Compyl

The CMMC Compliance Guide: Making the Phase 2 Deadline

July 08, 2026
Framework · CMMC

The CMMC Compliance Guide: Making the Phase 2 Deadline

By Compyl ResearchUpdated July 20265 min read

CMMC is the Department of Defense's program for verifying that contractors protect Federal Contract Information and Controlled Unclassified Information. Phase 2 begins November 10, 2026, when third-party Level 2 certification — not self-assessment — becomes the standard on applicable CUI contracts. With assessor capacity tightening, contractors who have not started are already late.

Key takeaways
  • Phase 1 went live Nov 10, 2025; Phase 2 (C3PAO certification standard) begins Nov 10, 2026.
  • Most contractors handling CUI need Level 2: all 110 controls of NIST SP 800-171.
  • Plan 9–18 months from standing start — and book your C3PAO while you remediate.
  • Inflated SPRS scores are False Claims Act exposure — score honestly.

The CMMC timeline

Milestone Date What it means
48 CFR acquisition rule published Sept 10, 2025 Contract clause (DFARS 252.204-7021) finalized
Phase 1 begins Nov 10, 2025 CMMC in new solicitations; self-assessments; DoD discretion to require certification early
Phase 2 begins Nov 10, 2026 C3PAO Level 2 certification becomes standard for applicable CUI contracts
Phase 3 begins Nov 10, 2027 Certification extends to option periods; Level 3 requirements appear
Phase 4 — full implementation Nov 10, 2028 CMMC in all applicable solicitations and contracts

Which level do you need?

Level Who Requirements Assessment
Level 1 FCI only 15 basic safeguards (FAR 52.204-21) Annual self-assessment + SPRS affirmation
Level 2 Handles CUI All 110 controls of NIST SP 800-171 Rev 2 Triennial C3PAO certification
Level 3 Highest-priority programs Level 2 + 24 controls from NIST SP 800-172 Government-led (DIBCAC)

Note the flow-down: primes must ensure subs meet the required level before award, so subcontractors feel Phase 2 pressure through their primes ahead of the formal date.

The realistic path to Level 2 certification

  1. Scope ruthlessly. An enclave architecture isolating CUI routinely cuts assessment scope, cost, and timeline by half or more.
  2. Gap-assess against NIST SP 800-171 and score honestly. Your SPRS score is a legal representation; the DOJ has pursued False Claims Act cases over inflated scores.
  3. Remediate with POA&M discipline. Conditional certification allows a POA&M closed within 180 days — but the highest-weighted controls cannot sit on one. Prioritize MFA, FIPS-validated encryption, logging, and incident response.
  4. Assemble evidence before the assessor asks. C3PAOs test artifacts: SSP, policies, configurations, logs. Continuously collected evidence beats last-month binder assembly.
  5. Book your C3PAO now. With Phase 2 months away, capacity is tightening. Get in the queue while you remediate.

Common failure points

  • FIPS-validated cryptography — “we encrypt” is not enough; modules must be FIPS 140-validated for CUI.
  • Undocumented inheritance — cloud/MSP coverage claims without a shared responsibility matrix; ESPs handling CUI need FedRAMP-equivalent standing.
  • Scope creep — CUI on unmanaged endpoints because nobody built an enclave.
  • SSP drift — a system security plan describing an environment that no longer exists is a fast fail.

Compyl maps all 110 NIST SP 800-171 controls into one control library shared with your other frameworks, automates evidence collection, tracks POA&M items to closure, and keeps your SSP live. See the NIST CSF 2.0 Implementation Guide and Continuous Controls Monitoring Guide.

Frequently asked questions

When does CMMC Phase 2 start?
November 10, 2026 — one year after Phase 1. From that date, third-party Level 2 certification assessments become the standard requirement in applicable CUI solicitations.
How long does Level 2 certification take?
Plan 9–18 months from a standing start: scoping and gap assessment, remediation, evidence assembly, plus C3PAO scheduling lead time — currently stretching as capacity tightens.
Can we still win contracts with a self-assessment after Phase 2?
Only where the specific solicitation permits it. From November 10, 2026, certification is the standard for CUI contracts — assume certification is required.
What does Level 2 certification cost?
C3PAO assessment fees typically run into the tens of thousands of dollars depending on scope, plus remediation. Scope reduction via an enclave is the biggest cost lever.
Does CMMC apply to subcontractors?
Yes. Requirements flow down: if CUI touches your environment as a sub, you need Level 2 at the same standard as your prime — and primes verify before award.

Make the Phase 2 deadline with Compyl

Compyl unifies governance, risk, compliance and audit on one source of truth — built by CISOs, with a human approving every consequential decision.

Request a demo →

About this guide. By Compyl Research. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.

Monitoring thousands of environments daily
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies