
CMMC 2.0 compliance is now a condition of winning and keeping many Department of Defense contracts, and small defense contractors feel it most. If your company touches Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), you need to know which level applies, what to post in SPRS, and what changed when the Department of War suspended Phase 2 in July 2026.
This guide explains the rules as of October 2026: levels, the 110 NIST SP 800-171 requirements, self-assessments versus C3PAO assessments, POA&Ms, costs and a checklist. If you would rather have a team map it to your environment, our IT governance, risk and compliance service runs gap assessments and readiness work for federal suppliers.
This article is general information, not legal advice. Confirm contract-specific obligations with your contracting officer, counsel or assessor.
Key takeaways
- The CMMC Program rule (32 CFR Part 170) took effect December 16, 2024, and the DFARS contract rule took effect November 10, 2025, which started Phase 1.
- On July 13, 2026 the Department of War suspended Phase 2, which was set for November 10, 2026. Phase 1 self-assessment requirements remain in place.
- During the suspension, new solicitations may only require CMMC Level 1 (Self) or Level 2 (Self). DFARS 252.204-7012 and NIST SP 800-171 Rev 2 still apply.
- Level 2 has 110 requirements. A Conditional status needs a score of at least 88, and the POA&M must be closed within 180 days.
- A senior Affirming Official must affirm compliance in SPRS after each assessment and every year, so the score has to be accurate.
Where this guidance comes from. We built this guide from primary sources: the CMMC Program final rule (32 CFR Part 170) in the Federal Register and eCFR, the DFARS CMMC acquisition rule and clauses 252.204-7012, 252.204-7019 and 252.204-7021, the DoD CIO “About CMMC” page, the July 2026 Phase 2 suspension procedures, and NIST’s SP 800-171 publication page. It also reflects our team’s field experience with gap assessments, policy work and managed security for small organizations.
What CMMC 2.0 compliance actually means
“CMMC 2.0” is the name most people use for the streamlined Cybersecurity Maturity Model Certification program. In the regulations it is simply the CMMC Program. Two rules make it real. The program rule, 32 CFR Part 170, was published October 15, 2024 and took effect December 16, 2024. It defines the levels, assessments, scoring and affirmations.
The DFARS acquisition rule was published September 10, 2025 and took effect November 10, 2025. It added clause 252.204-7021 and provision 252.204-7025, which put CMMC into contracts and tell contracting officers to check SPRS before award.
In practice, CMMC 2.0 compliance means you implement the required controls, assess them at the level the contract names, and have a senior official affirm in the Supplier Performance Risk System (SPRS) that you meet them.
Where CMMC stands as of October 2026
The DFARS rule started Phase 1 on November 10, 2025. Under 32 CFR 170.3(e), each later phase was set to start one calendar year after the one before it. Phase 2 would have added Level 2 third-party (C3PAO) assessments as a condition of award on November 10, 2026.
On July 13, 2026, the Department of War announced an immediate suspension of the Phase 2 requirements and a 60-day review of the program. The DoD CIO site states that all Phase I self-assessment requirements remain in place and that implementation is paused in Phase 1.
The implementing procedures are specific. During the suspension, program offices may only designate CMMC Level 1 (Self) or Level 2 (Self). They may not designate Level 2 (C3PAO) or Level 3 (DIBCAC). Existing contracts with those requirements are to be modified at the next option or administrative modification. DFARS 252.204-7012 remains in effect, and NIST SP 800-171 Rev 2 compliance will be enforced through self-assessments and select government-led assessments.
