Skip to content
Cyber Defense Technologies

Compliance

CMMC Explained: Levels, Assessments and Timelines for Defense Contractors

What the Cybersecurity Maturity Model Certification requires at each level, where the rollout stands after the Phase 2 suspension, and what defense contractors should be doing now.

By Cyber Defense Technologies September 22, 2026 5 min read

The Cybersecurity Maturity Model Certification (CMMC) program exists for one reason: to make sure the companies that support the Department of War (DoW) actually protect the sensitive information entrusted to them. For years, defense contractors self-attested to NIST SP 800-171 under DFARS 252.204-7012, and reviews repeatedly found that many had not implemented the requirements they claimed. CMMC adds verification, and it ties that verification to contract eligibility.

This guide explains the three levels, how assessments work, where the rollout stands today, and what a practical contractor should do next.

Two kinds of information, three levels

CMMC starts with the information you handle under a contract.

  • Federal Contract Information (FCI) is information provided by or generated for the government under a contract that is not intended for public release. Almost every contractor handles some.
  • Controlled Unclassified Information (CUI) is information that law, regulation or government policy requires to be safeguarded, such as controlled technical information, export-controlled data and many program documents.

The contract, not the contractor, determines which level applies.

The three CMMC levels

Level 1

Federal Contract Information (FCI)

  • 15 basic safeguarding requirements (FAR 52.204-21)
  • Annual self-assessment
  • Annual affirmation in SPRS

Level 2

Controlled Unclassified Information (CUI)

  • 110 requirements of NIST SP 800-171 Rev. 2
  • Self-assessment or third-party (C3PAO) assessment every three years, as the contract specifies
  • Annual affirmation in SPRS

Level 3

CUI facing advanced persistent threats

  • Level 2, plus 24 requirements from NIST SP 800-172
  • Government-led assessment (DIBCAC)
  • Annual affirmation in SPRS
Which level applies is set by the contract, based on the information you handle.

Level 1: basic safeguarding of FCI

Level 1 covers the 15 basic safeguarding requirements in FAR 52.204-21, such as limiting system access to authorized users, sanitizing media, and keeping malware protection current. Organizations perform an annual self-assessment and a senior official affirms compliance in the Supplier Performance Risk System (SPRS).

Level 2: protecting CUI

Level 2 aligns with the 110 security requirements of NIST SP 800-171 Revision 2. Depending on the contract, compliance is shown through a self-assessment or through an assessment by an authorized CMMC Third-Party Assessment Organization (C3PAO). Either way, scores are recorded, and a senior official affirms continued compliance every year.

Level 3: CUI facing advanced threats

Level 3 applies to a small number of programs where CUI is a priority target of advanced persistent threats. It requires a final Level 2 certification plus 24 selected requirements from NIST SP 800-172, assessed by the government through the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).

How the rollout has unfolded

The program rule, 32 CFR Part 170, took effect in December 2024 and defines the levels and assessment process. The acquisition rule that puts CMMC requirements into DoW contracts took effect on November 10, 2025, starting a planned four-phase rollout.

CMMC rollout milestones

  1. December 16, 2024

    Program rule takes effect

    32 CFR Part 170 establishes the CMMC program, its levels and its assessment process.

  2. November 10, 2025

    Phase 1 begins

    The DFARS acquisition rule takes effect. Solicitations can require Level 1 and Level 2 self-assessments.

  3. July 13, 2026

    Phase 2 suspended

    The Department of War pauses the planned Level 2 third-party (C3PAO) requirements and launches a 60-day reform review.

  4. Now

    Phase 1 still in force

    Self-assessments, SPRS scores and annual affirmations continue, as do DFARS 252.204-7012 obligations.

Phase 1 began on November 10, 2025. Solicitations can require Level 1 or Level 2 self-assessments as a condition of award.

Phase 2 was scheduled for November 10, 2026, when Level 2 third-party certification would have become a condition of award for many contracts involving CUI. On July 13, 2026, the Department suspended Phase 2, froze the later phases, and set up a CMMC Reform Task Force to review the program. The Department pointed to limited assessor capacity and the cost burden on small and midsize businesses. The task force's findings had not been made public at the time of writing, so contractors should watch for official announcements, class deviations or rule changes.

What the suspension did not change

It is easy to read "suspended" as "optional." That would be a mistake.

  • DFARS 252.204-7012 still applies. If you handle covered defense information, you must implement NIST SP 800-171 and report cyber incidents within 72 hours.
  • Phase 1 is still in force. Self-assessment requirements, SPRS scores and annual affirmations continue.
  • Affirmations carry legal weight. A senior official affirming compliance that does not exist creates False Claims Act exposure. The Department of Justice has pursued cybersecurity cases under its Civil Cyber-Fraud Initiative.
  • Primes still flow requirements down. Many prime contractors expect subcontractors to demonstrate compliance, regardless of the federal timeline.
  • Government-led assessments continue. DIBCAC retains its authority to assess contractors.

How scoring works

Level 2 self-assessments use the DoD Assessment Methodology. You start at 110 points and deduct 5, 3 or 1 point for each requirement that is not met, depending on its weight. A score can go far below zero; what matters is that it is accurate.

Under the CMMC rule, a Level 2 assessment can end in conditional status only if the score is at least 88 and every open item is eligible for a Plan of Action and Milestones (POA&M). High-weight requirements such as multifactor authentication must be met on assessment day. Open POA&M items must be closed within 180 days.

A practical plan for contractors

Whatever the task force recommends, the work that protects CUI is the same. We recommend this sequence:

  1. Confirm what you handle. Identify FCI and CUI flows for each contract, including what primes and customers send you.
  2. Scope deliberately. Decide where CUI lives and draw a boundary around it. A smaller, well-defined enclave is cheaper to secure and assess.
  3. Assess honestly. Evaluate all 110 requirements against evidence, not intentions, and correct your SPRS score if it is wrong.
  4. Document as you go. Keep your System Security Plan (SSP) and POA&M current; assessors expect both to match reality.
  5. Close the high-weight gaps first. Multifactor authentication, incident response, encryption and access control carry the most weight and the most risk.
  6. Rehearse an assessment. A mock assessment exposes gaps in evidence as well as in controls.

If your contracts do not yet require CMMC, starting now still pays off. Implementation typically takes months, not weeks, and assessor availability will be tight once third-party requirements resume in whatever form.

Frequently asked questions

Do we need CMMC if we only handle FCI? If your contracts include FCI and require CMMC, you need Level 1: the 15 basic safeguarding requirements, an annual self-assessment and an affirmation.

Is NIST SP 800-171 Revision 3 required? The Department has kept Revision 2, with 110 requirements, as the baseline for DFARS 252.204-7012 and CMMC. Watch for official changes before shifting your program to Revision 3.

What should subcontractors do? Subcontractors that handle FCI or CUI generally have the same obligations, flowed down from the prime. Ask your primes what they require of you, and expect questionnaires and evidence requests.

How CDT can help

CDT's CMMC and NIST SP 800-171 readiness engagements take organizations from gap analysis to assessment-ready, including scoping, SSP and POA&M development, and technical remediation. For a quick first look, try our free CMMC readiness self-check.

Sources

Let's talk

Ready to strengthen your security posture?

Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.