Almost every firm that asks "which CMMC level do we need" has already framed the question wrong. The level is not selected, negotiated, or scaled to headcount. It is determined by what kind of government information will sit on the company's systems, and the contracting officer reads it off the requirement before the solicitation is ever posted. A four-person shop handling controlled unclassified information carries the same one hundred and ten security requirements as a defense prime. A two-hundred-person firm that only ever touches federal contract information carries fifteen.
Everything below comes from the program rule at 32 CFR part 170, the DFARS acquisition rule, the clause text on acquisition.gov, and public statements by Department of Defense officials and the CMMC accreditation body. It is checkable by anyone willing to read the same documents.
Phase 2 is paused. Phase 1 is not.
On July 13, 2026 the Department of Defense halted the CMMC Phase 2 requirements that were scheduled to take effect on November 10, 2026 — the ones that would have required third-party Level 2 certification as a condition of award. Phase 1 self-assessment requirements, in force since November 10, 2025, continue. NIST SP 800-171 Revision 2 continues to be enforced through self-assessment and selected government-led assessments. A CMMC Reform Task Force is running a 60-day review. Nothing about this is settled, and the sections below flag where the ground is still moving.
What actually happened in July 2026
The announcement came from Department of Defense Chief Information Officer Kirsten Davies and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey. The stated reason was capacity and cost, not doctrine. Davies pointed to a mismatch between more than 100,000 companies in the defense industrial base that would need third-party assessments and roughly 100 approved assessor organizations able to perform them, and estimated that moving into the later phases could cost small and medium businesses on the order of $7 billion a year to reach compliance. Her summary line was blunt: the math simply does not work for small and medium firms to get compliant by the transition date.
A CMMC Reform Task Force stood up immediately and held its first meeting within days. Davies described it as drawing representatives from acquisition and sustainment, intelligence and security, the CIO's office, general counsel, public affairs, legislative affairs, the Small Business Administration, and the White House, and said the review would run 60 days with roughly another two weeks to synthesize findings before anything is reported publicly. She declined to name the members. She also said the outcome could range from small tweaks to an overhaul, and cautioned against changing things for the sake of changing them.
None of that surprised anyone tracking the program. In March 2026 the Government Accountability Office published GAO-26-107955, finding that the Department had produced substantial CMMC planning documentation but had not systematically identified the external factors, outside its own control, that could keep the program from reaching its goals. Assessor ecosystem capacity was one. Compliance costs pushing small businesses out of defense contracting was another. So was the program's reliance on a superseded revision of the underlying NIST standard.
The accreditation body's response two days later drew the line that matters for planning. Only the Phase 2 implementation requirements were suspended; every operating element of the program remained available, including C3PAO certification assessments, sanctioned training, and the professional exams. Its chief executive called a Level 2 certification a compelling calling card for subcontract viability with primes and the best available insurance against False Claims Act exposure. That is a vendor-side view. It is also a fair description of how primes behave.
FCI and CUI: the two terms that set the level
Federal contract information is the trigger for Level 1. It is defined in FAR 52.204-21 as information not intended for public release, provided by or generated for the Government under a contract to develop or deliver a product or service, and it excludes routine transactional information such as what appears on a purchase order. In practice, almost any contract that is not purely a catalog purchase produces FCI. Statements of work, delivery schedules, internal correspondence about performance, draft deliverables — all of it qualifies.
Controlled unclassified information is the trigger for Level 2. It is government-created or government-possessed information that law, regulation, or government-wide policy requires be safeguarded, and it arrives with markings. When CUI lands on a contractor system, the applicable safeguarding standard is NIST SP 800-171, and the contract clause that has required it since long before CMMC existed is DFARS 252.204-7012.
That last point is the one most often missed. CMMC did not create the obligation to implement NIST SP 800-171. DFARS 252.204-7012 has required it on covered contractor information systems since 2017, and it carries obligations CMMC does not: reporting cyber incidents to the Department within 72 hours of discovery, preserving affected system images for at least 90 days after a report, media submission on request, and a requirement that any external cloud service used for covered defense information meet security requirements equivalent to the FedRAMP Moderate baseline. That clause flows down without alteration. CMMC is a verification mechanism bolted onto an obligation that already existed.

Level 1, in full
CMMC Level 1 is fifteen security requirements, drawn directly from 48 CFR 52.204-21(b)(1)(i) through (xv). They are the basic safeguarding controls: limit system access to authorized users, control who can execute what, sanitize or destroy media before disposal, escort visitors, monitor at the boundary, use current antivirus, apply updates. Nothing in the list is exotic. Most firms that already run managed endpoints and a modern identity provider have implemented the substance without calling it anything.
