What is CMMC 2.0?
CMMC — the Cybersecurity Maturity Model Certification — is the Department of Defense's mechanism for verifying that its contractors actually protect sensitive government information. Before CMMC, contractors self-attested to meeting cybersecurity requirements and the department had little way to check. CMMC replaces the honour system with assessment.
Two categories of information drive it. Federal Contract Information (FCI) is information provided by or generated for the government under a contract that is not intended for public release. Controlled Unclassified Information (CUI) is more sensitive — technical data, drawings, specifications, and similar material requiring safeguarding. Which one you handle determines your level.
CMMC 2.0 has three levels:
- Level 1 (Foundational) — for FCI. 15 basic safeguarding requirements from FAR 52.204-21. Annual self-assessment plus an affirmation.
- Level 2 (Advanced) — for CUI. The 110 security requirements of NIST SP 800-171. Either a self-assessment or a third-party assessment by a C3PAO, depending on the contract.
- Level 3 (Expert) — for the most critical programs. Level 2 requirements plus selected controls from NIST SP 800-172, assessed by the government's DCMA DIBCAC.
The contractual hook is DFARS clause 252.204-7021, which requires you to achieve and maintain your required level — and to flow the requirement down to your subcontractors.
Where CMMC stands right now
Status as of late July 2026 — this program has moved repeatedly, and any date-specific claim should be re-verified before you rely on it.
The two rules that made CMMC real both took effect on November 10, 2025: the 32 CFR CMMC Program rule and the 48 CFR CMMC Acquisition rule. That began a phased rollout planned across roughly three years:
- Phase 1 (from November 10, 2025) — Level 1 and Level 2 self-assessment requirements appear in applicable new contracts
- Phase 2 (planned November 10, 2026) — mandatory C3PAO third-party certification for Level 2 contracts
- Phases 3 and 4 (planned November 2027 and November 2028) — Level 3 requirements and full implementation
Then, on July 13, 2026, the department paused the phased rollout and opened a 60-day review of the program. Two things about that pause matter:
- Phase 1 self-assessment requirements remain in effect. The pause did not switch CMMC off. If your contract carries the requirement today, it still carries it.
- The pause affects the schedule for third-party certification, not the substance of what is required. The underlying control set — NIST SP 800-171's 110 requirements — has been a DFARS obligation since 2017. Nothing about the pause makes those go away.
Our honest read: a delay in the assessment deadline is not a reason to stop work. Organizations that treated earlier CMMC delays as a reprieve are the ones now scrambling, because 800-171 implementation takes months regardless of when someone comes to check. If anything, a pause is the cheapest possible window in which to get ready.
Who needs CMMC?
CMMC applies across the Defense Industrial Base — an estimated 200,000+ organizations — wherever FCI or CUI is handled. It reaches much further down the supply chain than most companies expect, because prime contractors must flow the requirement down.
It is a fit for:
- Prime contractors to the DoD
- Subcontractors at any tier — including small machine shops and specialty fabricators
- Manufacturers of defense parts, assemblies and systems
- Engineering, design and technical-services firms working defense programs
- Software, IT and cloud providers serving defense customers
- Managed service providers and IT contractors supporting defense contractors
- Distributors and logistics providers handling controlled technical data
Two frequent misconceptions worth clearing up. First, you do not have to hold a DoD contract directly — if a prime flows the clause to you, you are in scope. Second, small does not mean exempt. A ten-person shop that receives controlled drawings is handling CUI and needs Level 2.
The practical test is simply: does controlled information touch our systems? If defense drawings land in an engineer's email, they are on your network, and your network is in scope.
What CMMC requires
For most organizations the target is Level 2, and that means the 110 security requirements of NIST SP 800-171 across fourteen families — access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
Beyond the controls themselves, several deliverables do the real work:
- Scoping and asset categorization — defining precisely which systems, people and facilities handle CUI. Getting this wrong in either direction is the most consequential error in the project.
