In July 2026, the Pentagon suspended CMMC Phase 2 enforcement and launched a 60-day review of the entire program. That headline caused plenty of confusion in the defense industrial base, but it did not change what most contractors actually have to do. This guide gives you the current, accurate picture of CMMC compliance at Level 1 and Level 2: which level applies to you, what each requires, how the assessments work, what the pause does and doesn't change, and what it all costs. If your contracts touch FCI or CUI, this is the reset you need before your next bid.
On July 13, 2026, the Department of War suspended CMMC Phase 2 requirements, which had been scheduled to make third-party certification a condition of applicable contract awards starting November 10, 2026. A new CMMC Reform Task Force will review the program and report within 60 days, and the department is issuing a request for information so contractors can weigh in directly. Officials cited a hard capacity problem: more than 100,000 companies needing assessments against roughly 100 approved assessors, plus projected compliance costs in the billions annually for small businesses.
Here is what the pause does not change. During the review, the department stated it will continue enforcing NIST SP 800-171 Revision 2 through self-assessments and select government-led assessments. Your DFARS 252.204-7012 obligations remain in every contract that contains them, SPRS scores are still required, and Phase 1 obligations continue in solicitations. The rule establishing the program remains on the books; what's suspended is the next enforcement phase.
The practical read for compliance leads: the deadline pressure eased, the underlying cybersecurity requirements did not. DoD leadership was explicit that money already spent improving your posture was not wasted, and a False Claims Act settlement over misrepresented compliance landed just weeks before the announcement. Treat this as breathing room to do the work properly, not permission to stop.

The Cybersecurity Maturity Model Certification streamlines the old five-tier CMMC 1.0 framework into three levels of CMMC. The level of CMMC you need tracks the sensitivity of the information you handle. The DoD's CMMC program documentation defines the structure, and it hasn't changed with the pause.
Level 1 focuses on protecting Federal Contract Information, or FCI, using basic cybersecurity practices: 15 security requirements drawn from FAR 52.204-21. Level 2 protects Controlled Unclassified Information (CUI) and requires all 110 security requirements of NIST SP 800-171. CMMC Level 3 builds on Level 2, adding selected requirements from NIST SP 800-172 for contractors supporting the DoD's highest-priority programs, with government-led assessment.
Most of the defense industrial base lands at the first two levels, which is why this checklist concentrates there. CMMC Levels 2 and 3 share the same foundation, and the gap between Level 2 and Level 3 is a set of add-on requirements, so nothing you do for Level 2 is wasted if a future contract pushes you higher. CMMC 2.0 Level 3 certification remains rare enough that your contracting officer will make it unmistakably clear when that maturity level is on the table.
The data decides, not the company size. If your systems touch only FCI, meaning information provided by or generated for the government under contract that isn't intended for public release, Level 1 is your lane. If you store, process, or transmit CUI, such as controlled technical information, export-controlled data, or certain program details, you need CMMC Level 2. The solicitation states the required CMMC level, but you shouldn't wait for one to determine which CMMC level applies to your environment; your certification level follows your data.
Two wrinkles catch contractors. First, flow-down: contracts that require CMMC pass the obligation to subcontractors handling the same information, and the level required follows the information, not the prime's own status. Second, marking problems: agencies don't always label CUI correctly, so the safe practice is to assess what you actually receive rather than trusting the stamp. When in doubt, ask the contracting officer in writing.
A candid note for the fence-sitters: many shops hoping they qualify at the first level discover legacy CUI in old project folders. An honest data inventory now costs a few days. Discovering unprotected CUI during an audit, or worse, a breach, costs contracts. If you genuinely handle no CUI, document that determination; it's your best defense if the question ever comes up.
Level 1 covers the basics that any business connected to the internet should already run. The 15 requirements from FAR 52.204-21 group into familiar themes: limit system access to authorized users, control connections to external systems, manage physical access, sanitize media before disposal, patch known flaws, run malware protection, and keep public-facing systems separate from internal ones.
On verification, the rule is straightforward: CMMC 2.0 Level 1 requires an annual self-assessment against all 15 requirements, with the results and a senior company official's affirmation entered in the Supplier Performance Risk System (SPRS). There is no third-party involvement at this level, and importantly, no POA&M allowance either: every requirement must be fully met, because the DoD considers these practices too fundamental to defer.
Don't let the word "basic" breed complacency. That executive affirmation carries personal accountability, and misstatements create False Claims Act exposure. The bar is low, but you must actually clear it, and be able to show how.

