CMMC 2.0, Rule & Timeline: Complete Guide [2026]

SaltyCloud Research Team

Updated Sep 7, 2026 Read Time 12 min

CMMC 2.0: The Model, the Rules, and the Timeline

CMMC 2.0 is the U.S. DoD restructured Cybersecurity Maturity Model Certification (CMMC) program that replaced the original five-level model with three levels in November 2021. The two federal rules that make it binding are the 32 CFR Part 170 program rule, which took effect December 16, 2024, and the 48 CFR DFARS acquisition rule that followed on November 10, 2025.

But the CMMC timeline can also be hard to follow in 2026. On July 13, 2026, the DoD suspended CMMC Phase 2 and opened a reform review, so mandatory third-party assessments are paused while Phase 1 self-assessment stays in force. Which obligations still apply during that pause is the question most contractors need answered first.

This guide covers CMMC 2.0’s three-level model, the two rules behind it, who must comply, and where the rollout stands after the suspension. For a high-level overview, start with the complete CMMC guide.

What Is CMMC 2.0?

CMMC 2.0 is a certification program with three cumulative levels, and each level ties to a NIST standard, according to CISA. Which level applies follows from how sensitive the information in a contract is. Because the levels build on each other, a Level 2 contractor also meets the Level 1 safeguards.

CMMC 2.0 is the Department of Defense program that checks whether defense contractors actually protect sensitive government information. It sets three levels, ties each one to a NIST security standard, and asks a contractor to prove the controls are in place through a self-assessment or an outside assessment.

CMMC 2.0 protects two information types. Which one a contract involves sets the level:

For example, contractors that only receive FCI usually land at Level 1, while contractors that store or transmit CUI tend to fall under Level 2.

The three levels map to distinct control sets.

The DoD’s CMMC Model Overview sets out how each level protects its information type.

CMMC Level Protects Security Standard Requirements Assessment Type
Level 1 FCI FAR 52.204-21 basic safeguards 15 Annual self-assessment
Level 2 CUI NIST SP 800-171 Rev 2 110 (14 families) Self-assessment or C3PAO
Level 3 High-value CUI Selected NIST SP 800-172 requirements 24 Government-led (DIBCAC)

Since Level 3 builds on Level 2, a Level 3 contractor implements 134 requirements in total — the 110 carried over from Level 2 plus the 24 selected enhanced requirements. Under 32 CFR §170.19, a company also needs Final Level 2 (C3PAO) status for the same assessment scope before DIBCAC conducts the Level 3 assessment.

Even though NIST withdrew SP 800-171 Rev 2 on May 14, 2024 and superseded it with Rev 3, CMMC Level 2 still pins to Rev 2 by incorporation in 32 CFR Part 170. A transition rule is planned but not yet published. DoD listed RIN 0790-AM01 in the 2026 Unified Agenda to set a deadline and transition period from Rev 2 to Rev 3, with an interim final rule targeted for July 2026.

Similarly, CMMC still carries the “maturity model” name from version 1.0, despite 2.0 dropping the tiered maturity-process requirements that the phrase originally described. In practice, CMMC is a set of NIST control baselines with a specific verification mechanism attached.

Who Must Comply With CMMC 2.0?

CMMC 2.0 applies to any company in the Defense Industrial Base (DIB) that stores, processes, or transmits FCI or CUI on a DoD contract. The required level follows the information type rather than the size of the contractor. [DFARS 252.204-7021](https://www.acquisition.gov/dfars/252.204-7021-contractor-compliance-cybersecurity-maturity-model-certification-level-requirements.) also requires a prime contractor to flow the same requirement down to subcontractors that handle either information type.

Three groups sort out in practice:

  • Contractors handling only FCI. These suppliers land at Level 1 and complete an annual self-assessment against the 15 basic safeguarding requirements in FAR 52.204-21.
  • Contractors handling CUI. Storing or transmitting CUI moves a company to Level 2 and its 110 NIST SP 800-171 Rev 2 requirements, with a small subset of programs designated for Level 3.
  • COTS-only suppliers. Contracts solely for commercially available off-the-shelf items are excepted, so a vendor selling only COTS products does not pick up a CMMC level through that work.

During Phase 1, a contracting officer decides at their discretion whether a given solicitation carries a CMMC requirement. That way, coverage expands contract by contract rather than all at once.

What Changed From CMMC 1.0 to CMMC 2.0

CMMC 2.0 cut the model from five levels to three and removed the CMMC-specific practices that version 1.0 layered on top of NIST SP 800-171. Published in 2020, CMMC 1.0 also carried separate “maturity process” requirements, and that structure proved heavy for the DIB to implement.

The November 2021 revision made three main changes:

  • Three levels instead of five. The old intermediate Levels 2 and 4 were removed.
  • No CMMC-only practices. Dropping the “delta 20” practices left Level 2 equal to the 110 NIST SP 800-171 requirements.
  • Limited self-assessment restored. Self-assessment and Plans of Action and Milestones (POA&Ms) returned at some levels.

The result is a program that leans on existing federal standards rather than a bespoke CMMC control set. For the requirement set that applies at each level today, see the CMMC requirements guide.

