---
title: "CMMC 2.0: What Defense Contractors Must Know"
description: "A practical guide to CMMC 2.0 for defense contractors — levels, timeline, preparation steps, and common mistakes to avoid."
url: https://policycortex.com/blog/cmmc-2-what-defense-contractors-need-to-know
sealed: 2025-11-20
register: blog/cmmc-2-what-defense-contractors-need-to-know
records: 3
digest: sha3:bf766a983eb29b77c30e8f48a1618bdca427f4f2fd41bbcab8b563df2a97c0e6
---

# CMMC 2.0: What Defense Contractors Need to Know

Register / Blog

The CMMC program is officially active with assessments underway. Here’s a practical guide for contractors navigating the requirements.

PolicyCortex Team · Sealed 2025-11-20 · Reading time 2 min

Filed under: [CMMC](https://policycortex.com/blog/tags/cmmc), [defense contractors](https://policycortex.com/blog/tags/defense-contractors), [compliance](https://policycortex.com/blog/tags/compliance), [NIST 800-171](https://policycortex.com/blog/tags/nist-800-171)

**Policy note, 2026-07-13.** The Department of War suspended CMMC Phase II on July 13, 2026. Phase I self-assessments, the NIST SP 800-171 Rev. 2 baseline, and DFARS 252.204-7012 safeguarding obligations remain in force while the Department reviews the program. [What changed and what still applies.](https://policycortex.com/blog/cmmc-phase-ii-suspension-what-defense-contractors-do-now) [Official release.](https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/)

**Summary**

- CMMC 2.0 is officially active — the 32 CFR Part 170 final rule took effect in December 2024, and assessments are underway through authorized C3PAOs.
- Level 2 certification (110 NIST 800-171 controls) is required for most contractors handling CUI, with mandatory third-party assessment.
- Reducing scope through CUI environment segmentation is the single most effective way to lower assessment cost and complexity.
- CMMC requires continuous monitoring, not one-time audits — automated compliance platforms dramatically reduce the operational burden of maintaining certification.
- Common mistakes include treating CMMC as a checkbox exercise, waiting too long to start, and ignoring cloud environment configurations.

## CMMC 2.0 Overview

The Cybersecurity Maturity Model Certification (CMMC) 2.0 framework establishes cybersecurity requirements for the Defense Industrial Base (DIB). It streamlines the original five-level model down to three levels and codifies the requirement for third-party assessments at Level 2 and above.

> If you handle Controlled Unclassified Information (CUI) for the Department of Defense, CMMC affects you.

---

## The Three Levels

**Level 1 — Foundational** covers 15 basic cybersecurity practices from FAR 52.204-21. This level requires annual self-assessment and applies to contractors handling Federal Contract Information (FCI).

**Level 2 — Advanced** maps directly to the 110 security requirements in NIST SP 800-171. Most contractors handling CUI will need Level 2 certification, which requires assessment by an authorized C3PAO (Certified Third-Party Assessor Organization).

**Level 3 — Expert** adds requirements from NIST SP 800-172 for enhanced security against advanced persistent threats. This level requires government-led assessment and applies to a smaller set of critical programs.

---

## Timeline and Enforcement

The CMMC program is now officially active. The 32 CFR Part 170 final rule took effect in December 2024, and CMMC requirements are being phased into DoD contracts through the 48 CFR DFARS rulemaking process.

> This is no longer a future requirement. Contractors who haven’t started preparation are already behind.

---

## Practical Steps for Preparation

### 1. Scope Your CUI Environment

Identify exactly where CUI flows and is stored in your organization. The scope of your assessment — and the cost — depends entirely on this boundary.

### 2. Conduct a Gap Assessment

Map your current security posture against all 110 NIST 800-171 practices. Common problem areas include access control, audit log management, configuration management, incident response, and system communications protection.

### 3. Build Your System Security Plan (SSP)

Your SSP documents how you implement each security requirement.

### 4. Address Gaps with a POA&M

A Plan of Action and Milestones (POA&M) documents known gaps and your plan to close them.

### 5. Establish Continuous Monitoring

CMMC is not a one-time audit. Organizations must maintain their security posture continuously between assessments.

---

## Common Mistakes

**Treating CMMC as a checkbox exercise.** The assessors are looking at actual security posture, not just documentation.

**Waiting too long to start.** Achieving compliance takes most organizations months, not weeks. C3PAO availability is limited.

**Ignoring the cloud.** Many contractors use AWS, Azure, or GCP without properly configuring these environments for CUI handling.

> Cloud misconfigurations are among the top findings in CMMC assessments. If your CUI touches cloud infrastructure, your cloud environment is in scope.

## Related records

Guides and articles describe the work. The evidence that work produces is described in three proof pages and one architecture page.

- **proof.state**: [Proof of State](https://policycortex.com/proof/state). What the environment was, as of a date someone else picks: point-in-time records, content hashed and chained.
- **proof.change**: [Proof of Change](https://policycortex.com/proof/change). Who or what altered the environment, under what authority, with before and after state hashes.
- **proof.agency**: [Proof of Agency](https://policycortex.com/proof/agency). What a machine was permitted to do before it acted, what it did, and what would have stopped it.
- **architecture**: [Architecture](https://policycortex.com/architecture). How the chain is built and where it lives: inside your tenant, with no egress of evidence.

### Further reading in this register

| Sealed | Entry | Reading |
|---|---|---|
| 2026-07-13 | [CMMC Phase II Is Suspended: What Defense Contractors Still Have to Do](https://policycortex.com/blog/cmmc-phase-ii-suspension-what-defense-contractors-do-now): The Department of War suspended CMMC Phase II on July 13, 2026, but kept Phase I self-assessments, NIST SP 800-171 Rev. 2 enforcement, and DFARS 252.204-7012 obligations in place. | 7 min |
| 2026-07-01 | [The $507K LOGZONE Settlement: Your SPRS Score Is Now False Claims Act Evidence](https://policycortex.com/blog/logzone-false-claims-act-sprs-score): DOJ settled with a defense contractor that posted a 110 SPRS score and later received a -170 government assessment. Phase II is paused, but the risk of an unsupported score remains. | 9 min |
| 2026-06-29 | [The C3PAO Capacity Math After the CMMC Phase II Suspension](https://policycortex.com/blog/c3pao-backlog-2026-cmmc-work-back-schedule): The Phase II countdown is gone, but C3PAO capacity still matters for contract-specific and voluntary assessment plans. Here is how to use the dated 2026 market snapshot without planning from a suspended milestone. | 10 min |

Verify the record this entry describes. [Request Access](https://app.policycortex.com/auth?mode=request-access) · [Book a call](https://policycortex.com/book)

Dates of record

- **Sealed**: 2025-11-20
- **Last amended**: Unchanged since sealing
- **Author**: PolicyCortex Team
- **Record**: https://policycortex.com/blog/cmmc-2-what-defense-contractors-need-to-know

## Register colophon

| Seq | Label | SHA3-256 | Prev |
|---|---|---|---|
| REC 0000 | HEAD | f501d285229a | 07f164747128 |
| REC 0001 | BODY | fea379557be2 | f501d285229a |
| REC 0002 | RELATED RECORDS | bf766a983eb2 | fea379557be2 |

Head sha3:bf766a983eb29b77c30e8f48a1618bdca427f4f2fd41bbcab8b563df2a97c0e6. Each digest is SHA3-256 over the previous digest, the register key, the record label, and the record copy; a second party can recompute it from this document.