The assessment is performed by the organization itself, annually. Scoring is binary. Every one of the fifteen must be MET; the assessment is scored MET or NOT MET in its entirety. There is no partial credit and, critically, no plan of action and milestones is permitted at Level 1. You cannot pass with an open remediation item. The result and an affirmation go into the Supplier Performance Risk System, with the CMMC level, status date, assessment scope, and the associated CAGE codes.
Scope at Level 1 is narrow by construction. It covers the systems that process, store, or transmit FCI, plus the people, technology, facilities, and external service providers around them. Systems that do not touch FCI fall outside. Specialized assets — internet-of-things devices, operational technology, government-furnished equipment, restricted systems, test equipment — are excluded outright.
Level 2, in full
CMMC Level 2 is the entirety of NIST SP 800-171 Revision 2: one hundred and ten security requirements across fourteen families. The rule says the requirements are identical, so there is no CMMC-specific control set to learn. The work is 800-171 implementation, documented in a system security plan and evidenced well enough that someone else can verify it.
Level 2 comes in two statuses. Level 2 (Self) is assessed by the organization itself. Level 2 (C3PAO) is assessed by an authorized or accredited third-party assessor organization. Both are valid for three years and both require an affirmation at assessment and annually after. The security requirements are the same. What differs is who signs off, and what the certificate is worth to a prime.
| Level 1 (Self) | Level 2 (Self) | Level 2 (C3PAO) | |
|---|---|---|---|
| Triggered by | Federal contract information | Controlled unclassified information | Controlled unclassified information, where the requirement specifies certification |
| Requirements | 15, from FAR 52.204-21 | 110, from NIST SP 800-171 R2 | 110, from NIST SP 800-171 R2 |
| Who assesses | You | You | An authorized or accredited C3PAO |
| Scoring | MET / NOT MET, all fifteen | Points out of 110 | Points out of 110 |
| POA&M allowed | No | Yes, at 88 or above, closed within 180 days | Yes, at 88 or above, closed within 180 days |
| Valid for | 1 year | 3 years | 3 years |
| Affirmation | Annual, in SPRS | At assessment and annually, in SPRS | At assessment and annually, in SPRS |
The score is arithmetic, and 88 is the number
Level 2 scoring is not a judgement call. The assessment starts at the total number of requirements — 110 — and subtracts points for each one not implemented. The weighting is set in the rule and is worth understanding before any remediation money is spent, because it is heavily unequal.
| Weight | How many requirements | Why they carry that weight |
|---|---|---|
| 5 points | 42 (23 basic, 19 derived) | Non-implementation could allow significant exploitation of the network or exfiltration of CUI. |
| 3 points | 14 (7 basic, 7 derived) | Effect on security is specific and confined rather than systemic. |
| 1 point | The remaining 54 derived requirements | Limited or indirect effect on the security of the system and its data. |
| Partial credit | 2 requirements | Multifactor authentication (IA.L2-3.5.3) loses 3 points if implemented only for remote and privileged users, 5 if not implemented at all. FIPS-validated encryption (SC.L2-3.13.11) loses 3 points if encryption is used but not FIPS-validated, 5 if not used. |
Forty-two requirements carry five points each. That is 210 of the roughly 306 points a firm can shed. The five-point items are where the score lives, and a readiness program that works alphabetically through the control families instead of by weight will spend the same money for a worse number.
A score of 88 or higher out of 110 permits a Conditional CMMC status with a plan of action and milestones attached. Eighty-eight is exactly eighty percent of 110, and the rule expresses it that way. The POA&M must be closed out within 180 days of the conditional status date; if it is not, the conditional status expires. The acquisition rule mirrors this — an award can be made against a conditional status, and that status is good for a maximum of 180 days.
Six requirements can never sit on a POA&M at any score. External connections and control of publicly posted information (AC.L2-3.1.20 and AC.L2-3.1.22), the system security plan itself (CA.L2-3.12.4), and the three physical-access requirements covering visitor escorting, physical access logs, and management of physical access (PE.L2-3.10.3, 3.10.4, and 3.10.5). If any of those six is not implemented, there is no conditional path. That list is short enough to check in an afternoon and expensive enough to be worth checking first.
Where the phase-in stood when it stopped
The program rule at 32 CFR part 170 became effective December 16, 2024. The acquisition rule that puts the clauses into contracts became effective November 10, 2025. Phase 1 began on the later of the two, so November 10, 2025 is the real start date, and each subsequent phase was set to begin one calendar year after the one before it.
The four-phase schedule and where it stalled
Read that sequence and the shape of the pause becomes clear. Phase 1 already permits the Department to require a C3PAO certification in place of a self-assessment where a requiring activity decides it is warranted. The suspension removed the automatic, date-driven trigger; it did not remove the ability to ask. A firm that reads "Phase 2 is paused" as "certification is off the table" is reading it wrong.
