CMMC 2.0: What Changed, the Three Levels, and What Contractors Must Do Now
CMMC 2.0 requirements are appearing in DoW solicitations under the 48 CFR acquisition rule. Here's what changed from 1.0, which level applies to you, where the phase-in actually stands after the July 2026 pause, and what a small or mid-size defense supplier should do this quarter.
See the phase-in timelineWhat changed from CMMC 1.0 to 2.0
| What to compare | CMMC 1.0 | CMMC 2.0 |
|---|---|---|
| Levels | Five | Three |
| Requirements | Extra practices invented for CMMC | Level 2 matches NIST SP 800-171 exactly |
| Who checks | An outside assessor, for nearly everyone | You can check yourself at Level 1 and on some Level 2 contracts |
CMMC 2.0 compliance is now simply CMMC compliance: the Department has dropped the version number. The security requirements themselves are older than either version. Two clauses put them in your contract:
- FAR 52.204-21 has required 15 basic safeguards since 2016 for Federal Contract Information (FCI), the everyday contract paperwork the government sends you.
- DFARS 252.204-7012 has required all 110 requirements in NIST SP 800-171 since 2017 for Controlled Unclassified Information (CUI), the sensitive material like drawings and technical specs.
What CMMC adds is checking. Before it, you signed a contract saying you met the requirements and nobody verified it.
The program rule took effect December 16, 2024. The buying rule that puts CMMC into contracts (48 CFR, DFARS 252.204-7021) took effect November 10, 2025, which is why the clause is turning up in solicitations now.
New to the program? Start with our plain language guide to what CMMC is and where it stands, or see the CMMC framework overview.
The three CMMC 2.0 levels
Each level builds on the one before it. Which one you need depends on the kind of information you handle, not the size of your company.
Level 1
FCI only: the 15 basic safeguarding requirements in FAR 52.204-21, verified by annual self-assessment.
Learn more about Level 1Level 2
CUI: the 110 requirements in NIST SP 800-171 Rev 2 and 320 assessment objectives, assessed every three years. Which assessment type applies depends on the CUI category. CUI in non-Defense registry categories takes Level 2 (Self). CUI in Defense categories, such as Controlled Technical Information, takes Level 2 (C3PAO), which is on hold pending review.
Learn more about Level 2Level 3
Adds 24 enhanced requirements from NIST SP 800-172 on top of the 110, assessed by the government (DIBCAC), and is reserved for CUI on high-priority programs facing advanced persistent threats. Also on hold pending review.
Learn more about Level 3All three levels require a yearly sign-off in SPRS from a named senior executive at your company. For most suppliers with 2 to 200 people, the question is simply whether you handle CUI. If you do, plan for Level 2, and start by working out where that CUI actually lives in your systems. That decision drives everything else.
The 48 CFR phase-in timeline
Phase 1
November 10, 2025
In effect. You check yourself and report your score when a contract is awarded.
Phase 2
Was November 10, 2026
Paused July 13, 2026. Would have required an outside assessor on new contracts.
Phase 3
November 2027
Waiting behind Phase 2. Adds Level 3.
Phase 4
November 2028
Waiting behind Phase 2. Applies to every contract, including renewals.
The pause covers the rollout, not the requirements. NIST SP 800-171 has been required by DFARS 252.204-7012 since 2017 and the government still enforces it. Your SPRS score, the yearly executive sign-off, the requirements your prime passes down to you, and your exposure under the False Claims Act are all still in force. A CMMC Reform Task Force reports back to the Department in mid-to-late September 2026.
Primes set their own deadlines. Those are business decisions about supply chain risk, made independently of the government's schedule, and many primes asked for proof of Level 2 well before the government's date without withdrawing the request. In our 2026 survey, 43% of defense contractors were already having compliance conversations with their own suppliers. If you have a live contract or an open bid, ask your buyer what they need rather than assuming.
Whatever the review decides, the companies that kept working on this will be ready. See the full path to certification, step by step.
Self-assessment vs. C3PAO certification
Checking yourself means you go through the 110 requirements, post your score in SPRS, and a named senior executive signs off every year that it's accurate. Overstating that score is what the Justice Department pursues under the False Claims Act.
A C3PAO assessment means a certified outside firm does the checking. The result is good for three years, with a yearly sign-off in between. That path is on hold while the program is under review.
Checking yourself is not the easy option. It covers the same 110 requirements and the same 320 things an assessor looks at. The only difference is who does the looking.
Your score starts at 110 and drops for each requirement you haven't fully met. You need 110 for full status and at least 88 to qualify for conditional status. How SPRS scoring works.
Which path applies to you is set by your contract and by the type of CUI involved. It isn't a preference.
How Secureframe helps defense contractors get to CMMC 2.0
Most of the cost and difficulty in CMMC is in doing the security work and keeping it done, not in the assessment. Secureframe Defense was built for that part.
Deploy and manage secure infrastructure
Secureframe stands up a CMMC-compliant environment in Microsoft GCC High or Google Workspace, with devices configured for the access control, logging, monitoring, notification, and segmentation that NIST 800-171 Rev 2 requires for storing and accessing CUI.
Implement and document controls following Defense Navigator
The 110 requirements and 320 assessment objectives become a guided implementation workflow, generating and maintaining your SSP, implementation statements, and policies from your actual configured environment rather than from templates.
Maintain continuous monitoring and operational guardrails
Ongoing control testing, automated evidence collection, drift detection, risk assessments, and vendor tracking keep your SPRS score aligned with your real posture, so the executive signing the annual affirmation has a record behind it.
That combination replaces stitching together an MSP, a consultant, and spreadsheets.
Frequently Asked Questions
Yes. Contractors and subcontractors that handle FCI or CUI in performance of a DoW contract are subject to CMMC requirements. The 48 CFR rule took effect November 10, 2025 and Phase 1 self-assessment requirements are in effect. Two things are mandatory regardless of rollout status: full NIST 800-171 Rev 2 implementation, 72-hour cyber incident reporting, and flowdown if the DFARS 7012 clause is in your contract; and a current self-assessment score and annual affirmation in SPRS, signed by a named senior executive.
If you only handle FCI, Level 1. If you store, process, or transmit CUI, including many machine shops and component suppliers, plan for Level 2. If you hold a government contract, you almost certainly have FCI. Whether you have CUI depends on what your prime or contracting officer sends you.
It depends on the CUI category and what the solicitation says, not on your preference. CUI in non-Defense registry categories takes Level 2 (Self). CUI in Defense categories such as Controlled Technical Information takes Level 2 (C3PAO), which is on hold pending review. Either way the body of work is the same 110 requirements and 320 assessment objectives.
You can achieve Conditional status with a score of at least 88 out of 110, provided no requirements listed in 32 CFR 170.21(a)(2)(iii) are outstanding and nothing on your POA&M is worth more than 1 point, except CUI encryption awaiting FIPS validation. Every POA&M item must be closed and verified within 180 days or the Conditional status expires.
Yes. Primes must flow CMMC requirements into every subcontract where FCI or CUI is processed, stored, or transmitted, and must determine the correct level for each subcontractor based on the information being shared. They may not flow FCI or CUI to a subcontractor that has not demonstrated compliance at the required level. Subcontractors cannot rely on a prime’s certification. You demonstrate compliance for your own systems.
Preparation dominates the timeline, not the assessment. Most organizations spend 12 months or more getting ready. In a Redspin survey, 68% took more than a year, even though 77% already reported strong NIST 800-171 and DFARS implementation. Preparation for a Level 2 self-assessment is the same 8 to 17 months as preparation for a C3PAO assessment, because the underlying work is identical.
