CMMC Assessment Checklist
Download our CMMC assessment checklist!
Quick Answer: CMMC Level 2 requires defense contractors to implement 110 security controls from NIST SP 800-171 across 14 control families, verified by a Certified Third-Party Assessment Organization (C3PAO). While Phase II third-party assessment requirements were suspended on July 13, 2026, Phase I self-assessments remain mandatory, and preparation for eventual certification remains critical for contract eligibility.
If your organization works with the U.S. Department of Defense, CMMC Level 2 compliance is no longer a future concern—it's an operational reality. Since November 2025, CMMC requirements have been embedded in defense contracts, reshaping how contractors validate their cybersecurity posture. And despite a significant policy shift in July 2026, the framework's core requirements haven't gone anywhere.
This post breaks down exactly what CMMC Level 2 entails, how the certification process works, and what the recent Phase II suspension means for your organization.
The Cybersecurity Maturity Model Certification (CMMC) is a DoD framework designed to verify that defense contractors are actually protecting sensitive government information—not just claiming to. Before CMMC, contractors self-attested compliance with NIST SP 800-171, which created a well-documented problem: many overstated their compliance while cyber incidents among defense suppliers continued to rise.
CMMC Level 2 sits at the middle tier of the three-level framework. It targets contractors who handle Controlled Unclassified Information (CUI)—data that, while not classified, is sensitive enough to require rigorous protection. The DoD estimates that approximately 80,000 companies in the Defense Industrial Base (DIB) will need CMMC Level 2 certification through a third-party assessor.
CMMC Level 2 requires full implementation of 110 security practices drawn directly from NIST SP 800-171 Revision 2. These practices are distributed across 14 control families, each governing a distinct aspect of cybersecurity:
To pass a CMMC Level 2 assessment, contractors must also demonstrate compliance with 320 assessment objectives as defined in NIST SP 800-171A. Assessors evaluate each objective through three methods: examining documentation, interviewing personnel, and testing controls under real conditions.
The scoring system uses a point-based methodology with a maximum of 110 points. Individual security requirements carry weights of 1, 3, or 5 points depending on their criticality. Organizations must achieve a minimum score of 88 out of 110 (80%) to receive a Conditional CMMC Level 2 certification. Any unmet requirements must be documented in a Plan of Action and Milestones (POA&M) and fully remediated within 180 days.
CMMC Level 2 certification applies to any contractor that stores, processes, or transmits CUI on unclassified information systems. This includes both prime contractors and subcontractors—CMMC requirements flow down through the supply chain via DFARS clause 252.204-7021. Awarding work to a subcontractor that lacks proper certification can place an entire prime contract at risk.
Most CMMC Level 2 contracts require third-party verification by a C3PAO. A limited number of non-prioritized acquisitions may permit self-assessment under specific conditions, but C3PAO certification is the default requirement for contracts involving CUI critical to national security.
C3PAO assessments follow four structured phases: pre-assessment, conformity assessment, reporting, and certificate issuance. The process typically takes 6 to 12 months from initial gap analysis to certification.
Here is what the path to certification looks like in practice:
On July 13, 2026, the Department of War announced the immediate pause of CMMC Phase II requirements, which had been scheduled to take effect on November 10, 2026. Phase II would have introduced mandatory C3PAO assessments across all contracts involving CUI.
DoW CIO Kirsten Davies, July 13 memo launched a 60-day CMMC Reform Task Force to recommend a restructured framework focused on speed to capability and reduced regulatory burden.
Critically, Phase I self-assessment requirements remain firmly in place. Contractors in applicable solicitations must still complete and submit CMMC Level 1 and Level 2 self-assessments.
Yes. Here is why.
Phase I self-assessments are still required today. The underlying NIST SP 800-171 controls that define CMMC Level 2 have not changed. And while the Phase II timeline is under review, the DoD's direction—moving from self-attestation toward verified cybersecurity standards—has not reversed.
Fewer than 100 authorized C3PAOs currently serve the roughly 80,000 organizations expected to need CMMC Level 2 certification. Assessment slots are limited and booking timelines are long. Organizations that begin preparation now will be better positioned when the revised framework emerges and third-party assessments resume.
Prime contractors are already screening for CMMC-ready suppliers. According to the Cyber AB, more than 1,000 organizations have achieved CMMC Level 2 certification—a small fraction of the 80,000 expected to need it. Early certification signals reliability and reduces supply chain risk for primes, making certified contractors preferred partners for new awards.
The CMMC program is evolving, but its fundamental purpose—ensuring defense contractors protect sensitive government data through verified, auditable controls—remains unchanged. Organizations that treat the Phase II suspension as a reason to pause preparation are misreading the regulatory direction.
Start with a formal gap assessment against the 110 NIST SP 800-171 controls. Define your CUI boundaries accurately. Secure executive alignment on budget and timeline. And engage with a C3PAO early, before scheduling constraints narrow your options further.
CMMC Level 2 compliance is not a simple checkbox—it reflects a genuine shift in how the DoD manages cybersecurity risk across its supply chain. Contractors who build that foundation now will be positioned to compete as the program evolves, not scramble to catch up.
Prepare your organization for CMMC Level 2 compliance today—request a quote or contact us to discuss how we can support your cybersecurity needs and ensure you're ready to meet DoD requirements.
CMMC Level 2 certification verifies that a defense contractor has fully implemented the 110 security controls from NIST SP 800-171 Revision 2, across 14 control families, to protect Controlled Unclassified Information. Certification is awarded by an accredited C3PAO and remains valid for three years.
Phase I self-assessments remain mandatory. The suspension applies specifically to Phase II, which would have required mandatory C3PAO assessments starting November 10, 2026. Phase II requirements are under review; DoD has not eliminated the third-party assessment requirement—it has paused its rollout.
The process typically takes 6 to 12 months, depending on an organization's existing cybersecurity maturity. Organizations with little to no existing cybersecurity program should plan for the longer end of that range.
Organizations must achieve a minimum score of 88 out of 110 points to receive Conditional CMMC Level 2 certification. Unmet requirements must be documented in a POA&M and remediated within 180 days to achieve full certification.
Prime contractors must flow CMMC Level 2 requirements down to all subcontractors that store, process, or transmit FCI or CUI. This is mandated through DFARS clause 252.204-7021. Primes can face contract termination risk if subcontractors do not meet the required certification level.