Defense acquisition atlas · 2026-09-05
The department is the buyer. These are the clerks.
DoD is the buyer. SAM, CAGE, SPRS, Cyber AB, DCSA, DDTC, NIST, and the FAR/DFARS text are the clerks. SSDF publishes a machine-readable atlas of that surface, including CMMC Phase 1 in force and the 13 July 2026 Phase 2 pause.
Map the clerks. Credential the purchase. Do not become the contractor, the C3PAO, or the exporter. That is the title-file rule on a different clerk.
Three objects
The contractor who processes it, under DFARS 252.204-7012 and 32 CFR 170
CUI / FCI
SSDF sells: Nothing. SSDF does not receive CUI.
DDTC registrant. License or exception before export.
ITAR technical data / USML article
SSDF sells: A map of who the clerk is. Not a DS-2032. Not a CJ request.
SSDF INC, merchant of record
First-party SKU
SSDF sells: This atlas, and a Passport over the purchase.
Hard rules
- SSDF is a Florida C-Corp merchant of record. SSDF is not a defense contractor, not a C3PAO, not a CMMC consultant, and not a DDTC registrant.
- The clerks are SAM (UEI), DLA (CAGE), SPRS, Cyber AB, DCSA, DDTC, NIST, and the FAR/DFARS text on eCFR. SSDF is none of them.
- CMMC Level 2 is NIST SP 800-171 Revision 2, identically. NIST already publishes the controls. OSCAL is the machine-readable clerk. This atlas does not restatement the 110 practices.
- CMMC Phase 1 (self-assessment) took effect 10 November 2025. Phase 2 (C3PAO as a condition of award) was paused 13 July 2026. Do not sell a roadmap that still treats 10 November 2026 as a hard C3PAO date.
- A Passport attests that a buyer paid this SKU. It does not attest CMMC status, a SPRS score, a facility clearance, or that the buyer handles CUI.
- SSDF SKUs are commercial digital files about public rules. They are not CUI and are not ITAR technical data. The powered-lift atlas is a public-process map, not a defense article.
- Map the clerks. Do not certify compliance. Do not handle CUI. Do not export a defense article.
Clerks
The registration clerk
SAM.gov / UEI
GSA's System for Award Management issues the Unique Entity ID. You cannot bid most federal work without an active SAM record. This is the county-clerk analog for entering the DIB — public, free, and not SSDF.
SSDF does not register entities in SAM and does not broker UEIs.
GET /api/defense/samThe identity number
CAGE code (DLA)
The Defense Logistics Agency issues Commercial and Government Entity codes. A CAGE is an identifier, not a clearance and not a CMMC certificate.
SSDF does not issue or look up CAGE codes as a service.
GET /api/defense/cageThe scoreboard
SPRS
DoD's Supplier Performance Risk System is where NIST SP 800-171 / CMMC self-assessment scores and annual affirmations land. False scores are a False Claims Act problem (DOJ Civil Cyber-Fraud Initiative), not a SKU problem.
SSDF does not file SPRS scores and does not attest anyone's score.
GET /api/defense/sprsThe C3PAO marketplace
Cyber AB
The Cyber Accreditation Body lists Certified Third-Party Assessment Organizations. It is a private clerk for CMMC assessments, not NIST and not SSDF. Voluntary C3PAO assessments remain available while Phase 2 is paused.
SSDF is not a C3PAO and does not place assessments.
GET /api/defense/cyber_abFacility clearance
DCSA
The Defense Counterintelligence and Security Agency is the clerk for facility security clearances and classified work. Unclassified CUI is a different object. Do not mix FCL with CMMC Level 2.
SSDF has no facility clearance and does not seek one from this SKU.
GET /api/defense/dcsaThe export clerk
DDTC / ITAR
The Directorate of Defense Trade Controls (State) administers ITAR. Manufacturers, exporters, and defense-service providers register on DECCS (DS-2032) before licensing. The USML is the catalog of defense articles. Publicly available information about published rules is not, by that fact, technical data.
SSDF is not a DDTC registrant. This atlas and the powered-lift atlas are public-process maps, not USML technical data.
GET /api/defense/ddtcThe control clerk
NIST
SP 800-171 Rev 2 is the CMMC Level 2 baseline (32 CFR 170.14). Rev 3 (May 2024) exists and has OSCAL content; DoD has not incorporated Rev 3 into CMMC. SP 800-171A is the assessment procedure. OSCAL is the machine-readable format. NIST publishes this for free.
SSDF does not sell the 110 controls as a how-to. That clerk already published them.
GET /api/defense/nistThe text
eCFR (FAR / DFARS / 32 CFR 170)
32 CFR Part 170 is the CMMC program rule. DFARS 252.204-7012 is the cyber-incident / 800-171 clause still in force. DFARS 252.204-7021 (NOV 2025) is contractor CMMC status. DFARS 252.204-7025 is the solicitation fill-in. COTS-only buys are excluded.
SSDF maps citations. SSDF does not rewrite DFARS.
GET /api/defense/ecfrRoles
The buyer
DoD / DoW contracting officer
Inserts the CMMC level into 7021/7025, or not. Phase 1 allows Level 1 or Level 2 self-assessment at award. Phase 2 would have required C3PAO at award; that milestone is paused.
SSDF is not bidding DoD work from this store.