Scope is the lever that sets the bill
What Level 2 costs a small firm is decided less by the control set than by how much of the company sits inside the assessment boundary. The rule's asset categories are the actual budget instrument.
CUI Assets. Systems that process, store, or transmit CUI. Assessed against all Level 2 requirements. Every machine in this category is a machine you pay to secure and evidence.
Security Protection Assets. Systems that provide security functions to the environment — identity providers, logging platforms, endpoint management. Assessed against the requirements relevant to what they do.
Contractor Risk Managed Assets. Systems not intended to handle CUI because policy and procedure keep it off them. These are documented rather than fully assessed, and only get examined if the system security plan raises a question. This is where a well-drawn boundary earns its money.
Specialized Assets. Equipment that cannot be fully secured — operational technology, test equipment, government-furnished gear, restricted systems. Documented and risk-managed, not assessed against the full set.
Out-of-Scope Assets. Systems that cannot process CUI and provide no security protection. Not assessed at all.
The consequence is that an enclave — a deliberately small, well-instrumented environment where all CUI work happens, reached through controlled interfaces — converts most of a company from CUI Assets into out-of-scope or risk-managed assets. Firms that skip the scoping exercise and assess their whole corporate network pay for a far larger assessment than the contract requires. That decision is made once, early, and is expensive to reverse.
The clauses that bind, and the affirmation that carries the risk
Four DFARS clauses do the work, and they are worth knowing by number because they appear in solicitations without explanation.
252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. The original obligation: implement NIST SP 800-171, report incidents within 72 hours, preserve images 90 days, use cloud services meeting FedRAMP Moderate equivalency. Flows down without alteration.
252.204-7019 and 252.204-7020, the NIST SP 800-171 assessment notice and requirement. These put a summary-level self-assessment score into SPRS and give the Department the right to conduct its own assessments.
252.204-7021, Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements. Requires current CMMC status in SPRS before award, before an option is exercised, and before a period of performance is extended; requires the status to be maintained for the life of the contract; requires an affirming official to complete an annual affirmation of continuous compliance; and requires CMMC unique identifiers for each information system that handles FCI or CUI. It flows down to subcontractors at all tiers that will process, store, or transmit FCI or CUI, and those subcontractors enter their own results and affirmations in SPRS.
252.204-7025, Notice of CMMC Level Requirements. The solicitation provision. It tells offerors what level the contract will require and obliges them to have that status in SPRS before they are eligible for award.
The annual affirmation is the clause with teeth. A named official attests in a government system that the organization continues to meet the requirements. An assessment that was accurate the day it was signed and has quietly drifted since is the fact pattern that produces False Claims Act exposure. The pause on Phase 2 did nothing to reduce that. A firm holding a Level 2 self-assessment score it has not revisited since Phase 1 began is carrying more risk now than it was a year ago, not less.
What the pause did not suspend
- DFARS 252.204-7012. The safeguarding and 72-hour incident reporting clause is untouched and predates CMMC by years.
- NIST SP 800-171 Revision 2. The Department said it will keep enforcing it through self-assessment and selected government-led assessments during the review.
- Phase 1 award conditions. Level 1 (Self) and Level 2 (Self) statuses in SPRS are still conditions of award on applicable contracts.
- The annual affirmation. Named-official attestation in SPRS continues, with the same legal weight it always had.
- Subcontract flowdown. 252.204-7021 flows to all tiers handling FCI or CUI, and primes set their own terms regardless of the Department's calendar.
- The C3PAO ecosystem. Certification assessments, training, and exams all remain available; the accreditation body confirmed this two days after the announcement.
- Requiring-activity discretion. Phase 1 already lets the Department call for a Level 2 (C3PAO) status on a specific requirement.
How to decide, given that the ground is moving
Three questions settle it for most firms, in this order.
Will CUI touch our systems under this contract? If no — and it genuinely is no for a large share of software and services work — Level 1 is the ceiling. Fifteen requirements, an annual self-assessment, an affirmation. Do it properly, document it, move on. If yes, or if the requirement is ambiguous, ask the contracting officer in writing before award rather than after.
Can we get to 88 and hold it? A self-assessment against the 110, scored honestly with the five-point items first, tells a firm in a couple of weeks whether Level 2 is a quarter of work or a year of it. Score the six never-POA&M requirements before anything else; if any fails, that is the first project regardless of the total.
Do our primes care about the certificate? This is a commercial question, not a regulatory one, and the pause put it in play. Primes sourcing work that runs into 2028 and beyond have to assume some verification regime survives the review. A subcontractor already holding a Level 2 (C3PAO) status is a lower-risk pick than one promising to get there. That advantage is real today and unaffected by the phase schedule.
