Complete Guide to CMMC 2.0 Compliance for Defense Contractors (2026)

06/08/2026
Compliance
Complete Guide to CMMC 2.0 Compliance for Defense Contractors (2026)

CMMC 2.0 is the DoD's mandatory cybersecurity certification framework for defense contractors. Three levels exist, 17 practices for Level 1, 110 for Level 2, 134 for Level 3. The Final Rule took effect December 16, 2024. Phase 2 mandatory C3PAO assessments start November 2026. If you handle CUI on a DoD contract, you need Level 2, and the prep timeline is longer than most contractors expect.

CMMC 2.0 compliance is the process by which defense contractors meet the Cybersecurity Maturity Model Certification requirements to remain eligible for DoD contracts. Three levels apply based on information sensitivity, Level 1 for Federal Contract Information, Level 2 for Controlled Unclassified Information, Level 3 for the highest-risk programs. Phase 2 enforcement requiring third-party C3PAO assessments begins November 10, 2026.

Fewer than 1% of affected defense contractors are fully prepared for CMMC audits, according to a Redspin survey cited by Defense Scoop. That number has actually dropped from 4% in 2025 and 8% in 2023. The program is getting harder to avoid, and preparation rates are moving in the wrong direction.

If your company is in the Defense Industrial Base and handles Controlled Unclassified Information, this isn't a future problem. The companion acquisition rule took effect November 10, 2025, meaning the DoD began inserting CMMC clauses into new solicitations that day. Phase 1 is already active. Phase 2 mandatory C3PAO assessments start November 2026. The timeline isn't theoretical anymore.

This guide explains what CMMC 2.0 actually requires, how the three certification levels work, what changed under the Final Rule, and what Southern California defense contractors and manufacturers need to do right now to protect contract eligibility.

See how Consilien's CMMC compliance services support Southern California defense contractors

What Is CMMC 2.0 and Why Did It Replace Self-Attestation?

CMMC 2.0 is a mandatory cybersecurity certification framework developed by the Department of Defense to verify that defense contractors have actually implemented the security controls they've been required to have since 2017.

That last part is the key. DFARS 252.204-7012, in effect since 2017, required contractors to implement NIST SP 800-171 and self-attest compliance. The self-attestation model had no verification mechanism. A 2019 DoD Inspector General report found contractors routinely claimed compliance without implementing required controls, and adversaries, particularly nation-state actors from China and Russia, exploited those gaps to steal sensitive data including weapons system specifications and submarine warfare technology.

CMMC fixes the verification problem. The framework doesn't introduce many new controls, the 110 requirements in Level 2 are largely the same NIST SP 800-171 requirements that existed before. What changed is who confirms implementation. Under the old model, a contractor checked boxes. Under CMMC Level 2, a Cyber AB-authorized C3PAO independently verifies every control through documentation review, personnel interviews, and live testing.

The key dates:

December 16, 2024: 32 CFR Part 170 (the CMMC Program Rule) took effect

November 10, 2025: DFARS 252.204-7021 took effect — DoD began inserting CMMC clauses into solicitations

November 10, 2026: Phase 2 begins — mandatory C3PAO assessments for Level 2 CUI contracts

November 10, 2027: Phase 3 — C3PAO requirements expand to additional contract types

What Are the Three CMMC Levels?

What Are the Three CMMC Levels?

CMMC 2.0 has three certification levels based on the type and sensitivity of information a contractor handles, not on company size. Small businesses face the same requirements as large primes if they handle the same information.

Level 1: Foundational

Applies to contractors handling Federal Contract Information only, with no CUI in scope. Requires implementation of 17 basic cybersecurity practices drawn from FAR 52.204-21. Verified through annual self-assessment submitted to the Supplier Performance Risk System. A senior company official must affirm the results each year.

