Interweave Technologies
Sep 19

What Does CMMC 2.0 Mean for DoD Suppliers and Their IT Plans

CMMC 2.0 is the Department of Defense framework that verifies contractors are protecting sensitive defense information on their own IT systems. For suppliers, it converts cybersecurity from a promise made in a proposal into an assessed result that decides whether you can be awarded the contract at all.

Below we cover what the framework requires, how it changed from the original model, where the rollout actually stands in 2026 after the Phase 2 suspension, and the specific work CMMC 2.0 creates inside your network, from access control and encryption to boundary design, logging, and the documentation you have to keep current between assessments.

What Does CMMC 2.0 Mean for DoD Suppliers?

CMMC 2.0 means your cybersecurity posture is now a condition of contract award rather than a statement you make about yourself. Statements made about yourself still matter, because the program runs on self-assessment at the lower tiers, and a senior official signs an affirmation that the statement is accurate.

Accuracy is verified through three features the Department has used to describe the program since it was redesigned. The model is tiered, so requirements rise with the sensitivity of the data you hold. Assessment is required, through either self-assessment or a third-party review. Implementation runs through contracts, so the required level appears in the solicitation and the clause. The table below sets out the three levels, and its requirement counts come from 32 CFR Part 170 along with the NIST standards each level is built on.

LevelData TypeSecurity RequirementsSource StandardAssessment RouteLevel 1 (Foundational)FCI only15FAR 52.204-21Annual self-assessmentLevel 2 (Advanced)CUI110NIST SP 800-171 Rev. 2Self-assessment or C3PAO certificationLevel 3 (Expert)Critical CUI110 plus 24 enhancedNIST SP 800-172Government-led (DIBCAC)

Suppliers that want a deeper read on which tier applies to their own contracts will find that question worked through in detail in our CMMC guide, and the rest of this article deals with what the framework does to your IT plans once the level is known. Plenty of that work is the same at every tier, which is the part most government contractors underestimate.

How Does CMMC 2.0 Differ From CMMC 1.0?

CMMC 2.0 differs from CMMC 1.0 in four ways: five levels became three, maturity process requirements were removed entirely, the control sets were aligned to existing NIST standards, and self-assessment was reinstated at the lower tiers. The lower tiers matter most to the supply chain, because the original model required a third-party assessment of every contractor regardless of what data they held.

Data sensitivity now drives the tier instead. The Department pared the 130 practices in the original Level 3 baseline down to the 110 security requirements already published in NIST SP 800-171, and dropped the non-NIST controls that had no equivalent anywhere else. Removing those controls ended a long-running complaint from the Defense Industrial Base, which is that CMMC 1.0 asked suppliers to meet a standard that existed nowhere but CMMC itself.

Nowhere-but-CMMC requirements are gone, and the practical effect is that a supplier already working toward NIST compliance under DFARS 252.204-7012 is already most of the way through Level 2. The maturity process scoring that graded how well documented your procedures were also disappeared, so the model now measures technical implementation rather than organizational habit.

When Was CMMC 2.0 Announced and When Did It Take Effect?

CMMC 2.0 was announced in November 2021 and took effect in contracts on November 10, 2025, when the acquisition rule became enforceable. Enforceability arrived at the end of a long rulemaking sequence rather than all at once, and the milestones below are the ones worth knowing:

  1. March 2019: the Department begins developing the CMMC program.
  2. January 2020: CMMC 1.0 is finalized with five maturity levels.
  3. November 2020: the DFARS interim rule takes effect, requiring NIST SP 800-171 self-assessment scores in the Supplier Performance Risk System (SPRS).
  4. November 2021: CMMC 2.0 is announced after an internal review, cutting five levels to three.
  5. December 2023: the proposed program rule is published for comment.
  6. October 2024: 32 CFR Part 170, the rule establishing the program, is published, taking effect December 16, 2024.
  7. September 10, 2025: the 48 CFR acquisition rule is published in the Federal Register.
  8. November 10, 2025: the acquisition rule takes effect and Phase 1 begins, putting CMMC requirements into new solicitations.

New solicitations have carried those requirements ever since, and DoD estimates published with the program rule expected Phase 1 to reach roughly 65 percent of the Defense Industrial Base. Reaching most of the base in the first phase is what made the following year's developments significant for everyone in it.

What Is the CMMC Timeline for 2026?

The CMMC timeline for 2026 is Phase 1 active and everything after it on hold. Holding the later phases was announced on July 13, 2026, when the Department of War suspended Phase 2 along with Phases 3 and 4, and stood up a CMMC Reform Task Force to run a top-to-bottom review. Phase 2 was the point at which third-party certification would have become a prerequisite for most contracts involving CUI, originally scheduled for November 10, 2026.

