The Department of War suspended CMMC Phase II on July 13, 2026, but that does not mean the requirements went away. Phase I self-assessment obligations remain in force right now, and the three-level structure that governs the Cybersecurity Maturity Model Certification program is still the standard every defense contractor will eventually be measured against.
Here is what you need to know before you do anything else:
- Level 1 requires 15 basic safeguarding practices from FAR clause 52.204-21, with annual self-assessment and affirmation in SPRS.
- Level 2 requires all 110 security requirements from NIST SP 800-171 Revision 2, assessed either by self-assessment or by a Certified Third-Party Assessment Organization (C3PAO).
- Level 3 layers a selected subset of NIST SP 800-172 controls on top of Level 2, reserved for programs handling the most sensitive controlled unclassified information (CUI).
Pro Tip: Treat the Phase II pause as a scoping and gap-analysis window, not a reprieve. When third-party certification requirements resume, contractors with a stable System Security Plan will move through assessments faster than those starting from zero.
Key Takeaways
CMMC 2.0 requires 15 FAR 52.204-21 controls at Level 1, all 110 NIST SP 800-171 Rev 2 controls at Level 2, and a NIST SP 800-172 subset at Level 3, with Phase I self-assessment obligations still active despite the Phase II suspension.
| Point | Details |
|---|---|
| Phase II is paused, not gone | DoD suspended Phase II certification requirements on July 13, 2026, but Phase I self-assessment still applies. |
| Know your exact count | Level 1 has 15 requirements, Level 2 has 110, and Level 3 adds a NIST SP 800-172 subset. |
| POA&Ms have limits | Where permitted, POA&M items must close within 180 days; Level 1 allows no POA&Ms at all. |
| Scope drives cost | Isolating CUI into a segmented enclave shrinks the assessed control set and audit time. |
| Use the pause productively | Mindpodtech's free technology assessment builds a prioritized 90-day plan while certification demand is paused. |
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Table of Contents
- What Are CMMC 2.0 Requirements, and Who Sets Them?
- CMMC Levels Explained: Exact Requirement Counts by Level
- How Are CMMC Assessments Scored, and How Often Are They Required?
- What Are the 14 CMMC Domains, and How Do You Scope an Assessment?
- Which Contracts Require CMMC, and What Happens to Subcontractors?
- What Should Contractors Do During the Phase II Pause?
- Get a Prioritized Compliance Plan Before Phase II Resumes
- Sources
- FAQ
What Are CMMC 2.0 Requirements, and Who Sets Them?
CMMC 2.0 is not a standalone rulebook. It is a certification framework that verifies contractors already meet cybersecurity obligations spelled out elsewhere: FAR 52.204-21 for basic safeguarding, NIST SP 800-171 Rev 2 for protecting CUI, and select NIST SP 800-172 enhanced controls for high-value programs. The CISA program summary describes this as a deliberate consolidation. CMMC 1.0 had five levels and its own maturity processes; CMMC 2.0 dropped that complexity and aligned tightly with standards the defense industrial base already had to follow under DFARS 252.204-7012.
The legal backbone sits in 32 CFR Part 170, the CMMC program rule, and the acquisition-side clauses that will appear in DFARS. Bookmark these four resources now:
- The DoD CIO CMMC homepage for program status and announcements.
- The CMMC Model Overview for domain-to-requirement mapping.
- The CMMC Assessment Guide – Level 2 for assessment objectives and evidence expectations.
- SPRS entry guidance for recording self-assessment scores and affirmations.
CMMC Levels Explained: Exact Requirement Counts by Level
Knowing your level determines everything else: your budget, your assessment path, and how much of your network falls inside scope. The mapping is fixed by rule, not open to interpretation.
Level 1 applies when you only handle Federal Contract Information (FCI), not CUI. It maps to the 15 basic safeguarding requirements in FAR 52.204-21: things like limiting system access to authorized users and sanitizing media before disposal. Level 1 requires annual self-assessment with no third-party involvement, and — critically — no Plan of Action and Milestones (POA&M) is permitted. You either meet all 15 requirements or you do not.
Level 2 applies once CUI enters your environment. The 110 requirements are identical to NIST SP 800-171 Rev 2, no additions, no subtractions. Depending on contract sensitivity, you will either self-assess every three years with annual affirmation, or undergo certification by a C3PAO.
Level 3 builds on Level 2 by adding a curated set of NIST SP 800-172 enhanced requirements, assessed by the Defense Contract Management Agency's DIBCAC. This level is reserved for the highest-priority programs and is not something most subcontractors will encounter.
| Level | Authoritative Standard | Requirement Count | Typical Assessment |
|---|---|---|---|
| Level 1 | FAR 52.204-21 | 15 | Annual self-assessment |
| Level 2 | NIST SP 800-171 Rev 2 | 110 | Self-assessment (3-year) or C3PAO certification |
| Level 3 | NIST SP 800-172 (subset) | Selected enhanced controls | DIBCAC government-led assessment |
"Meeting the level" does not always mean a perfect scorecard. The final rule sets a minimum passing score for Level 2 and 3 with limited, time-bound POA&Ms permitted for lower-weighted controls. Certifications, once granted, carry a three-year validity window before reassessment.
How Are CMMC Assessments Scored, and How Often Are They Required?
Assessment cadence depends on level and path. Level 1 contractors self-assess annually. Level 2 contractors on the self-assessment track do so every three years, with an annual affirmation filed in between confirming continued compliance. Level 2 contractors on the certification track undergo a full C3PAO assessment, also valid for three years. Level 3 assessments are conducted directly by DIBCAC, the government's own assessment arm, reflecting the sensitivity of what those programs protect.
- Every score, self-assessed or certified, gets logged in the Supplier Performance Risk System.
- A senior company official must submit an annual affirmation attesting the score still reflects reality, not just the year it was recorded.
- Where POA&Ms are permitted, the final rule requires closeout within 180 days, and "conditional" certification status expires if that deadline slips.
Here is the timeline that matters most right now. Phase 1 began November 10, 2025, rolling self-assessment requirements into new solicitations. Phase 2, which would have introduced mandatory C3PAO certification for many Level 2 contracts, was scheduled for November 10, 2026. On July 13, 2026, the Department of War suspended Phase II and launched a comprehensive program review. Third-party certification demand is paused, but Phase 1 self-assessment obligations were explicitly left untouched. If you assumed the suspension bought you a full pass, it did not.
What Are the 14 CMMC Domains, and How Do You Scope an Assessment?
CMMC organizes its requirements into 14 domains that map directly onto the NIST SP 800-171 Rev 2 control families: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity.
Scope, not just domain count, drives cost. You need to identify every asset that processes, stores, or transmits CUI, distinguish those from Contractor Risk Managed Assets, and decide whether you are scoring your entire enterprise network or a defined enclave.
Pro Tip: Isolate CUI-handling systems into a dedicated, segmented enclave rather than spreading CUI across your whole network. Narrowing the boundary shrinks the number of systems pulled into the 110-control assessment and cuts both audit time and remediation cost.

