CMMC 2.0: What Changed & Your Certification Timeline
Here's the short version. The Cybersecurity Maturity Model Certification program is no longer a proposal you can watch from the sidelines. The contract rule that puts CMMC into Department of Defense awards took effect on November 10, 2025, self-assessment requirements are already showing up in solicitations, and mandatory third-party certification for many contracts that touch Controlled Unclassified Information arrives on November 10, 2026. If you build for the defense supply chain and you haven't started, the clock you're racing is shorter than the calendar suggests. A serious compliance readiness program is measured in quarters, not weeks.
This guide does two things. It explains what actually changed when CMMC moved from version 1.0 to 2.0, and it walks the real certification timeline backward from the deadline so you can tell whether you're early, on pace, or already behind.
Where CMMC 2.0 stands in 2026
CMMC has two rules behind it, and people confuse them constantly. The first, the 32 CFR rule, established the program itself. It cleared its congressional review and took effect on December 16, 2024, according to the DoD's CMMC resource hub. That rule defined the levels and the assessment process, but it didn't yet force CMMC into your contracts.
The second rule did. The DFARS acquisition rule was published in the Federal Register on September 10, 2025 and became effective November 10, 2025. That's the one that matters to your bid team. It introduced two contract clauses: DFARS 252.204-7021, used in awarded contracts, and DFARS 252.204-7025, used in solicitations. When a contracting officer drops one of those clauses into an opportunity, you can't win the award without the required CMMC status on file. No certification, no contract. It's that blunt.
So the answer to "is this real yet" is yes. It's been live since late 2025, and the scope only widens from here.

What actually changed from CMMC 1.0 to 2.0
Version 1.0 was heavier, slower, and more expensive to satisfy. Version 2.0 trimmed it down. Three changes carry most of the weight.
Five levels became three
The original model had five maturity levels. CMMC 2.0 collapsed that to three, and it did so by removing the two transitional levels and re-mapping the rest to the type of data you handle, as Kiteworks lays out in its 1.0-versus-2.0 breakdown. Level 1 stayed roughly where it was. The old Level 3 became the new Level 2. The new Level 3 sits at the top for the most sensitive work. Cleaner, and easier to map to a real contract.
Self-assessment came back, and so did limited POA&Ms
Under 1.0, a third party had to assess nearly everything, and a Plan of Action and Milestones wasn't allowed. You either met a practice or you failed. CMMC 2.0 reintroduced self-assessment for the lowest-risk work and allowed a narrow, time-bound use of POA&Ms for the rest. The catch is real, though. POA&Ms must be closed within 180 days, and roughly 40 percent of the 110 Level 2 controls are weighted so heavily that they can't sit on a POA&M at all. You have to actually implement them before you pass.
The model now points straight at NIST
CMMC 2.0 dropped the extra maturity processes that 1.0 layered on top and aligned its requirements directly to existing NIST publications. Level 2 is NIST SP 800-171. Level 3 adds a subset of NIST SP 800-172. If you've been working a 800-171 program already, you're not starting from zero. You're formalizing and proving what you claim to have.
The three CMMC levels, and which one applies to you
Your level isn't a choice. It follows the kind of government information that lives in your environment. Federal Contract Information points you to Level 1. Controlled Unclassified Information almost always points you to Level 2. A small slice of programs guarding against advanced, persistent threats reach Level 3.

The three levels map cleanly to the data you hold:
- Level 1 (Foundational): Protects FCI. 15 safeguards from FAR 52.204-21, verified by an annual self-assessment.
- Level 2 (Advanced): Protects CUI. All 110 controls in NIST SP 800-171, verified by a self or C3PAO assessment every three years, depending on the contract.
- Level 3 (Expert): Protects CUI on high-priority programs. The 800-171 baseline plus 24 controls from NIST SP 800-172, verified by a government-led (DIBCAC) assessment every three years.
Level 1: Foundational
Level 1 covers the 15 basic safeguards in FAR 52.204-21 and applies to companies handling Federal Contract Information. You assess yourself, you affirm it, and you do it annually. Most firms can reach it with disciplined IT hygiene.
Level 2: Advanced
This is where most defense manufacturers land. Level 2 means all 110 requirements in NIST SP 800-171, the framework built to protect CUI, per the DoD CIO's model overview. Some Level 2 contracts allow a self-assessment. Many will require an independent assessment by a Certified Third-Party Assessment Organization, a C3PAO, with results filed in the Supplier Performance Risk System every three years. If your shop floor touches CUI, plan for the third-party path and treat the self-assessment as the exception. Our manufacturing cybersecurity solutions are built around exactly this population.
Level 3: Expert
Level 3 adds 24 selected controls from NIST SP 800-172 on top of the full 800-171 baseline, aimed at advanced persistent threats. There's no self-assessment option here. The government's own Defense Industrial Base Cybersecurity Assessment Center, DIBCAC, runs the assessment, and you affirm continuously. Few of our clients need it. The ones who do already know.
The phased rollout timeline that binds you
DoD isn't flipping a single switch. CMMC phases in over four years, and each phase widens the requirement. The phase schedule from Secureframe matches what the legal analysts at Arnold & Porter published on the final rule.