The originally scheduled date is now the date nothing happens. A class deviation issued on September 3, 2026 made the suspension binding on contracting officers rather than leaving it to discretion, and the task force was due to deliver recommendations to the Department's Chief Information Officer in mid-September 2026. Recommendations go to the CIO first, and the Department then decides what to adopt, so the report itself changes nothing on its own.

Nothing changing on its own is exactly why suppliers should read the suspension carefully rather than quickly. A great deal of published guidance still on the web, including pages updated well into 2026, continues to describe Phase 2 as starting in November. Current CMMC requirements look different from that description, and the difference is narrower than most readers assume.

Is CMMC Level 2 Still Suspended?

CMMC Level 2 third-party certification is suspended as a condition of award, and nothing else about CMMC Level 2 is suspended. Everything else stands: Level 1 and Level 2 self-assessments, the requirement to post results in SPRS, the annual affirmation signed by a senior official, DFARS 252.204-7012, and the full NIST SP 800-171 control set behind it.

What Did the Phase 2 Suspension Actually Change?

The suspension changed who verifies your work, not what the work is. Under Secretary of War for Acquisition and Sustainment Michael Duffey put it plainly when the announcement came, saying the Department expects businesses to adhere to the standards NIST has outlined and that what is being removed is the bureaucracy of the third-party assessment. Removing the assessment layer leaves the security baseline untouched and shifts the entire burden of accuracy onto the supplier's own signature.

Your own signature carries real weight. Prime contractors continue to flow down cybersecurity obligations on their own schedules, independent of the federal rollout, and a subcontract is a contract regardless of what phase the program sits in. Suppliers who paused their remediation work because of the news have usually discovered that their prime did not pause anything.

Will CMMC Go Away?

CMMC is unlikely to go away, because the requirement underneath it comes from regulations the suspension never touched. Regulations that predate CMMC still bind: FAR safeguarding requirements for Federal Contract Information have applied since 2016, and DFARS 252.204-7012 has required NIST SP 800-171 implementation since 2017. CMMC was built to verify those obligations rather than to create them.

History points the same direction. The original program paused for review in 2021 and returned within a year as CMMC 2.0, leaner and narrower, with five levels cut to three and self-assessment restored where the data allowed it. A pause for reform has so far meant a pause followed by a lighter version of the same idea, and the Department has been explicit that cost and barriers to small business are the targets of this review.

Is the Department Enforcing CMMC Right Now?

Yes, the Department is enforcing CMMC right now through Phase 1, which requires a current self-assessment status at the time of award for applicable contracts. Award eligibility turns on that status being posted and current, and a missing or expired entry can take a bid off the table before anyone evaluates the technical proposal.

Technical proposals are not where the real exposure sits. The affirmation a senior official signs is a representation to the government, and an inaccurate one carries False Claims Act liability that no suspension has paused. Federal cybersecurity fraud enforcement has produced settlements against contractors whose stated security posture did not match their actual one, and those cases turned on the gap between the score posted and the environment that existed.

The environment that exists is therefore the thing worth fixing, and fixing it is an IT project before it is a paperwork project.

What Changes in Your IT Environment Under CMMC 2.0?

CMMC 2.0 changes seven areas of a typical supplier's IT environment, and most suppliers underestimate at least four of them. Underestimating them is what turns a nine-month project into an eighteen-month one:

  • Identity and access: multifactor authentication, least privilege, separate administrative accounts, and a defined process for granting and removing access.
  • Encryption: FIPS-validated cryptography protecting CUI at rest and in transit, including laptops, servers, backups, and file transfer.
  • Boundary architecture: segmentation that separates systems holding controlled data from general corporate IT.
  • Logging and monitoring: centralized collection, defined retention periods, and someone actually reviewing what the logs report.
  • Endpoint and media control: managed devices, removable media restrictions, mobile device policy, and sanitization before disposal.
  • Backup and recovery: protected copies, tested restoration, and incident response procedures that have been exercised rather than written.
  • Asset inventory: a current, accurate list of every system inside the boundary, since an asset nobody knew about is a finding waiting to happen.

A finding waiting to happen is usually a machine, not a policy. The 110 requirements at Level 2 expand into 320 separate assessment objectives under NIST SP 800-171A, and each objective has to hold true on every system inside the boundary rather than on a representative sample.

Does CMMC Require MFA and Encryption?

Yes, CMMC requires multifactor authentication and encryption, and both carry specific conditions that trip up suppliers who assume their existing setup already qualifies. Existing setups usually cover part of the ground. Multifactor authentication has to protect privileged accounts and all network access, which includes remote access paths that were configured years ago and never revisited.