As of October 2, 2026, we found no Federal Register amendment to either CMMC rule and no published new Phase 2 date. The procedures say further guidance will follow the CIO’s review. Check the DoD CIO CMMC pages before relying on any date below.
| Phase | Start date in the rules | What the rules call for | Status as of October 2026 |
|---|---|---|---|
| Phase 1 | November 10, 2025 | Level 1 (Self) or Level 2 (Self) as a condition of award | In effect |
| Phase 2 | November 10, 2026 | Adds Level 2 (C3PAO) for applicable awards; Level 3 at DoD discretion | Suspended July 13, 2026; no new date published |
| Phase 3 | One year after Phase 2 | Level 2 (C3PAO) for all applicable awards and options; Level 3 for applicable awards | Rule text unchanged; depends on review outcome |
| Phase 4 | One year after Phase 3 | CMMC in all applicable solicitations and contracts, including option periods | Rule text unchanged; depends on review outcome |
FCI vs CUI: which CMMC level applies to you
Your level follows the information, not your company size. DFARS defines Federal Contract Information as information, not intended for public release, that is provided by or generated for the government under a contract to develop or deliver a product or service. Public website content and simple payment transactions do not count.
Controlled Unclassified Information is defined in 32 CFR 2002.4(h). It is information that law, regulation or policy requires or permits to be handled with safeguarding or dissemination controls.
Under the flow-down rule in 32 CFR 170.23, a subcontractor that handles only FCI needs Level 1 (Self). A subcontractor that handles CUI needs at least Level 2 (Self). If the prime contract requires Level 2 (C3PAO) or Level 3, a subcontractor handling CUI needs Level 2 (C3PAO). Primes must flow the right level down to every tier.
CMMC levels 1, 2 and 3 compared
| Level 1 | Level 2 | Level 3 | |
|---|---|---|---|
| Protects | FCI | CUI | CUI, with enhanced protections |
| Requirements | 15 from FAR 52.204-21 | 110 from NIST SP 800-171 Rev 2 | The 110, plus 24 selected from NIST SP 800-172 |
| Who assesses | You (self) | You (self) or a C3PAO, as the contract says | DCMA DIBCAC, after a Final Level 2 (C3PAO) |
| How often | Every year | Every 3 years | Every 3 years |
| POA&M allowed | No | Yes, limited, closed in 180 days | Yes, limited, closed in 180 days |
| Affirmation in SPRS | After each assessment and yearly | After each assessment and yearly | After each assessment and yearly |
Level 1: basic safeguarding of FCI
Level 1 covers the 15 requirements in FAR 52.204-21, such as limiting access to authorized users, sanitizing media and updating malware protection. All must be met, and you post a self-assessment in SPRS every year.
Level 2: the 110 NIST SP 800-171 requirements
Level 2 maps to the 110 requirements in NIST SP 800-171 Rev 2. NIST has since published Rev 3, but the CMMC rule still references Rev 2, so build to Rev 2 for now.
Level 3: enhanced requirements
Level 3 adds 24 enhanced requirements from NIST SP 800-172, assessed by the government. It cannot be designated while Phase 2 is suspended.
Self-assessment vs C3PAO assessment
In a self-assessment, you score yourself against the NIST SP 800-171A objectives, enter results in SPRS, and your Affirming Official attests to them. A C3PAO assessment is performed by an authorized third-party organization that submits results to the government’s CMMC eMASS system.
The suspension means new DoD solicitations should not require a C3PAO assessment right now. That is not a pause on security. The requirements are the same 110 controls, the government can still run its own assessments, your affirmation is a representation to the government, and DFARS 252.204-7012 still requires reporting cyber incidents to DoD within 72 hours.
Primes may still ask suppliers for more, so read your subcontract terms carefully.
Not sure where your environment stands today? Start with our free cyber risk check, or request a CMMC gap assessment online and we will scope it with you.
SPRS scores, POA&Ms and affirmations
The Level 2 score starts at 110. Each requirement that is not met subtracts 5, 3 or 1 point, depending on how much risk the gap creates, and the score can go negative. DFARS 252.204-7019 separately requires a current NIST SP 800-171 assessment in SPRS that is not more than three years old for covered systems.
A plan of action and milestones (POA&M) lets you reach a Conditional Level 2 status with some gaps open, but only within tight limits set by 32 CFR 170.21:
- Your score must be at least 80 percent of the requirements, which is 88 of 110.
