Webinar

From CUI to CMMC: Understanding the Requirements that Drive Compliance

August 27, 2026

With the CMMC Phase II suspension creating additional uncertainty, many defense contractors are asking the same questions: Which requirements still apply? What do our contracts actually require? And what should we be doing now?

While the certification timeline is under review, the cybersecurity and contractual requirements that underpin CMMC remain in place. CUI, DFARS contract clauses, NIST SP 800-171, SPRS scores, and CMMC are all interconnected. But understanding how they fit together isn’t always straightforward. This webinar will explain how these requirements relate to one another and provide a practical framework for determining what applies to your organization.

Join experts from Coalfire Federal, Teramis, and DTC Global as they connect the dots between federal contract requirements and CMMC compliance.

What You’ll Learn

  • What qualifies as Controlled Unclassified Information (CUI), how to identify it, and common misconceptions surrounding its handling and protection
  • The purpose of DFARS clauses 252.204-7012, 7019, 7020, and 7021, and what each requires of contractors
  • How CMMC requirements are incorporated into contracts
  • What the Phase II suspension means and what prime contractors and subcontractors should expect moving forward
  • Common gaps between contractual obligations, documented compliance, and actual implementation 
  • Practical steps organizations can take to determine which requirements apply

 


Watch the Webinar:

Learn More about the CMMC Pause

Explore frequently asked questions defense contractors are asking about the CMMC Phase II suspension.

CMMC Suspension FAQs