What Is CMMC?
CMMC 2.0 (Cybersecurity Maturity Model Certification) is the Department of Defense’s mandatory cybersecurity framework for contractors and subcontractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Level 2 requires alignment with all 110 NIST 800-171 practices, verified by either a self-assessment or a third-party C3PAO assessment, depending on the contract. CMMC Phase 1 has been in effect since November 10, 2025. Phase 2, which would have made C3PAO assessments the norm for Level 2 contracts, was suspended on July 13, 2026 while the Department reviews the program (DoD CIO).
CMMC Level 2: What It Requires
CMMC Level 2 applies to defense contractors and subcontractors that process, store, or transmit Controlled Unclassified Information (CUI) on their own systems. You have to implement all 110 security requirements in NIST SP 800-171 Revision 2 and prove it through an assessment (32 CFR 170.16). That assessment is either your own self-assessment or a certification assessment by an accredited third party (a C3PAO), and the contract tells you which (32 CFR 170.3). As of September 2026, CMMC is paused in Phase 1, so most solicitations ask for a Level 2 self-assessment. The underlying obligation to protect CUI under DFARS 252.204-7012 never went away.
Who needs Level 2
The CMMC rule covers every DoD contract and subcontract where FCI or CUI will live on contractor information systems, except contracts solely for commercial off-the-shelf items and purchases at or below the micro-purchase threshold (32 CFR 170.3). The DoD program manager picks the required level based on the information involved. FCI alone means Level 1. CUI means Level 2 at minimum. Primes must flow the requirement down to subcontractors that handle the same CUI (32 CFR 170.23). If you machine parts from controlled drawings, host engineering data, or support a defense program’s IT, plan for Level 2. Our aerospace and defense IT page covers the typical environments we see.
The 110 requirements
Level 2 is the 110 requirements of NIST SP 800-171 Rev 2, spread across 14 families such as access control, audit and accountability, incident response, and system and communications protection (NIST SP 800-171 Rev 2). CMMC assesses against Revision 2, not the newer Revision 3 (DoD CIO). Assessors check each requirement against the objectives in NIST SP 800-171A, and the evidence has to be final. Drafts, working papers, and unapproved policies do not count (32 CFR 170.24). Our NIST 800-171 compliance page walks through the control families in more detail.
Self-assessment or C3PAO certification
There are two Level 2 statuses:
- Level 2 (Self). You assess your own environment, enter the score in the Supplier Performance Risk System (SPRS), and a senior official affirms it. You repeat the assessment every three years (32 CFR 170.16).
- Level 2 (C3PAO). An authorized or accredited CMMC Third-Party Assessment Organization runs the assessment and submits the results through the CMMC instance of eMASS, which feeds SPRS. A C3PAO status also satisfies Level 1 (Self) and Level 2 (Self) for the same scope (32 CFR 170.17).
You don’t get to choose. The solicitation states the required status. Even in Phase 1, DoD may require Level 2 (C3PAO) instead of Level 2 (Self) on a given contract (32 CFR 170.3(e)).
Scoring, POA&Ms, and the 88-point line
The maximum Level 2 score is 110. Each requirement you haven’t met subtracts 1, 3, or 5 points depending on its weight, and the total can go negative (32 CFR 170.24). A perfect score earns Final Level 2 status.
Fall short of 110 and you can still hold Conditional status with a Plan of Action and Milestones (POA&M), but only if all of these hold (32 CFR 170.21):
- Your score is at least 80 percent of 110, which works out to 88 points.
- Every item on the POA&M is worth 1 point. The one exception is CUI encryption (SC.L2-3.13.11), which can be deferred if you use encryption that isn’t FIPS-validated.
- None of six specific requirements is open, including the System Security Plan (CA.L2-3.12.4), external connections, public information control, and three physical access controls.
The POA&M has to be closed by a closeout assessment within 180 days of the Conditional status date. Miss that window and the Conditional status expires. For a self-assessment you run the closeout yourself. For a C3PAO assessment, a C3PAO has to do it (32 CFR 170.21(b)).
Timeline and phase status (as of September 2026)
- October 15, 2024: DoD published the CMMC Program rule, 32 CFR Part 170, effective December 16, 2024 (Federal Register).
- November 10, 2025: The DFARS acquisition rule (48 CFR) took effect, which started Phase 1 (Federal Register). Phase 1 requires Level 1 (Self) or Level 2 (Self) as a condition of award, with C3PAO assessments at DoD’s discretion.
- Phase 2 (planned for November 10, 2026): Level 2 (C3PAO) becomes a condition of award for applicable contracts.
- Phase 3 (one year after Phase 2): Level 2 (C3PAO) applies to all applicable contracts and to option periods, and Level 3 requirements begin.
