← Custodia

CMMC 2.0 Explained: What Changed and What It Means (2026)

CMMC 2.0 in plain English: what it is, how it changed from the original CMMC 1.0, the three levels, self assessment vs C3PAO, and where the rollout actually stands after DoD suspended Phase 2 in July 2026.

By David Fuentes· Compliance Officer, CustodiaJuly 5, 20268 min readReviewed by a Cyber AB Registered Practitioner

If you read about CMMC a few years ago and found five levels and a mandatory audit for everyone, that was CMMC 1.0. It is gone. The version that actually applies to your contracts is CMMC 2.0, and it is meaningfully simpler. Here is what it is and what changed.

What CMMC 2.0 is

CMMC 2.0 is the current version of the Cybersecurity Maturity Model Certification, the DoD program that verifies its contractors protect federal information. It was announced in 2021 and finalized in the 2024 rules. The goal was to keep the security bar high while cutting the complexity and cost that made the original model unworkable for small businesses.

What changed from CMMC 1.0

CMMC 1.0CMMC 2.0
Levels53
AssessmentThird party for nearly everyoneSelf assessment for L1 and many L2 contracts
Maturity processesExtra process maturity requirementsRemoved; aligned to NIST SP 800-171
Level 2 standardCustom control setThe 110 requirements of NIST SP 800-171
POA&MsNot allowedAllowed at L2 under the 88 rule

The headline changes: fewer levels, self assessment restored for a large share of contractors, and Level 2 mapped cleanly onto a standard that already existed. For a small contractor, CMMC 2.0 is both cheaper and clearer than what came before.

The three levels

  1. Level 1: Federal Contract Information (FCI). 15 safeguarding requirements. Self assessed and affirmed annually in SPRS.
  2. Level 2: Controlled Unclassified Information (CUI). The 110 requirements of NIST SP 800-171. Self assessed or C3PAO assessed.
  3. Level 3: the most sensitive programs. Level 2 plus a subset of NIST SP 800-172, assessed by the government.

Which level applies to you is decided entirely by the information your contracts hand you. See do you actually handle CUI for the test.

The rollout timeline

  • Dec 16, 2024: the CMMC Program Rule (32 CFR Part 170) took effect.
  • Nov 10, 2025: the DFARS acquisition rule that puts CMMC into contracts took effect (Phase 1). Level 1 and Level 2 self assessments become a condition of award in applicable solicitations.
  • Jul 13, 2026: DoD suspended Phase 2 and opened a 60 day top to bottom review of the CMMC program, per a memo signed by DoD Chief Information Officer Kirsten Davies. The memo cites prohibitive compliance costs, severe shortages in third-party assessment capacity, and complex regulatory timelines that are pushing small businesses out of DoD contracts. A CMMC Reform Task Force will deliver findings and recommendations within 60 days. Responses to the associated RFI are due by 12pm ET on Friday, August 14, 2026.
  • Nov 10, 2026: Phase 2 was scheduled to begin here, phasing C3PAO certification requirements into applicable Level 2 solicitations. That date is suspended and is no longer an operative deadline.

Follow the moving pieces on the State of CMMC timeline.

What it means for you

For most small defense contractors, CMMC 2.0 is good news: the path is shorter than 1.0 promised, and Level 1 is fully self serve. The Phase 2 suspension does not change the job. Phase 1 self assessment requirements are in force today, your contracts still carry the requirement, and primes still ask. If you handle CUI, the obligations underneath Level 2, DFARS 252.204-7012 and NIST SP 800-171, apply either way, so readiness work keeps its value. What the suspension removed is the deadline pressure, not the requirement. You still have to know your level, and getting ready, especially for Level 2, takes months.

Frequently asked questions

What is CMMC 2.0?

CMMC 2.0 is the current version of the Cybersecurity Maturity Model Certification, the Department of Defense program that verifies contractors protect federal information. Announced in 2021 and finalized in the 2024 rules, it streamlined the original model to three levels, aligned Level 2 directly with NIST SP 800-171, and restored self assessment for many contractors. It is the version now phasing into DoD contracts.

How is CMMC 2.0 different from CMMC 1.0?

CMMC 1.0 had five maturity levels and required a third-party assessment for essentially everyone. CMMC 2.0 reduced that to three levels, dropped the extra maturity processes, aligned Level 2 exactly with the 110 requirements of NIST SP 800-171, and allowed self assessment for Level 1 and for many Level 2 contracts. It is simpler and less costly for most small contractors.

What are the three levels of CMMC 2.0?

Level 1 covers Federal Contract Information (FCI) with 15 safeguarding requirements, self assessed. Level 2 covers Controlled Unclassified Information (CUI) with the 110 requirements of NIST SP 800-171, self assessed or assessed by a C3PAO. Level 3 is for the most sensitive programs and is government assessed against Level 2 plus a subset of NIST SP 800-172.

When does CMMC 2.0 take effect?

It is phasing in, and it is already in effect. The program rule (32 CFR Part 170) took effect December 16, 2024, and the acquisition rule that puts CMMC into contracts took effect November 10, 2025. Since then, Phase 1 solicitations can require Level 1 and Level 2 self assessments as a condition of award, and that remains in force today. Phase 2, which would have added C3PAO certification requirements for applicable Level 2 contracts starting November 10, 2026, was suspended on July 13, 2026 pending a 60 day DoD review of the program. Phase 2 is paused, not cancelled, and November 10, 2026 is no longer an operative deadline.

Does CMMC 2.0 require third-party assessment?

Not for everyone, and not today for most contractors. Level 1 is always self assessed. Under Phase 1, which is in force now, Level 2 solicitations rely on a self assessment filed in SPRS with an annual affirmation. The phase that would have pushed most Level 2 contracts to certification by an accredited C3PAO was suspended on July 13, 2026, so read each solicitation for what it actually requires. Restoring self assessment for a large share of contractors was one of the biggest changes from CMMC 1.0.

Keep reading
  1. CMMC Level 2
    POA&M Explained: What It Is and How It Works in CMMC (2026)

    A POA&M is your written plan to close a security gap by a deadline. At CMMC Level 1 you get zero of them. At Level 2 they are allowed, but only under strict rules. Here is how it actually works.

    Read →
  2. CMMC Level 1
    CMMC Level 1 vs Level 2: Which One Do You Actually Need? (2026 Plain-English Guide)

    Most small defense contractors are Level 1, not Level 2, but the wrong answer here costs you a year and tens of thousands of dollars. Here's the single question that decides it.

    Read →
  3. Frameworks
    FAR 52.204-21 vs NIST 800-171 vs CMMC Level 1 vs Level 2: A Plain-English Comparison

    Four overlapping frameworks, one decision: which one do you actually have to comply with? A side-by-side comparison for small DoD contractors.

    Read →
Free · Every Monday

Get the federal bids a small business can win, in your inbox.

The Monday Bid Digest: brand-new SAM.gov solicitations matched to your NAICS, pre-filtered to Level 1 fit, with the CMMC gate called out on every one. Two minutes, no spam.

Get the Monday Bid Digest
Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements, no signup, no card. If you like what you see, the 30 day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

30 day free trial · No credit card required · $458.33/mo with a Custodia Officer included ($5,000/yr on annual, save $500 a year)

Stuck on CMMC? Ask Charlie, or book an officer.