
Introduction
` for these minor issues, per prioritization rules (fewer than 5 other changes are being made, and fixes require unavailable source data or would push against the word budget).
Winning a Department of War contract used to mean checking a box. You self-attested your cybersecurity was adequate, signed the paperwork, and moved on. That era is over.
CMMC 2.0 now requires verified proof, not promises. And just when contractors thought they understood the rules, the Department suspended a major piece of the program on July 13, 2026 — throwing timelines into question again.
The confusion is real. Contractors are juggling three compliance levels, a rollout schedule that keeps shifting, and the constant burden of documenting NIST SP 800-171 compliance well enough to survive an audit. Many teams pass once, then scramble before every reassessment.
This guide breaks down what CMMC 2.0 actually requires, where the 2026 timeline stands today, what compliance really costs, and how to build capability that outlasts any single certification cycle.
Key Takeaways
- CMMC 2.0 has three levels (not five), tied to whether you handle FCI or CUI
- Level 2's 110 NIST SP 800-171 controls trip up most contractors — documentation is the real bottleneck
- DoW suspended Phase II third-party audits (July 13, 2026); Phase I self-assessment and DFARS 7012 remain active
- C3PAO certification for Level 2 runs over $100,000 in federal cost modeling, so budget accordingly
- Sustained compliance beats certification cramming every time an assessor shows up
What Is CMMC 2.0?
CMMC 2.0 is the Department of Defense's (DoD) tiered certification framework verifying that defense contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Instead of trusting contractors to self-report, higher levels now require independent, third-party verification.
Why the change? The old self-certification model had an obvious flaw: nobody checked. Meanwhile, adversaries went straight for the weakest links in the defense supply chain — often smaller subcontractors with thin security budgets.
That's not hypothetical. A joint CISA, FBI, and NSA advisory confirmed Russian state-sponsored actors targeted cleared defense contractors from at least January 2020 through February 2022, exfiltrating sensitive technical data and maintaining network access for six months or longer in some cases. That's the threat CMMC exists to blunt.
FCI vs. CUI: Why It Determines Your Level
Your required certification level depends entirely on what flows through your systems:
- FCI (FAR 4.1901): Non-public information provided by or generated for the government under a contract. Excludes simple transactional data like invoices.
- CUI (32 CFR 2002.4(h)): Information the government requires you to safeguard under law, regulation, or government-wide policy.
Handle only FCI, and Level 1 likely applies. Handle CUI, and you're looking at Level 2 or above. There's no shortcut around this distinction: it's the foundation everything else builds on.
CMMC 2.0's Three Compliance Levels
The 2020 version of CMMC had five confusing levels. Industry pushback simplified that down to three, each building on the one below it. Here's how they compare:
| Level | Requirements | Assessment | POA&Ms Allowed |
|---|---|---|---|
| 1 – Foundational | 15 safeguards (FAR 52.204-21) | Annual self-assessment + SPRS affirmation | No |
| 2 – Advanced | 110 controls (NIST SP 800-171 Rev. 2) | Self-assessment or C3PAO, every 3 years | Yes, 80% minimum, 180-day closeout |
| 3 – Expert | Level 2 + 24 practices (NIST SP 800-172) | DIBCAC triennial assessment | Limited, same 180-day rule |
Level 1: Foundational
Level 1 covers the 15 basic safeguarding requirements under FAR clause 52.204-21 — access control, physical protection, and media protection for FCI. You self-assess annually, and a senior company official must affirm the results in SPRS.
There's no wiggle room here: all 15 requirements must be fully met. POA&Ms (partial compliance with a fix-it plan) aren't permitted at this level.
Level 2: Advanced
This is where most contractors land. Level 2 requires all 110 security requirements from NIST SP 800-171 Rev. 2, spread across 14 control families, mandated by DFARS 252.204-7012.
