Sentrix

Breakdown · Defense

CMMC 2.0: levels, final rule and the real timeline

The three levels of CMMC 2.0, the 32 CFR part 170 final rule, the phased rollout in DoD contracts and the 2026 suspension of Phase 2, from the official texts.

By Sentrix · Published 2026-09-20

The Cybersecurity Maturity Model Certification (CMMC) ended up becoming a rule of law, then a contract clause, then, in 2026, a partially suspended program. For a supplier or subcontractor of the United States Department of Defense (DoD), the risk is not missing a date: it is reading it in a newsletter rather than in the Federal Register. Here is what the official texts say.

What the rules say

The final rule that creates the program, codified at title 32 of the Code of Federal Regulations, part 170, was published in the Federal Register on October 15, 2024 and took effect on December 16, 2024. It defines three levels.

Level 1: self-assessment of the 15 requirements of FAR clause 52.204-21, which protects federal contract information (FCI).

Level 2: the 110 requirements of NIST SP 800-171 Revision 2, already required by DFARS clause 252.204-7012, for controlled unclassified information (CUI). Depending on the contract, Level 2 is demonstrated by self-assessment or by a certification issued by an accredited third-party assessor (C3PAO).

Level 3: 24 additional requirements drawn from NIST SP 800-172, assessed by DIBCAC, the government assessment body, for critical programs.

The rule also sets the mechanics: a plan of action (POA&M) accepted for a conditional status must be closed out within 180 days; a certification is valid for three years from the status date; a designated official must affirm continuous compliance every year in the SPRS system. And it provides four implementation phases, triggered by the effective date of the acquisition rule at title 48: Phase 1, Level 1 and Level 2 self-assessments as a condition of award; Phase 2, one year later, Level 2 C3PAO certification as a condition of award; Phase 3, one more year later, Level 3; Phase 4, one year after that, requirements in all applicable contracts, including option periods.

The acquisition rule, published in the Federal Register on September 10, 2025, took effect on November 10, 2025. It inserts DFARS clause 252.204-7021 in contracts and provision 252.204-7025 in solicitations, requires the annual affirmation of compliance in SPRS for each system concerned, and flows the self-assessment and affirmation requirements down to subcontractors. November 10, 2025 therefore marks the start of Phase 1.

Then the timeline changed. A DoD CIO memorandum, whose attached procedures are published on the office's site, suspends the transition planned for November 2026 to Phase 2. During the suspension, program managers may only require Level 1 (Self) or Level 2 (Self); they may not designate Level 2 (C3PAO) or Level 3 (DIBCAC). Active solicitations that contained those requirements must be amended, and existing contracts modified before the next option period. No waivers are granted during the review. One point remains clear: the requirements of DFARS clause 252.204-7012, hence NIST SP 800-171 Revision 2, remain in effect, and the Department says it will enforce baseline compliance through self-assessments and select government-led assessments. Further guidance will follow at the end of the CIO's 60-day review.

Why it matters

Some read the suspension as the end of CMMC. That is not what the text says. Three things do not change.

The 110 requirements remain contractual. Clause 7012 has required NIST SP 800-171 for years, and the Level 2 self-assessment is its measure. An inaccurate SPRS score is a statement made to the government, with or without a third-party certifier.

The annual affirmation commits a person. The rule names an official who affirms continuous compliance. That is a personal commitment, and it holds during the suspension.

The timeline can resume without a new delay. The memorandum suspends; it does not repeal. A company that stops its program loses the months it had gained.

For Canadian suppliers, the question comes in two forms: DoD contracts on one side, the Canadian Program for Cyber Security Certification (CPCSC) on the other, aligned with CMMC. One well-documented set of controls serves both.

What we think at Sentrix

Use the suspension to do what Phase 2 would have required, without the pressure of the date.

  1. Scope the CUI boundary: which systems, which accounts, which cloud providers touch CUI. A narrow, documented boundary reduces the effort and avoids certifying the whole company.
  2. Complete the NIST SP 800-171 self-assessment honestly and file it in SPRS with a dated plan of action. Treat each unmet requirement as an audit finding, not as a checkbox.
  3. Close the plans of action within the rule's deadline, 180 days, even if no assessor will come this year. That is the pace the resumed timeline will demand.
  4. Reuse what you have: an organization certified to ISO 27001:2022 or covered by a SOC 2 report already holds a large part of the evidence (access management, logging, incident management, supplier security). The mapping is done control by control in the compliance framework, not in a spreadsheet.
  5. Name the affirming official and give them a quarterly report of open gaps. Signing an affirmation without data is the most underestimated risk in the program.
  6. Prepare CPCSC in parallel if you target Canadian defence contracts; the same controls carry over to both programs.

Our page on CMMC follows the official texts, and our CPCSC guide explains the Canadian program. The CPCSC compliance service covers both sides.

The next step

Reread your last SPRS score and the date it was filed. If you cannot explain each missing point with a dated plan, start there. To follow the DoD's next directives without going through rumours, our watch relays the official texts, and you can write to us.

Sources

Frequently asked questions

What are the three levels of CMMC 2.0?
Level 1 covers the 15 requirements of FAR clause 52.204-21 for federal contract information (FCI), by self-assessment. Level 2 covers the 110 requirements of NIST SP 800-171 Revision 2 for controlled unclassified information (CUI), by self-assessment or by certification from a third-party assessor (C3PAO). Level 3 adds 24 requirements drawn from NIST SP 800-172, assessed by DIBCAC, the government body.
Where does the rollout timeline stand?
The 48 CFR rule took effect on November 10, 2025 and started Phase 1: Level 1 and Level 2 self-assessments required in contracts. Phase 2, which was to make C3PAO certification mandatory from November 2026, is suspended by a DoD CIO memorandum of July 2026, pending a review of the program. The NIST SP 800-171 requirements under DFARS clause 252.204-7012 remain in effect.
Is a Canadian company concerned?
Yes, as soon as it is a subcontractor on a DoD contract that contains the CMMC clause: the self-assessment and affirmation requirements flow down to subcontractors that process FCI or CUI. Canada is preparing on its side the Canadian Program for Cyber Security Certification (CPCSC), aligned with CMMC, for Canadian defence contracts. One set of controls serves both.

Let's talk about your compliance program.

Last updated: 2026-09-20