Skip to main content

CMMC Pause: What Still Applies & What's Next

CMMC Level 2 Compliance: Meet All 110 NIST 800-171 Controls

CMMC Level 2, sometimes still called CMMC 2.0 Level 2, is written into defense contracts under 48 CFR. Secureframe Defense pairs a compliance automation platform with expert advisory to take you from scoping to an assessment-ready package, without hiring a compliance department.

Get the Level 2 checklist

Request a CMMC demo

What CMMC Level 2 actually requires

CMMC Level 2 compliance applies to contractors handling Controlled Unclassified Information (CUI). It requires all 110 requirements in NIST SP 800-171 Rev 2, grouped into 14 families, with 320 assessment objectives behind them.

Who verifies depends on the type of CUI. Non-Defense categories take the self-assessment form. Defense categories, like Controlled Technical Information, take a third-party (C3PAO) assessment every three years, and that path has been on hold since July 13, 2026. The 110 requirements are identical either way. Only the verifier changes.

Anything that touches CUI is in scope: where it's stored, what it moves through, who opens it. So are the systems protecting those assets, like your firewall and identity provider. Scope drives cost and timeline more than any other decision, which is why enclave vs. full environment comes first.

New to the program? Start with our plain language guide to what CMMC is and where it stands, or see the CMMC framework overview.

Technician in safety glasses operating manufacturing equipment

Your SSP and POA&M carry the assessment

Your System Security Plan (SSP) describes how you meet each of the 110 requirements. It's the document your assessor works from. If a control or piece of evidence is missing from it, that requirement can be marked NOT MET, and an incomplete SSP is one of the most common reasons assessments stall.

An assessor does three things: reads your documentation, interviews your people from executives to engineers, and tests your systems directly. Screenshots gathered the week before don't survive that.

A Plan of Action and Milestones (POA&M) lets you carry a limited set of gaps past assessment. You need a score of at least 88, nothing on the list worth more than 1 point, and every item closed and verified within 180 days or your conditional status expires.

Secureframe generates and maintains both from your live environment instead of a static document that goes stale.

The full path from scoping to submission, including where the paused C3PAO step sits, is on our CMMC certification page.

Timeline and cost: what actually moves them

Three things drive it: how big your scope is, how mature your current environment is, and whether you have security expertise in house. Most companies spend 8 to 17 months getting ready. In a Redspin survey, 68% took more than a year, and 77% of those already had solid NIST 800-171 and DFARS practices in place.

Primes set their own deadlines regardless of the government's schedule, so work backward from your contract pipeline rather than the rollout calendar. Not sure where you stand? Take the free CMMC readiness assessment.

Get the CMMC Level 2 compliance checklist

A control-by-control worksheet for planning your Level 2 effort: scoping questions, the 14 control families, SSP and POA&M prep, and assessment logistics.

What you'll get:

  • Break down CMMC Level 2 compliance into clear, actionable steps
  • See what actions you’ll need to take as you prepare for, achieve, and maintain compliance
  • Check off tasks to stay organized and gauge your assessment readiness

Why contractors choose Secureframe over point solutions

MSPs run your IT but rarely own your compliance documentation. Enclave vendors solve where CUI lives but not the other controls around it. Secureframe Defense covers the full 110-requirement lifecycle in one platform, and Secureframe holds a CMMC Level 2 certification of its own.

Deploy and manage secure infrastructure

Secureframe stands up a CMMC-compliant environment in Microsoft GCC High or Google Workspace, with devices configured for the access control, logging, monitoring, notification, and segmentation that NIST 800-171 Rev 2 requires for storing and accessing CUI.

Implement and document controls following Defense Navigator

The 110 requirements and 320 assessment objectives become a guided implementation workflow, generating and maintaining your SSP, implementation statements, and policies from your actual configured environment rather than from templates.

Maintain continuous monitoring and operational guardrails

Ongoing control testing, automated evidence collection, drift detection, risk assessments, and vendor tracking keep your SPRS score aligned with your real posture, so the executive signing the annual affirmation has a record behind it.

Frequently Asked Questions

The data you handle. Level 1 covers Federal Contract Information and requires 15 basic safeguards, self-assessed annually. Level 2 applies when you handle Controlled Unclassified Information and requires all 110 requirements in NIST SP 800-171 Rev 2 and 320 assessment objectives, assessed every three years.

The certification requirement paused.The one in your contract did not.

Request a CMMC demo