The honest position on timing is that nobody outside the task force knows what the program looks like after the review. Changes could be small or structural. What will not change is the obligation to protect CUI on nonfederal systems, because that obligation lives in DFARS 252.204-7012 and NIST SP 800-171, not in the phase schedule. Work spent implementing the 110 is not at risk from the review. Only the paperwork wrapper around it is.
Where this shows up outside a defense contract
CMMC is a Department of Defense program, established in 32 CFR part 170 and implemented through DFARS clauses. It does not attach to civilian agency contracts or to state and local procurements. Three qualifications matter for a firm working across markets.
First, flowdown reaches firms that never sign a defense contract directly. A company subcontracting to a defense prime inherits 252.204-7021 at whatever tier it sits, as long as it handles FCI or CUI. The prime's compliance schedule becomes the sub's.
Second, a government-wide CUI rule for the Federal Acquisition Regulation was published as a proposed rule on January 15, 2025 and had not been issued in final form as of this writing. If it is finalized, CUI handling obligations extend well beyond the defense market. Check its status before assuming either way; this is a live docket, not settled law.
Third, state and local buyers impose their own safeguarding regimes, and a CMMC certificate satisfies none of them. IRS Publication 1075 governs federal tax information. The FBI CJIS Security Policy governs criminal justice data. HIPAA governs protected health information. GovRAMP, which operated as StateRAMP until its rebrand, is what a growing number of states require of hosted offerings. What transfers between all of these is the engineering, not the paperwork: access control, logging, encryption, media handling, and incident response built once to an 800-171 standard will carry most of the technical weight under any of them. The artifacts have to be rewritten each time. The controls do not.
Two loose threads worth watching
The program is pegged to a superseded NIST revision
CMMC Level 2 is defined against NIST SP 800-171 Revision 2, which NIST published in January 2021. Revision 3 was published in May 2024 and supersedes it. The program rule still points at Revision 2, and GAO flagged the gap in March 2026. Any future move to Revision 3 would be a substantive change to the control set, not a renumbering, and the reform review is the natural place for that decision to surface.
Conditional status is a 180-day clock, not a grace period
A conditional Level 2 status permits award with an open POA&M, but the closeout assessment has to happen within 180 days of the conditional status date. Miss it and the status expires, which puts the contract's award condition in question mid-performance. Firms treat conditional status as breathing room; the rule treats it as a deadline with a consequence attached.
COTS-only awards and the micro-purchase floor sit outside the requirement
The acquisition rule excludes awards solely for commercially available off-the-shelf items and does not reach acquisitions at or below the micro-purchase threshold. It does apply to acquisitions of commercial products and services under FAR part 12, which surprises vendors who assume commercial-item status is itself an exemption. It is not.
Bottom line
Level 1 and Level 2 are not tiers of ambition. They are two obligations attached to two kinds of information, and the contract tells you which applies. Level 1 is fifteen requirements, all of which must be met, assessed annually by you, with no room for an open item. Level 2 is one hundred and ten, where 88 buys 180 days and six specific requirements buy nothing at all. The July 2026 suspension moved the date on which third-party certification becomes automatic. It did not move the standard, the clause, the affirmation, or the exposure that comes with signing one. A firm that spends the review period implementing the 110 and drawing a tight boundary will be in a stronger position under whatever the task force recommends than one that spends it waiting to find out.
Frequently asked questions
Not automatically. Phase 2, which would have made Level 2 (C3PAO) a standard condition of award starting November 10, 2026, is suspended pending a reform review. Phase 1 remains in force, and Phase 1 already allows the Department to require a Level 2 (C3PAO) status on a specific requirement at its discretion. Certification assessments also remain available from accredited assessors, and many primes ask for them independent of the Department's schedule.
The assessment starts at 110 and subtracts 5, 3, or 1 point per unimplemented requirement. A score of 110 is a final status. A score of 88 or above — eighty percent — permits a conditional status with a plan of action and milestones that must be closed within 180 days. Six requirements can never appear on a POA&M: AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4 and PE.L2-3.10.5.
Yes. DFARS 252.204-7021 flows down to subcontractors at all tiers that will process, store, or transmit federal contract information or controlled unclassified information, and those subcontractors post their own results and affirmations in SPRS. Beyond the clause, primes set their own sourcing standards and frequently prefer a supplier that already holds a certification over one that intends to obtain it.
No. CMMC is established under 32 CFR part 170 and implemented through DFARS clauses on Department of Defense contracts. State and local safeguarding obligations run through other documents — IRS Publication 1075, the FBI CJIS Security Policy, HIPAA, and GovRAMP for hosted offerings. The technical controls overlap heavily with NIST SP 800-171, so the engineering carries over even though the certification does not.
