CMMC 2.0: What Changed & Your Certification Timeline

06/05/2026
Compliance
CMMC 2.0: What Changed & Your Certification Timeline

Here's the short version. The Cybersecurity Maturity Model Certification program is no longer a proposal you can watch from the sidelines. The contract rule that puts CMMC into Department of Defense awards took effect on November 10, 2025, self-assessment requirements are already showing up in solicitations, and mandatory third-party certification for many contracts that touch Controlled Unclassified Information arrives on November 10, 2026. If you build for the defense supply chain and you haven't started, the clock you're racing is shorter than the calendar suggests. A serious compliance readiness program is measured in quarters, not weeks.

This guide does two things. It explains what actually changed when CMMC moved from version 1.0 to 2.0, and it walks the real certification timeline backward from the deadline so you can tell whether you're early, on pace, or already behind.

Where CMMC 2.0 stands in 2026

CMMC has two rules behind it, and people confuse them constantly. The first, the 32 CFR rule, established the program itself. It cleared its congressional review and took effect on December 16, 2024, according to the DoD's CMMC resource hub. That rule defined the levels and the assessment process, but it didn't yet force CMMC into your contracts.

The second rule did. The DFARS acquisition rule was published in the Federal Register on September 10, 2025 and became effective November 10, 2025. That's the one that matters to your bid team. It introduced two contract clauses: DFARS 252.204-7021, used in awarded contracts, and DFARS 252.204-7025, used in solicitations. When a contracting officer drops one of those clauses into an opportunity, you can't win the award without the required CMMC status on file. No certification, no contract. It's that blunt.

So the answer to "is this real yet" is yes. It's been live since late 2025, and the scope only widens from here.

What actually changed from CMMC 1.0 to 2.0

What actually changed from CMMC 1.0 to 2.0

Version 1.0 was heavier, slower, and more expensive to satisfy. Version 2.0 trimmed it down. Three changes carry most of the weight.

Five levels became three

The original model had five maturity levels. CMMC 2.0 collapsed that to three, and it did so by removing the two transitional levels and re-mapping the rest to the type of data you handle, as Kiteworks lays out in its 1.0-versus-2.0 breakdown. Level 1 stayed roughly where it was. The old Level 3 became the new Level 2. The new Level 3 sits at the top for the most sensitive work. Cleaner, and easier to map to a real contract.

Self-assessment came back, and so did limited POA&Ms

Under 1.0, a third party had to assess nearly everything, and a Plan of Action and Milestones wasn't allowed. You either met a practice or you failed. CMMC 2.0 reintroduced self-assessment for the lowest-risk work and allowed a narrow, time-bound use of POA&Ms for the rest. The catch is real, though. POA&Ms must be closed within 180 days, and roughly 40 percent of the 110 Level 2 controls are weighted so heavily that they can't sit on a POA&M at all. You have to actually implement them before you pass.

The model now points straight at NIST

CMMC 2.0 dropped the extra maturity processes that 1.0 layered on top and aligned its requirements directly to existing NIST publications. Level 2 is NIST SP 800-171. Level 3 adds a subset of NIST SP 800-172. If you've been working a 800-171 program already, you're not starting from zero. You're formalizing and proving what you claim to have.

The three CMMC levels, and which one applies to you

Your level isn't a choice. It follows the kind of government information that lives in your environment. Federal Contract Information points you to Level 1. Controlled Unclassified Information almost always points you to Level 2. A small slice of programs guarding against advanced, persistent threats reach Level 3.

The three CMMC levels

The three levels map cleanly to the data you hold:

  • Level 1 (Foundational): Protects FCI. 15 safeguards from FAR 52.204-21, verified by an annual self-assessment.
  • Level 2 (Advanced): Protects CUI. All 110 controls in NIST SP 800-171, verified by a self or C3PAO assessment every three years, depending on the contract.
  • Level 3 (Expert): Protects CUI on high-priority programs. The 800-171 baseline plus 24 controls from NIST SP 800-172, verified by a government-led (DIBCAC) assessment every three years.

