If you sell to the Department of Defense, CMMC 2.0 is no longer a distant compliance problem. It is a gate you have to clear to keep bidding.
Quick answer: CMMC 2.0 is the DoD program that checks whether contractors actually protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). It has three levels, and most small contractors that handle CUI need Level 2, which maps to the 110 requirements in NIST SP 800-171 Rev 2. Phase 1 started November 10, 2025, so self-assessments are already showing up in DoD solicitations.
The Cybersecurity Maturity Model Certification program sets the cybersecurity requirements defense contractors must meet, and its rules are now written into DoD contracts. The program rule at 32 CFR Part 170 took effect on December 16, 2024, and the DFARS acquisition rule that puts CMMC into contracts took effect on November 10, 2025. That date started Phase 1 of the rollout.
This guide explains what small defense contractors need to know: the levels, what Level 2 really requires, how it connects to NIST SP 800-171, where the timeline stands after DoD paused Phase 2 in July 2026, what DoD itself estimates CMMC will cost, and how to prepare without a dedicated security team.
CMMC 2.0 is the Department of Defense program that verifies contractors protect sensitive defense information on their own systems. It applies to companies that handle Federal Contract Information or Controlled Unclassified Information under a DoD contract. Instead of trusting a contractor's word, CMMC requires a self-assessment, a third-party assessment or a government assessment, depending on the level.
The goal is to protect the defense industrial base, the network of companies that supply the U.S. military, from attackers who go after the weakest link. Adversaries do not need to breach the DoD directly if they can break into a small subcontractor holding the same data. Self-attestation alone left too many gaps, so CMMC adds verification on top of rules contractors were already supposed to follow.
CMMC 2.0 replaced the original CMMC 1.0 model, which had five levels, extra CMMC-unique maturity processes and no self-assessment option. Small businesses argued it would price them out of defense work. The rebuilt program has three levels, drops the extra practices and aligns directly with existing federal standards: FAR 52.204-21 at Level 1 and NIST SP 800-171 at Level 2.
For a defense contractor, CMMC is now a condition of award. When a solicitation names a CMMC level, you need that status in place at the time of award, and you must keep it for the life of the contract. The contract clause behind this is DFARS 252.204-7021.

CMMC 2.0 has three levels, and the type of information you handle decides which one applies. Level 1 covers FCI and requires 15 basic safeguarding requirements. Level 2 covers CUI and requires the 110 NIST SP 800-171 Rev 2 requirements. Level 3 covers CUI on the most sensitive programs and adds 24 requirements from NIST SP 800-172.

Level 1 is basic cyber hygiene for companies that handle only FCI, the non-public information provided by or generated for the government under a contract. It requires the 15 safeguarding requirements in FAR 52.204-21, such as limiting system access to authorized users, sanitizing media and keeping antivirus up to date. You self-assess every year and a senior official affirms the result in SPRS. No requirement can be left open on a plan of action at Level 1: all 15 must be met.
Level 2 is where most contractors land, because so much DoD work involves CUI. It requires all 110 requirements in NIST SP 800-171 Rev 2. The contract will say whether you need Level 2 (Self), a self-assessment every three years, or Level 2 (C3PAO), a certification assessment by an authorized third-party assessment organization every three years. Either way, a senior official must affirm continued compliance every year.
Level 3 is for contractors on the DoD's highest-priority programs. You must first hold a final Level 2 (C3PAO) status, then meet 24 additional requirements selected from NIST SP 800-172. The assessment is done by the government, through the Defense Contract Management Agency's DIBCAC, not by a commercial assessor. Few small businesses will need it, but the levels stack: Level 2 includes Level 1, and Level 3 includes both.
CMMC Level 2 does not invent new controls. It uses the 110 security requirements in NIST SP 800-171 Revision 2, the same standard DoD has required for years through DFARS clause 252.204-7012. What CMMC adds is proof: an assessment that confirms the controls are in place before you can win Level 2 work.
The 110 requirements are organized into 14 families, including access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, media protection, physical protection, risk assessment, system and communications protection, and system and information integrity. Each requirement has assessment objectives, and an assessor checks every one. A control that is written in a policy but not working in practice counts as not met.

NIST published Revision 3 of SP 800-171 in May 2024, but DoD has not moved to it yet. In May 2024 DoD issued class deviation 2024-O0013, which ties DFARS 252.204-7012 to Revision 2, and the CMMC rule itself incorporates Revision 2. So build your program and your assessment evidence against the 110 Rev 2 requirements, and watch for a future rule before switching to Rev 3.
For contractors already working on NIST SP 800-171, this is good news. The work you have done on those 110 controls carries straight into CMMC Level 2 readiness. Our NIST 800-171 compliance checklist walks through each control family, and our CUI guide explains what counts as CUI and how it should be marked and handled.