- Only 1-point requirements can go on the POA&M. The single exception is CUI encryption that is in place but not FIPS-validated.
- Six requirements can never be deferred, including the system security plan (CA.L2-3.12.4) and several physical access controls.
- Every POA&M item must be closed and confirmed by a closeout assessment within 180 days, or the Conditional status expires.
Under 32 CFR 170.22, a senior Affirming Official must affirm continuing compliance after each assessment, after POA&M closeout and every year. DFARS 252.204-7021 also requires you to give the contracting officer a CMMC unique identifier (UID) for each system handling FCI or CUI, and to make sure subcontractors affirm before award.
What does CMMC 2.0 compliance cost?
The best public numbers come from the 2024 final rule’s regulatory impact analysis. They cover assessment and affirmation only, because DoD assumed the controls were already required and in place.
| Activity (small entity) | DoD estimate per assessment | Three-year estimate |
|---|---|---|
| Level 1 self-assessment and affirmation | $5,977 (every year) | Not stated as a three-year figure |
| Level 2 self-assessment and affirmation | $34,277 | $37,196 with two annual reaffirmations |
| Level 2 C3PAO assessment and affirmation | $101,752 | $104,670 with two annual reaffirmations |
These are 2024 government estimates, not quotes, and market forces set C3PAO pricing. For most small contractors the bigger cost is closing gaps first. The main cost drivers are:
- Scope. The more systems, people and locations that touch CUI, the more you have to secure and document.
- Starting score. A company near 110 pays for documentation and evidence. A company with a low score pays for remediation projects.
- Identity and access. Multifactor authentication, least privilege and account reviews often need new tools or identity and access security work.
- Cloud choices. A cloud service that stores CUI must meet the FedRAMP requirements in DFARS 252.204-7012, which can force a platform change.
- Logging and response. Audit logging, log review and cyber incident response need people or a managed service to run them.
- Ongoing upkeep. Annual affirmations, re-assessments and evidence collection are recurring costs, not one-time projects.
CMMC 2.0 compliance readiness checklist
Use this sequence for Level 1, Level 2 (Self) or a future C3PAO requirement.
- Read your contracts and solicitations for DFARS 252.204-7012, -7019, -7021 and -7025 and any prime flow-down terms.
- Identify every place FCI and CUI enter, live and leave your company, including email, file shares, laptops and cloud apps.
- Define the assessment scope. Isolating CUI in a smaller enclave can shrink what must be secured and assessed.
- Score yourself honestly against all 110 requirements using the NIST SP 800-171A objectives.
- Write or update the system security plan so it describes how the environment really works.
- Fix the 5-point and 3-point gaps first, then the items that can never go on a POA&M.
- Build a POA&M only for allowed items, with owners and dates that fit inside 180 days.
- Collect evidence as you go, and document every external service provider and cloud service in your system security plan.
- Enter results in SPRS, have your Affirming Official affirm, and set a calendar for annual affirmations and re-assessment.
How long does CMMC readiness take?
It depends on your starting score, scope and tooling. For example, consider a hypothetical 20-person machine shop that already uses multifactor authentication and managed antivirus. It may mostly need scoping, a system security plan and evidence. A shop storing CUI in personal email will likely need a platform change first. Either way, plan around the 180-day POA&M clock, which effort cannot extend.
How Honeybadger Solutions helps with CMMC 2.0 compliance
Honeybadger Solutions is a veteran-owned, service-disabled veteran-owned small business (SDVOSB) based in Casa Grande, Arizona. We deliver cyber and compliance work nationwide. We are not a C3PAO and we do not certify anyone. Our role is to get you ready and keep you ready, so you can affirm with confidence. Our SDVOSB government contracting page explains how we work with federal buyers.
- Gap assessment and roadmap. Through our governance, risk and compliance service, we measure your current state against NIST SP 800-171 and CMMC and return a prioritized remediation roadmap.
- Policies and the system security plan. We write policies that match how your company actually operates, so an assessor can verify them.
