← Back to blog

Phase 1 began Nov 10, 2026: CMMC 2.0 actions DoD contractors must take

August 29, 2026
Phase 1 began Nov 10, 2026: CMMC 2.0 actions DoD contractors must take

CMMC 2.0 requirements split into three levels, each tied to a specific baseline and verification method: Level 1 involves annual self-assessment for Federal Contract Information (FCI); Level 2 involves self-assessment or C3PAO third-party certification for Controlled Unclassified Information (CUI) depending on the contract; Level 3 entails a government-led DIBCAC assessment following Level 2 certification. The DoD solicitation, not your own guess, tells you which one applies.


TL;DR:

  • Contractors must accurately classify their data (FCR or CUI) to determine the applicable CMMC level and avoid costly scope misjudgments.
  • Full compliance requires concise asset inventories, a well-defined scope, and documented security controls, especially for Level 2 and above.
  • Remediating non-allowable POA&Ms before assessment is critical, as unresolved issues can cause immediate assessment failure.
  • Building the smallest, most defensible CUI enclave reduces assessment costs and simplifies ongoing security efforts.
  • Starting readiness preparations early with comprehensive documentation, internal gap assessments, and continuous monitoring increases the likelihood of passing inspections without surprises.

Table of Contents

What each CMMC 2.0 level requires

The level assigned to your contract determines which control set you have to implement, and the gap between levels is wider than most contractors expect.

Level 1 maps to FAR 52.204-21, the basic safeguarding rule for FCI. It covers 17 practices around access control, media protection, and physical security. No SSP is mandated at this level, though most compliance leads build one anyway because the annual self-assessment goes faster with documentation already in hand.

Level 2 maps to NIST SP 800-171 Rev.2, the 110-control framework built for CUI. This is where the real work sits, covering everything from multifactor authentication to incident response planning to encryption of data at rest and in transit. An SSP is required here, not optional, along with a Basis of Evidence (BOE) your assessor will expect to review line by line.

Level 3 adds a subset of NIST SP 800-172 enhanced controls on top of Level 2, aimed at defending against advanced persistent threats. Only a small slice of the defence industrial base will ever need it.

What this looks like in practice:

  • A machine shop handling only purchase orders and shipping schedules: Level 1, self-attest annually, done.
  • A systems integrator storing technical drawings marked CUI: Level 2, full SSP, likely a C3PAO audit.
  • A prime working on a classified weapons program subcontract: Level 3, DIBCAC assessment, nested inside an existing Level 2 scope.

Who needs which level and how the DoD decides

Your contracting officer decides your level, not you. It appears as a clause in the solicitation or RFP, referencing the specific CMMC status required for award. Waiting for that clause is correct. Guessing at a level and building toward the wrong baseline wastes budget contractors rarely get back.

What you can and should do before the solicitation lands:

  • Classify the data you already handle: is it FCI, CUI, both, or neither?
  • Review current and recent contracts for CUI markings or DFARS 252.204-7012 clauses, which signal Level 2 territory.
  • Keep your Supplier Performance Risk System (SPRS) score current, since self-assessment results and annual affirmations feed directly into that record.
  • Push the CMMC clause requirement down to any subcontractor who touches the same FCI or CUI, because flow-down obligations follow the data, not the org chart.

A prime cannot certify at Level 2 while a subcontractor handling the same CUI stays uncovered. If your subcontractors aren't ready, that gap becomes your risk on award day.

Scoping guidance: asset categories and how to specify assessment scope

Under 32 CFR § 170.19, you must define your CMMC Assessment Scope before an assessor sets foot in your environment. This isn't paperwork for its own sake. Scope determines which systems get evaluated, and getting it wrong either exposes systems that don't need scrutiny or hides ones that do.

The scoping guides break assets into five categories:

  1. CUI assets — systems that process, store, or transmit CUI directly.
  2. Security protection assets — firewalls, SIEM platforms, and similar tools that provide security functions for the CUI environment.
  3. Contractor risk-managed assets — systems that could touch CUI but aren't intended to, managed through policy rather than technical isolation.
  4. Specialized assets — IoT devices, OT, government-furnished equipment, and restricted systems, which get documented in the inventory but not assessed against every requirement.
  5. Out-of-scope assets — systems architecturally separated from CUI with no logical path to reach it.

Every assessment requires an asset inventory, a network diagram, and an SSP referencing both. When using cloud or managed service providers, the responsibilities for security controls should be documented clearly in a Customer Responsibility Matrix to provide assessors with explicit boundaries.

Pro Tip: Build the smallest CUI enclave you can defend, not the widest one you can imagine. Contractors who isolate CUI to a handful of systems routinely cut assessment time and cost compared to those who leave CUI scattered across the whole network.

