CMMC Level 2 Is Now a Supply Chain Requirement: What Every Small Business Must Do Before November 2026

Effective November 10, 2026, self-assessment is no longer sufficient for contractors handling Controlled Unclassified Information on DoD contracts. CMMC Level 2 certification through an accredited third-party assessment organization is now a hard requirement, and major prime contractors are already enforcing it through their supply chains. Here is what you need to know and exactly what to do.

Category: Certifications · 14 min read · Published 2026-06-19

Key takeaways

  • Status update: on July 13, 2026 the Department of War suspended CMMC Phase II, so the November 10, 2026 third-party certification deadline described in this guide is on hold. Phase I self-assessment and all NIST SP 800-171 obligations remain in force.
  • CMMC 2.0 has three levels. Level 1 covers Federal Contract Information and requires 17 basic safeguarding practices aligned with FAR 52.204-21, with annual self-assessment.
  • Level 2 covers Controlled Unclassified Information and requires all 110 security requirements in NIST SP 800-171 Revision 2, organized across 14 domains.
  • Level 3 covers the most sensitive programs and adds 24 practices from NIST SP 800-172, assessed directly by the Defense Contract Management Agency.
  • DFARS 252.204-7021 embedded CMMC into defense contracts through a final rule published September 10, 2025.
  • As designed, contractors file annual affirmations of continued compliance to SPRS and undergo a full C3PAO reassessment every three years.

The Cybersecurity Maturity Model Certification program has moved from pending policy to enforceable contract requirement. On September 10, 2025, the Department of Defense published the final rule amending the Defense Federal Acquisition Regulation Supplement through DFARS 252.204-7021, formally embedding CMMC requirements into defense contracts. Phase 1 took effect November 10, 2025. Phase 2 takes effect November 10, 2026. By that date, any contractor or subcontractor that handles Controlled Unclassified Information on a DoD contract must hold a CMMC Level 2 certification assessed by an accredited Certified Third-Party Assessment Organization (C3PAO), not a self-assessment.

This is not a future concern. It is a present compliance obligation for anyone in the defense industrial base. Major prime contractors are already flowing the requirement down to their supply chains and disqualifying suppliers who cannot demonstrate certified compliance.

What CMMC 2.0 Is and Why It Was Created

The Cybersecurity Maturity Model Certification program was created by the Department of Defense to protect sensitive unclassified information shared with defense contractors. The DoD has long required contractors to implement cybersecurity controls under DFARS 252.204-7012 and NIST SP 800-171, but self-reporting compliance created inconsistency across the defense industrial base. CMMC 2.0 was designed to verify that contractors are actually implementing the required controls, not merely claiming to.

CMMC 2.0 has three levels. Level 1 applies to contractors that handle Federal Contract Information (FCI), which is non-public information provided by or generated for the government under a contract. Level 1 requires implementation of 17 basic safeguarding practices aligned with FAR 52.204-21 and allows annual self-assessment with attestation by a senior company official submitted to the DoD Supplier Performance Risk System (SPRS). Level 2 applies to contractors that handle Controlled Unclassified Information (CUI), a broader and more sensitive category than FCI. Level 2 requires implementation of all 110 security requirements specified in NIST SP 800-171 Revision 2, organized across 14 domains. Level 3 applies to contractors supporting the most sensitive programs and requires implementation of 24 additional practices drawn from NIST SP 800-172, with assessments conducted directly by the Defense Contract Management Agency.

The Phase 2 Deadline: November 10, 2026

CMMC implementation is structured in phases. Phase 1, which became effective November 10, 2025, began introducing CMMC Level 1 and Level 2 self-assessment requirements into applicable DoD solicitations and contracts. Phase 2, which takes effect November 10, 2026, is the critical inflection point for most contractors. Starting on that date, Level 2 certification by a C3PAO becomes mandatory in applicable contracts that require handling of CUI. Self-attestation will no longer be accepted as a substitute for third-party certification on those contracts.

The practical consequence is significant. A contractor that currently holds only a self-assessment for NIST 800-171 compliance will not meet the requirements for new DoD contract awards or option exercises on covered contracts after November 10, 2026. The certification must be active, documented in SPRS, and available for review upon request.

After initial certification, contractors must provide annual affirmations of continued compliance submitted to SPRS, and must undergo a full reassessment by a C3PAO every three years.

Prime Contractors Are Enforcing It Now

Federal prime contractors are not waiting for the government to enforce Phase 2 through contract clauses. They are issuing their own formal requirements to subcontractors and suppliers, setting internal deadlines that align with or precede the November 10, 2026 regulatory deadline.