Level 2: Advanced

Applies to contractors handling Controlled Unclassified Information on DoD contracts. Requires full implementation of all 110 security requirements in NIST SP 800-171 Revision 2, organized across 14 control families. For most CUI contracts, Level 2 requires formal third-party assessment by a Cyber AB-authorized C3PAO. Some non-prioritized programs may allow self-assessment — your contract language determines which path applies. Certification is valid for three years with annual affirmation.

Level 3: Expert

Reserved for contractors handling the most sensitive CUI on high-priority DoD programs. Requires all 110 NIST SP 800-171 controls plus 24 additional controls from NIST SP 800-172, totaling 134 requirements. Assessed by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) — a government body, not a C3PAO. As a prerequisite, organizations must hold a valid Level 2 certification before seeking Level 3.

Level | Who It Applies To | Controls | Assessment Method

  • Level 1 | FCI only, no CUI | 17 | Annual self-assessment
  • Level 2 | CUI on DoD contracts | 110 (NIST SP 800-171 Rev 2) | C3PAO third-party assessment
  • Level 3 | Highest-sensitivity CUI | 134 (NIST SP 800-172 + 171) | DIBCAC government assessment

How Does CMMC Scoring Work?

CMMC Level 2 uses the NIST SP 800-171 DoD Assessment Methodology for scoring. The maximum score is 110. Each unimplemented control reduces the score by a defined point value based on the control's weight in the methodology. Scores can go negative — the full range is -203 to +110.

Partial implementation counts the same as no implementation. A control deployed in one system but not documented, or documented but not enforced on all in-scope users, scores as a gap.

SPRS scores are visible to contracting officers. Prime contractors can also request SPRS verification from subcontractors. As Holland and Knight's January 2026 False Claims Act analysis makes clear, submitting an inaccurate SPRS score — whether inflated intentionally or the result of a sloppy self-assessment — creates serious legal exposure for the contractor and personal liability for the affirming official.

If gaps exist at assessment time, conditional certification is available. Open controls go into a Plan of Action and Milestones, and all POA&M items must be remediated and verified within 180 days or conditional certification expires. Certain controls cannot be on a POA&M at all — they must be fully implemented before the C3PAO arrives.

Who Needs CMMC Compliance?

Every company in the Defense Industrial Base supply chain that handles FCI or CUI. That's approximately 300,000 companies, according to the DoD CMMC Program Office — primes, subcontractors, and suppliers at every tier.

The flow-down obligation is where a lot of smaller suppliers get caught. Under 32 CFR § 170.23 and DFARS 252.204-7021, prime contractors are required to flow CMMC requirements down to every subcontractor at every tier that handles FCI or CUI. The prime's certification doesn't cover its subs. Each subcontractor's environment, controls, documentation, and CUI handling are evaluated separately.

A 12-person precision machining shop in Torrance that receives controlled customer drawings from a tier-1 aerospace supplier is subject to CMMC Level 2. The same as a 500-person prime. Company size is not a factor.

The question isn't whether your company is big enough to matter. It's whether CUI flows to your systems. If it does, you're in scope.

What Does a CMMC Level 2 Assessment Actually Involve

What Does a CMMC Level 2 Assessment Actually Involve?

A C3PAO assessment isn't a questionnaire. The NIST SP 800-171A methodology verifies every applicable control through three methods.

Examine — the assessor reviews your System Security Plan, policies, procedures, and configuration records against each control requirement.

Interview — the assessor asks personnel named as control owners to explain their role in implementing and maintaining the control in their own words.

Test — the assessor verifies that controls operate as documented in production. MFA is enabled, not just documented as planned. Audit logs are being reviewed by a named person on the documented cadence, not just retained.

All three methods apply. A control that works technically but isn't documented fails the Examine phase. A control that's documented but whose owner can't describe it fails the Interview phase. A control that's documented and understood but not operating as described fails the Test phase.

