CMMC Level 1 and Level 2

The road to CMMC, and what the Phase 2 suspension changed

The certification timeline moved. The obligations did not. What defense contractors actually have to do right now, and why pausing your program would be the expensive reading of the news.

Phase 2 was suspended on 13 July 2026

The Department of War suspended CMMC Phase 2 effective immediately, halting the 10 November 2026 move to third-party C3PAO assessments, and opened a review of the program. What did not change: DFARS 252.204-7012, all 110 NIST SP 800-171 controls, annual affirmations, SPRS scoring, incident reporting, and flow-down to subcontractors. Level 1 and Level 2 self-assessment obligations remain in force. Contractors who stop work now will face the same requirements later with less time, and misrepresenting a SPRS score carries False Claims Act exposure whether or not anyone is coming to assess it.

CMMC verifies something that has been contractually required since 2017. DFARS 252.204-7012 already obliges contractors handling covered defense information to implement all 110 controls in NIST SP 800-171. CMMC was the mechanism to check. The checking has been paused; the requirement has not.

Read this if

  • You hold or bid on DoD contracts containing DFARS 252.204-7012
  • A prime contractor has flowed CMMC requirements down to you
  • You handle Federal Contract Information or Controlled Unclassified Information
  • You paused your CMMC program after July 2026 and are wondering whether that was right
The roadmap

What the program actually looks like.

Durations assume a first attempt with a team that has other work to do. They are the numbers we would give you on a call, not the ones in a sales deck.

Determine what you actually hold

2 to 4 weeks

Federal Contract Information and Controlled Unclassified Information are different things with different obligations. FCI means Level 1 and 15 basic safeguarding requirements from FAR 52.204-21. CUI means Level 2 and all 110 controls. Read your contracts rather than assuming.

You come out with: A contract-by-contract determination of FCI and CUI, with the clauses that triggered each.

Map where CUI lives and moves

3 to 6 weeks

Follow it: email, file shares, engineering workstations, the ERP, the contract manager's laptop, the shop floor. This is the single highest-leverage activity in the whole program, because every system CUI touches falls in scope.

You come out with: A data flow map and an honest inventory of every system, person and process that handles CUI.

Design the boundary

4 to 8 weeks

Decide whether to bring the whole company into scope or build an enclave that CUI lives inside. For most small and mid-sized suppliers the enclave is dramatically cheaper, and the decision to build one is usually worth more than the entire rest of the engagement.

You come out with: A defensible system boundary, an architecture for the enclave, and a documented shared responsibility split with any cloud or managed provider.

Implement the 110 controls

3 to 9 months

NIST SP 800-171 across access control, audit, configuration, identification and authentication, incident response, maintenance, media protection, personnel, physical, risk, security assessment, communications and system integrity. Some are technical, many are procedural, and the procedural ones are the ones that get skipped.

You come out with: Implemented controls with evidence, and honest scoring rather than optimistic scoring.

SSP, POA&M and SPRS

3 to 5 weeks, then continuous

The System Security Plan documents how each control is met. The POA&M covers what is not yet met, with dates. The score goes into the Supplier Performance Risk System. Note that not every control can sit on a POA&M, and the ones that cannot are the ones assessors look at first.

You come out with: A current SSP, a POA&M with real dates, and a SPRS score you can defend line by line to someone hostile.

Self-assess and affirm

2 to 3 weeks, then annual

Phase 1 requirements are active: self-assessment and an annual affirmation from a senior official. Level 2 self-assessments continue every three years with annual affirmation. The affirmation is a signed statement, and that signature is what creates personal exposure if the score is wrong.

You come out with: A completed assessment, a submitted affirmation, and the evidence to support both.

Prepare for third-party assessment

When Phase 2 resumes

C3PAO assessment is paused, not cancelled. Organizations that keep their evidence current will need a mock assessment and a short readiness pass. Organizations that stopped will be starting the implementation again against a shorter runway.

You come out with: A mock assessment against the same criteria a C3PAO would use, and gaps closed before anyone external looks.
Where the time goes

The five things that consume the calendar.