Locked isolated server rack as data enclave

Assessment process, evidence, and how POA&Ms actually work

Assessors evaluate against NIST SP 800-171A using three methods: examine (review documents like the SSP and configuration files), interview (talk to the people who actually run the systems), and test (verify the control functions as described). Bring your SSP, your BOE, system logs, and staff who can speak to daily operations without reading from a script.

Plans of Action and Milestones work differently by level:

  • Level 1: no POA&Ms permitted. Every practice must be fully in place at assessment time.
  • Levels 2 and 3: limited POA&M use is allowed, but open items must close within 180 days of the final assessment results, and certain critical controls can never sit on a POA&M at all.

Attempting certification with a non-allowable control parked on a POA&M is one of the fastest routes to a failed assessment. Identify those controls early and fix them before the assessor arrives.

Each requirement gets scored MET, NOT MET, or N/A. A NOT MET on a critical control with no allowable POA&M path typically means the assessment stops there until it's remediated and rescheduled.

Something worth flagging: the Federal Register final rule makes clear that verification method (self-assessment, C3PAO, or DIBCAC) is fixed by level and contract type, not negotiable after the fact.

Implementation timeline and how it affects solicitations

Phase 1 of the rollout began on November 10, 2025. Full implementation runs on a 36-month schedule from that start date, meaning DoD can phase in CMMC clauses across new solicitations and, in some cases, existing contract option periods over the next three years.

What this means for capture and procurement teams:

  • Don't assume your current contract is exempt just because it predates the clause. Option-year exercises can introduce CMMC requirements mid-contract.
  • Track solicitations in your pipeline specifically for CMMC status language, since the requirement can appear earlier than the broader rollout schedule suggests for high-priority CUI programs.
  • Build certification lead time into any bid decision. A C3PAO audit isn't something you schedule the week before award.

The safest posture is treating CMMC readiness as a standing requirement, not a reaction to a specific RFP.

Practical preparation checklist and how Nexus supports readiness

Before an assessor ever contacts you, get these in order:

  • Define and document your assessment scope.
  • Build a complete asset inventory and network diagram.
  • Draft your SSP and start collecting Basis of Evidence now, not the month before assessment.
  • Identify any non-allowable POA&M items and remediate them first.
  • Confirm your logging and SIEM coverage actually reaches every in-scope asset.
  • Document ESP and CSP responsibilities in a Customer Responsibility Matrix.

Operationally, isolate your CUI enclave, apply least-privilege access controls, verify your patching cadence, and run a mock assessment interview so your team isn't fumbling for evidence live. A cloud security posture that's poorly documented is one of the most common reasons Level 2 assessments stall.

Pro Tip: Run your own internal gap assessment against the NIST SP 800-171A methodology months before your C3PAO audit. Most contractors who fail on the first attempt fail on documentation, not technical controls.

Nexus supports this work directly through 24/7 monitoring, incident response, and compliance assessment services built around exactly this kind of preparation.

Why compliance-first beats certification-panic

Most CMMC coverage treats this as a certification hurdle to clear once and forget. That framing is backwards. The control requirements underneath Level 2, largely NIST SP 800-171, describe reasonable security hygiene that any contractor handling sensitive data should already have. Treating the assessment as the goal, rather than a checkpoint on an ongoing security posture, is exactly why so many organizations scramble in the final ninety days before a C3PAO audit.

Why compliance-first beats certification-panic — overview diagram

The scoping decision matters more than most contractors realize going in. Overbuilt scope isn't caution, it's cost. Every system pulled unnecessarily into your CUI enclave adds assessment time, documentation burden, and ongoing monitoring overhead for no security benefit.

If you take one thing from this: build the narrowest defensible scope first, then get your logging and evidence collection running continuously, not just before an audit. Contractors who treat CMMC as a byproduct of good daily security practice pass assessments with far less drama than those chasing a certificate.

— Nick - Sr. Executive

Getting your environment ready with Nexus

Most contractors trying to reach CMMC 2.0 requirements piece it together from a compliance consultant, a separate managed IT provider, and whatever internal staff can spare the time, which means nobody owns the whole picture when an assessor starts asking questions. AccountNext-Nexus consolidates the pieces that actually determine whether you pass: 24/7 threat monitoring and incident response, cloud security management across AWS, Azure, and Google Cloud, and compliance assessment work built specifically around frameworks like NIST SP 800-171.

AccountNext-Nexus

That consolidation matters most at scoping time, when documenting exactly which controls your cloud provider owns versus which you own is the difference between a clean audit and a stalled one. Nexus also works alongside partner guidance on cloud security for defence supply chain vendors when your environment spans multiple providers. If your next solicitation could carry a Level 2 clause, get your scope and asset inventory reviewed now, not after the RFP drops. Book a readiness assessment with AccountNext-Nexus to find out where your gaps actually are.

Sources

Keep local copies of your SSP, BOE, and scoping artifacts referenced against these documents. Assessors expect version-controlled records, not reconstructed ones.