CMMC Phase 2 Deadline (November 2026): What Every Defense Contractor Needs to Do Now
Phase 1 is already live. Phase 2 hits in 8 months. Most contractors aren't ready. Here's the four-phase timeline, what each level requires, and the six steps you should be taking right now.
What Is CMMC Phase 2?
CMMC Phase 2, effective November 10, 2026, is when DoD intends to require defense contractors handling Controlled Unclassified Information (CUI) to hold a CMMC Level 2 certification — verified by an authorized C3PAO third-party assessor — for applicable solicitations and contracts that include CMMC requirements. DoD may defer Level 2 (C3PAO) requirements to an option period for some awards. This marks the shift from self-assessed compliance to independently verified certification under the Cybersecurity Maturity Model Certification (CMMC) 2.0 framework established by 32 CFR Part 170.
Phase 1 Is Already Here
As of November 10, 2025, Phase 1 is in effect. For solicitations and contracts that include CMMC requirements, DoD contracting officers require offerors to have a current CMMC Level 1 status posted in SPRS. If you haven't completed your Level 1 self-assessment and annual affirmation, you may be ineligible for new contract awards that specify CMMC compliance.
The Four-Phase CMMC Rollout Timeline
CMMC 2.0 is being implemented in four phases per 32 CFR 170.3(e). Each phase expands the scope of solicitations and contracts that require certification. Understanding where we are in this timeline is critical for planning your compliance roadmap.
Phase 1: November 10, 2025
ACTIVE NOWLevel 1 self-assessment required on applicable new solicitations and contracts. Level 2 self-assessment option for some contracts. Contractors must have a current CMMC status in SPRS to be eligible for award on contracts that include CMMC requirements.
Phase 2: November 10, 2026
8 MONTHS AWAYLevel 2 C3PAO certification required on applicable new solicitations and contracts involving CUI. DoD may defer Level 2 (C3PAO) requirements to an option period at its discretion. This marks the shift from self-assessed to independently verified compliance.
Phase 3: November 10, 2027
EXPANDING SCOPEPhase 3 broadens the scope of contracts requiring CMMC certification. DoD intends to include Level 2 (C3PAO) requirements on option periods for applicable existing contracts per 32 CFR 170.3(e).
Phase 4: November 10, 2028
FULL IMPLEMENTATIONFull CMMC implementation across all applicable DoD solicitations, contracts, and option periods. All covered contractors must hold the required CMMC level status as specified in their contract terms.
What Phase 2 Actually Changes
The core change is straightforward: after November 10, 2026, DoD intends to require Level 2 C3PAO certification on applicable new solicitations and contracts involving CUI, where the solicitation specifies a Level 2 (C3PAO) assessment. DoD retains discretion to defer this requirement to an option period for some awards. Self-assessment alone will no longer be sufficient for these covered contracts.
What Changes
- Applicable new CUI solicitations/contracts require C3PAO verification
- L2 certifications generally valid for 3 years with annual affirmations
- Industry observations indicate C3PAO scheduling backlog is growing
What Doesn't Change (Yet)
- Existing contracts without CMMC requirements generally unaffected during Phase 2, though DoD may apply CMMC to option periods at its discretion
- L1 self-assessment process stays the same
- Option exercises on active contracts: Phases 3-4 (2027-2028), at DoD discretion
The pipeline problem: Industry reporting suggests that only a small fraction of defense contractors who handle CUI have completed Level 2 certification as of early 2026. With industry observations indicating C3PAO assessment scheduling backlogs are growing, contractors who wait until November 2026 to start the process risk missing the assessment pipeline window for timely certification.
Level 1 vs Level 2: Which Applies to You?
The level you need depends on the type of information you handle under your DoD contracts. Getting this determination right is the critical first step — inaccurate self-assessments may carry False Claims Act risk depending on materiality and the specific contract terms.
Level 1 — FCI Only
- Applies when: You handle Federal Contract Information (FCI) but no CUI
- Controls: 15 security requirements from FAR 52.204-21
- Assessment: Annual self-assessment with executive affirmation in SPRS
- POA&Ms: Not allowed — all 15 controls must be fully implemented
- Market size: Industry estimates suggest a majority of DIB contractors fall into Level 1
Level 2 — CUI
- Applies when: You handle Controlled Unclassified Information (CUI)
- Controls: All 110 controls from NIST SP 800-171 Rev. 2
- Assessment: C3PAO third-party certification (as specified in solicitation); valid 3 years
- POA&Ms: Allowed for some controls with time-bound remediation plans
- Cost: Varies by scope (industry estimates: $30,000-$100,000+)
How to Determine Your Level
Check your contracts for DFARS 252.204-7012 clauses and CUI markings. If you only handle FCI (no CUI), Level 1 applies. If any contract involves CUI, you need Level 2. A common misconception among small subcontractors is that CMMC doesn't apply to them — but flowdown requirements mean that if your prime holds a CUI contract and you touch that data, Level 2 applies to you as well.
6 Steps Defense Contractors Should Take Right Now
Whether you need Level 1 or Level 2, the time to prepare is now. Phase 1 is already enforcing, and Phase 2 is closer than most contractors realize once you factor in assessment scheduling backlogs.
Determine Your CMMC Level Requirement
Review your active and anticipated DoD contracts. Check for DFARS 252.204-7012 clauses and CUI markings. If you only handle Federal Contract Information (FCI) with no CUI, Level 1 applies. If any contract involves CUI, you need Level 2. When in doubt, check with your contracting officer — getting this wrong has legal consequences.