The CMMC Rules: 32 CFR Part 170 and the 48 CFR DFARS Acquisition Rule

Two federal rules turn the CMMC model into a binding requirement, and they do different jobs.

  • 32 CFR Part 170, the CMMC Program rule, was published October 15, 2024 and took effect December 16, 2024. It defines the program, the three levels, the scoping rules, and the assessment types.
  • The 48 CFR DFARS acquisition rule took effect November 10, 2025. It adds the contract clause that carries CMMC into solicitations.

Here, the operative clause is DFARS 252.204-7021. It obligates a contractor to hold a current CMMC status for the life of the contract and to post its CMMC unique identifier (UID) in the Supplier Performance Risk System (SPRS). That contractor must also complete an annual affirmation and flow the requirement down to subcontractors that handle FCI or CUI. For how those obligations translate into day-to-day program work, see the CMMC compliance guide.

CMMC Timeline and Current Status in 2026

The CMMC rollout was built as a four-phase ramp tied to the November 10, 2025 acquisition-rule date, and the DoD’s CMMC phase-in schedule spread those phases across three years. Read the phases below as originally scheduled, now under review:

Phase 1: Self-Assessment Requirements Begin (November 10, 2025)

Phase 1 introduced Level 1 and Level 2 self-assessment requirements, applied at contracting-officer discretion rather than across every solicitation at once. This phase is in force today and was not affected by the July 2026 suspension.

Phase 2: Third-Party Level 2 Assessments (November 10, 2026)

Phase 2 was scheduled to require Level 2 assessment by a CMMC Third-Party Assessment Organization (C3PAO) for contracts involving CUI. This phase is suspended as of July 2026, and no replacement date has been set. Assessor capacity was one of the pressures on the schedule. GAO counted 92 authorized C3PAOs as of December 2025, with another 28 awaiting or already past a DIBCAC Level 2 assessment.

Phase 3: Government-Led Level 3 Assessments (November 10, 2027)

Phase 3 would add Level 3 assessment by the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). It remains on the original schedule on paper, though the reform review could change it.

Phase 4: Full Application Across Contracts (November 10, 2028)

Phase 4 would apply CMMC to all applicable FCI and CUI contracts, with commercially available off-the-shelf(COTS) products excepted. Like Phase 3, it is scheduled but subject to the review.

Where the Timeline Stands After the July 2026 Suspension

On July 13, 2026, the DoD suspended Phase 2 and stood up a CMMC Reform Task Force for a 60-day, top-to-bottom review informed by industry input. The department also opened a public Request for Information, with responses due August 14, 2026. That announced review deadline passed around September 11.

No outcome, recommendations, or replacement Phase 2 schedule had been published as of September 14, 2026, and the DoD CIO CMMC page still describes Phase 2 as suspended while Phase 1 stays in effect. During the interim, contracting officers may not require Level 2 (C3PAO) or Level 3 (DIBCAC) assessments.

Still, several obligations remain in force, including:

  • Phase 1 self-assessment
  • DFARS 252.204-7012, the safeguarding and incident-reporting clause built on NIST SP 800-171 Rev 2
  • Level 1 (Self) or Level 2 (Self) requirements

For how each assessment path works in practice, see the CMMC assessment and audit guide and the CMMC certification guide.

What the September 2026 Class Deviation Requires

Class Deviation 2026-O0025, Revision 3, signed September 3, 2026, is the controlling contracting guidance during the suspension. It tells acquisition teams how to clean up affected work. Four directions matter most to contractors:

  • Review the whole portfolio. New and existing solicitations and contracts get reviewed so that affected CMMC requirements are removed or revised.
  • Amend active solicitations promptly. Requiring activities initiate the amendments, and contracting officers issue them as soon as practicable.
  • Modify contracts at the next natural touchpoint. Existing contracts carrying suspended requirements are modified before the next option is exercised or through the next scheduled administrative modification.
  • Keep the self-assessment requirements. Level 1 and Level 2 self-assessment requirements may remain in place or be added, and NIST SP 800-171 Rev 2 compliance under DFARS 252.204-7012 still applies to covered defense information.

The deviation stays effective until it is rescinded or incorporated into the regulations. However, it does not say whether each contract modification is unilateral or bilateral, and it does not automatically provide price or schedule relief.

What Still Runs During the Suspension

The suspension pauses mandatory Phase 2 acquisition advancement, not the entire CMMC assessment and recordkeeping ecosystem.

  • Voluntary third-party assessments continue.
  • C3PAOs still issue Level 2 Certificates of CMMC Status.
  • SPRS keeps recording assessments.

A July 2026 release made Level 2 C3PAO and Level 3 DIBCAC records available for vendor affirmation. On a Level 2 self-assessment:

  • A score of 110 earns a final Level 2 status and covers a three-year assessment period, though it still needs an annual affirmation from the company’s Affirming Official.
  • A score of 88 to 109 earns conditional status, which runs on a 180-day POA&M window.

