Defense acquisition atlas · 2026-09-05

The department is the buyer. These are the clerks.

DoD is the buyer. SAM, CAGE, SPRS, Cyber AB, DCSA, DDTC, NIST, and the FAR/DFARS text are the clerks. SSDF publishes a machine-readable atlas of that surface, including CMMC Phase 1 in force and the 13 July 2026 Phase 2 pause.

Map the clerks. Credential the purchase. Do not become the contractor, the C3PAO, or the exporter. That is the title-file rule on a different clerk.

Three objects

The contractor who processes it, under DFARS 252.204-7012 and 32 CFR 170

CUI / FCI

SSDF sells: Nothing. SSDF does not receive CUI.

DDTC registrant. License or exception before export.

ITAR technical data / USML article

SSDF sells: A map of who the clerk is. Not a DS-2032. Not a CJ request.

SSDF INC, merchant of record

First-party SKU

SSDF sells: This atlas, and a Passport over the purchase.

Hard rules

  • SSDF is a Florida C-Corp merchant of record. SSDF is not a defense contractor, not a C3PAO, not a CMMC consultant, and not a DDTC registrant.
  • The clerks are SAM (UEI), DLA (CAGE), SPRS, Cyber AB, DCSA, DDTC, NIST, and the FAR/DFARS text on eCFR. SSDF is none of them.
  • CMMC Level 2 is NIST SP 800-171 Revision 2, identically. NIST already publishes the controls. OSCAL is the machine-readable clerk. This atlas does not restatement the 110 practices.
  • CMMC Phase 1 (self-assessment) took effect 10 November 2025. Phase 2 (C3PAO as a condition of award) was paused 13 July 2026. Do not sell a roadmap that still treats 10 November 2026 as a hard C3PAO date.
  • A Passport attests that a buyer paid this SKU. It does not attest CMMC status, a SPRS score, a facility clearance, or that the buyer handles CUI.
  • SSDF SKUs are commercial digital files about public rules. They are not CUI and are not ITAR technical data. The powered-lift atlas is a public-process map, not a defense article.
  • Map the clerks. Do not certify compliance. Do not handle CUI. Do not export a defense article.

Clerks

The registration clerk

SAM.gov / UEI

GSA's System for Award Management issues the Unique Entity ID. You cannot bid most federal work without an active SAM record. This is the county-clerk analog for entering the DIB — public, free, and not SSDF.

SSDF does not register entities in SAM and does not broker UEIs.

GET /api/defense/sam

The identity number

CAGE code (DLA)

The Defense Logistics Agency issues Commercial and Government Entity codes. A CAGE is an identifier, not a clearance and not a CMMC certificate.

SSDF does not issue or look up CAGE codes as a service.

GET /api/defense/cage

The scoreboard

SPRS

DoD's Supplier Performance Risk System is where NIST SP 800-171 / CMMC self-assessment scores and annual affirmations land. False scores are a False Claims Act problem (DOJ Civil Cyber-Fraud Initiative), not a SKU problem.

SSDF does not file SPRS scores and does not attest anyone's score.

GET /api/defense/sprs

The C3PAO marketplace

Cyber AB

The Cyber Accreditation Body lists Certified Third-Party Assessment Organizations. It is a private clerk for CMMC assessments, not NIST and not SSDF. Voluntary C3PAO assessments remain available while Phase 2 is paused.

SSDF is not a C3PAO and does not place assessments.

GET /api/defense/cyber_ab

Facility clearance

DCSA

The Defense Counterintelligence and Security Agency is the clerk for facility security clearances and classified work. Unclassified CUI is a different object. Do not mix FCL with CMMC Level 2.

SSDF has no facility clearance and does not seek one from this SKU.

GET /api/defense/dcsa

The export clerk

DDTC / ITAR

The Directorate of Defense Trade Controls (State) administers ITAR. Manufacturers, exporters, and defense-service providers register on DECCS (DS-2032) before licensing. The USML is the catalog of defense articles. Publicly available information about published rules is not, by that fact, technical data.

SSDF is not a DDTC registrant. This atlas and the powered-lift atlas are public-process maps, not USML technical data.

GET /api/defense/ddtc

The control clerk

NIST

SP 800-171 Rev 2 is the CMMC Level 2 baseline (32 CFR 170.14). Rev 3 (May 2024) exists and has OSCAL content; DoD has not incorporated Rev 3 into CMMC. SP 800-171A is the assessment procedure. OSCAL is the machine-readable format. NIST publishes this for free.

SSDF does not sell the 110 controls as a how-to. That clerk already published them.

GET /api/defense/nist

The text

eCFR (FAR / DFARS / 32 CFR 170)

32 CFR Part 170 is the CMMC program rule. DFARS 252.204-7012 is the cyber-incident / 800-171 clause still in force. DFARS 252.204-7021 (NOV 2025) is contractor CMMC status. DFARS 252.204-7025 is the solicitation fill-in. COTS-only buys are excluded.

SSDF maps citations. SSDF does not rewrite DFARS.

GET /api/defense/ecfr

Roles

The buyer

DoD / DoW contracting officer

Inserts the CMMC level into 7021/7025, or not. Phase 1 allows Level 1 or Level 2 self-assessment at award. Phase 2 would have required C3PAO at award; that milestone is paused.

SSDF is not bidding DoD work from this store.

