By Syed Waseem
CMMC 2.0 requirements explained: the three levels, the 110 NIST 800-171 controls at Level 2, and what the July 2026 Phase 2 suspension changed. The CMMC rule still sets three levels and a four phase rollout, but the Department of War suspended Phase 2 on 13 July 2026. Here is what a defense contractor actually owes today. Ask about CMMC 2.0 requirements in October 2026 and you need two answers, not one. The published rule still sets three levels, a 110 requirement baseline at Level 2, and a four phase rollout. Then, on 13 July 2026, the Department of War suspended Phase 2. So the certification half of the program sits on hold while the self-assessment half still gates awards. A contractor today implements NIST SP 800-171 Revision 2, posts a score, affirms it every year, and waits for the review to finish. Nobody should read the pause as a cancellation. CMMC 2.0 Requirements By Level The CMMC Program rule at 32 CFR part 170 took effect on 16 December 2024. It defines three levels and anchors each one to a standard that already exists, rather than to a bespoke control set. That choice matters for a proposal writer. The evidence an assessor wants looks much like the evidence a DFARS self-assessment already produces. | Level | Protects | Requirements | Who assesses | |---|---|---|---| | 1 | Federal Contract Information | 15, from FAR 52.204-21 | The contractor, annually | | 2 | Controlled Unclassified Information | 110, from NIST SP 800-171 Rev 2 | The contractor, or a C3PAO | | 3 | CUI on highest risk programs | 110 plus 24 from NIST SP 800-172 | DCMA DIBCAC | Level 1 asks for basic hygiene on systems that hold FCI. Level 2 is where most of the defense industrial base lives, because most contracts that mention CUI land there. Level 3 applies to a small set of programs, and it sits on top of a Level 2 certification rather than replacing it. The CMMC Program final rule (https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program) names the February 2021 edition of NIST SP 800-172 for those 24 extra requirements. ! Four CMMC rollout phases on a timeline, with Phase 1 self-assessment live from 10 November 2025 and Phase 2 certification marked suspended on 13 July 2026 (https://mhhifytmrlyksfrjacvi.supabase.co/storage/v1/object/public/blog-images/2026/10/cmmc-2-0-requirements-figure.png) Phase 1 self-assessment still gates awards, and everything from third party certification onward now waits for a date nobody has published. The line between Level 1 and Level 2 turns on one question. Does the contract hand the firm Controlled Unclassified Information, or only Federal Contract Information? Many contractors answer that question wrongly, usually too high. A firm that reads every attachment as CUI buys an assessment it does no
The CMMC rule still sets three levels and a four phase rollout, but the Department of War suspended Phase 2 on 13 July 2026. Here is what a defense contractor actually owes today.
Ask about CMMC 2.0 requirements in October 2026 and you need two answers, not one. The published rule still sets three levels, a 110 requirement baseline at Level 2, and a four phase rollout. Then, on 13 July 2026, the Department of War suspended Phase 2. So the certification half of the program sits on hold while the self-assessment half still gates awards. A contractor today implements NIST SP 800-171 Revision 2, posts a score, affirms it every year, and waits for the review to finish. Nobody should read the pause as a cancellation. CMMC 2.0 Requirements By Level The CMMC Program rule at 32 CFR part 170 took effect on 16 December 2024. It defines three levels and anchors each one to a standard that already exists, rather than to a bespoke control set. That choice matters for a proposal writer. The evidence an assessor wants looks much like the evidence a DFARS self-assessment already produces. | Level | Protects | Requirements | Who assesses | |---|---|---|---| | 1 | Federal Contract Information | 15, from FAR 52.204-21 | The contractor, annually | | 2 | Controlled Unclassified Information | 110, from NIST SP 800-171 Rev 2 | The contractor, or a C3PAO | | 3 | CUI on highest risk programs | 110 plus 24 from NIST SP 800-172 | DCMA DIBCAC | Level 1 asks for basic hygiene on systems that hold FCI. Level 2 is where most of the defense industrial base lives, because most contracts that mention CUI land there. Level 3 applies to a small set of programs, and it sits on top of a Level 2 certification rather than replacing it. The CMMC Program final rule (https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program) names the February 2021 edition of NIST SP 800-172 for those 24 extra requirements. ! Four CMMC rollout phases on a timeline, with Phase 1 self-assessment live from 10 November 2025 and Phase 2 certification marked suspended on 13 July 2026 (https://mhhifytmrlyksfrjacvi.supabase.co/storage/v1/object/public/blog-images/2026/10/cmmc-2-0-requirements-figure.png) Phase 1 self-assessment still gates awards, and everything from third party certification onward now waits for a date nobody has published. The line between Level 1 and Level 2 turns on one question. Does the contract hand the firm Controlled Unclassified Information, or only Federal Contract Information? Many contractors answer that question wrongly, usually too high. A firm that reads every attachment as CUI buys an assessment it does no