- Phase 4 (one year after Phase 3): Full implementation, including option periods on contracts awarded before Phase 4 (32 CFR 170.3(e)).
- July 13, 2026: The Department of War suspended Phase II and set up a CMMC reform task force. Phase 1 self-assessment requirements stay in place, and the Department says it will keep enforcing NIST 800-171 Rev 2 through self-assessments and select government-led assessments (DoD CIO).
The Phase 2 through 4 language is still in the published regulation (32 CFR 170.3). The pause could end with a new rule or a revised one. If a prime or a program office is already asking about third-party assessment, treat that as the signal to get ready.
How long Level 2 status lasts
Final Level 2 status is valid for three years from the status date, for both self and C3PAO assessments. On top of that, an Affirming Official, a senior person in your company, must affirm continuing compliance in SPRS after every assessment, after any POA&M closeout, and every year after that (32 CFR 170.22). Skip the annual affirmation and the status lapses (DoD CIO). For C3PAO assessments, you also keep hashed copies of your assessment evidence for six years (32 CFR 170.17).
What DoD estimates Level 2 will cost
The final rule’s cost analysis gives these figures for the assessment and affirmations alone (Federal Register, 89 FR 83092):
| Level 2 path | Small entity, first assessment | Small entity, 3-year total | Other than small, first assessment | Other than small, 3-year total |
|---|
| Self-assessment | $34,277 | $37,196 | $43,403 | $48,827 |
| C3PAO certification | $101,752 | $104,670 | $112,345 | $117,768 |
Read the fine print. DoD assumed you had already implemented the 800-171 requirements, so these numbers leave out remediation, new tools, and the staff time it takes to close gaps. If you are starting from a low SPRS score, budget for that work separately.
How to prepare for CMMC Level 2
- Confirm you handle CUI. Look for DFARS 252.204-7012 in your contracts and CUI markings on the drawings and data you receive. Ask your prime which CMMC status they will flow down.
- Draw the assessment boundary. List every system, person, and facility that touches CUI, plus the security tools and service providers that protect them. Cloud services that hold CUI need FedRAMP Moderate authorization or an equivalent (32 CFR 170.17).
- Write the System Security Plan first. It is one of the requirements that can never go on a POA&M.
- Score yourself honestly. Use the 1, 3, and 5 point values from the rule, not a friendly estimate.
- Fix the 3 and 5 point gaps before anything else. They can’t be deferred, and a few of them can drop you below 88 on their own.
- Collect evidence in final form. Signed policies, configuration exports, logs, and training records. No drafts.
- Post your score in SPRS and affirm. Put a calendar reminder on the annual affirmation.
- Line up a C3PAO early if your contracts point that way. Assessor calendars fill up once requirements tighten.
AdVran is not a C3PAO. We handle the preparation: gap assessment, SSP and POA&M writing, control implementation, and coordination with the independent assessor you choose. See our compliance and risk management services, or request a CMMC Level 2 readiness assessment to find out where your score stands today.
Why Choose AdVran for CMMC?
When a contract calls for a C3PAO assessment, self-attestation won’t satisfy it. Your managed service provider counts as a Security Protection Asset inside your audit boundary, so the assessor looks at their security as part of yours. If your MSP’s controls are weak, the C3PAO can write that up as a finding before reviewing any of your own documents.
1. Audit-Ready Evidence
Logs alone don’t pass an assessment. We run a centralized GRC platform that automates evidence collection for all 110 NIST 800-171 controls, so when a C3PAO auditor shows up, your System Security Plans (SSP) and Plans of Action and Milestones (POA&M) are already timestamped and organized.
2. We Hold Ourselves to Level 2
Under CMMC 2.0, an MSP that touches your CUI environment is in scope for your audit. We keep our own security aligned to Level 2 standards so our internal tools and remote access protocols don’t turn into findings against you.
3. Sovereignty and Data Residency
We work within ITAR and DFARS requirements. Our support teams are US-based, and our cloud architectures use FedRAMP Moderate/High environments like Azure Government and AWS GovCloud. Your data stays on US soil and out of reach of unauthorized foreign nationals.
4. Proactive Threat Hunting
An assessment shows where your controls stood on the day of the review, and threats keep coming after that. Our MSSP division offers Managed Detection and Response (MDR) tuned specifically for the Defense Industrial Base, including a documented incident response capability that satisfies NIST 800-171 IR control family requirements. Our analysts hunt for the advanced persistent threats that go after defense contractors, along with the commodity malware that shows up in generic threat feeds.
5. A Clear Shared Responsibility Matrix
We give you a written Shared Responsibility Matrix that shows which of the 110 controls we manage, which you own, and which we share, so nobody is guessing at assessment time.
