Contact Us
 

CMMC Level 2 Certification for DoD Contractors

 

CMMC Program Update | July 13, 2026

The U.S. Department of War has suspended CMMC Phase II requirements and other pending implementation milestones while it conducts a 60-day program review. Phase I remains in effect, including CMMC Level 1 and Level 2 self-assessment requirements. Contractors and subcontractors must continue protecting FCI and CUI and meeting applicable contractual obligations.

 
 

What CMMC Means for DoD Contractors

CMMC defines how defense contractors must protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Organizations that handle CUI must meet CMMC Level 2 requirements, which align with the security practices defined in NIST SP 800-171 Rev. 2. Depending on the contract, organizations may be required to complete an independent assessment by a Certified Third-Party Assessment Organization (C3PAO).

Contractors that handle CUI are generally subject to CMMC Level 2 requirements. During the current program review, Department procurements are limited to Level 1 and Level 2 self-assessment requirements.

 
 

CMMC requirements are included in applicable federal solicitations and contracts. Contractors should review each opportunity carefully, confirm the required assessment level, and maintain the security practices necessary to protect FCI and CUI.

CMMC consists of three certification levels that reflect the maturity of a contractor’s cybersecurity program.

  • Level 1: Protects FCI. Validated through self-assessment.
  • Level 2: Applies to contractors handling CUI. Requires full NIST SP 800-171 implementation and may require independent certification by a C3PAO.
  • Level 3: Applies to a limited set of high-risk programs. Assessed by the U.S. government.

 

 

 

Path to CMMC Certification

Defense contractors typically progress through the following steps before achieving CMMC Level 2 certification.

Level 2 of the CMMC includes all the 110 requirements from NIST SP 800-171, verbatim. CISO Global can perform a NIST SP 800-171 gap analysis – a great starting point to determine if you are meeting the CMMC requirements.

With nearly two decades of experience in multiple certification frameworks, CISO Global can provide you with the skills and a roadmap necessary to prepare for CMMC compliance, saving your company time and money. 

 
 

CMMC Core Services

CISO Global and TalaTek support defense contractors preparing for CMMC Level 2 certification through readiness services, advisory support, and official assessment. As an authorized Certified Third-Party Assessment Organization (C3PAO), we conduct formal CMMC Level 2 assessments. Or we can provide advisory services to help organizations prepare. Our team evaluates your environment against the security practices in NIST SP 800-171 Rev. 2 to identify compliance gaps and support your path to certification.

 
 
 
 
 

Maintaining CMMC Compliance

CMMC Level 2 certification is valid for three years and requires ongoing monitoring, documentation, and annual affirmation of compliance.

Organizations must demonstrate that required security controls remain implemented and effective throughout the certification period.

 
 

FAQs

The Cybersecurity Maturity Model Certification (CMMC) program verifies that defense contractors and subcontractors meet cybersecurity requirements for protecting Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The required CMMC level and assessment type depend on the information an organization handles and the requirements included in an applicable Department of War solicitation or contract.

The Department of War has suspended CMMC Phase II requirements and later implementation milestones while it conducts a review of the program. Phase I remains in effect. During the suspension, Department procurements may require CMMC Level 1 or Level 2 self-assessments, but may not designate Level 2 C3PAO or Level 3 government assessments.

The suspension does not eliminate contractors’ responsibility to protect covered defense information. Applicable cybersecurity and safeguarding requirements, including those established under DFARS 252.204-7012, remain in effect.

The required CMMC level depends on the type of information your organization handles and the requirements included in the applicable solicitation or contract.

  • Level 1: For organizations handling Federal Contract Information (FCI). It requires an annual self-assessment and annual affirmation.
  • Level 2: For organizations handling Controlled Unclassified Information (CUI). It aligns with the 110 security requirements in NIST SP 800-171 Revision 2.
  • Level 3: Applies to a small number of high-risk programs and is assessed by the U.S. government.

During the current program suspension, Department procurements may designate only Level 1 or Level 2 self-assessments. Level 2 C3PAO and Level 3 assessment requirements are not currently being designated.

NIST SP 800-171 defines the 110 security requirements organizations must implement to protect Controlled Unclassified Information in nonfederal systems.

CMMC Level 2 uses those same requirements and establishes a formal process for assessing, reporting, and affirming an organization’s implementation. Depending on current program and contract requirements, that process may involve a self-assessment, an independent C3PAO assessment, or a government-led assessment. During the current suspension, new procurement requirements are limited to Level 1 and Level 2 self-assessments.

A CUI boundary identifies the systems, assets, networks, and environments that process, store, or transmit Controlled Unclassified Information. Defining this boundary helps determine which assets must meet CMMC requirements and be included in the organization’s assessment scope.

Under the current CMMC Phase II suspension, Department program managers and requiring activities may not designate Level 2 C3PAO assessments in solicitations or contracts. Current procurement requirements are limited to Level 1 and Level 2 self-assessments.

Organizations should continue addressing NIST SP 800-171 requirements, organizing evidence, defining their assessment scope, and preparing for possible future independent assessment requirements. Updated guidance is expected following the Department’s review of the program.

Organizations conduct their own Level 1 and Level 2 self-assessments. Cyber AB–authorized Certified Third-Party Assessment Organizations conduct independent Level 2 certification assessments, while authorized Department assessors conduct Level 3 and other government-led assessments.

During the current program suspension, new Department procurement requirements are limited to Level 1 and Level 2 self-assessments.

Level 1 requires an annual self-assessment and annual affirmation of compliance. Level 2 self-assessments are completed every three years, with an affirmation of continuous compliance submitted annually.

The CMMC regulations also establish three-year assessment cycles and annual affirmations for Level 2 C3PAO assessments, but those assessment requirements are not currently being designated in Department procurements during the Phase II suspension.

 

Speak With a CISO Global Security Specialist Today

Our experts maintain the most respected credentials in the industry across cybersecurity, risk and compliance, forensics, incident response, ethical hacking, security engineering, and more.