Level 2 requires implementing all 110 security requirements of NIST SP 800-171 Revision 2, organized in 14 families covering access control, incident response, encryption, auditing, and more, and verified against 320 assessment objectives. The CMMC Level 2 requirements are identical whichever assessment path applies. One accuracy note that trips people up: NIST published Revision 3 in 2024, but the CMMC rule locks assessments to Revision 2 until new rulemaking says otherwise. Build to Rev 2; track Rev 3 for the future.
Documentation carries as much weight as technology. Level 2 requires a System Security Plan describing how each requirement is met, a POA&M for gaps, and evidence an assessor can verify. Under the scoring methodology, a conditional status is possible at 80 percent or better, with remaining POA&M items closed within 180 days, though the highest-weighted requirements can't be deferred at all.
Under the CMMC framework as written, most contracts handling CUI will eventually require Level 2 certification through a triennial third-party assessment, while a smaller set of Level 2 contracts allow self-assessment. The Phase 2 pause suspends the enforcement timeline for that certification mandate, not the requirements themselves, and every path still demands the same 110 requirements plus an annual affirmation.
At the first level, and for a subset of Level 2 contracts, you assess yourself: score your implementation, post results to SPRS, and have a senior official affirm annually. It's inexpensive, but the affirmation makes it legally serious. Treat your annual self-assessment with the rigor of an external audit, because the government can check your math through select reviews at any time.
The certification path runs through a certified third-party assessment organization, better known as a C3PAO, accredited by the CMMC Accreditation Body, which now operates as The Cyber AB; every CMMC third party assessor working these engagements is credentialed through it. Its marketplace is the authoritative directory for finding an assessor; under the rule's design, a passing CMMC third-party assessment yields CMMC Level 2 certification good for three years, paired with annual affirmations in between as evidence of ongoing compliance. That assessment every three years is what Phase 2 would have made mandatory for applicable awards.
Where does the pause leave third-party work? Voluntary, for now, but not pointless. Assessor capacity was the choke point DoD itself named, and contractors who complete or prepare for a C3PAO assessment during the lull will be first in line however the reform lands. Some primes are also asking for certification status regardless of what the government requires, so market pressure hasn't paused even though the mandate has.

Here is the sequence that works for a Level 1 organization:
Most small shops can complete this in weeks, not months. The discipline of steps four through six is what separates contractors who maintain compliance from those who scramble every renewal.
Level 2 is a standing compliance program, so sequence it like one:
Prepare for CMMC as if verification were certain, because in one form or another, it is. Whether the assessor is you, a C3PAO, or the government, what it takes to meet CMMC Level 2 stays constant: the same CMMC 2.0 requirements, all 110 of them.
Under the rule, the CMMC certification process runs: readiness, then engagement with a C3PAO, then a formal assessment reviewed for quality before certification issues, then annual affirmations across a three-year cycle. Preparation dominates the timeline; organizations typically need six to eighteen months of readiness work before an assessor walks in, which is precisely why waiting for regulatory certainty is a costly strategy.
The pause changes the "when" of compliance with CMMC 2.0, not the "what." Until the Reform Task Force reports and the department acts, third-party certification isn't being newly mandated in solicitations, and the path to CMMC for most contractors runs through honest self-assessment, a defensible SPRS score, and steady remediation. Contracts awarded with existing clauses keep their existing CMMC compliance requirements.
Watch three signals over the coming months: the task force's report, the RFI and what industry says in it, and how primes adjust their flow-down demands. Achieving CMMC 2.0 compliance was never really about a single date; contractors who require compliance discipline of themselves regardless of enforcement schedules are the ones who win work in every scenario the review could produce.
For Level 1, the cost is mostly time: a few days to inventory, map, and document, then a light annual cycle. DoD's own estimates put the recurring burden for a small business in the low thousands of dollars per year, which is why nobody should let those 15 requirements linger unmet.
Level 2 is a different budget conversation. Expect readiness, remediation, and documentation to run from tens of thousands into six figures depending on your starting cybersecurity posture and how tightly you scope the CUI environment, with a C3PAO engagement historically adding a low-six-figure triennial line for smaller firms. The cost of CMMC drops meaningfully with smart scoping, which is where experienced guidance pays for itself fastest; our breakdown of what cybersecurity consulting should cost offers useful benchmarks.
Two cost mistakes to avoid: gold-plating the entire network when an enclave would do, and pausing all spending because of the Phase 2 news. The compliance process rewards steady, scoped investment; firms that budget this way achieve CMMC compliance at a fraction of panic pricing, and the DoD's stated concern about cost points to a cheaper path to verification, not a world with no verification at all. To demonstrate compliance whenever asked remains the requirement underneath every scenario.

Whether you're a Level 1 shop tightening the basics or a Level 2 contractor sequencing 110 requirements, the fastest path is a clear, prioritized plan. VisioneerIT Security's CMMC preparation practice helps defense contractors scope CUI environments, run gap assessments, build audit-grade evidence, and meet CMMC requirements without over-buying; guidance on selecting outside help is in our pieces on choosing a CMMC consultant for Level 2 readiness and how expert CMMC consultants protect contracts. Our GovCon security team works with DIB contractors from 50 to 500 seats.
Request the CMMC readiness checklist, a practical, level-specific worksheet your team can start on this week. The review period is a gift of time; the contractors who use it will achieve CMMC certification on their own schedule instead of a waitlist's.
At VisioneerIT Security, we're committed to safeguarding your business. Reach out to us with your questions or security concerns, and our team will provide tailored solutions to protect your digital assets and reputation.