Some contracts allow self-assessment every three years. Others (typically those tied to the Defense Organizational Index Grouping for national security-critical work) require full C3PAO third-party certification. Your solicitation language tells you which applies; it's not your choice to make.
POA&Ms are allowed here, but only if you score at least 80% and close remaining gaps within 180 days.
Level 3: Expert
Level 3 stacks 24 additional practices from NIST SP 800-172 on top of Level 2, targeting advanced persistent threats through proactive threat hunting and advanced analytics. A DIBCAC assessment replaces the C3PAO route.
This level applies narrowly: only contractors supporting the most sensitive national security programs need it.

Who Needs CMMC Certification?
Certification requirements travel down the entire supply chain, not just to prime contractors. The specific level gets written directly into DFARS clauses within the solicitation itself.
That obligation doesn't stop at the prime. It flows to:
- Subcontractors and suppliers handling CUI, regardless of whether they contract directly with the Department
- Cloud and SaaS providers storing, processing, or transmitting CUI on a contractor's behalf
- Any tier in the chain touching regulated information, since Tier 3 suppliers aren't exempt just because they're small
One notable exception: contracts covering exclusively commercial off-the-shelf (COTS) items are excluded from flow-down requirements.
A common misconception worth correcting: FedRAMP authorization does not substitute for CMMC. A cloud provider handling CUI needs FedRAMP Moderate authorization (or equivalent) for the offering itself, but the contractor using that cloud service still carries its own separate CMMC obligations.
Prime contractors are on the hook for verifying subcontractor compliance before any CUI flows downstream — verification duty doesn't transfer away.
CMMC Certification Timeline, Process & the 2026 Update
Getting certified follows a predictable sequence:
- Run a gap analysis and self-score against NIST SP 800-171 in SPRS
- Remediate identified gaps: policies, tooling, documented evidence
- Undergo C3PAO assessment if your contract requires third-party certification
- Receive DoW approval and marketplace listing confirming your status
The Original Four-Phase Rollout
| Phase | Date | Scope |
|---|---|---|
| Phase 1 | Nov 2025 | Level 1/2 self-assessments begin |
| Phase 2 | Nov 2026 | Level 2 C3PAO certification requirements begin |
| Phase 3 | Nov 2027 | Extension to existing contracts, Level 3 introduced |
| Phase 4 | Nov 2028 | Full applicability across all applicable contracts |
The July 2026 Suspension
Here's the development every contractor needs on their radar. On July 13, 2026, the Department of War officially suspended the transition to Phase II, pausing the planned rollout of broader C3PAO third-party audit requirements.
A CMMC Reform Task Force is now conducting a top-to-bottom program review, with a report due to the DoW CIO within 60 days.
What's still fully in force:
- Phase I self-assessment obligations
- DFARS 252.204-7012 compliance duties
- NIST SP 800-171 requirements through self-assessment and select government-led reviews
What this pause actually means for you: heavier reliance on self-attestation raises your False Claims Act exposure. Fewer third-party checks means the government leans harder on the honesty and accuracy of what you attest.
That makes documentation discipline more important during this review window, not less, since sloppy evidence now becomes a liability later, regardless of when Phase II eventually resumes. Tools built specifically for this, like QMS Learning's AI Workbench, generate the auditor-ready documentation and evidence trail that keeps self-attestation defensible.
Practical next step: monitor the DoW CMMC website, Federal Register notices, and the pending Reform Task Force report closely. Nobody knows the restart date yet.

Cost of CMMC Compliance
Budgeting for CMMC means separating three distinct cost buckets: certification fees, remediation, and ongoing maintenance.
Assessment and Certification Fees
The federal cost model (2023 dollars) puts assessment-plus-affirmation costs at:
| Level & Assessment Type | Small Entity | Other-Than-Small |
|---|---|---|
| Level 1 self-assessment | $4,042 | $4,042 |
| Level 2 self-assessment | $34,227 | $48,827 |
| Level 2 C3PAO certification | $104,670 | $117,901 |
| Level 3 DIBCAC assessment | $10,298 | $41,110 |
These are modeled figures, not fixed fee schedules; actual C3PAO market pricing varies with network complexity and current security posture.
