A Defense Contractor's Guide to CMMC 2.0 Certification, Levels, and Compliance

By: Patrick Voight
August 24, 2026

I talk to defense contractors every week who know they need CMMC certification but aren't sure where to start. Some are waiting for more clarity from the government. Some think the recent pause on certification means they have more time than they do. And some don't realize the underlying requirement has already landed in their contracts — pause or no pause.

So here's what's changed, what hasn't, and what it means for your business — as of August, 2026.

What does CMMC stand for?

CMMC stands for Cybersecurity Maturity Model Certification. It is a major Department of Defense program built to protect the defense industrial base from increasingly frequent and complex cyberattacks — particularly aimed at safeguarding controlled unclassified information (CUI) and federal contract information (FCI).

In plain terms: The DoD wants to verify that the companies it works with are actually protecting sensitive information — not just saying they are. CMMC is how they enforce that.

What is CMMC 2.0, and what changed from CMMC 1?

CMMC 2.0 is the current, streamlined version of the original framework. The CMMC program was formally established by a final rule published October 15, 2024, and is being implemented through a Defense Federal Acquisition Regulation Supplement (DFARS) rule that went into effect November 10, 2025.

The key change from the original level 1 CMMC framework: CMMC 2.0 reduced the original 5 certification levels down to three and aligned them more directly with existing NIST standards, making the path to compliance clearer — though not necessarily easier — for most contractors.

CMMC levels explained

cmmc-2.0-levels-at-a-glance

The CMMC framework requires a systematic approach to certification mapped to three organizational maturity levels. Which level applies to your organization depends on the type of information you handle under your DoD contracts.

Level 1

Level 1 applies to contractors whose work involves federal contract information (FCI) but not controlled unclassified information (CUI). It requires an annual self-assessment verifying compliance with the 17 basic cybersecurity practices in FAR clause 52.204-21, and a senior official must affirm compliance annually via the Supplier Performance Risk System (SPRS).

Think of this as basic cyber hygiene: access controls, password management, malware protection. If your DoD work is relatively limited in scope and doesn't involve sensitive technical data, this is likely your level.

Level 2

Level 2 requires implementing all 110 security requirements in NIST SP 800-171 Rev. 2, which governs the protection of CUI. It comes in two versions: self-assessment (for contractors handling CUI outside the Defense CUI Registry) and third-party certification by an accredited C3PAO (for contractors handling CUI within the Defense Organizational Index Grouping). Both require reassessment every three years with annual compliance affirmations.

As of July 2026, the C3PAO certification path is on pause while the government reviews the program — but the self-assessment path, and the 110 underlying controls, remain fully in effect. This is where most mid-market defense contractors land. The 110 NIST 800-171 controls span 14 domains — from access control and incident response to system and communications protection. If your work involves technical drawings, specifications, or any information marked CUI, Level 2 applies.

For a deeper look at how NIST frameworks work, our NIST Cybersecurity Framework guide is a useful starting point.

Level 3

Level 3 requires all Level 2 controls plus 24 additional enhanced requirements from NIST SP 800-172. Contractors at this level must undergo assessment every three years by the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).

Level 3 is reserved for contractors working on the most sensitive defense programs — those involving advanced technology, large aggregations of CUI, or systems where a single breach would create widespread DoD vulnerability.

When Will CMMC Be Required?

CMMC is being rolled out in four phases over three years. Here's how the timeline breaks down.

cmmc-2.0-implementation-timeline

Level 1 and Level 2 self-assessments are required right now. That's been true since Phase 1 took effect November 10, 2025, and it hasn't changed. What's genuinely uncertain is everything after that: Phase 2 was set to add third-party C3PAO certification to new contracts starting November 10, 2026, but the Department of War suspended that requirement on July 13, 2026, pending a 60-day review by a new CMMC Reform Task Force.

Phase 3 and Phase 4 — which would extend certification to existing contracts and apply CMMC across the board by November 2028 — are on hold behind it, with no confirmed dates.

What To Know

The backlog didn't pause with it. As of mid-2026, roughly 1,200 contractors had completed certification out of an estimated 8,000 that need to be — and even with the industry adding roughly 180 certifications a month, that gap was already wide before the suspension. The review won't shrink it.