Which Contracts Require CMMC, and What Happens to Subcontractors?
Solicitations will state the minimum CMMC status required for award, and that requirement triggers the moment a contractor handles FCI or CUI on a nonfederal system. This is not limited to primes.
- Primes must flow applicable CMMC clauses down to subcontractors and confirm those subcontractors can meet and affirm the required level in SPRS.
- A subcontractor that cannot meet its flowed-down level can knock the entire team out of award eligibility, not just its own piece of the work.
- Contracts commonly tie option-period exercise to maintained certification status, and expired conditional status or an unresolved POA&M can trigger standard contract remedies, including loss of award.
What Should Contractors Do During the Phase II Pause?
Use the suspension as a working window, not a waiting room. A staged plan keeps remediation manageable and prevents a scramble when certification demand returns.
First 30 days:
- Identify every system that touches CUI or FCI and assign a single accountable owner.
- Run a lightweight gap analysis against the NIST SP 800-171 Rev 2 controls.
- Confirm your organization's SPRS access and review your last submitted score.
Days 31 to 90: 4. Stabilize your System Security Plan so it reflects your actual environment, not last year's architecture. 5. Implement the highest-impact controls first: multifactor authentication, centralized logging, patch management, and encryption for CUI at rest and in transit. 6. Build evidence packages mapped to likely assessment objectives, using the CMMC Assessment Guide's examine, interview, and test methods.
Days 91 to 180: 7. Close out high-priority POA&M items wherever POA&Ms are permitted for your level. 8. Run a tabletop incident response exercise and walk through your evidence with a fresh set of eyes. 9. Schedule any third-party assessment prep or assessor coordination you'll need once certification demand resumes.
Pro Tip: Assessors spend more time hunting for evidence than judging control quality. A well-organized evidence folder, indexed to each of the 110 requirements, often shaves days off a Level 2 assessment. A structured compliance program framework can help formalize this before certification requirements return, and dedicated self-assessment platforms simplify SPRS reporting and evidence tracking along the way.

Why the Suspension Should Not Slow You Down
Acting now, while certification demand is paused, reduces future audit cost and schedule risk. Contractors who stabilize their SSP and close gaps today will bid on DoD solicitations with a real compliance edge once Phase II resumes.
Get a Prioritized Compliance Plan Before Phase II Resumes
Mindpodtech turns CMMC ambiguity into a plan you can execute, not another binder that sits on a shelf. Our free technology assessment reviews your current System Security Plan, maps your environment against the 110 NIST SP 800-171 Rev 2 requirements, and hands you a prioritized 90-day implementation playbook built around your actual risk, not a generic checklist.

The assessment identifies which systems genuinely need to be in scope, which controls close the biggest gaps first, and what evidence you should be collecting now so a future assessment does not turn into a scramble. If you handle CUI or FCI under a DoD contract and want a clear-eyed view of where you stand, start with a free technology assessment from Mindpodtech and get a plan you own from day one.
Sources
- Cybersecurity Maturity Model Certification
- About CMMC
- Cybersecurity Maturity Model Certification (CMMC) Model Overview
- Cybersecurity Maturity Model Certification; Final Rule (Federal Register)
- CMMC Assessment Guide – Level 2
FAQ
What Are the Requirements for CMMC 2.0 Compliance?
Requirements depend on your level: 15 FAR 52.204-21 practices for Level 1, all 110 NIST SP 800-171 Rev 2 controls for Level 2, and a NIST SP 800-172 subset for Level 3, each with its own assessment and affirmation cadence.
Is CMMC Level 2 Suspended?
No. The Department of War suspended Phase II, which governs the rollout of mandatory third-party C3PAO certification, but Phase I self-assessment requirements for Level 2 remain active.
How Many Requirements Are in CMMC Level 2?
CMMC Level 2 has 110 security requirements, matching NIST SP 800-171 Revision 2 exactly, with no additions or exceptions.
Can You Self-Certify for CMMC Level 2?
Yes, for contracts that specify the self-assessment path. Level 2 self-assessment occurs every three years with an annual affirmation filed in SPRS; higher-sensitivity contracts require third-party C3PAO certification instead.