This supply chain enforcement matters for small businesses because it does not depend on whether your company holds a direct DoD contract. If you supply products, services, or support to a prime contractor on a DoD program, and that work involves handling CUI, the prime can and will require you to meet CMMC Level 2 certification as a condition of continued participation in their supply chain. Suppliers who have not achieved C3PAO certification by the prime's deadline may be disqualified from award of new task orders, renewals, and new subcontract opportunities. The certification must be documented in SPRS and the DoD Supplier Performance Risk System must reflect your active certification status.

Understanding the 110 Controls Across 14 Domains

CMMC Level 2 maps directly to the 110 security requirements in NIST SP 800-171 Revision 2. These requirements are organized into 14 domains: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity.

Each domain contains specific practices that a contractor must implement and be able to demonstrate to a C3PAO assessor. The assessment is not a documentation review only. An accredited C3PAO will review your policies and procedures, conduct interviews with personnel, and technically validate that the controls are actually implemented and operating as intended. A finding of non-compliance with any of the 110 requirements can result in a Plan of Action and Milestones (POA&M) that must be resolved before certification is granted, depending on the severity of the finding.

The SPRS Score: Your Starting Point

Before engaging a C3PAO, your organization should complete a NIST SP 800-171 self-assessment and calculate your SPRS score. The SPRS scoring methodology assigns a point value to each of the 110 controls, starting from a maximum of 110 points and subtracting for each unimplemented control based on its assessed impact weight. The resulting score, which can range from negative 203 to positive 110, is submitted to SPRS and represents your current compliance posture.

Your SPRS score is the baseline that tells you how far you are from meeting all 110 requirements and where your gaps are concentrated. It is also visible to contracting officers and prime contractors when they review your SPRS record. A SPRS score that has not been updated, or that reflects a score significantly below 110, signals compliance risk to any organization reviewing your record.

The Average Company Needs Six Months to Reach 110 Controls

One of the most frequently cited facts in CMMC compliance planning is that the average organization needs approximately six months to go from zero to full implementation of all 110 NIST 800-171 controls. For organizations starting from a low SPRS score or those that have not previously conducted a formal NIST 800-171 assessment, the path to C3PAO readiness includes gap assessment, remediation of identified deficiencies, staff training, policy and procedure development, and technical implementation of controls that may require new tools or infrastructure.

Add to that the C3PAO scheduling reality. C3PAO lead times currently range from three to six months. With a limited number of accredited assessment organizations and a large volume of contractors needing certification before November 2026, assessment slots are filling well in advance of the deadline. Organizations that begin the process in the fall of 2026 will likely find that no C3PAO can complete their assessment before the November 10 deadline.

Step-by-Step Guide: How to Achieve CMMC Level 2 Certification

Step 1: Determine your CMMC level requirement.
Identify whether your contracts require handling of CUI or only FCI. Review your active contracts and any solicitations you are pursuing for references to CMMC, DFARS 252.204-7021, or DFARS 252.204-7012. If you work as a subcontractor, contact your prime contractor and ask directly what CMMC level they require from suppliers in your role.

Step 2: Conduct a NIST SP 800-171 self-assessment and calculate your SPRS score.
Use the DoD's NIST SP 800-171 Assessment Methodology to assess your organization against all 110 controls. Score each control as implemented, not implemented, or partially implemented. Calculate your SPRS score and submit it to SPRS at sprs.apps.mil. This score is your baseline and your public compliance record.

Step 3: Build a System Security Plan (SSP).
The SSP is a required document for Level 2 certification. It describes your information systems, the CUI you handle, the network boundaries within which CUI exists, and the specific controls implemented to protect it. The SSP must be current, accurate, and detailed. Your C3PAO will use it as a primary reference during the assessment.

Step 4: Address gaps with a Plan of Action and Milestones (POA&M).
For every control that is not yet fully implemented, document the deficiency, the planned corrective action, and the target completion date in a POA&M. Prioritize remediating the highest-weight controls first, as these have the greatest impact on your SPRS score and represent the most significant compliance gaps in the eyes of an assessor.

Step 5: Implement missing controls and validate implementation.
Work through your POA&M systematically. This step often involves technical changes such as implementing multi-factor authentication, configuring audit logging, establishing encrypted backups, and enforcing access controls on systems that handle CUI. It may also involve policy changes and staff training. Document evidence of implementation for every control, since the C3PAO will require evidence during the assessment.

Step 6: Select an accredited C3PAO and schedule your assessment.
The Cyber AB Marketplace at cyberab.org is the authoritative source for the list of accredited C3PAOs. Select a C3PAO, verify their accreditation status, and engage them as early as possible given current lead times of three to six months. The C3PAO will conduct a pre-assessment review of your SSP and other documentation before scheduling the formal assessment.