GET /api/defense/buyer

Flows the clause down

Prime contractor

Must flow DFARS 252.204-7021 to subs that store, process, or transmit FCI or CUI, and keep current CMMC status on covered systems for the life of the contract.

SSDF is not a prime and does not flow down clauses.

GET /api/defense/prime

Same CUI, smaller firm

Subcontractor / supplier

If the sub handles FCI or CUI, CMMC status follows the information, not the logo on the building. COTS-only suppliers are the usual exception.

Buying a digital atlas from SSDF does not put CUI on SSDF's systems.

GET /api/defense/sub

The assessor

C3PAO

Accredited by Cyber AB. May still perform voluntary Level 2 assessments while Phase 2 is paused. Not NIST. Not a software vendor.

SSDF does not assess, certify, or 'get you CMMC ready.'

GET /api/defense/c3pao

FY26 NDAA relief

Small business / NDC

Small businesses are already CAS-exempt, so they qualify as nontraditional defense contractors under 10 U.S.C. § 3014. FY2026 NDAA § 1826 exempts NDCs from FAR Part 31 cost principles and certified cost-or-pricing data. § 1806 raises CAS applicability to $35M and full coverage to $100M (contracts after 30 June 2026). This is accounting relief, not a CMMC holiday.

SSDF does not file a size representation or a CAS disclosure.

GET /api/defense/small_ndc

This store

Commercial digital merchant

Sells files about public rules. Does not process FCI or CUI. Does not manufacture USML articles. Accepts USDC for first-party SKUs.

That is SSDF. Do not turn this SKU into a defense contract.

GET /api/defense/merchant

Docket

2024-12-16 · Program rule

in force

32 CFR Part 170 in force

CMMC Program procedures (Title 32) became effective. Level 1 uses FAR 52.204-21 (15 basic safeguarding requirements). Level 2 uses NIST SP 800-171 Rev 2 (110 requirements). Level 3 uses selected 800-172 requirements, assessed by DIBCAC.

32 CFR 170

GET /api/defense/cmmc-32cfr

2025-09-10 · 48 CFR

in force

DFARS CMMC acquisition rule published

DoD published the final DFARS rule putting CMMC into contracts: 252.204-7021 (contractor compliance) and 252.204-7025 (solicitation notice). Effective 10 November 2025. Applies to contracts that use contractor systems to process FCI or CUI; excludes COTS-only.

48 CFR 252.204-7021 / 7025

GET /api/defense/dfars-final

2025-11-10 · Self-assessment at award

in force

CMMC Phase 1 begins

Contracting officers may include Level 1 (Self) or Level 2 (Self) as a condition of award. Annual affirmation of continuous compliance in SPRS. DFARS 252.204-7012 cyber-incident reporting stays in force independently of CMMC phase.

DFARS 252.204-7021

GET /api/defense/phase-1

2025-12-18 · NDC and CAS thresholds

in force

FY2026 NDAA signed

Section 1826 exempts nontraditional defense contractors (including small businesses) from FAR Part 31 cost principles and certified cost-or-pricing data. Section 1806 raises CAS applicability from $2.5M to $35M and full CAS coverage from $50M to $100M, generally for awards after 30 June 2026. TINA certified-data threshold moves to $10M.

FY2026 NDAA §§ 1806, 1826; 10 U.S.C. § 3014

GET /api/defense/ndaa-fy26

2026-07-13 · C3PAO-at-award on hold

paused

CMMC Phase 2 paused

DoW CIO paused Phase 2 (C3PAO certification as a condition of award, which had been set for 10 November 2026) and froze later milestones pending a 60-day reform review. Phase 1 self-assessment remains. DFARS 7012 remains. Voluntary C3PAO assessments remain valid. Active solicitations that already required C3PAO/Level 3 were to be amended to remove those requirements.

DoW CIO memo 26-P-1023 (13 Jul 2026)

GET /api/defense/phase-2-pause

Do not confuse the TAMs

SIPRI military expenditure for 2025 is about $2.887 trillion globally, with the United States at $954 billion. Vendor 'defense market' reports that print $500–$590 billion are a different product (equipment and services TAM), not SIPRI spending. Neither number is a reason to sell NIST's free controls as a $69 protocol.

GET /api/defense/tam

What already publishes for free

NIST SP 800-171 / 171A, 32 CFR 170, DFARS 7021/7025 on eCFR, NASA TRL definitions, DoD MRL Deskbook (dodmrl.com, 2025 edition), OSCAL catalogs (including 800-171 Rev 3 JSON/XML/YAML), and SBA/APEX Accelerator counseling. A paid SSDF SKU that restates those texts loses to the clerk. This atlas is the map of who is who, what phase is live, and what SSDF will not become.

  • CMMC Compliance Atlas that restates the 110 practices
  • NIST 800-171 Protocol as a how-to
  • TRL/MRL Protocol (NASA and DoD already publish the scales)
  • Defense Contracting Protocol as 'how to win a DoD contract'
  • A claim that SSDF is CMMC compliant on the buyer's behalf
  • Weapons, classified work, CUI processing, pentest, or MDR

Phase 1 self-assessment remains. Phase 2 C3PAO-at-award is paused. NIST 800-171 Rev 2 is still the Level 2 baseline. OSCAL is already the machine-readable control clerk — this SKU does not restate the 110 practices.