This is why the most common CMMC assessment failure isn't a security technology gap. It's documentation, specifically, an SSP that doesn't match the real environment. Greenberg Traurig's October 2025 assessment analysis found 25% of contractors fail their pre-assessment due to an incomplete or inaccurate SSP. The technology is often there. The paper trail isn't.

What Is Controlled Unclassified Information and How Do You Find It?

Controlled Unclassified Information is any data the government requires contractors to safeguard under law, regulation, or government-wide policy, but that hasn't been classified. CUI categories include technical data, engineering drawings, export-controlled information, privacy data, and dozens of other defined categories under the National Archives CUI Registry.

Finding it is harder than it sounds.

For a manufacturing company, CUI doesn't stay at a desk. It enters through email and customer portals, gets printed for shop-floor use, travels physically on job travelers, sits in ERP and MRP systems, appears in inspection reports, and ends up in certificates of conformance. A customer drawing marked with a distribution statement B is CUI whether it's on a screen, in a shared drive, or taped to a machinist's workstation near the anodizing line.

Scoping your CUI correctly is the single most consequential decision in a CMMC program. Over-scope and you apply controls to systems that don't touch CUI, driving unnecessary cost. Under-scope and you leave real CUI handling events outside your compliance boundary — which shows up as a finding when an assessor walks your floor.

null

The CMMC Compliance Checklist: What You Actually Need to Do

Here's the realistic preparation sequence for Level 2 certification.

1. Conduct a CMMC gap assessment. Walk all 110 NIST SP 800-171 controls against your real environment. Rate each as implemented, partially implemented, or not implemented. Produce a documented SPRS score with the methodology behind it. Every downstream decision — platform selection, remediation sequence, documentation scope, POA&M structure, assessment scheduling — depends on this step being accurate.

2. Define your CUI boundary. Map where CUI actually flows through the organization, not where it theoretically should. For manufacturers, this includes shop-floor systems, printed documents, ERP, and any physical environment where CUI exists. The boundary drives the SSP scope.

3. Build your System Security Plan. The SSP is a living document that maps all 110 controls to your specific environment — naming real tools, real roles, real escalation paths, and real evidence for each control. A template with names swapped in doesn't satisfy an assessor. Neither does an SSP authored without input from the people who actually run the controls. See our CMMC SSP and POA&M development services for how this works in practice.

4. Develop supporting documentation. The SSP references a documentation hierarchy beneath it: Information Security Policies and Standards, incident response playbooks, an Operations Security Procedures Manual, and Shared Responsibility Matrices for external service providers. Each document needs to be accurate, current, and signed.

5. Establish an evidence collection program. Controls in place is not the same as assessment-ready. You need dated, verifiable artifacts for each of the 320 NIST SP 800-171A assessment objectives. An assessor asking for audit log review records from 90 days ago needs to find them. If your cadence started six weeks before the assessment, they won't exist. Learn more about our CMMC evidence program approach.

6. Schedule your C3PAO assessment now. Assessment slots are booking 6 to 9 months out. By Q3 2026, some projections put scheduling lead times at 18 months or more as Phase 2 demand accelerates. You do not need to be fully ready before scheduling. You schedule the date, then build the preparation timeline backward from it.

7. Run a mock assessment before the real one. A mock assessment using the NIST SP 800-171A methodology surfaces findings that are correctable before the C3PAO arrives — without the cost of an adverse readiness determination or a failed assessment. Our C3PAO assessment preparation services cover this step.

How Does CMMC Affect Manufacturers Specifically

How Does CMMC Affect Manufacturers Specifically?

Manufacturers face complications that don't appear in standard CMMC guidance written for office environments.

CUI flows through physical production environments — printed job travelers, drawings near process lines, inspection workstations, quality records, shipping documents. The Physical Protection family in NIST SP 800-171 governs all of this. Most IT-led CMMC programs never address it.