Subcontractors aren't off the hook. Primes are still responsible for flowing CMMC requirements down their supply chain, and many were already demanding compliance on timelines ahead of the official government schedule before this pause.

If you're a downstream supplier in a defense manufacturing chain, your effective deadline may still be set by your prime — regardless of what the 60-day review recommends.

What CMMC compliance actually requires

Getting CMMC certified isn't a paperwork exercise. What assessors evaluate is evidence — not plans, not intent, not an Excel spreadsheet that says the controls are in place. When a C3PAO comes in to assess a Level 2 contractor, they need documented proof that every required control is implemented and operating as intended.

For most organizations pursuing Level 2, the compliance work spans several interconnected areas:

Policies and documentation

Every required security control needs a written policy, procedure, or plan behind it. This includes a System Security Plan (SSP), a Plan of Action and Milestones (POA&M) for any gaps, and an incident response plan.

Technical controls

The 110 NIST 800-171 controls cover everything from multi-factor authentication and access management to audit logging, configuration management, and media protection. Most organizations discover gaps they didn't know existed once they start mapping their current environment against the full control set.

Continuous monitoring and evidence collection

Controls need to be not just implemented but evidenced — with screenshots, logs, configurations, and documentation that demonstrate ongoing compliance, not just a snapshot at assessment time.

Training

Security awareness training for all users handling CUI is a specific requirement, not an optional add-on.

The risk of a false self-attestation

You still have to protect CUI. That rule hasn't changed.

So if you submit a self-attestation and SPRS score that turn out to be incorrect, you can still be sued under the False Claims Act. That means triple damages, plus a separate penalty for every invoice you submitted while the false score was on file.

Don’t assume that just because you can still self-report, it’s safe to guess.

The CMMC compliance checklist: where most organizations fall short

Based on what I see working with organizations across the defense supply chain, these are the areas where gaps consistently appear:

  • Multi-factor authentication (MFA) — Often partially deployed. CMMC requires MFA everywhere users access CUI, including cloud applications and remote access. Partial deployment doesn't pass.
  • CUI identification and data flow mapping — Many organizations don't have a clear picture of where CUI actually lives in their environment. You can't protect what you haven't found.
  • Audit logging and log retention — Systems need to generate logs, those logs need to be retained for defined periods, and someone needs to be reviewing them. The review piece is frequently missing.
  • System Security Plan (SSP) — The SSP must document your entire environment, all the controls, how they're implemented, and who's responsible. Generic templates don't satisfy assessors.
  • Incident response plan — A robust incident response plan that exists but has never been tested is a documentation risk, not a security control.
  • Supply chain risk management — If you're handling CUI, you need visibility into the security posture of your own vendors and subcontractors.

None of these is insurmountable. But addressing them takes time — typically 6 to 18 months for a Level 2 organization starting from a baseline, depending on the current state of the environment.

Our team just put together a helpful checklist to get a gut-check on where you may have gaps. Download an ungated copy through the link below:

How to get CMMC certification

The certification path depends on your required level.

Level 1

Complete a self-assessment against the 17 FAR 52.204-21 practices, document your results, and have a senior official submit your SPRS score. This can be done internally, though working with an experienced CMMC consultant helps ensure your assessment holds up to scrutiny.

Level 2 (self-assessment path)

Complete a self-assessment against all 110 NIST 800-171 controls, submit your SPRS score, and affirm compliance annually. A thorough gap assessment before you start is critical — your SPRS score is a public-facing signal of your security posture, and submitting an inflated score carries legal liability under the False Claims Act.

Level 2 (C3PAO certification path)

C3PAO certification is paused while the government reviews the program, so there's nothing to schedule right now. Once it resumes, you'll engage a certified Third-Party Assessment Organization (C3PAO) to formally evaluate your program, with certification renewed every three years. Use this window for a readiness assessment — showing up to a formal assessment before you're ready wastes time and fees.

Level 3

Engage the Defense Contract Management Agency's DIBCAC directly. This is a government-led assessment process. Organizations at this level typically work with experienced security advisors throughout the preparation process.

Frequently asked questions about CMMC

CMMC raises a lot of questions. Here are the ones I hear most often from contractors working through the compliance process.