- Readiness and evidence. We handle control implementation, evidence design, continuous control monitoring and a pre-assessment review before you self-assess or engage an assessor.
- Security leadership. A virtual CISO (vCISO) provides fractional leadership for strategy, risk and CMMC compliance decisions.
- Managed security. Our managed cyber security (MSSP) team provides 24/7 monitoring and compliance support, so the controls you affirm keep running. Our MSSP guide explains what that service includes.
The fastest way to start is online. Submit a service request online for a CMMC gap assessment, or book a consultation online to talk through your contracts and scope first.
Why the online intake is faster than a phone call: it takes about two minutes, and your answers are routed straight to the specialist team that handles your kind of matter, whether that is cyber and forensics, investigations or field security. That team sees the full picture before it replies, so you skip phone tag and get a real answer and next steps sooner. If it cannot wait for business hours, use the urgent intake form, which is read seven days a week.
Frequently asked questions
Is CMMC 2.0 compliance still required after the July 2026 suspension?
Yes, in part. The July 13, 2026 suspension stopped the move to C3PAO and DIBCAC assessments. Phase 1 stays in force, so solicitations can still require Level 1 (Self) or Level 2 (Self), and DFARS 252.204-7012 still requires NIST SP 800-171.
What SPRS score do I need for a Conditional Level 2 status?
Under 32 CFR 170.21, you need at least 88 of 110 (80 percent). Only limited 1-point items can go on the POA&M, and every open item must be closed within 180 days.
Do I need CMMC if I only handle Federal Contract Information?
If a DoD contract will put FCI on your systems, expect CMMC Level 1 (Self): all 15 FAR 52.204-21 requirements, a yearly self-assessment and a yearly affirmation in SPRS. No POA&M is allowed.
Can a small business do a CMMC Level 2 self-assessment without outside help?
It is allowed, though DoD’s cost estimate assumed most small businesses would use an external service provider. The hard part is scoping correctly, writing an accurate system security plan and scoring honestly.
How much does CMMC 2.0 compliance cost a small contractor?
The 2024 final rule estimated $5,977 a year for Level 1, $34,277 for a Level 2 self-assessment and $101,752 for a Level 2 C3PAO assessment for a small entity. Remediation costs are extra.
Is Honeybadger Solutions a C3PAO?
No. We do not issue CMMC certifications. We help with readiness: gap assessment, policies, remediation, evidence and managed security.
Sources and further reading
- Cybersecurity Maturity Model Certification (CMMC) Program final rule, 89 FR 83092 (Oct. 15, 2024) — Program rule, effective date, level table and small-entity cost estimates.
- eCFR: 32 CFR Part 170, CMMC Program — Phases, scoring, POA&M limits, affirmations and subcontractor flow-down.
- DFARS CMMC acquisition final rule, 90 FR 43560 (Sept. 10, 2025) — November 10, 2025 effective date and DFARS 252.204-7021 and -7025.
- DoD CIO: About CMMC — Phase 2 suspension notice and current level descriptions.
- Department of War: CMMC Procedures During Phase II Suspension (July 2026) — Self-assessment-only designations, contract modifications and 60-day review.
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting — NIST SP 800-171 obligation and 72-hour incident reporting.
- DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements — Current SPRS assessment not more than three years old.
- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems — The 15 Level 1 safeguarding requirements.
- NIST SP 800-171 Rev. 2 — The 110 Level 2 requirements and their status relative to Rev. 3.
- eCFR: 32 CFR Part 2002, Controlled Unclassified Information — Definition of CUI.
- Supplier Performance Risk System (SPRS) — Where scores and affirmations are posted.
Written and reviewed by the Honeybadger Solutions security and investigations team, a veteran-led Arizona firm (Arizona DPS private investigation agency license No. 1759795). Facts checked against the cited sources on October 2, 2026. This article is general information, not legal advice.
Browse by topic
Security guard services · Private investigations · Cybersecurity · Digital forensics · Financial fraud investigation · Executive protection · All articles