Revisiting encryption produces a similar surprise. The requirement is not strong encryption in general but cryptography validated under the Federal Information Processing Standard 140 program, verified by certificate number. A product that ships with a FIPS mode satisfies nothing unless that mode is actually enabled, which is one of the more common gaps we find when we review how a supplier handles file encryption across endpoints and backups.

Do You Need to Separate CUI From Your Regular Network?

Separating CUI from your regular network is not strictly required, and it is the single most effective way to keep the cost and scope of compliance under control. Scope is what costs money. A CUI enclave is a segmented part of your environment where controlled data lives and nothing else does, protected by its own access controls, its own encryption, and its own monitoring.

Its own boundary is the point. Controlled data confined to one segment pulls only that segment into the assessment, while controlled data circulating freely through email, shared drives, and shop-floor machines pulls the entire company into it. The assessment boundary decides how many systems have to carry all 110 requirements, which makes segmentation a budget decision before it is a security decision.

Budget decisions of this kind are best made before hardware is purchased, since the shape of your network infrastructure determines how much of it falls inside the line. Suppliers who design the enclave first routinely bring their in-scope system count down by half or more, and every system removed is a system that never needs the full control set applied to it.

What Documentation Does CMMC 2.0 Require?

CMMC 2.0 requires a system security plan, written policies and procedures, a remediation plan for open gaps, retained evidence, and an annual affirmation from a senior company official. A senior official signs at the end of the chain, but the artifacts below are what make that signature defensible:

  • System security plan (SSP): defines the boundary, names every in-scope system, and describes how each requirement is met.
  • Policies and procedures: the written rules behind each control family, from access control through incident response.
  • Plan of Action and Milestones (POA&M): the record of unmet requirements with owners and dates attached.
  • Evidence artifacts: configuration screenshots, training records, access reviews, vulnerability scan output, and incident tickets.
  • Retained logs: collected centrally and kept for a defined period rather than overwritten when storage fills.

Storage filling up has ended more than one assessment, because logs that no longer exist cannot prove a control was operating. Documentation is also not a one-time deliverable: the SSP has to stay current as systems change, which is the part suppliers most often let drift between assessments. Keeping it current is the ongoing half of a compliance program rather than the closing task of a project.

What Is an SSP in CMMC?

An SSP in CMMC is the system security plan, the document that describes your environment and how it satisfies each applicable security requirement. It names the systems inside the assessment boundary, the people responsible, the tools in use, and the specific way every requirement is implemented. Assessors read it first, and the rest of the assessment is largely a test of whether the plan matches reality, which is why we build the system security plan alongside the technical work rather than after it.

Does CMMC Apply to Your Cloud Services and IT Provider?

Yes, CMMC applies to cloud services and IT providers that sit inside your assessment boundary, and their shortcomings become your findings. Your findings are what the assessor records, regardless of which company caused them. A cloud service that stores, processes, or transmits CUI has its own security requirements attached, and an external service provider with administrative access to your environment is treated as part of that environment.

Part of that environment means part of the assessment. Ask any provider three questions before you scope the project: what security requirements do you meet and can you show evidence, do you support FIPS-validated encryption in the configuration we will actually run, and will you sign an agreement covering your responsibilities under our framework obligations. Providers who handle defense work answer those quickly, and the answers belong in your SSP. Suppliers running an outsourced or co-managed environment often find this is the fastest part of the project to close when the provider already delivers managed compliance work.

What Is a Get Well Plan for CMMC 2.0?

A get well plan for CMMC 2.0 is the defense industry's informal name for the Plan of Action and Milestones, the document that records unmet requirements and commits to dates for closing them. Committed dates are what separate a get well plan from a wish list. Each entry names the requirement, the gap, the person responsible, the remediation steps, and the completion date.

Completion dates carry a hard limit at Level 2. A supplier whose assessment score reaches at least 88 of the 110 available points can hold a Conditional status while the plan runs, and the open items must close within 180 days to convert that status to Final. High-value requirements worth 5 points, including multifactor authentication and FIPS-validated encryption of CUI, cannot be deferred to a POA&M at all and must be fully met at the time of assessment.

How Should a Supplier Budget IT Projects Around CMMC?

A supplier should sequence CMMC work so that scoping comes before purchasing, because every decision after the boundary is drawn depends on how big that boundary is. Boundary size determines license counts, hardware counts, and labor hours, so buying tools first routinely means buying the wrong quantity of the right thing.

The right sequence is straightforward. Map your data flow, draw the boundary, run a gap analysis against the applicable requirements, then build the roadmap and buy against it. Suppliers with a hardware refresh already on the calendar have the easiest path available to them, since replacing endpoints and servers once, with compliance requirements already specified, costs far less than replacing them twice.

