CMMC Level 2 requirements - Corsica Technologies

CMMC Level 2 Requirements: Where Things Stand

On July 13, 2026, the Department of Defense announced the immediate suspension of CMMC Compliance Phase 2, which would have gone into effect November 10, 2026, affecting Level 2 compliance. This suspension also included all pending and future CMMC implementation milestones.

The Department of Defense is expected to announce the findings of a task force that was set to review the requirement. That announcement should come in mid-September 2026.

In the meantime, where do things stand?

Should defense contractors continue to pursue compliance with their Level 2 requirements? (Yes, absolutely, whether doing it in-house or working with a CMMC compliance consultancy. More on this below.)

Here’s everything you need to know.

Key takeaways:

  • CMMC Level 2 compliance requires the implementation of all 110 security controls from NIST SP 800-171 Rev. 2.
  • CMMC Level 2 compliance is aligned to NIST SP 800-171 Rev. 2 even though NIST’s latest version of the standard is Rev. 3. This is a common point of confusion.
  • While Level 2 compliance has been suspended, Phase 1 Level 1 and Level 2 self-assessments, SPRS score submissions, annual affirmations, and DFARS 252.204-7012 safeguarding obligations have not been suspended.
  • Organizations should continue to pursue Level 2 compliance to stay ahead of the curve, anticipating the announcement of the new timeline in mid-September 2026.

Table of Contents

💡 EXCLUSIVE Guide: 

CMMC Compliance Cheatsheet

What are the requirements of CMMC Level 2?

CMMC Level 2 compliance requires the implementation of all 110 security controls from NIST SP 800-171 Rev. 2, organized across 14 control families and separated into 320 assessment objectives. (Note that while Rev. 2 has been superseded by Rev. 3 for NIST’s official standards, CMMC compliance is still based on Rev. 2.) These requirements apply to defense contractors and subcontractors that handle Controlled Unclassified Information (CUI).

Compliance must be documented in a System Security Plan (SSP), scored in SPRS, and verified either by self-assessment or by a C3PAO third-party assessment depending on the contract. Currently, during the Department of Defense’s Phase 2 review pause that went into effect July 2026, new solicitations designate self-assessment only.

A minimum score of 80% with a POA&M can earn conditional status, but higher-weighted controls must be fully implemented and POA&M items closed out within 180 days.

CMMC Level 2 requirements

Control Family

Requirements

Focus

Access Control (AC)

22

Limit system access to authorized users and functions

Awareness & Training (AT)

3

Security awareness and role-based training

Audit & Accountability (AU)

9

Logging, log review, and audit records

Configuration Management (CM)

9

Baseline configurations and change control

Identification & Authentication (IA)

11

User identity, MFA, password requirements

Incident Response (IR)

3

Detect, report, and respond to incidents

Maintenance (MA)

6

Controlled and monitored system maintenance

Media Protection (MP)

9

Protect, sanitize, and control media with CUI

Personnel Security (PS)

2

Screening and access removal on termination

Physical Protection (PE)

6

Limit physical access to systems and facilities

Risk Assessment (RA)

3

Risk assessments and vulnerability scanning

Security Assessment (CA)

4

SSP, control assessments, remediation plans

System & Communications Protection (SC)

16

Network boundaries, encryption, CUI in transit

System & Information Integrity (SI)

7

Flaw remediation, malware protection, monitoring

There are 110 controls and 320 assessment objectives in total, plus the supporting artifacts that assessors expect. Companies must produce an SSP, POA&M, SPRS score submission, and evidence for each objective.

CMMC Level 2: NIST 800-171 Rev. 2 or Rev. 3?

Does CMMC Level 2 compliance align with NIST SP 800-171 Rev. 2 or Rev. 3?

This is a common point of confusion. NIST has updated their standard to Rev. 3, yet CMMC compliance is still based on Rev. 2. Therefore, defense contractors should build their compliance program around Rev. 2, not Rev. 3. In fact, building it around Rev. 3 is a common and expensive mistake.

Who must comply with CMMC Level 2?

CMMC Level 2 applies to Department of Defense contractors and subcontractors whose systems process, store, or transmit Controlled Unclassified Information (CUI). This includes manufacturers, engineering firms, IT service providers, and other suppliers throughout the defense industrial base (DIB), not just prime contractors.

The DoD estimates that these organizations make up over a third of the DIB, making Level 2 the most common CMMC requirement. Whether a given company needs it is determined by its specific contracts. The requirement appears in individual solicitations, awards, and option periods rather than applying as a blanket mandate, and prime contractors often flow the requirement down to subcontractors, sometimes ahead of DoD-wide milestones. Notably, external service providers such as MSPs and MSSPs that handle CUI on behalf of defense contractors can also fall within assessment scope.

When is the deadline for CMMC Level 2 compliance?

There is no single universal deadline. CMMC Level 2 requirements attach to individual contracts as they appear in solicitations, awards, and option periods, following a phased rollout that began November 10, 2025. Since that date, applicable new contracts have required Level 1 or Level 2 self-assessments at time of award, and those Phase 1 requirements remain in force today.

The major upcoming milestone is Phase 2, which would have made third-party (C3PAO) certification a condition of award for most CUI-handling contracts starting November 10, 2026. However, this milestone was administratively paused on July 13, 2026, when the DoD launched a 60-day reform task force review. Further guidance is expected around mid-September 2026.

The pause is administrative, not a rule change: 32 CFR Part 170 and the DFARS rule remain unamended, and the underlying NIST 800-171 obligations still apply. Also note that prime contractors can flow requirements down to subcontractors ahead of these DoD-wide dates.