None of these are the parts people budget for, and all of them are the parts that slip.

  • Finding CUI, which is always in more places than anyone expects, particularly email and personal drives.
  • The procedural controls, which need written procedures and evidence people follow them, not just technology.
  • Segmenting operational technology without stopping production, where change windows are measured in shifts.
  • Getting a straight answer from an MSP about which controls they cover and which are yours.
  • Documenting the SSP properly, which is a substantial writing exercise and cannot be delegated to a tool.
Cost drivers

What moves the number.

Two organizations of the same size can differ several-fold on price. This is usually why.

  • Whether you scope an enclave or bring the whole company in
  • How much CUI has spread into email and unmanaged endpoints
  • Whether operational technology touches the same network
  • Existing maturity against NIST SP 800-171, which is usually lower than assumed
  • Level 1 versus Level 2, which is 15 requirements versus 110
Deliverables

What you have to produce.

Every one of these will be asked for. Missing any of them is a finding.

ArtifactWhat it has to contain
CUI and FCI determinationWhich contracts, which clauses, which data
Data flow mapWhere CUI enters, lives, moves and leaves
System Security PlanHow each of the 110 controls is met, in your environment
POA&MWhat is not met, who owns it, when it closes
SPRS score and submissionCalculated honestly, with the working shown
Annual affirmationSigned by a senior official who understands what they signed
Shared responsibility matrixWhat your cloud and managed providers cover, in writing
Incident response planWith the 72-hour DFARS reporting obligation built in
How it goes wrong

Five failures we see repeatedly.

Each of these turns a manageable program into an expensive one. All five are avoidable at the start and very hard to fix in the middle.

Never defining the boundary

Without a deliberate CUI enclave, the entire company falls in scope: every laptop, every server, every user. The cost difference between a scoped enclave and a whole-company implementation is routinely five to one.

Assuming your cloud provider covers you

A FedRAMP authorized service is a component of your compliance, not a substitute for it. The controls that remain yours are numerous, and the shared responsibility split needs to be documented rather than assumed.

Using the POA&M as a parking lot

Not every control is eligible to be deferred, and a POA&M loaded with the ones that are not is the fastest way to fail. Dates that have already slipped once are read as an indicator of everything else.

An inflated SPRS score

Scoring generously feels harmless while nobody is checking. The affirmation is a signed representation to the government, and False Claims Act cases have already been brought on exactly this. The suspension of assessments does not suspend that exposure.

Treating the July 2026 suspension as a stand-down

The obligations survived intact. The organizations that keep going will be ready when Phase 2 resumes and can say so to primes in the meantime, which is itself becoming a discriminator in flow-down decisions.

Questions

What people ask us about CMMC.

Should we pause our CMMC program after the suspension?
No. Third-party assessment is paused; nothing else is. DFARS 252.204-7012, the 110 controls, self-assessment, annual affirmation, SPRS scoring, incident reporting and subcontractor flow-down all remain in force. Pausing means facing the same requirements later with a shorter runway, while carrying the same legal exposure in the meantime.
What is the difference between Level 1 and Level 2?
Level 1 applies to Federal Contract Information and requires the 15 basic safeguarding requirements in FAR 52.204-21, self-assessed annually. Level 2 applies to Controlled Unclassified Information and requires all 110 NIST SP 800-171 controls. The gap between them is very large.
How long does Level 2 take?
Nine to eighteen months for most suppliers starting from a typical commercial IT baseline. Scoping an enclave shortens it considerably. The implementation of procedural controls, not the technical ones, is usually the long pole.
Can our MSP just handle this?
Partly. An MSP can implement and operate many technical controls, but the obligation stays with you, the SSP is yours to defend, and the affirmation is signed by your senior official. Get the shared responsibility split in writing before you rely on it.
What happens when Phase 2 resumes?
Third-party C3PAO assessment returns for the contracts that require it. The practical difference between organizations at that point will be whether they have current evidence or a two-year gap in their records.

Want this run for you?

We run these programs end to end: scoping, control design, evidence, auditor management, and the operating rhythm that keeps year two boring.