Skip to main content

CMMC 2.0: What Changed, the Three Levels, and What Contractors Must Do Now

CMMC 2.0 requirements are appearing in DoW solicitations under the 48 CFR acquisition rule. Here's what changed from 1.0, which level applies to you, where the phase-in actually stands after the July 2026 pause, and what a small or mid-size defense supplier should do this quarter.

See the phase-in timeline

Request a CMMC demo

What changed from CMMC 1.0 to 2.0

What to compareCMMC 1.0CMMC 2.0
LevelsFiveThree
RequirementsExtra practices invented for CMMCLevel 2 matches NIST SP 800-171 exactly
Who checksAn outside assessor, for nearly everyoneYou can check yourself at Level 1 and on some Level 2 contracts

CMMC 2.0 compliance is now simply CMMC compliance: the Department has dropped the version number. The security requirements themselves are older than either version. Two clauses put them in your contract:

  • FAR 52.204-21 has required 15 basic safeguards since 2016 for Federal Contract Information (FCI), the everyday contract paperwork the government sends you.
  • DFARS 252.204-7012 has required all 110 requirements in NIST SP 800-171 since 2017 for Controlled Unclassified Information (CUI), the sensitive material like drawings and technical specs.

What CMMC adds is checking. Before it, you signed a contract saying you met the requirements and nobody verified it.

The program rule took effect December 16, 2024. The buying rule that puts CMMC into contracts (48 CFR, DFARS 252.204-7021) took effect November 10, 2025, which is why the clause is turning up in solicitations now.

New to the program? Start with our plain language guide to what CMMC is and where it stands, or see the CMMC framework overview.

The three CMMC 2.0 levels

Each level builds on the one before it. Which one you need depends on the kind of information you handle, not the size of your company.

Level 1

FCI only: the 15 basic safeguarding requirements in FAR 52.204-21, verified by annual self-assessment.

Learn more about Level 1

Level 2

CUI: the 110 requirements in NIST SP 800-171 Rev 2 and 320 assessment objectives, assessed every three years. Which assessment type applies depends on the CUI category. CUI in non-Defense registry categories takes Level 2 (Self). CUI in Defense categories, such as Controlled Technical Information, takes Level 2 (C3PAO), which is on hold pending review.

Learn more about Level 2

Level 3

Adds 24 enhanced requirements from NIST SP 800-172 on top of the 110, assessed by the government (DIBCAC), and is reserved for CUI on high-priority programs facing advanced persistent threats. Also on hold pending review.

Learn more about Level 3

All three levels require a yearly sign-off in SPRS from a named senior executive at your company. For most suppliers with 2 to 200 people, the question is simply whether you handle CUI. If you do, plan for Level 2, and start by working out where that CUI actually lives in your systems. That decision drives everything else.

The 48 CFR phase-in timeline

  1. Phase 1

    November 10, 2025

    In effect. You check yourself and report your score when a contract is awarded.

  2. Phase 2

    Was November 10, 2026

    Paused July 13, 2026. Would have required an outside assessor on new contracts.

  3. Phase 3

    November 2027

    Waiting behind Phase 2. Adds Level 3.

  4. Phase 4

    November 2028

    Waiting behind Phase 2. Applies to every contract, including renewals.

The pause covers the rollout, not the requirements. NIST SP 800-171 has been required by DFARS 252.204-7012 since 2017 and the government still enforces it. Your SPRS score, the yearly executive sign-off, the requirements your prime passes down to you, and your exposure under the False Claims Act are all still in force. A CMMC Reform Task Force reports back to the Department in mid-to-late September 2026.

Primes set their own deadlines. Those are business decisions about supply chain risk, made independently of the government's schedule, and many primes asked for proof of Level 2 well before the government's date without withdrawing the request. In our 2026 survey, 43% of defense contractors were already having compliance conversations with their own suppliers. If you have a live contract or an open bid, ask your buyer what they need rather than assuming.

Whatever the review decides, the companies that kept working on this will be ready. See the full path to certification, step by step.

Self-assessment vs. C3PAO certification

Checking yourself means you go through the 110 requirements, post your score in SPRS, and a named senior executive signs off every year that it's accurate. Overstating that score is what the Justice Department pursues under the False Claims Act.

A C3PAO assessment means a certified outside firm does the checking. The result is good for three years, with a yearly sign-off in between. That path is on hold while the program is under review.

Checking yourself is not the easy option. It covers the same 110 requirements and the same 320 things an assessor looks at. The only difference is who does the looking.

Your score starts at 110 and drops for each requirement you haven't fully met. You need 110 for full status and at least 88 to qualify for conditional status. How SPRS scoring works.

Which path applies to you is set by your contract and by the type of CUI involved. It isn't a preference.

How Secureframe helps defense contractors get to CMMC 2.0

Most of the cost and difficulty in CMMC is in doing the security work and keeping it done, not in the assessment. Secureframe Defense was built for that part.

Deploy and manage secure infrastructure

Secureframe stands up a CMMC-compliant environment in Microsoft GCC High or Google Workspace, with devices configured for the access control, logging, monitoring, notification, and segmentation that NIST 800-171 Rev 2 requires for storing and accessing CUI.

Implement and document controls following Defense Navigator

The 110 requirements and 320 assessment objectives become a guided implementation workflow, generating and maintaining your SSP, implementation statements, and policies from your actual configured environment rather than from templates.

Maintain continuous monitoring and operational guardrails

Ongoing control testing, automated evidence collection, drift detection, risk assessments, and vendor tracking keep your SPRS score aligned with your real posture, so the executive signing the annual affirmation has a record behind it.

That combination replaces stitching together an MSP, a consultant, and spreadsheets.

Frequently Asked Questions

Yes. Contractors and subcontractors that handle FCI or CUI in performance of a DoW contract are subject to CMMC requirements. The 48 CFR rule took effect November 10, 2025 and Phase 1 self-assessment requirements are in effect. Two things are mandatory regardless of rollout status: full NIST 800-171 Rev 2 implementation, 72-hour cyber incident reporting, and flowdown if the DFARS 7012 clause is in your contract; and a current self-assessment score and annual affirmation in SPRS, signed by a named senior executive.

The verification requirement paused.The one in your contract did not.

Request a CMMC demo