Replacing anything twice is the outcome worth avoiding, and it is the most common expensive mistake we see. Our certified assessors work the scoping and the roadmap first for exactly that reason, so the money goes toward systems that will still be in scope a year from now.

How Does CMMC 2.0 Affect Small Businesses?

CMMC 2.0 affects small businesses most through capacity rather than through the controls themselves, since the pool of authorized assessors is small relative to the number of companies that will eventually need one. The numbers are stark. Department estimates place more than 80,000 organizations at Level 2, while fewer than 85 authorized CMMC Third Party Assessment Organizations (C3PAOs) exist to assess them. The accreditation body reported 896 final Level 2 certificates of status as of its February 2026 town hall, up from 431 four months earlier.

Four months of growth at that pace does not close a gap of 80,000. More than 300,000 companies perform under contract in the Defense Industrial Base, and when third-party requirements return, assessor availability becomes the constraint on who wins work rather than readiness alone. Around Huntsville, where a dense base of small suppliers feeds missile defense, space, and aviation programs, the companies already documented and remediated will simply be first in a line that everyone else is still joining.

Joining that line costs nothing to start. The Department's Project Spectrum platform offers free cybersecurity training, tools, and cyber advisor support aimed specifically at small and mid-sized suppliers, and it is a reasonable first stop for a company that has not begun.

Frequently Asked Questions

Who Needs CMMC Level 2?

CMMC Level 2 is needed by any contractor or subcontractor that processes, stores, or transmits Controlled Unclassified Information under a Department of Defense contract. Department estimates place roughly 37 percent of the Defense Industrial Base, more than 80,000 organizations, in that group. Contractors handling only Federal Contract Information sit at Level 1 instead.

Can You Self-Attest CMMC Level 2?

You can self-attest CMMC Level 2 when your contract calls for the self-assessment route rather than certification, and the assessment covers the same 110 requirements either way. Results from a self-assessment go into SPRS under your own signature, and a senior official affirms them annually. The accuracy of that affirmation carries legal weight independent of who performed the assessment.

How Often Is a CMMC Level 2 Assessment Required?

A CMMC Level 2 assessment is required every three years, whether it is a self-assessment or a certification assessment. An affirmation is submitted annually in the intervening years. A material change to your environment, such as a new boundary, a platform migration, or a merger, can invalidate the scope that was assessed and prompt a fresh review.

How Many Companies Have CMMC Level 2 Certification?

The accreditation body reported 896 organizations holding a final Level 2 certificate of status as of its February 2026 town hall, compared with 431 in October 2025. That figure represents about 1 percent of the more than 80,000 organizations the Department expects to require Level 2. The gap between those two numbers is the reason assessor capacity dominates planning conversations.

What Happens If You Don't Get CMMC Certified?

A contractor without the required CMMC status in SPRS at the time of award is ineligible for that award, and the same applies when an option period is exercised on an existing contract. Prime contractors also flow these obligations down, so a subcontractor without a current status can lose work from a prime well before any federal deadline arrives. Posting an inaccurate status carries separate legal exposure.

Do You Still Have to Report a SPRS Score?

Yes, you still have to report your assessment results in the Supplier Performance Risk System, and that requirement was not affected by the Phase 2 suspension. Assessment reporting now runs through the CMMC structure following the February 2026 clause reorganization, which deleted DFARS 252.204-7019 and renumbered 252.204-7020 to 252.240-7997. The underlying obligation to assess and report did not change with the clause numbers.

The Bottom Line

CMMC 2.0 turns the security of your own network into a condition of doing defense work, and the framework behind it comes from NIST standards that have applied to contractors handling controlled data for years. Three levels, 15 or 110 or 134 requirements depending on the data you hold, and an assessment route set by your contract. Phase 1 is live and enforced. Phase 2 and everything after it sits under review, with the third-party assessment layer paused and the security baseline entirely intact.

What that means for your IT plans is unchanged by the pause. Access control, FIPS-validated encryption, a deliberate boundary around controlled data, centralized logging with real retention, tested backups, an accurate asset inventory, and documentation that stays current are the work. Suppliers who treat the current window as time to build rather than time to wait will be the ones ready when verification returns, and their competitors will be starting the same projects with less runway.

We have spent more than 20 years helping organizations around Huntsville and across the Southeast turn framework requirements into working infrastructure, with certified staff guiding the scoping, the remediation, and the evidence trail. If you want a straight read on where your environment stands against the requirements in your contracts, talk it through with our team or call (256) 837-2300. That first conversation is the one that usually saves the most money, and it is the work Interweave Technologies does every day.