The CMMC Compliance Guide: Making the Phase 2 Deadline
CMMC is the Department of Defense's program for verifying that contractors protect Federal Contract Information and Controlled Unclassified Information. Phase 2 begins November 10, 2026, when third-party Level 2 certification — not self-assessment — becomes the standard on applicable CUI contracts. With assessor capacity tightening, contractors who have not started are already late.
- Phase 1 went live Nov 10, 2025; Phase 2 (C3PAO certification standard) begins Nov 10, 2026.
- Most contractors handling CUI need Level 2: all 110 controls of NIST SP 800-171.
- Plan 9–18 months from standing start — and book your C3PAO while you remediate.
- Inflated SPRS scores are False Claims Act exposure — score honestly.
The CMMC timeline
| Milestone | Date | What it means |
|---|---|---|
| 48 CFR acquisition rule published | Sept 10, 2025 | Contract clause (DFARS 252.204-7021) finalized |
| Phase 1 begins | Nov 10, 2025 | CMMC in new solicitations; self-assessments; DoD discretion to require certification early |
| Phase 2 begins | Nov 10, 2026 | C3PAO Level 2 certification becomes standard for applicable CUI contracts |
| Phase 3 begins | Nov 10, 2027 | Certification extends to option periods; Level 3 requirements appear |
| Phase 4 — full implementation | Nov 10, 2028 | CMMC in all applicable solicitations and contracts |
Which level do you need?
| Level | Who | Requirements | Assessment |
|---|---|---|---|
| Level 1 | FCI only | 15 basic safeguards (FAR 52.204-21) | Annual self-assessment + SPRS affirmation |
| Level 2 | Handles CUI | All 110 controls of NIST SP 800-171 Rev 2 | Triennial C3PAO certification |
| Level 3 | Highest-priority programs | Level 2 + 24 controls from NIST SP 800-172 | Government-led (DIBCAC) |
Note the flow-down: primes must ensure subs meet the required level before award, so subcontractors feel Phase 2 pressure through their primes ahead of the formal date.
The realistic path to Level 2 certification
- Scope ruthlessly. An enclave architecture isolating CUI routinely cuts assessment scope, cost, and timeline by half or more.
- Gap-assess against NIST SP 800-171 and score honestly. Your SPRS score is a legal representation; the DOJ has pursued False Claims Act cases over inflated scores.
- Remediate with POA&M discipline. Conditional certification allows a POA&M closed within 180 days — but the highest-weighted controls cannot sit on one. Prioritize MFA, FIPS-validated encryption, logging, and incident response.
- Assemble evidence before the assessor asks. C3PAOs test artifacts: SSP, policies, configurations, logs. Continuously collected evidence beats last-month binder assembly.
- Book your C3PAO now. With Phase 2 months away, capacity is tightening. Get in the queue while you remediate.
Common failure points
- FIPS-validated cryptography — “we encrypt” is not enough; modules must be FIPS 140-validated for CUI.
- Undocumented inheritance — cloud/MSP coverage claims without a shared responsibility matrix; ESPs handling CUI need FedRAMP-equivalent standing.
- Scope creep — CUI on unmanaged endpoints because nobody built an enclave.
- SSP drift — a system security plan describing an environment that no longer exists is a fast fail.
Compyl maps all 110 NIST SP 800-171 controls into one control library shared with your other frameworks, automates evidence collection, tracks POA&M items to closure, and keeps your SSP live. See the NIST CSF 2.0 Implementation Guide and Continuous Controls Monitoring Guide.
Frequently asked questions
When does CMMC Phase 2 start?
How long does Level 2 certification take?
Can we still win contracts with a self-assessment after Phase 2?
What does Level 2 certification cost?
Does CMMC apply to subcontractors?
Make the Phase 2 deadline with Compyl
Compyl unifies governance, risk, compliance and audit on one source of truth — built by CISOs, with a human approving every consequential decision.
About this guide. By Compyl Research. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.