GET /api/defense/buyerFlows the clause down
Prime contractor
Must flow DFARS 252.204-7021 to subs that store, process, or transmit FCI or CUI, and keep current CMMC status on covered systems for the life of the contract.
SSDF is not a prime and does not flow down clauses.
GET /api/defense/primeSame CUI, smaller firm
Subcontractor / supplier
If the sub handles FCI or CUI, CMMC status follows the information, not the logo on the building. COTS-only suppliers are the usual exception.
Buying a digital atlas from SSDF does not put CUI on SSDF's systems.
GET /api/defense/subThe assessor
C3PAO
Accredited by Cyber AB. May still perform voluntary Level 2 assessments while Phase 2 is paused. Not NIST. Not a software vendor.
SSDF does not assess, certify, or 'get you CMMC ready.'
GET /api/defense/c3paoFY26 NDAA relief
Small business / NDC
Small businesses are already CAS-exempt, so they qualify as nontraditional defense contractors under 10 U.S.C. § 3014. FY2026 NDAA § 1826 exempts NDCs from FAR Part 31 cost principles and certified cost-or-pricing data. § 1806 raises CAS applicability to $35M and full coverage to $100M (contracts after 30 June 2026). This is accounting relief, not a CMMC holiday.
SSDF does not file a size representation or a CAS disclosure.
GET /api/defense/small_ndcThis store
Commercial digital merchant
Sells files about public rules. Does not process FCI or CUI. Does not manufacture USML articles. Accepts USDC for first-party SKUs.
That is SSDF. Do not turn this SKU into a defense contract.
GET /api/defense/merchantDocket
2024-12-16 · Program rule
in force
32 CFR Part 170 in force
CMMC Program procedures (Title 32) became effective. Level 1 uses FAR 52.204-21 (15 basic safeguarding requirements). Level 2 uses NIST SP 800-171 Rev 2 (110 requirements). Level 3 uses selected 800-172 requirements, assessed by DIBCAC.
32 CFR 170
GET /api/defense/cmmc-32cfr2025-09-10 · 48 CFR
in force
DFARS CMMC acquisition rule published
DoD published the final DFARS rule putting CMMC into contracts: 252.204-7021 (contractor compliance) and 252.204-7025 (solicitation notice). Effective 10 November 2025. Applies to contracts that use contractor systems to process FCI or CUI; excludes COTS-only.
48 CFR 252.204-7021 / 7025
GET /api/defense/dfars-final2025-11-10 · Self-assessment at award
in force
CMMC Phase 1 begins
Contracting officers may include Level 1 (Self) or Level 2 (Self) as a condition of award. Annual affirmation of continuous compliance in SPRS. DFARS 252.204-7012 cyber-incident reporting stays in force independently of CMMC phase.
DFARS 252.204-7021
GET /api/defense/phase-12025-12-18 · NDC and CAS thresholds
in force
FY2026 NDAA signed
Section 1826 exempts nontraditional defense contractors (including small businesses) from FAR Part 31 cost principles and certified cost-or-pricing data. Section 1806 raises CAS applicability from $2.5M to $35M and full CAS coverage from $50M to $100M, generally for awards after 30 June 2026. TINA certified-data threshold moves to $10M.
FY2026 NDAA §§ 1806, 1826; 10 U.S.C. § 3014
GET /api/defense/ndaa-fy262026-07-13 · C3PAO-at-award on hold
paused
CMMC Phase 2 paused
DoW CIO paused Phase 2 (C3PAO certification as a condition of award, which had been set for 10 November 2026) and froze later milestones pending a 60-day reform review. Phase 1 self-assessment remains. DFARS 7012 remains. Voluntary C3PAO assessments remain valid. Active solicitations that already required C3PAO/Level 3 were to be amended to remove those requirements.
DoW CIO memo 26-P-1023 (13 Jul 2026)
GET /api/defense/phase-2-pauseDo not confuse the TAMs
SIPRI military expenditure for 2025 is about $2.887 trillion globally, with the United States at $954 billion. Vendor 'defense market' reports that print $500–$590 billion are a different product (equipment and services TAM), not SIPRI spending. Neither number is a reason to sell NIST's free controls as a $69 protocol.
GET /api/defense/tamWhat already publishes for free
NIST SP 800-171 / 171A, 32 CFR 170, DFARS 7021/7025 on eCFR, NASA TRL definitions, DoD MRL Deskbook (dodmrl.com, 2025 edition), OSCAL catalogs (including 800-171 Rev 3 JSON/XML/YAML), and SBA/APEX Accelerator counseling. A paid SSDF SKU that restates those texts loses to the clerk. This atlas is the map of who is who, what phase is live, and what SSDF will not become.
- CMMC Compliance Atlas that restates the 110 practices
- NIST 800-171 Protocol as a how-to
- TRL/MRL Protocol (NASA and DoD already publish the scales)
- Defense Contracting Protocol as 'how to win a DoD contract'
- A claim that SSDF is CMMC compliant on the buyer's behalf
- Weapons, classified work, CUI processing, pentest, or MDR
Phase 1 self-assessment remains. Phase 2 C3PAO-at-award is paused. NIST 800-171 Rev 2 is still the Level 2 baseline. OSCAL is already the machine-readable control clerk — this SKU does not restate the 110 practices.