Frequently Asked Questions About CMMC Compliance
What is CMMC 2.0 and who does it apply to?
CMMC 2.0 applies to all DoD prime contractors and subcontractors who handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). DoD puts the defense industrial base at over 220,000 companies that process, store, or transmit CUI or FCI, and estimates that 8,350 medium and large entities will require a Level 2 certification assessment (89 FR 83092). Southern California holds a significant share of that base, near the major defense primes in Long Beach, El Segundo, Anaheim, and Pasadena. CMMC requirements flow down through the supply chain. If a prime requires CMMC, their subcontractors handling CUI must also comply.
What is the difference between CMMC Level 1, 2, and 3?
CMMC Level 1 covers 15 basic security requirements from FAR 52.204-21 for contractors handling FCI and requires annual self-assessment. Level 2 covers 110 practices aligned to NIST 800-171 for contractors handling CUI; most contracts require triennial third-party assessment by a C3PAO. Level 3 adds 24 enhanced requirements from NIST SP 800-172 for the most sensitive DoD programs and requires a government-led assessment by DCMA DIBCAC. Most Southern California defense contractors need Level 2.
What is a C3PAO and is a third-party assessment required?
A C3PAO (CMMC Third-Party Assessment Organization) is an accredited firm authorized by the Cyber AB to conduct official CMMC Level 2 assessments. The contract decides whether Level 2 is a self-assessment or a C3PAO assessment. During Phase 1 most Level 2 requirements are self-assessments, and Phase 2, which would have made C3PAO assessments standard, was suspended in July 2026. DoD can still require a C3PAO on any contract. AdVran prepares clients for C3PAO assessments by documenting all 110 controls, maintaining a System Security Plan, and closing gaps found during pre-assessment reviews.
How does having AdVran as my MSP affect my CMMC audit scope?
Under CMMC 2.0, any external service provider that processes, stores, or transmits CUI on your behalf is potentially in scope for your assessment. AdVran operates as a Security Protection Asset within your audit boundary, so our security affects your certification outcome. We keep our own environment aligned to CMMC Level 2 standards so that having us in scope doesn’t add findings to your assessment.
How long does CMMC Level 2 preparation take?
Most organizations need 6-18 months to reach CMMC Level 2 certification from a cold start, depending on their current posture and the gap between existing practices and all 110 NIST 800-171 controls. Organizations with an existing NIST 800-171 self-assessment score above 100 points can typically wrap up preparation in 3-6 months. AdVran starts with a gap assessment that produces a realistic timeline and remediation roadmap before any investment commitment.
What is CMMC Level 2?
CMMC Level 2 is the middle tier of the DoD’s Cybersecurity Maturity Model Certification, required for contractors that handle Controlled Unclassified Information. It requires all 110 security requirements in NIST SP 800-171 Rev 2, verified by a self-assessment or a C3PAO certification assessment, whichever the contract specifies (32 CFR 170.16, 32 CFR 170.17).
Can we self-assess for CMMC Level 2?
Yes, if the contract calls for Level 2 (Self). During Phase 1, which began November 10, 2025, most Level 2 requirements are self-assessments, though DoD can require a C3PAO on any contract. Phase 2 would have made C3PAO assessments standard, but it was suspended on July 13, 2026 (DoD CIO). You enter the score in SPRS and a senior official affirms it.
What score do we need for CMMC Level 2?
A perfect 110 earns Final status. A score of 88 or higher (80 percent of 110) can earn Conditional status with a POA&M, as long as the open items are 1-point requirements and none are on the rule’s excluded list. All POA&M items must be closed within 180 days or the Conditional status expires (32 CFR 170.21).
How long is CMMC Level 2 status valid?
Three years from the status date. You also need an annual affirmation in SPRS from a senior official, and the status lapses if you miss one (32 CFR 170.22).
How AdVran helps: AdVran’s managed CMMC compliance services handle gap assessment, SSP and POA&M authoring, control implementation, and C3PAO coordination, so your team isn’t running the project on top of its day jobs.
AdVran’s vulnerability management service runs scheduled scans across your environment, prioritizes findings by exploitability, and tracks remediation to closure, meeting CMMC CA.L2-3.11.2, which requires periodic scanning of organizational systems and real-time scanning of files from external sources.
Defense contractors pursuing CMMC certification often operate under additional frameworks. CJIS Security Policy requirements apply to defense and law enforcement contractors handling criminal justice information. FedRAMP applies to cloud service providers supporting DoD or federal agency systems within CMMC scope. FIPS 140-2 cryptographic validation is explicitly required by CMMC Level 2 and above for protecting CUI at rest and in transit. API Cybersecurity Standards govern oil, gas, and pipeline operators in the defense industrial supply chain.