CMMC · NIST SP 800-171 · ITAR · RMF · Insider threat+1 571 410 3066
Cybersecurity Consulting

CMMC

What does CMMC Level 2 actually require in 2026?

CMMC Level 2 requires a defense contractor that handles Controlled Unclassified Information to implement the 110 security requirements in NIST SP 800-171 Rev 2 and to prove it. The requirements themselves did not change this year. What changed is when a contractor will face a third party assessment. On July 13, 2026 the Department of War suspended the planned Phase 2 rollout of third party assessments and ordered a 60 day review; self assessment, SPRS and the annual affirmation were not suspended. This article sets out what still applies, what the suspension does and does not mean, and what a small contractor should be doing this quarter.

What does CMMC Level 2 actually require?

It requires every one of the 110 requirements in NIST SP 800-171 Rev 2 to be implemented in the systems that store, process or transmit Controlled Unclassified Information, and in the systems that protect them. Those requirements are spread across fourteen families, from access control to system and information integrity, and each one is broken into assessment objectives in NIST SP 800-171A. An assessor, whether that is you or a third party, judges each objective as met or not met.

In practice that means three things have to exist at the same time. The control has to be in place, it has to be written down in a System Security Plan that says how it is met, and there has to be evidence that it operates. A firewall rule nobody documented, or a policy nobody follows, fails the same way.

Where does the requirement come from?

It comes from two layers of regulation that work together. The first is the contract clause DFARS 252.204-7012, which has required contractors to provide adequate security for covered defense information by implementing NIST SP 800-171 for years. It also requires cyber incident reporting to DoD, preservation of images and flow down to subcontractors who handle covered defense information.

The second layer is the assessment and certification structure. DFARS 252.204-7019 and 252.204-7020 require a current NIST SP 800-171 assessment score posted in SPRS and give DoD the right to assess you. The CMMC program rule at 32 CFR part 170 defines the levels and how each is assessed, and DFARS 252.204-7021 is the clause that puts a CMMC level into a contract.

What changed on July 13, 2026?

On July 13, 2026 the Department of War suspended the planned Phase 2 rollout of third party assessments and ordered a 60 day review; self assessment, SPRS and the annual affirmation were not suspended. That is narrower than it sounds. It affects when contracts will call for a certification by an authorized third party assessor. It does not remove NIST SP 800-171, it does not remove DFARS 7012, and it does not remove the obligation to post a score and affirm it.

We are not going to predict the outcome of the review, and you should be wary of anyone who does. The sound planning assumption is that third party assessments come back in some form, and that a contractor who keeps building toward an assessment ready environment loses nothing if it does not.

Is a self assessment still required?

Yes. A contractor subject to DFARS 252.204-7019 must have a current NIST SP 800-171 assessment, no more than three years old, posted in SPRS before a covered contract can be placed with it. The CMMC Level 2 self assessment follows the same requirements and the same assessment objectives a third party would use.

The self assessment is not a lighter version of the real thing. It is the same test, run by you, and it carries your company's name. A score that a later DoD assessment cannot reproduce is a problem of its own, separate from any security gap.

How is the SPRS score calculated?

The score is calculated under the DoD Assessment Methodology, which starts at 110 and subtracts a weighted value for every requirement that is not fully met. Most requirements carry a weight of one, three or five points depending on how much the gap would hurt, so the score can fall well below zero for an environment with major gaps.

A requirement that is partly implemented generally counts as not met. The methodology allows partial credit on a small number of requirements, multifactor authentication and FIPS validated encryption among them, and only under the conditions it describes. A missing System Security Plan is treated more severely still, because without one the assessment cannot be completed at all.

What is the annual affirmation and who signs it?

The annual affirmation is a statement entered in SPRS by a senior official of the company that it continues to meet the requirements of its CMMC level. Under 32 CFR part 170 the person who makes it is called the Affirming Official, and the affirmation is required after each assessment, after closing a POA&M and at least once a year in between.

That signature is the part owners should take most seriously. It is a representation to the government. If the score or the affirmation does not match what is actually in place, the exposure is legal, not just technical, and it attaches to the company and to the person who signed. The affirmation should be backed by a current SSP and evidence, never by memory.

What can still sit on a POA&M?

A POA&M can carry a limited set of open items, under rules that are stricter than many contractors expect. Under 32 CFR part 170 a Level 2 assessment can reach conditional status only if the score is at least 88 out of 110, only if the open items are ones the rule allows to be deferred, and only if every open item is closed out within 180 days.

The requirements with the heaviest weights generally cannot be left open, and a few are named in the rule as never eligible. The practical reading is simple. A POA&M is for finishing touches with a date attached, not for a program that has not started. If your list of open items is long, the plan should be to close them, not to argue about which ones can wait.

What should a contractor do this quarter?

Keep building as if a third party assessor is coming, because the requirements and the affirmation did not move. Start by confirming where your CUI actually lives and drawing a scope you can defend, then compare the environment requirement by requirement against the 800-171A objectives and post an honest score.

From there the order is usually the same. Write or refresh the System Security Plan, close the high weighted gaps first, collect evidence as you go rather than at the end, and schedule a mock assessment once the open list is short. Revisit the plan when the review concludes. Whatever it decides, an environment that meets NIST SP 800-171 and can prove it is the position that holds up.

Which engagements cover this?

CMMC Level 2 program leadership

Fractional CISO leadership for a CMMC Level 2 certification run, from the first assessment to the C3PAO visit.

SSP and POA&M review and assessor readiness

Review of your System Security Plan and POA&M against NIST SP 800-171A, so both documents are assessor ready for CMMC Level 2.

C3PAO readiness and mock assessment

CMMC Level 2 mock assessment and C3PAO readiness, including C3PAO selection, for defense contractors preparing for certification.

What else do readers ask?

Did the suspension remove CMMC Level 2?

No. It suspended the planned Phase 2 rollout of third party assessments and ordered a 60 day review. NIST SP 800-171, DFARS 252.204-7012, the self assessment, the SPRS score and the annual affirmation remain.

Should we stop preparing for a C3PAO assessment?

We would not. The requirements did not change, the affirmation still has to be true, and the review could bring third party assessments back. Work done toward assessment readiness is the same work the self assessment needs.

How long is an SPRS score valid?

Under DFARS 252.204-7019 the assessment must be current, which means no more than three years old, and the annual affirmation has to be kept up in between.

Who should sign the annual affirmation?

A senior official of the company with authority to make the representation, called the Affirming Official in 32 CFR part 170. That person should see the SSP and evidence before signing.

This article is general information about the regulations as written, not legal advice. Read your contract clauses and the regulation text, and take legal advice where the answer matters.

Ready to talk it through?

BOOK A CALL

Pick a time for a 30 minute call with the practice.

What happens in 30 minutes

  1. We learn about your company, the contracts you hold or are bidding on, and what is driving your timeline.
  2. We talk through where you stand and which engagement fits, if any does.
  3. If there is a fit, we follow up with a written scope. No slides.