started · updated
CMMC compliance remains mandatory for defense contractors
Defense contractors, including those in the architecture, engineering, and construction (AEC) sectors, must maintain cybersecurity compliance to remain eligible for Department of Defense (DoD) contracts. While there has been a pause in certain Cybersecurity Maturity Model Certification (CMMC) assessment activities, existing obligations under DFARS and NIST SP 800-171 remain in effect.
Contractors handling Controlled Unclassified Information (CUI) or Federal Contract Information (FCI) must demonstrate compliance to avoid losing work to competitors. This includes performing self-assessments and reporting scores through the Supplier Performance Risk System (SPRS). Failure to manage these requirements, including subcontractor flow-down obligations, poses a significant risk to firms relying on federal revenue streams.
Entities
Aethon Security · Department of Defense · Derek Kernus · NIST