Where a solicitation still lawfully carries a CMMC requirement, [DFARS 252.204-7025](https://www.acquisition.gov/dfars/252.204-7025-notice-cybersecurity-maturity-model-certification-level-requirements.) governs what the contracting officer checks. That check covers the SPRS status, its affirmation, and the system-specific CMMC UID rather than a certificate PDF.

How to Simplify CMMC 2.0 Self-Assessments

Most of the CMMC 2.0 readiness work is a self-assessment against the 110 NIST SP 800-171 Rev 2 requirements, plus documenting the evidence behind every response. Isora GRC is the GRC Assessment Platform™ for security teams run assessments, manage assets and vendors, track risks, and prove compliance.

Assessment Management

Assessment management maps to the Level 2 self-assessment that Phase 1 keeps in force today. Teams see the status of every assessment in one centralized view, so a 110-requirement review stays trackable while it runs across owners and departments.

Questionnaires and Surveys

Questionnaires and surveys supply the requirement set a Level 2 self-assessment starts from. The prebuilt library covers CMMC alongside NIST, CIS, HIPAA, GLBA, and HECVAT, so a team works from a ready template instead of rebuilding 14 requirement families in a spreadsheet.

Isora GRC supports self-assessment readiness. It does not issue a CMMC certification, produce a Certificate of CMMC Status, or guarantee an SPRS score, because a CMMC status comes only from a self-affirmation or an authorized C3PAO or DIBCAC assessment.

See how Isora GRC simplifies CMMC compliance →

Key Takeaways

The move most contractors should make now is to run the Level 2 self-assessment against NIST SP 800-171 Rev 2 and keep the evidence behind it. That work is required today, and it holds its value whatever the reform review decides. The model has been stable since November 2021, and both rules took effect in December 2024 and November 2025.

What changed in mid-2026 is enforcement rather than the standard. Phase 1 self-assessment is active, the third-party assessment phase is suspended pending a 60-day review, and the DFARS 252.204-7012 obligation to implement NIST SP 800-171 never lapsed. Because no replacement Phase 2 date exists yet, waiting for a new schedule mostly costs preparation time.

Teams that stay ready through the interim usually run the self-assessment on a repeatable cycle, with evidence captured as the work happens rather than reconstructed later.

See the GRC Assessment Platform™ in action →

CMMC 2.0 FAQs

What is CMMC 2.0?

CMMC 2.0 is the Department of Defense’s Cybersecurity Maturity Model Certification program, restructured in November 2021 into three levels. Each level verifies that a defense contractor protects Federal Contract Information or Controlled Unclassified Information by meeting a set of NIST security requirements. It became enforceable through federal rulemaking in 2024 and 2025.

What is the difference between CMMC 1.0 and CMMC 2.0?

CMMC 1.0 had five maturity levels and added CMMC-specific practices and maturity-process requirements on top of NIST SP 800-171. CMMC 2.0 cut that to three levels and removed the CMMC-only practices, so Level 2 now equals the 110 NIST SP 800-171 Rev 2 requirements. It also brought back limited self-assessments and Plans of Action and Milestones.

Is CMMC 2.0 still required in 2026?

The program remains in force, though the third-party assessment phase is paused. On July 13, 2026, the Department of Defense suspended CMMC Phase 2 and began a 60-day reform review. Class Deviation 2026-O0025, Revision 3, signed September 3, 2026, continues that suspension without setting a new date. Contracts can carry Level 1 (Self) or Level 2 (Self) requirements during the interim, and the underlying DFARS 252.204-7012 and NIST SP 800-171 Rev 2 obligations still apply.

Is there a CMMC 3.0 or CMMC 2.1?

There is no CMMC 3.0 or CMMC 2.1. The current published version is CMMC 2.0, with its three levels codified in 32 CFR Part 170. The 60-day CMMC Reform Task Force stood up in July 2026 could restructure the program, though no new version has been published.

What are the three CMMC 2.0 levels?

Level 1 protects Federal Contract Information and covers the 15 basic safeguarding requirements from FAR 52.204-21 through an annual self-assessment. Level 2 protects Controlled Unclassified Information and requires the 110 NIST SP 800-171 Rev 2 requirements, assessed by the contractor or by a C3PAO. Level 3 covers the most sensitive CUI and adds 24 requirements selected from NIST SP 800-172, assessed by the government.

When did CMMC 2.0 go into effect?

CMMC 2.0 became enforceable through two rules. The 32 CFR Part 170 program rule was published October 15, 2024 and took effect December 16, 2024, and the 48 CFR DFARS acquisition rule took effect November 10, 2025, when CMMC clauses began appearing in contracts. The phase-in beyond that first phase is under review following the July 2026 suspension, and no replacement Phase 2 date had been published as of September 14, 2026.

This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.

The InfoSec GRC Brief
Join 1,500+ security and compliance professionals who get monthly regulatory updates, GRC strategies, and threat intel with actionable next steps.
Let’s Chat
See the GRC Assessment Platform in action
Isora GRC is the GRC Assessment Platform™ that gives security teams one connected workspace to run assessments, manage vendors and assets, track risks, and prove compliance.
Book a Demo