In the first post in this series, we mapped out three common paths teams take after earning SOC 2 by industry: healthcare, defense and government, and general regulated enterprise. Defense deserves its own deeper look, because 2026 has been the most volatile year yet for the framework everyone assumed was settled.
If you sell into the Department of War (DOW, formerly the Department of Defense), or into a prime contractor that does, SOC 2 is likely what got you into the diligence conversation. It doesn't tell you what to build toward next, and this year, the answer moved twice.
Two things anchor the roadmap here: NIST SP 800-171, the control baseline, and CMMC, the verification layer on top of it. Both are still required. Only one of them is currently stable.
Why Defense Doesn't Play by the Typical Rules
For most SaaS companies, the next framework after SOC 2 is a market bet. A buyer asks for ISO 27001, the team weighs the deal size against the lift, and it either moves forward or it doesn't.
Defense doesn't work that way. The moment a contract or a subcontract flow-down clause references DFARS 252.204-7012 or 252.204-7021, the requirement isn't a market signal. It's a condition of award, written into the contract itself. A vendor three tiers down from the prime, with no direct DOW relationship, can still be on the hook if Controlled Unclassified Information (CUI) moves through its systems. Treating NIST 800-171 as a someday project, the way a fintech company might treat ISO 27001, is the mistake that ends contracts.
NIST 800-171 Is the Baseline (and It's Shifting)
NIST SP 800-171 sets 110 security requirements across 14 control families, covering everything from access control and incident response to media protection and physical security for systems that handle CUI. SOC 2 already covers a real share of that ground. Access controls, audit logging, encryption, and vulnerability management overlap heavily between the two. The work is mapping what a team already has against the 110 requirements and closing what's missing, not rebuilding a security program from the ground up.
CMMC is the layer that verifies a team actually meets that baseline via a Certified Third-Party Assessment Organization (C3PAO) and it's the piece that is currently in flux. DFARS 252.204-7021 phased in on November 10, 2025, requiring CMMC Level 1 or Level 2 self-assessments as a condition of award on applicable contracts. Phase 2, due November 10, 2026, was supposed to add third-party Level 2 assessments conducted by a certified C3PAO to the mix.
On July 13, 2026, the DOW suspended that Phase 2 rollout and stood up a 60-day CMMC Reform Task Force to rework the program, aiming for a model that lowers the barrier for small and midsize contractors instead of leaning entirely on third-party assessments. Phase 1 self-assessment obligations under DFARS 252.204-7021 is still being enforced as a requirement. The third-party assessment requirement that was supposed to start expanding across new contracts this November is currently on pause.
That's the part most post-SOC 2 planning is going to get wrong over the next few months: treating the pause as a reason to wait. The 110 controls in NIST 800-171 didn't go anywhere. Any Organization Seeking Certification (OSC) is still bound to accurately self-attest to their Supplier Performance Risk System (SPRS) score. Submitting an inaccurate or inflated SPRS score to the DoW exposes contractors to legal liability under the False Claims Act (FCA), which can cause massive legal and financial risks. Whatever the Reform Task Force lands on for verification, the underlying safeguard obligation only gets stricter from here.
Where CMMC Fits + When It's Worth the Spend
CMMC comes in three levels, and matching the level to what the contract actually requires is where teams waste the most money.
- Level 1 covers Federal Contract Information (FCI) only: 15 basic safeguarding practices pulled from FAR 52.204-21, assessed through an annual self-assessment that’s run internally. This is the floor for any contractor touching FCI, regardless of CUI exposure.
- Level 2 covers CUI and requires all 110 NIST 800-171 controls. While some organizations who have non-prioritized contracts with the DOW can perform a self-assessment, the majority of OSC's require a third-party assessment performed by a C3PAO.
- Level 3, assessed by the Defense Contract Management Agency's DIBCAC, layers NIST SP 800-172's enhanced requirements on top of a completed Level 2 C3PAO assessment. It's reserved for the highest-sensitivity CUI programs.
Before scoping anything, confirm what the contract or the prime's flow-down clause actually requires today, not what a vendor assumes a defense buyer wants. When in doubt, ask your Contracting Officer (CO). Plenty of teams have started budgeting for C3PAO assessments this year because Phase 2 was on the calendar. With Phase 2 paused and under review, that spend should wait until a specific contract calls for it or the Reform Task Force publishes its recommendations; but don’t delay the implementation and NIST 800-171 requirements.
The Sequencing That Works
- Identify the specific contract, prime, or agency driving the requirement, and read the DFARS flow-down clause before scoping anything.
- Map existing SOC 2 controls against NIST 800-171's 110 requirements, close the gaps, and document the pieces SOC 2 doesn't touch, like media protection and DOW-specific incident reporting timelines.
- Self-assess against the applicable CMMC level and post the score to the Supplier Performance Risk System (SPRS). This is a DOW requirement independent of where Phase 2 lands.
- Hold on C3PAO or DIBCAC assessment spending until a specific contract requires it or the Reform Task Force's recommendations clarify the model.
- Layer in FedRAMP only when the business is selling a cloud product directly to federal agencies. It's a separate milestone from CMMC, not a substitute for it, and it carries its own timeline and cost.
What This Looks Like in Practice
Take a defense logistics software vendor that earned SOC 2 to close its first commercial contracts, then won a subcontract on a DOW sustainment program in early 2026. The prime's flow-down clause called for a Level 2 self-assessment posted to SPRS, plus a documented roadmap toward C3PAO readiness once the contract required it.
The vendor mapped its SOC 2 controls against the 110 NIST 800-171 requirements and found roughly two-thirds already covered by existing evidence. Closing the remaining gaps, mostly around media protection and CUI-specific incident reporting, took about eight weeks. The team posted its SPRS score and kept a running gap list for the eventual C3PAO assessment, which functions as a Plan of Action and Milestones (PO&AM).
When Phase 2 paused in July, that vendor didn't lose ground. It had already built to the control baseline instead of the assessment model, so the pause changed a spend decision, not a security posture. SOC 2 opened the subcontract conversation. A NIST 800-171-first sequence kept the vendor ready regardless of which way CMMC's verification requirements moved next.
Common Mistakes to Avoid
A few patterns show up again and again in defense post-SOC 2 planning:
- Waiting for the CMMC Reform Task Force's outcome before starting on NIST 800-171, when the 110 controls aren't going anywhere no matter how the verification model changes.
- Assuming a contract requires a C3PAO Level 2 assessment when the flow-down clause only calls for a self-assessment posted to SPRS.
- Treating a SPRS score as a one-time filing instead of a number that needs updating every time the control environment changes.
- Building only to NIST 800-171 Revision 2 and ignoring that DOW has already signaled a move to Revision 3's stricter requirements.
Building Your Defense Compliance Roadmap with Drata
None of this has to mean separate audits in separate silos. Drata maps NIST 800-171 and CMMC controls against the evidence a team is already collecting for SOC 2, so the same access reviews, audit logs, and incident response documentation carry across frameworks instead of getting rebuilt for every new contract requirement. Centralized evidence and continuous control monitoring mean a team stays ready for whatever the CMMC Reform Task Force recommends next, because the underlying control environment was never built around one assessment model in the first place.
Ready to build your compliance roadmap? Schedule your demo with the Drata team.

