Regulation · Filed · New York · 8 min read

CMMC 2.0 for Defense Contractors: What Level You Need and When

The Cybersecurity Maturity Model Certification 2.0 is being phased into DoD contracts. A practical guide to Level 1, 2, and 3 obligations, assessments, and timelines.

By Cyber Inspect Editorial Board

The three levels

Level 1 (Foundational): 15 basic safeguards, annual self-assessment. Level 2 (Advanced): NIST SP 800-171 alignment, third-party assessment for prioritized contracts. Level 3 (Expert): NIST SP 800-172 subset, government assessment.

The rollout curve

CMMC 2.0 is being phased into DoD solicitations. Most contractors handling Controlled Unclassified Information will require Level 2 certification within the current contract cycle.