- A System Security Plan (SSP) — documenting how each of the 110 requirements is met in your environment. Assessors read this first.
- A Plan of Action and Milestones (POA&M) — for requirements not yet fully met, within the limits the rules allow. Not everything may be deferred, and not indefinitely.
- An SPRS score — your assessment result, submitted to the Supplier Performance Risk System, which is where contracting officers look.
- An annual affirmation by a senior official — a personal attestation, with False Claims Act exposure behind it if it is knowingly wrong.
- Evidence — logs, configurations, policies, training records. Assessors test claims; they do not accept assertions.
The single most useful scoping decision is often enclaving: rather than dragging your whole company into scope, isolate CUI into a defined, well-controlled environment. Done properly it cuts the cost and duration of the project substantially.
Why act now
Contract eligibility. Where the clause applies, this is not a differentiator — it is a gate. No compliance, no award, and primes are already screening their supply chains.
Timeline reality. Implementing 110 controls, writing an SSP, generating evidence and remediating findings takes most organizations six to twelve months. C3PAO assessment capacity is finite, and when Phase 2 resumes there will be a queue. The gap between deciding to comply and being able to prove it is measured in quarters.
Legal exposure. This is underappreciated: the DOJ's Civil Cyber-Fraud Initiative has pursued False Claims Act cases against contractors who misrepresented their cybersecurity posture, with substantial settlements. Because CMMC requires a named senior official to affirm compliance annually, a careless affirmation is a personal risk, not merely a corporate one.
Competitive position. Many small and mid-size suppliers will not do this work, and some will exit defense contracting because of it. If you are ready and your competitors are not, the pause is an advantage rather than an inconvenience.
How QSE gets you ready
We bring 30+ years of building management systems, 900+ organizations certified, and a 100% first-time pass rate. CMMC is a newer program than most of what we do, but it rewards exactly what we are good at: disciplined scoping, honest gap assessment, documentation people can actually maintain, and an internal review harder than the real assessment.
To be clear on roles: QSE is not a C3PAO and cannot be. Assessors must be independent of the organizations they assess, and a consultant who offers to both prepare and certify you is a problem. We prepare you; an accredited C3PAO assesses you.
We start with scope — what CUI and FCI you actually handle, where it lives, which level your contracts require, and whether an enclave can dramatically shrink the footprint. That single decision often determines the cost of the whole program. Then we run a gap assessment against all 110 requirements, build the SSP and POA&M, implement and document the controls with your IT team or provider, train your people, and get your SPRS score submitted correctly.
Then we assess you ourselves, against the same criteria a C3PAO will use, and fix what we find. Most organizations reach assessment-readiness in about 6 to 12 months depending on level and starting posture. Where you already hold ISO 27001, a good deal of governance, risk and evidence discipline carries over and the project moves faster.
Common pitfalls we help you avoid
- Treating the July 2026 pause as a reprieve. Phase 1 requirements are still in effect, NIST SP 800-171 has been a DFARS obligation since 2017, and implementation takes months whenever the clock restarts.
- Scoping the entire company into the assessment when an enclave would have contained CUI to a fraction of the environment
- Scoping too narrowly and missing CUI that sits in email, shared drives, engineering workstations or a subcontractor's systems
- Assuming Microsoft 365 or a cloud provider makes you compliant — you still own scoping, documentation, evidence and most of the controls, and commercial tenants may not meet the required standard
- An SSP written as marketing rather than as a control-by-control description assessors can test
- Abusing the POA&M — deferring requirements that may not be deferred, or with no credible closure plan
- A senior official signing the annual affirmation without understanding the False Claims Act exposure attached to it
- Failing to flow requirements down to subcontractors who handle your controlled data
- No evidence behind implemented controls — policies with no logs, configurations or training records to support them
- Believing small companies are exempt. If controlled drawings reach your network, you are in scope.