Level 1: Foundational

Level 1 covers the 15 basic safeguards in FAR 52.204-21 and applies to companies handling Federal Contract Information. You assess yourself, you affirm it, and you do it annually. Most firms can reach it with disciplined IT hygiene.

Level 2: Advanced

This is where most defense manufacturers land. Level 2 means all 110 requirements in NIST SP 800-171, the framework built to protect CUI, per the DoD CIO's model overview. Some Level 2 contracts allow a self-assessment. Many will require an independent assessment by a Certified Third-Party Assessment Organization, a C3PAO, with results filed in the Supplier Performance Risk System every three years. If your shop floor touches CUI, plan for the third-party path and treat the self-assessment as the exception. Our manufacturing cybersecurity solutions are built around exactly this population.

Level 3: Expert

Level 3 adds 24 selected controls from NIST SP 800-172 on top of the full 800-171 baseline, aimed at advanced persistent threats. There's no self-assessment option here. The government's own Defense Industrial Base Cybersecurity Assessment Center, DIBCAC, runs the assessment, and you affirm continuously. Few of our clients need it. The ones who do already know.

The phased rollout timeline that binds you

DoD isn't flipping a single switch. CMMC phases in over four years, and each phase widens the requirement. The phase schedule from Secureframe matches what the legal analysts at Arnold & Porter published on the final rule.

The phased rollout timeline

The rollout runs in four annual phases:

  • Phase 1, November 10, 2025: Level 1 and Level 2 self-assessments start appearing in new contracts.
  • Phase 2, November 10, 2026: C3PAO Level 2 certification becomes a condition of award for applicable CUI contracts.
  • Phase 3, November 10, 2027: Level 3 (DIBCAC) requirements phase in, and certification extends to contract option years.
  • Phase 4, November 10, 2028: Full implementation across all applicable DoD contracts and renewals.

Phase 1 is already here

Since November 2025, contracting officers have been allowed to require Level 1 and Level 2 self-assessments, with the score reported in SPRS. If you bid federal work, you may have already met one of these clauses. Phase 1 is the warm-up.

Phase 2 is the one circled on the calendar

On November 10, 2026, third-party Level 2 certification becomes mandatory for the contracts that require it. For a discrete manufacturer handling CUI, that's the deadline that decides whether you can keep bidding the same work you bid today. As of this writing in mid-2026, that's roughly five months out. Read the timeline below before you decide you have time.

Your real certification timeline

Your real certification timeline, working backward from the deadline

This is the part the compliance brochures gloss over. Certification isn't a purchase. It's a project with a critical path, and the path is longer than most leadership teams assume. Here's what the work actually looks like.

The phases of the work

A Level 2 effort moves through four stages, and they don't fully overlap:

  • Gap assessment. You inventory where CUI lives, map your environment, and score yourself against all 110 controls. Budget 2 to 8 weeks, depending on how many sites and systems are in scope. Start with a real cybersecurity assessment rather than a guess.
  • Documentation. Writing the System Security Plan and the POA&M takes another 4 to 8 weeks, and assessors want implementation narratives, not policy boilerplate. This is where thin documentation gets exposed.
  • Remediation. Closing the gaps is the long pole. For a shop with meaningful findings, this runs months, not weeks, and it often involves new tooling, network changes, and habit changes across the team.
  • Assessment. The C3PAO engagement itself is a focused crunch, but scheduling one is its own problem. Lead times run 3 to 6 months, and Coalfire Federal reports C3PAO backlogs stretching well into 2026.

Add it up. A clean organization with a capable IT team and modest gaps can reach Level 2 in roughly 6 months. An organization with real gaps, limited internal IT, or a complex multi-site footprint should plan for 12 to 18 months, and some take 24. That's not padding. That's the honest range the assessment community quotes.

The backlog is why "start now" isn't a sales line

There are a finite number of authorized C3PAOs, and roughly 300,000 companies in the Defense Industrial Base are working toward this. The math is unforgiving. Even if your controls were perfect tomorrow, you'd still wait in line for an assessor. Every month you delay pushes you further back in a queue that is filling ahead of the Phase 2 deadline. The firms that wait for a contract to demand certification are the firms that lose the contract.

