Skip to Content

CMMC: deadlines, subcontractors and incidents in the US

Deadline calendar, subcontractor tracking, cyber incidents and a security plan for US federal defence contracts.
October 2, 2026 by
CMMC: deadlines, subcontractors and incidents in the US

Missing a reassessment deadline, copying the wrong required level onto a subcontractor, counting a cyber incident's deadline from the wrong date: ordinary mistakes for a company subject to the CMMC programme on its US federal defence contracts. This application brings together the deadline calendar, subcontractor tracking, incident tracking and the system security plan.

Who the application is for

For cybersecurity managers, IT teams and contract managers at a company holding US federal defence contracts, subject to the CMMC programme and the NIST SP 800-171 standard.

What the application does

  • Describes an assessment scope with its target level, its identifiers and the date from which the deadlines run.
  • Keeps the inventory of assets that process, store or transmit the information covered by the contract, and the requirements catalogue shipped as data.
  • Records a response per requirement (met, not met, not applicable) with its evidence, calculates the score, and keeps the plan of action and milestones with its closeout deadline.
  • Sets out the calendar of reassessment, annual affirmation, action-plan closeout and evidence-retention deadlines, each dated from the scope, with an automatic reminder as each one approaches.
  • Calculates the minimum level required of a subcontractor from what they process and your prime contract's level, rather than simply copying it across, and records their declared status through a manual log.
  • Keeps the cyber incident register with two distinct deadlines — one from discovery, the other from report submission — and compiles a dated, versioned, printable system security plan.

Day to day

  1. Describe your assessment scope and its status date, then inventory the relevant assets.
  2. Respond to each requirement in the catalogue with its evidence, and let the score be calculated.
  3. Generate the deadline calendar and let the automatic reminders warn as each one approaches.
  4. For each subcontractor, enter what they process and let the application calculate the minimum level required of them, then record their declared status.
  5. In the event of a cyber incident, record the discovery date and then the report submission date, and keep the system security plan up to date.

What the application does not do

  • It does not file anything with the US Department of Defense on your behalf: the filing and the annual affirmation remain an action you take yourself, and one that personally commits you.
  • It never says that you are compliant, that a supplier must be excluded, or that you can affirm your status: it records dates and gaps, it does not draw conclusions on your behalf.
  • It does not draft the system security plan's own sections: only you know your own IT environment.
  • It does not connect to any federal system to look up or file a status: that system offers no such public access, so a subcontractor's status is still recorded manually.
  • According to its publisher, it has not yet been tested in production: no deadline it produces has been put to a real contracting officer, and no export has yet been copied into the federal reference system. The rules of the CMMC programme change and do not replace your assessor or your contracting officer.

Free and full editions

The free edition already carries the assessment scope, the asset inventory, the requirements catalogue, assessments with their evidence and score, and the plan of action and milestones. The full edition installs on top without losing anything, and adds the deadline calendar with its reminders, subcontractor tracking, the cyber incident register, the printable system security plan and a score export ready to be copied across.

Getting started

Describe your assessment scope with its target level and status date, inventory the relevant assets, then respond to the catalogue's requirements — always checking with your assessor or your contracting officer the rules that apply to your contract, as these rules change regularly.

Going further

To find out whether this application suits your business and how to activate it, compare the plans or write to us.

Compare the plans

Write to us

Sports club: classes, sessions and waiting lists
Class catalogue, dated sessions, capacity-limited bookings and an automatic waiting list for a gym or studio.