Remediation Costs
This is where budgets often blow past expectations. NDIA's 2025 Vital Signs survey found 49% of respondents spent more than $100,000 on nonrecurring NIST SP 800-171 implementation, with 28% exceeding $500,000 and 16% topping $1 million. Expect spending on:
- MFA, endpoint protection, and continuous monitoring tools
- Policy and SSP documentation development
- Staff training hours pulled from other work
Structured, role-specific training, such as QMS Learning's compliance pathways, can convert that staff-training line item into a predictable annual cost rather than an open-ended drain on senior staff time.
Ongoing Costs
Compliance doesn't end at certification. Budget for annual affirmations, continuous monitoring, and reassessment every three years. Organizations that treat compliance as a continuous discipline, rather than a fire drill every 36 months, consistently spend less at reassessment time and lose fewer sleepless nights.
Building Audit-Ready CMMC Compliance Capability
Passing your first CMMC assessment feels like the finish line. It isn't. Plenty of contractors certify once, then watch their evidence discipline decay within a year — and get caught flat-footed at reassessment.
The repeat findings almost always trace back to the same gaps:
- Undocumented policies that exist only in someone's head
- Inconsistently applied controls: great on paper, patchy in practice
- Teams that freeze when an assessor flags something unexpected
A Practical Readiness Checklist
- Map every FCI/CUI data flow through your systems, since you can't protect what you haven't identified
- Assign named control owners for each requirement, not a vague "IT handles it"
- **Build a centralized evidence repository** so documentation isn't scattered across inboxes
- Rehearse your self-assessment and SPRS scoring process well before a real deadline forces it
QMS Learning is building its Defense Cybersecurity Readiness pathway, opening for pilot cohorts in Q3 2026, specifically to close this gap. Rather than a one-time cram session, it trains teams on all 14 NIST SP 800-171 control families, System Security Plan development, and POA&M management.
The pathway pairs that training with an AI Workbench trained on CMMC assessment guides and DFARS flow-down requirements. The goal is a team that understands why each control exists, not simply a certificate on the wall.
That distinction matters more than it sounds. Teams that grasp the reasoning behind controls can respond when an assessor asks an unexpected question or a supplier relationship changes overnight. Teams trained only on templates freeze, and usually end up calling a consultant to bail them out.

Frequently Asked Questions
What is CMMC certification?
CMMC is the Department of War's mandatory, tiered cybersecurity certification framework verifying that contractors protect FCI and CUI. It has three levels, each requiring progressively stronger safeguards and verification.
How do I get CMMC certified?
Run a gap analysis and self-score in SPRS, remediate identified gaps, complete a self-assessment or C3PAO assessment depending on your contract, then receive DoW approval and marketplace listing.
How hard is it to get CMMC certified?
Difficulty scales sharply with level: Level 1's 15 controls are straightforward, but Level 2's 110 requirements and documentation burden trip up most organizations, and Level 3 demands mature security operations most companies don't have in-house.
How much does CMMC certification cost?
Costs vary by level and company size. Federal modeling puts Level 2 C3PAO certification above $100,000, before counting remediation tooling, staff time, and ongoing monitoring costs.
Does CMMC apply to subcontractors and vendors?
Yes. Requirements flow down through the entire supply chain to any subcontractor, supplier, or cloud/SaaS provider handling FCI or CUI, regardless of whether they contract directly with the Department. Contracts limited to commercial off-the-shelf (COTS) items are exempt.
What happened to CMMC Phase II in 2026?
The Department of War suspended Phase II C3PAO third-party assessment requirements on July 13, 2026, pending a Reform Task Force review. Phase I self-assessment obligations and DFARS 252.204-7012/NIST SP 800-171 compliance remain fully in effect.