Start dates for CMMC compliance phases

Phase

Original Start Date

Requirement

Current Status

Phase 1

Nov 10, 2025

Level 1 or Level 2 self-assessments required in applicable new contracts

Active — still mandatory

Phase 2

Nov 10, 2026

Level 2 C3PAO certification as condition of award for applicable CUI contracts

Suspended (July 13, 2026) pending DoD review

Phase 3

Nov 10, 2027

C3PAO certification required for all applicable contracts; Level 3 (DIBCAC) assessments roll out

On hold pending review

Phase 4

Nov 10, 2028

Full implementation — CMMC in all applicable DoD contracts

On hold pending review

 

Is CMMC Level 2 still suspended by the Department of Defense?

Yes, as of this writing, the suspension remains in effect, though it’s narrower than the phrase “CMMC Level 2 is suspended” might imply. On July 13, 2026, the DoD announced the immediate suspension of Phase 2, which would have made third-party C3PAO certification a condition of contract award starting November 10, 2026. This suspension also included all pending and future CMMC implementation milestones. Concurrently with the suspension, the DoD launched a Reform Task Force conducting a 60-day review, with its report expected in mid-September.

What’s paused is the third-party assessment expansion. New Level 2 (C3PAO) and Level 3 designations are suspended, and existing contracts containing those requirements are being amended to remove them by modification.

What is not suspended is significant:

  • Phase 1 Level 1 and Level 2 self-assessments
  • SPRS score submissions
  • annual affirmations
  • DFARS 252.204-7012 safeguarding obligations

These and the underlying NIST SP 800-171 Rev. 2 requirements all remain fully in force, and contracting officers are still forbidden to award a contract without current CMMC status in SPRS.

The rules themselves (32 CFR Part 170 and DFARS) remain unamended. This is an administrative pause pending the review’s outcome.

In the meantime, there’s one notable shift. With the third-party assessor removed, legal weight has moved onto contractors’ own self-attestations, which are the express target of DOJ’s Civil Cyber-Fraud Initiative. Therefore, “suspended” emphatically does not mean compliance is optional. Expect this answer to change when the task force releases its report.

Is the Department of Defense going to reinstate CMMC Level 2 compliance?

No one knows yet, but the answer is most likely yes, and it should arrive soon. The CMMC Reform Task Force is due to deliver its recommendations to the DoD CIO on or about September 13, 2026, and the outcome could range from a narrowly restructured Phase 2 to a wholesale redesign. DoD officials have declined to rule out ending the program entirely.

That said, the signals lean toward reinstatement in some modified form rather than elimination. Communications from the DoD and prime contractors indicate that the assessment transition is expected to return, though possibly different from what the current rules codified. The task force’s mandate is to recommend a framework that lowers barriers for small and mid-sized businesses and replaces “prohibitive third-party compliance models with scalable, realistic security measures.” We can interpret this as reform language, not repeal language.

Two structural points reinforce this interpretation:

  1. The underlying regulations (32 CFR Part 170 and the DFARS rule) were never amended, and the suspension is a memo, which can be reversed as quickly as it was issued.
  2. Phase 1 self-assessment obligations continued uninterrupted throughout.

 

Worth noting for planning purposes: even after the report lands mid-September, formal determinations may not come until mid-October at the earliest, and possibly not until late 2026 or early 2027.

Should we pursue CMMC Level 2 compliance while the requirements are suspended?

Absolutely. It’s critical to understand that “suspended” overstates the situation. The only thing on hold is the third-party (C3PAO) certification mandate. The substantive compliance obligation never went away. Contractors handling CUI remain contractually bound by DFARS 252.204-7012 to implement all 110 NIST SP 800-171 Rev. 2 controls. They still must submit current SPRS scores and annual affirmations to remain award-eligible.

Contractors also remain subject to government audits, with self-attestations now carrying more legal weight, not less, since inaccurate scores are the express target of DOJ’s Civil Cyber-Fraud Initiative and False Claims Act enforcement.

Meanwhile, prime contractors can still flow requirements down regardless of the DoD-wide pause, and voluntary C3PAO assessments remain available for those wanting a competitive differentiator. Likewise, the reform review is widely expected to return third-party assessment in some form, meaning contractors who pause remediation now risk falling behind when the new timeline emerges. Those who maintain momentum are positioned for award eligibility today and certification later.

CMMC consultancies typically offer practical guidance here: separate certification-specific spend, which can reasonably wait for the task force outcome, from control-implementation spend—which should continue without interruption. Contractors must complete the security work either way.

The takeaway: Don’t pause on CMMC Level 2 certification efforts

Defense contractors must not fall behind in their CMMC compliance efforts. DoD hitting pause on Phase 2 is a welcome breather, giving companies time to work on compliance, rather than a lifting of the requirements. If you need help with CMMC compliance, get in touch with us. We maintain deep expertise in this regulatory framework, and we’ve helped many defense contractors on their journey. Contact us, and let’s take the next step in CMMC compliance today.

Related posts

Ross Filipek is Corsica Technologies’ CISO. He has more than 20 years’ experience in the managed cyber security services industry as both an engineer and a consultant. In addition to leading Corsica’s efforts to manage cyber risk, he provides vCISO consulting services for many of Corsica’s clients. Ross has achieved recognition as a Cisco Certified Internetwork Expert (CCIE #18994; Security track) and an ISC2 Certified Information Systems Security Professional (CISSP). He has also earned an MBA degree from the University of Notre Dame.

Ready to take your next step?

Contact us today to get the outside perspective you need for the next step on your journey.

Contact Us Now →

Moving forward with AI- Corsica Technologies

Table of Contents

💡 EXCLUSIVE Guide: 

CMMC Compliance Cheatsheet

Ready to talk to an expert?

We’ll respond within 1 business day, or you can grab time on our calendar.