Budget honestly

Cost surprises end programs more often than technical problems do. The third-party assessment alone runs from about $35,000 to over $100,000 depending on scope. The assessment is the smaller line item, though. When you count preparation, remediation, and the technology you have to buy, PreVeil's cost analysis puts a first certification cycle in the range of $138,000 to $285,000 for many small and mid-size firms. Know that number before you commit, not after. A virtual CISO can right-size the scope so you're not paying to protect systems that never touch CUI.

What manufacturers and subcontractors should do this quarter

If you're a prime, your obligation doesn't stop at your own walls. You have to identify which subcontractors handle FCI or CUI and flow the correct CMMC level down to them, and you're on the hook for their compliance. A sub's required level follows the data it handles, not automatically the prime's level. A small machine shop that only receives CUI drawings still needs Level 2.

There's also an ongoing duty most teams forget. The rule requires an annual affirmation of continuous compliance, filed in SPRS by a named affirming official. That affirmation can't be more than a year old, and a lapse can put your award eligibility at risk even after you certify. Certification is a state you maintain, not a trophy you win once.

What to do this quarter

A practical order of operations for the next 90 days:

  1. Confirm your target level by mapping where FCI and CUI actually live in your business.
  2. Run a gap assessment against NIST SP 800-171 so you know the size of the real problem.
  3. Stand up the System Security Plan and a defensible POA&M for what you can't close immediately.
  4. Get on a C3PAO's calendar now, before the Phase 2 rush peaks.
  5. Name your affirming official and build the SPRS reporting habit into your operations.

For shops with a lean internal IT team, this is hard to carry alone while also running production. That's the gap our co-managed IT and manufacturing IT compliance services were built to fill, and you can see how the work plays out in our CMMC case studies from real aerospace and metal-finishing suppliers.

Don't Wait for a Contract to Force the Issue

CMMC 2.0 is simpler than 1.0, but simpler doesn't mean fast. The rule is live, the C3PAO line is forming, and the Phase 2 deadline doesn't move because your quarter got busy. If you build for the defense supply chain in California, the smart play is to scope your gap now and protect your eligibility while there's still runway. Let's find out exactly where you stand before an assessor does.

Frequently Asked Questions About CMMC 2.0

Is CMMC 2.0 in effect right now?
Yes. The program rule took effect in December 2024, and the contract rule that places CMMC clauses into DoD solicitations and awards became effective November 10, 2025. Self-assessment requirements are already appearing in contracts.
What is the difference between CMMC Level 1 and Level 2?
Level 1 protects Federal Contract Information with 15 basic safeguards and an annual self-assessment. Level 2 protects Controlled Unclassified Information with all 110 controls in NIST SP 800-171, and many contracts require a third-party C3PAO assessment every three years rather than a self-assessment.
Can I still use a self-assessment, or do I need a C3PAO?
It depends on the contract. Some Level 2 contracts allow a self-assessment, but most CUI work will require certification by an authorized C3PAO once Phase 2 begins on November 10, 2026. If you handle CUI, plan for the third-party path.
How long does CMMC Level 2 certification take?
Plan for 6 to 18 months from a serious start to a passed assessment. Organizations with modest gaps and strong IT can move faster. Those with significant gaps, limited internal IT, or multiple sites should expect the longer end, plus a three-to-six-month wait to schedule a C3PAO.
Do subcontractors need CMMC certification?
Yes, if they handle FCI or CUI. Primes must flow the appropriate CMMC level down to subcontractors at every tier. A subcontractor's required level follows the sensitivity of the information it handles, so a sub can need the same level as the prime, or a different one.
What happens if I'm not certified by the Phase 2 deadline?
You become ineligible for award on any contract whose clauses require the certification you don't have. In practice, that means losing access to the defense work you currently depend on until you certify.

Related Articles

Stay ahead with expert tips, industry trends, and actionable strategies.