030 deprecation and 2035 disallowance dates remain proposed. EO 14412 has made December 31, 2030 and December 31, 2031 binding milestones for federal high value assets and high impact systems.
Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” was signed June 22, 2026. It directs OMB to require agencies to transition high value assets and high impact systems, excluding national security systems, to PQC for key establishment by December 31, 2030 and for digital signatures by December 31, 2031. It also directs the FAR Council to publish a proposed rule requiring covered contractors to comply with NIST’s FIPS, including those incorporating PQC algorithms, by December 31, 2030.
The order pushes migration into the supply chain. It also directs directs DHS, through CISA and in coordination with NIST, to publish guidance within 270 days on the minimum elements for a cryptographic bill of materials, elements intended to enable automated assessment of the cryptographic assets in a hardware or software component.
Why act now? Data encrypted today can be harvested now and decrypted once quantum capability arrives, a risk known as “harvest now, decrypt later.” The sensitivity horizon of the data sets the deadline, and long-lived industrial systems run 15 to 25 years.
Procurement also moves faster than regulation. Federal buyers and primes will ask suppliers for PQC migration plans and cryptographic inventories before the rules require them.
How Keyfactor can help
The controls above share a common need: FIPS-validated PKI, disciplined key management, and a defensible cryptographic inventory. Keyfactor maps directly to that work.
- AgileSec builds the cryptographic asset inventory that backs your SSP and POA&M evidence for C3PAO review.
- EJBCA delivers FIPS-validated issuance, certificate-backed TLS, and mutually authenticated remote access, supporting §3.13.11, §3.13.8, §3.13.16, §3.13.7, and §3.1.12.
- Command provides key establishment and management plus device and user authentication, supporting §3.13.10 and §3.5.1 to §3.5.3.
These fit together in the Keyfactor Trust Control Plane. It is one platform that observes, analyzes, provisions, orchestrates, and governs every cryptographic asset and machine identity across IT, OT, and shipped products. The result: the evidence any framework asks for comes from a single system of record.
Key takeaways
CMMC 2.0 has changed what cryptographic compliance demands from the Defense Industrial Base. A few principles carry the most weight.
- Treat cryptographic compliance as an operating capability, a program rather than a one-time project.
- Prioritize FIPS-validated modules, not merely FIPS-compliant algorithms, especially ahead of the September 21, 2026 CMVP historical list transition.
- Document the full key lifecycle: generation, distribution, storage, and destruction across the entire CUI environment.
- Build the evidence package spanning all 110 controls before the assessor arrives, not during the assessment.
Ready to assess your CMMC cryptographic readiness? Request a Demo to see how Keyfactor can support your PKI, key management, and cryptographic inventory across the controls that matter most.
Got CMMC and NIST SP 800-171 cryptography questions? We’ve got answers.
What is the difference between CMMC 2.0 and NIST SP 800-171?
NIST SP 800-171 Revision 2 defines the security controls that protect CUI. CMMC 2.0 is the DoW tiered verification program layered on top of it, replacing self-attestation with independently assessed evidence. In short, NIST SP 800-171 is the requirement, and CMMC verifies it.
Is CMMC still required during the Phase 2 suspension?
Yes. Phase 1 remains in full effect, including self-assessment requirements, DFARS 252.204-7012, NIST SP 800-171 Rev. 2 compliance, SPRS score postings, and annual affirmations. Existing certifications retain their full value while the program review proceeds.
Which CMMC level do most contractors need?
Most contractors handling CUI need Level 2, which covers all 110 NIST SP 800-171 controls. Level 2 is most commonly verified by a C3PAO every three years. Level 1 covers FCI with 15 basic practices, and Level 3 adds enhanced requirements for the most sensitive programs.
What does FIPS validated cryptography mean under CMMC?
FIPS-validated means a cryptographic module has been formally tested under NIST’s Cryptographic Module Validation Program (CMVP). This is stricter than FIPS-compliant, which only means an approved algorithm is used. Control §3.13.11 requires FIPS-validated cryptography to protect CUI confidentiality.
Which NIST SP 800-171 controls carry the cryptographic obligations?
The direct cryptographic obligations concentrate in the §3.13 (System and Communications Protection) and §3.5 (Identification and Authentication) families. These cover FIPS-validated cryptography, key management, CUI protection in transit and at rest, authentication, and remote access. The §3.13 family is one of the hardest to pass.
What evidence do C3PAO assessors look for?
Assessors focus on verified implementation of all 110 controls, not documentation alone. They look for FIPS validation evidence, documented key management, CUI encrypted across all boundaries, certificate-based credentials, and an accurate SSP with a current POA&M. Everything should sit in an organized, assessment-ready evidence package.
How does key management factor into CMMC?
Control §3.13.10 requires documented cryptographic key establishment and management: generation, distribution, storage, and destruction across the full CUI environment. Assessors check that the documented lifecycle is consistently followed in practice, not just written down.
Should CMMC contractors start planning for post-quantum now?
Yes. EO 14412 directs the FAR Council to propose a rule requiring covered contractors to comply with NIST’s FIPS, including those incorporating PQC algorithms, by December 31, 2030, and procurement often moves faster than regulation. Data can be harvested now and decrypted later, and long-lived systems run 15 to 25 years. A cryptographic inventory and migration plan are worth building early.