Step 7: Complete the C3PAO assessment.
The formal assessment involves document review, personnel interviews, and technical testing conducted by the C3PAO's assessors. All findings are documented. If minor deficiencies are identified that do not prevent certification, they may be captured in a residual POA&M. After the assessment is complete and any conditions are resolved, the C3PAO submits your certification to the CMMC Accreditation Body.

Step 8: Affirm compliance in SPRS and maintain certification.
Once certified, your organization must submit an annual affirmation of continued compliance to SPRS. A senior company official is responsible for this affirmation. Plan for a full reassessment by a C3PAO every three years to maintain active certification status.

How ProposalApp Helps You Track and Respond to CMMC Requirements

When you are reviewing RFPs and active solicitations in ProposalApp, the Proposal Assistant reads the full text of solicitation documents and can identify CMMC-related requirements embedded in the contract clauses, Section H or I of the RFP, or the Statement of Work. If a solicitation references DFARS 252.204-7021 or specifies a CMMC level requirement, ProposalApp surfaces that requirement and flags it as a compliance consideration for your proposal.

For proposals on contracts requiring CMMC Level 2, ProposalApp can help you draft the cybersecurity sections of the technical approach and management plan, articulate your current compliance posture and timeline to full certification, and describe the controls you have implemented to protect CUI. ProposalApp's Proposal Assistant helps you frame your compliance narrative accurately and professionally.

Use ProposalApp's Find Opportunities page to search for CMMC requirements across active solicitations. Search for "CMMC Level 2," "DFARS 252.204-7021," or "Controlled Unclassified Information" to identify opportunities in your pipeline where certification is an explicit requirement or evaluation factor.

Sources

- [CMMC Phase 2 Deadline November 10, 2026 | StrikeGraph](https://www.strikegraph.com/blog/cmmc-phase-2-deadline-november-2026)
- [CMMC 2.0 Certification: DoD Contractor Guide for 2026 | Elevate Consulting](https://elevateconsult.com/insights/cmmc-2-0-certification-for-dod-contractors-what-you-need-to-know-before-2026-deadlines/)
- [CMMC 2.0 Deadlines and Rules | Godlan](https://godlan.com/cmmc-2-0-deadlines-rules/)
- [CMMC 2.0 Compliance Requirements | Infor](https://www.infor.com/industries/aerospace-defense/cmmc-2-0-compliance-requirements)
- [Navigating CMMC Changes in 2026 | VC3](https://www.vc3.com/blog/navigating-cmmc-changes-in-2026)
- [CMMC Level 1 Requirements and Self-Assessment Guide | Secureframe](https://secureframe.com/blog/cmmc-level-1-compliance)
- [CMMC Goes Live: New Cybersecurity Requirements for Defense Contractors | Holland and Knight](https://www.hklaw.com/en/insights/publications/2025/09/cmmc-goes-live-new-cybersecurity-requirements)
- [CMMC Level 2: How to Engage a C3PAO | Elevate Consulting](https://elevateconsult.com/insights/cmmc-2-0-certification-how-to-engage-a-c3pao-for-level-2/)
- [CMMC Compliance | NSTXL](https://nstxl.org/cmmc-compliance/)

Frequently asked questions

Is CMMC Level 2 third-party certification still required?

The requirement is currently on hold. On July 13, 2026 the Department of War suspended CMMC Phase II, which would have made C3PAO certification mandatory on November 10, 2026. Phase I self-assessment requirements, DFARS 252.204-7012, and the 110 NIST SP 800-171 controls all remain fully in force.

What is the difference between CMMC Level 1 and Level 2?

Level 1 applies to contractors handling Federal Contract Information and requires 17 basic safeguarding practices aligned with FAR 52.204-21, with annual self-assessment and attestation by a senior company official submitted to SPRS. Level 2 applies to contractors handling Controlled Unclassified Information and requires all 110 security requirements in NIST SP 800-171 Revision 2, organized across 14 domains.

What is a C3PAO?

A Certified Third-Party Assessment Organization, an accredited body authorized to perform CMMC Level 2 assessments. Under the Phase II design that is currently suspended, a C3PAO assessment would have replaced self-attestation for contracts involving CUI.

What is the difference between FCI and CUI?

Federal Contract Information is non-public information provided by or generated for the government under a contract. Controlled Unclassified Information is a broader and more sensitive category. FCI triggers CMMC Level 1 requirements, while CUI triggers Level 2.

How often would CMMC recertification be required?

Under the program as designed, contractors provide annual affirmations of continued compliance submitted to SPRS and undergo a full reassessment by a C3PAO every three years.

What is CMMC Level 3?

Level 3 applies to contractors supporting the most sensitive programs. It requires implementation of 24 additional practices drawn from NIST SP 800-172, with assessments conducted directly by the Defense Contract Management Agency rather than a C3PAO.

🤖 /llms.txt