Complete Your Level 1 Self-Assessment
If you haven't affirmed your CMMC Level 1 status in SPRS, you are already non-compliant for Phase 1 contracts being awarded today. Level 1 requires implementing all 15 controls from FAR 52.204-21 and achieving a perfect score — no Plan of Action and Milestones (POA&Ms) are allowed. Your senior official must sign the annual affirmation in SPRS.
Conduct a Gap Assessment Against NIST SP 800-171
If Level 2 applies to your organization, identify which of the 110 controls you have fully implemented versus where gaps exist. This is not a checklist exercise — each control has specific assessment objectives that must be met. A thorough gap assessment is the foundation of your remediation roadmap.
Document Your System Security Plan (SSP)
The SSP is both an assessment artifact that the C3PAO will review and an operational document your organization lives by. It describes your system boundaries, data flows, implemented controls, and how you meet each NIST 800-171 requirement. If you don't have an SSP, start building one now.
Budget for Your C3PAO Assessment
Level 2 assessments vary significantly in cost depending on the scope and complexity of your environment — industry estimates range from $30,000 to $100,000 or more, though official pricing is set by individual C3PAOs. Factor in the growing scheduling backlog for C3PAO assessments. Contractors who wait until November 2026 to begin the process risk not clearing the assessment pipeline in time.
Engage a CMMC Registered Practitioner (RP)
An RP provides expert readiness guidance without the conflict of interest that would arise if the same entity both prepared and assessed your organization. An RP can evaluate your current controls, identify gaps, guide your remediation, and confirm your readiness before you engage a C3PAO. Think of it as a trusted advisor who ensures you pass — before you take the test.
What is a CMMC Registered Practitioner?The False Claims Act Risk Is Real
When you affirm your CMMC status in SPRS, you are making a legal representation to the federal government. An inaccurate self-assessment may expose your organization to False Claims Act (FCA) risk, depending on factors including materiality, scienter (knowledge or reckless disregard), and the specific terms of your contract. The Department of Justice's Civil Cyber-Fraud Initiative has signaled its intent to pursue enforcement actions against contractors who misrepresent their cybersecurity compliance posture.
For Level 1, the stakes are particularly clear: there are no POA&Ms allowed. Every one of the 15 controls and their associated assessment objectives must be fully implemented before you sign. There is no "getting most of the way there" — it is a pass/fail assessment, and your senior official is personally attesting to its accuracy.
This is one of the strongest reasons to engage a qualified Registered Practitioner before you affirm. An RP can independently validate your self-assessment, identify gaps you may have overlooked, and give you confidence that what you're signing is accurate.
Note: This article provides general compliance guidance, not legal advice. FCA liability depends on specific facts and contract terms. Consult qualified legal counsel for advice on your organization's specific FCA exposure.
A Practitioner's Perspective
As a CMMC Registered Practitioner, I've seen a consistent pattern among defense contractors approaching compliance for the first time: they underestimate what "self-assessment" actually requires. Many assume that because Level 1 is a self-assessment, it's simple. The reality is that each of the 15 controls maps to specific assessment objectives (59 total, per the official CMMC Level 1 Assessment Guide) that must be demonstrably met — not just documented in a policy, but implemented and evidenced.
At Cloud Solutions Consulting, we approach CMMC readiness as an extension of our virtual CISO services. Rather than rushing you through a checklist, we assess your current security posture, map it against the applicable CMMC requirements, and produce a clear readiness picture — so you know exactly where you stand before you make that affirmation in SPRS.
The organizations that are most successful with CMMC are those that treat it as an ongoing compliance posture, not a one-time project. That's the difference between a readiness partner and an implementation vendor — and it's why the vCISO model works particularly well for small defense contractors who need expert guidance without the overhead of a full-time compliance officer.
Frequently Asked Questions
CMMC Phase 2 begins on November 10, 2026 — one calendar year after Phase 1 per 32 CFR 170.3(e). During Phase 2, DoD intends to require Level 2 (C3PAO) certification for applicable solicitations and contracts involving CUI. DoD may defer Level 2 (C3PAO) requirements to an option period for some awards. CMMC follows a four-phase rollout: Phase 1 (Nov 2025), Phase 2 (Nov 2026), Phase 3 (Nov 2027), and Phase 4 or full implementation (Nov 2028).
CMMC Level 1 applies to contractors handling Federal Contract Information (FCI) and requires implementing 15 security controls from FAR 52.204-21, verified through annual self-assessment. CMMC Level 2 applies to contractors handling Controlled Unclassified Information (CUI) and requires implementing all 110 controls from NIST SP 800-171 Rev. 2, verified through a C3PAO third-party assessment as specified in the solicitation. Level 2 certifications are valid for three years with annual affirmations.
Yes. CMMC requirements flow down through the supply chain. If your prime contractor holds a contract requiring CMMC Level 2 and you handle CUI as part of that work, you must also achieve Level 2 certification. Even if you only handle FCI, Level 1 self-assessment and SPRS affirmation are required for covered contracts.
A CMMC Registered Practitioner (RP) is a credentialed professional authorized by the Cyber AB to provide CMMC consulting and readiness guidance. RPs help organizations prepare for assessments but do not conduct the assessments themselves — this separation ensures the integrity of the assessment process.
For organizations with some existing cybersecurity practices in place, CMMC Level 1 compliance can typically be achieved in 3 to 6 months. This includes scoping, gap assessment, control implementation, policy documentation, and the final executive affirmation in SPRS. Organizations starting from a lower cybersecurity baseline may need up to 9 months.
Free CMMC Level 1 Readiness Review
Find out where your organization stands against the 15 Level 1 controls before your next contract opportunity requires it. Our RP-credentialed team will assess your current posture and tell you exactly what needs to happen.