What does CMMC stand for?

CMMC stands for Cybersecurity Maturity Model Certification. It is a Department of Defense program requiring defense contractors and subcontractors to verify their cybersecurity practices meet defined standards before being eligible for contract awards involving federal contract information or controlled unclassified information.

What is CMMC 2.0?

CMMC 2.0 is the current version of the framework, finalized in late 2024. It streamlined the original five-level model into three levels and aligned the requirements more directly with existing NIST standards — specifically NIST SP 800-171 at Level 2 and NIST SP 800-172 at Level 3. Phase 1 implementation began on November 10, 2025.

What are the CMMC levels?

CMMC 2.0 has three levels: Level 1 covers basic cyber hygiene for contractors handling only FCI; Level 2 requires all 110 NIST 800-171 controls for contractors handling CUI; Level 3 adds 24 enhanced controls from NIST 800-172 for contractors on the most sensitive programs.

When will CMMC be required?

CMMC was set to roll out in four phases over three years, but the Department of War suspended Phase 2 on July 13, 2026, pending a 60-day review.

Phase 1 began on November 10, 2025, requiring Level 1 and Level 2 self-assessments as a condition of award for new contracts, and that requirement is still in effect.

Phase 2 would have added Level 2 C3PAO third-party certification requirements to applicable new contracts starting November 10, 2026 — this is the piece now suspended.

Phase 3 and Phase 4, which would extend certification requirements to existing contracts and apply CMMC to all applicable DoD contracts above the micro-purchase threshold, are on hold behind Phase 2 with no new dates set. COTS-only contracts remain exempt.

Does CMMC apply to subcontractors?

Yes. Prime contractors are responsible for flowing CMMC requirements down to their subcontractors based on the sensitivity of information the subcontractor handles. There are no exemptions for sole-source subcontractors. Some primes are already pushing compliance timelines on subcontractors ahead of the official government schedule.

What is a CMMC audit?

A CMMC audit (formally called an assessment) is the formal evaluation of an organization's cybersecurity program against the required CMMC controls. Level 1 and some Level 2 contractors complete self-assessments. Higher-risk Level 2 contractors are assessed by an accredited C3PAO when that requirement is active — currently paused pending the government's review. Level 3 contractors are assessed by the Defense Contract Management Agency.

How long does CMMC certification take?

It depends on your starting point and target level. Level 1 self-assessment can be completed in weeks if basic controls are in place. Level 2 readiness — from gap assessment through control implementation to formal C3PAO assessment — typically takes 6 to 18 months for organizations that haven't previously aligned to NIST 800-171. Starting early is not optional at this point.

How can Marco help with CMMC compliance?

Marco provides cybersecurity assessments, NIST framework implementation, technical control deployment, compliance documentation support, and fractional CISO services. Our team works alongside defense contractors to assess their current posture, close identified gaps, and prepare for formal assessment. To get started, take our cybersecurity assessment or talk to our security team.

Where to start with CMMC compliance

If you're a defense contractor and haven't started your CMMC compliance journey, the first step is understanding where you stand. That means a structured gap assessment against the NIST 800-171 controls — not a checklist you fill out yourself, but a thorough technical review of your environment, your documentation, and your actual security posture.

The current CMMC consultant shortage

There are approximately 80,000 contractors and subcontractors that need to be CMMC compliant, but as of early June 2026, only around 100 accredited C3PAOs are in the ecosystem.

The shortage isn't just on the assessment side — it's on the readiness side too. Experienced partners who can come in, do the IT work, implement controls, and build out the compliance documentation are in short supply.

Marco's CMMC compliance services

At Marco, our team has deep experience with the NIST frameworks that underpin CMMC compliance — including NIST CSF and NIST 800-171. And our security team regularly works alongside defense contractors — often through our fractional CISO services — to continuously improve their current posture, close identified gaps, and maintain the documentation and technical controls required for certification.

If you haven't started your CMMC compliance journey, the right first step is understanding where you stand.

We can work with you to assess current posture, close identified gaps, and build the documentation and technical controls required for certification, with a clear path from Tier 1 assessment through to C3PAO readiness.

 

 

Topics: Manufacturing, CMMC