Shop-floor operational technology — CNC controllers, coordinate measuring machine software, heat-treat monitoring systems — often runs on older operating systems that can't be patched or instrumented under standard IT controls. The Cyber AB scoping guidance provides a Specialized Asset category for exactly this. Properly classifying shop-floor OT systems limits the controls that apply to them and prevents over-scoping.

For manufacturers holding AS9100D certification or NADCAP accreditation, there's a significant advantage most CMMC content ignores. The document control, internal audit, corrective action, and supplier management disciplines in AS9100 map directly to CMMC management controls. You don't rebuild those from scratch. You extend them to cover CMMC's specific evidence requirements.

Our CMMC for aerospace manufacturers page covers how we build on existing quality management infrastructure rather than running parallel programs.

Our Take

CMMC 2.0 isn't a compliance exercise. It's a verification program for security controls that defense contractors were already required to have. The organizations that move through it cleanly are the ones who treat it as a documentation and evidence problem, not a technology problem.

Most of the technical controls in NIST SP 800-171 are already deployed in some form at a functioning defense contractor. What's usually missing is the SSP that documents them accurately, the evidence collection cadence that makes them provable, and the personnel readiness that makes them survive an assessor's interview questions.

Start with the gap assessment. Know your actual score. Build backward from the assessment date you schedule today.

Consilien works with Southern California defense contractors, aerospace manufacturers, and tier-2 suppliers on the full path from gap assessment through C3PAO readiness. Schedule a CMMC scoping call to start with a clear picture of where your program stands.

Need CMMC 2.0 certification before your next DoD contract?

Consilien works with Southern California defense contractors, aerospace manufacturers, and tier-2 suppliers on the full path from gap assessment through C3PAO readiness, delivered as a structured program with predictable timelines.

Common Questions About CMMC 2.0 Compliance

How long does CMMC Level 2 compliance take for a defense contractor?
Six to 18 months is the realistic range, depending on starting posture. Redspin's 2025 survey found 68% of contractors had been preparing for over a year. Organizations with a genuine NIST SP 800-171 foundation from years of DFARS 7012 work start ahead. Those starting from scratch on documentation, especially manufacturers with hybrid digital-physical CUI footprints, should plan for the longer end. Be skeptical of any quote under six months — the documentation and evidence work takes real time regardless of how strong the technical controls are.
What's the difference between CMMC Level 1 and Level 2?
Level 1 covers 17 basic practices for contractors handling Federal Contract Information only. It's self-assessed annually with no C3PAO required. Level 2 covers all 110 requirements from NIST SP 800-171 Rev 2 for contractors handling CUI. Most Level 2 contracts require third-party C3PAO assessment starting November 2026. If your DoD contracts include controlled drawings, technical specifications, or program data, you almost certainly need Level 2.
Does CMMC apply to subcontractors?
Yes, at every tier where CUI flows. The prime's certification covers the prime's environment only. Under 32 CFR § 170.23 and DFARS 252.204-7021, primes are required to flow CMMC requirements down to every subcontractor that receives FCI or CUI. A tier-3 machining shop receiving controlled drawings from a tier-2 supplier is in scope for CMMC Level 2. See our CMMC for defense subcontractors page for the full flow-down picture.
What is a Plan of Action and Milestones?
A POA&M is a structured remediation document tracking controls that aren't fully implemented at assessment time. The Final Rule allows conditional certification when a POA&M is accepted by the assessor. All items must be remediated and verified in a closeout assessment within 180 days or conditional certification expires. Not every control can carry through a POA&M — the SSP requirement itself must be fully implemented at assessment time. Gaps in access control, CUI handling, and documentation quality are harder to carry than configuration gaps in lower-risk controls.
How does CMMC enforcement affect contract awards?
As of November 2025, contracting officers can require CMMC certification as a condition of award on applicable solicitations. An organization without the required CMMC level is ineligible to bid. Promising future compliance doesn't work — the certification must exist before contract award. Contractors whose current contracts come up for recompete will face the same requirement. The enforcement window is already open.