CMMC rolls out in four phases, each starting one year after the last. Phase 1 began November 10, 2025, when the DFARS rule took effect, and covers Level 1 and Level 2 self-assessments. Phase 2 was set to add third-party Level 2 certification on November 10, 2026, but DoD paused it in July 2026 for a review.
Here is how the phases are written in 32 CFR 170.3(e):
On July 13, 2026, DoD's Chief Information Officer suspended the planned Phase 2 move to mandatory third-party Level 2 assessments and launched a 60-day review of the program, as reported by Federal News Network. Phase 1 self-assessment requirements continue, and the underlying obligations have not gone away: DFARS 252.204-7012 and NIST SP 800-171 Rev 2 still apply to contracts that include them, and CMMC self-assessment results and affirmations are still entered in SPRS.
As of this writing, DoD has not published final changes from that review. Because the dates may shift again, treat the phase schedule above as the rule on the books and check the DoD CIO CMMC page for the current status before you plan around a specific deadline. What has not changed is the lead time: closing gaps against 110 requirements takes months, so a pause is a chance to get ready, not a reason to stop.
The only official CMMC cost figures come from DoD's regulatory analysis in the 32 CFR Part 170 final rule. For a small business, DoD estimates about $5,977 per year for Level 1, $37,196 over three years for a Level 2 self-assessment, and $104,670 over three years for a Level 2 C3PAO assessment.
Those numbers need careful reading. DoD assumes contractors have already implemented the security requirements, because FAR 52.204-21 and DFARS 252.204-7012 already require them. So the estimates cover planning, the assessment itself and the annual affirmations only. They do not include the cost of fixing gaps, which is where most small businesses spend the most.
Your actual spend depends far more on your starting point than on the assessment fee. The main cost drivers are:
For a small shop, those costs sting. But losing access to DoD work costs more, and the same controls lower the chance of a breach that could do real damage to the business.
Preparing for CMMC means finding out which level your contracts need, scoping where FCI and CUI live, assessing yourself honestly against the requirements, recording your score in SPRS, and closing gaps before a solicitation forces your hand. For Level 2 C3PAO work, it also means booking an authorized assessor early, since capacity is limited.
Start with your pipeline. Look at the DoD opportunities you plan to bid and note which ones carry CMMC requirements and at what level. You can search SAM.gov opportunities in Polaris by agency, NAICS code and set-aside to see what is coming up in your market, then plan your CMMC work around those dates. Knowing the government procurement cycle helps you time this.
Map which systems, people, facilities and service providers process, store or transmit FCI or CUI. Everything in that boundary is assessed. Limiting where sensitive data flows can shrink your scope and your cost dramatically. Include your cloud providers and managed service providers, because the requirements reach them too.
Assess yourself against every requirement for your level, using the official assessment objectives. Most firms find that controls they assumed were in place are only partly working. Document your environment and how each requirement is met in a System Security Plan. Assessors will read it and test whether your written procedures match reality.
Level 1 and Level 2 self-assessment results and annual affirmations are entered in the Supplier Performance Risk System (SPRS), which contracting officers check before award. A Level 2 score is out of 110, and the record includes your assessment scope, CAGE codes and any POA&M use. Accuracy matters: a senior company official is affirming the result to the government.
CMMC limits how far a Plan of Action and Milestones (POA&M) can carry you. At Level 2 you need at least 88 of 110 points (80 percent) to receive a Conditional status, and only certain lower-weighted requirements may be left open. Every open item must be fixed and verified in a closeout assessment within 180 days, or the conditional status expires. At Level 1 no POA&M is allowed at all.
Fix the highest-value gaps first: access control, multi-factor authentication, network segmentation, encryption and logging. Turn logging on early so you can show controls have been running over time, not installed the week before the assessment. Train your people, because assessors interview staff, and a control nobody operates correctly is a control you fail.
Level 2 (C3PAO) assessments are performed by Certified Third-Party Assessment Organizations authorized by the Cyber AB, the CMMC accreditation body, which lists them in its CMMC Marketplace. Assessment slots can fill up when demand spikes, so contact assessors well before a bid needs the certificate. Many run a readiness review first, which is your chance to fix issues before the formal assessment.

CMMC does not stop at the prime. Primes must flow the requirement down to subcontractors that handle FCI or CUI, at the level that matches the information each sub touches. A prime will not risk its own award on a sub that cannot show the right status, so for small firms that mainly subcontract, CMMC readiness matters just as much. Our guide on who is responsible for protecting CUI covers this shared responsibility.
Readiness can also be a selling point. A small business with its CMMC status in place is a safer teaming partner, and that shows in RFP responses that have to state your compliance posture. When you look for primes or subs, OryonIQ's Orbit suggests teaming partners and explains why each match fits, and Ask Oryon answers FAR and DFARS questions, such as what a CMMC clause in a solicitation means, in plain English. For more on building those relationships, read why your network matters in GovCon.
Yes, in part. Phase 1 began November 10, 2025, so many DoD solicitations now require a Level 1 or Level 2 self-assessment entered in SPRS. In July 2026 DoD paused the Phase 2 requirement for third-party Level 2 certification while it reviews the program, so check dodcio.defense.gov for the current status.
Level 1 covers Federal Contract Information and requires 15 basic safeguarding requirements with an annual self-assessment. Level 2 covers Controlled Unclassified Information and requires the 110 requirements of NIST SP 800-171 Rev 2, by self-assessment or C3PAO assessment. Level 3 adds 24 NIST SP 800-172 requirements and a government-led assessment.
DoD's own estimates for small entities are about $5,977 for a Level 1 self-assessment, $37,196 over three years for a Level 2 self-assessment, and $104,670 over three years for a Level 2 C3PAO assessment. These figures cover the assessment and affirmations only, not the cost of implementing missing controls.
You need at least 88 of 110 points (80 percent) to receive a Conditional Level 2 status, and only certain requirements may be placed on a POA&M. Every open item must be fixed and verified in a closeout assessment within 180 days, or the conditional status expires.
Sometimes. The contract sets whether Level 2 (Self) or Level 2 (C3PAO) applies. Self-assessment is allowed for some CUI contracts, with results posted in SPRS every three years and an annual affirmation by a senior company official. Higher-priority CUI work requires a certified third-party assessment.
Yes. Primes must flow CMMC requirements down to subcontractors that process, store or transmit FCI or CUI, at the level that matches the information the sub handles. A sub that only touches FCI needs Level 1, while one that handles CUI needs the appropriate Level 2 status.

Are you curious about the networking events near you? Together we can expand your network and watch your pipeline exponentially grow.