loading min read

Cybersecurity Maturity Model Certification (CMMC): A road map to compliance

Important CMMC Update (July 2026):

On July 13, 2026, the Department of War suspended CMMC Phase II requirements (originally effective November 10, 2026) and launched a 60-day program review, though Phase I self-assessments remain in place. This pause does not remove your obligation to protect federal data (federal contract information or controlled unclassified information—contractors must still meet the NIST SP 800-171 Rev. 2 standard and comply with DFARS clause 252.204-7012. Organizations that keep advancing their readiness now will be best positioned once the program's future is finalized. Contact CohnReznick's team to understand what this means for your compliance roadmap.

The Department of Defense (DoD) has officially published the CMMC final rule, effective Dec. 16, 2024. Read what this could mean for your organization and next steps to take.

1. Confirm your scope includes Controlled Unclassified Information (CUI) and thus seeking CMMC level 2 status.

2. Review the CMMC framework to understand the practices and processes your organization will need to meet Level 2 maturity requirements.

3. Conduct a preparedness assessment – work with a third party or with your team to identify technical gaps in existing vs. required practices.

4. Develop and implement practices that are found to be non-existent (or fixes for those determined to be partially implemented) based on the results of the assessment.

5. Deploy technical solutions where needed.

6. Remediate other process gaps as identified in the preparedness assessment.

7. If the organization’s SPRS score is greater than 85, identify/select a CMMC Third-Party Assessor Organization (C3PAO) firm for your CMMC audit. 

8. Obtain your desired CMMC level maturity certification based on the audit.

Receive CohnReznick insights and event invitations on topics relevant to your business and role.
Subscribe

This has been prepared for information purposes and general guidance only and does not constitute legal or professional advice. You should not act upon the information contained in this publication without obtaining specific professional advice. No representation or warranty (express or implied) is made as to the accuracy or completeness of the information contained in this publication, and CohnReznick, its partners, employees and agents accept no liability, and disclaim all responsibility, for the consequences of you or anyone else acting, or refraining to act, in reliance on the information contained in this publication or for any decision based on it.

"CohnReznick" is the brand name under which CohnReznick LLP and CohnReznick Advisory LLC and their respective subsidiaries provide professional services. CohnReznick LLP and CohnReznick Advisory LLC (and their respective subsidiaries) practice in an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable law, regulations, and professional standards. CohnReznick LLP is a licensed CPA firm that provides attest services to its clients. CohnReznick Advisory LLC provides tax and business consulting services to its clients. CohnReznick Advisory LLC and its subsidiaries are not licensed CPA firms.

member of nexia

CohnReznick is a member of Nexia, a leading, global network of independent accounting and consulting firms. Please see the “Member firm disclaimer (Opens a new window)” for further details.

© 2026 CohnReznick Advisory LLC, All Rights Reserved.