The rollout runs in four annual phases:
- Phase 1, November 10, 2025: Level 1 and Level 2 self-assessments start appearing in new contracts.
- Phase 2, November 10, 2026: C3PAO Level 2 certification becomes a condition of award for applicable CUI contracts.
- Phase 3, November 10, 2027: Level 3 (DIBCAC) requirements phase in, and certification extends to contract option years.
- Phase 4, November 10, 2028: Full implementation across all applicable DoD contracts and renewals.
Phase 1 is already here
Since November 2025, contracting officers have been allowed to require Level 1 and Level 2 self-assessments, with the score reported in SPRS. If you bid federal work, you may have already met one of these clauses. Phase 1 is the warm-up.
Phase 2 is the one circled on the calendar
On November 10, 2026, third-party Level 2 certification becomes mandatory for the contracts that require it. For a discrete manufacturer handling CUI, that's the deadline that decides whether you can keep bidding the same work you bid today. As of this writing in mid-2026, that's roughly five months out. Read the timeline below before you decide you have time.

Your real certification timeline, working backward from the deadline
This is the part the compliance brochures gloss over. Certification isn't a purchase. It's a project with a critical path, and the path is longer than most leadership teams assume. Here's what the work actually looks like.
The phases of the work
A Level 2 effort moves through four stages, and they don't fully overlap:
- Gap assessment. You inventory where CUI lives, map your environment, and score yourself against all 110 controls. Budget 2 to 8 weeks, depending on how many sites and systems are in scope. Start with a real cybersecurity assessment rather than a guess.
- Documentation. Writing the System Security Plan and the POA&M takes another 4 to 8 weeks, and assessors want implementation narratives, not policy boilerplate. This is where thin documentation gets exposed.
- Remediation. Closing the gaps is the long pole. For a shop with meaningful findings, this runs months, not weeks, and it often involves new tooling, network changes, and habit changes across the team.
- Assessment. The C3PAO engagement itself is a focused crunch, but scheduling one is its own problem. Lead times run 3 to 6 months, and Coalfire Federal reports C3PAO backlogs stretching well into 2026.
Add it up. A clean organization with a capable IT team and modest gaps can reach Level 2 in roughly 6 months. An organization with real gaps, limited internal IT, or a complex multi-site footprint should plan for 12 to 18 months, and some take 24. That's not padding. That's the honest range the assessment community quotes.
The backlog is why "start now" isn't a sales line
There are a finite number of authorized C3PAOs, and roughly 300,000 companies in the Defense Industrial Base are working toward this. The math is unforgiving. Even if your controls were perfect tomorrow, you'd still wait in line for an assessor. Every month you delay pushes you further back in a queue that is filling ahead of the Phase 2 deadline. The firms that wait for a contract to demand certification are the firms that lose the contract.
Budget honestly
Cost surprises end programs more often than technical problems do. The third-party assessment alone runs from about $35,000 to over $100,000 depending on scope. The assessment is the smaller line item, though. When you count preparation, remediation, and the technology you have to buy, PreVeil's cost analysis puts a first certification cycle in the range of $138,000 to $285,000 for many small and mid-size firms. Know that number before you commit, not after. A virtual CISO can right-size the scope so you're not paying to protect systems that never touch CUI.
What manufacturers and subcontractors should do this quarter
If you're a prime, your obligation doesn't stop at your own walls. You have to identify which subcontractors handle FCI or CUI and flow the correct CMMC level down to them, and you're on the hook for their compliance. A sub's required level follows the data it handles, not automatically the prime's level. A small machine shop that only receives CUI drawings still needs Level 2.
There's also an ongoing duty most teams forget. The rule requires an annual affirmation of continuous compliance, filed in SPRS by a named affirming official. That affirmation can't be more than a year old, and a lapse can put your award eligibility at risk even after you certify. Certification is a state you maintain, not a trophy you win once.

A practical order of operations for the next 90 days:
- Confirm your target level by mapping where FCI and CUI actually live in your business.
- Run a gap assessment against NIST SP 800-171 so you know the size of the real problem.
- Stand up the System Security Plan and a defensible POA&M for what you can't close immediately.
- Get on a C3PAO's calendar now, before the Phase 2 rush peaks.
- Name your affirming official and build the SPRS reporting habit into your operations.
For shops with a lean internal IT team, this is hard to carry alone while also running production. That's the gap our co-managed IT and manufacturing IT compliance services were built to fill, and you can see how the work plays out in our CMMC case studies from real aerospace and metal-finishing suppliers.