Regulation · Filed · New York · 8 min read
CMMC 2.0 for Defense Contractors: What Level You Need and When
The Cybersecurity Maturity Model Certification 2.0 is being phased into DoD contracts. A practical guide to Level 1, 2, and 3 obligations, assessments, and timelines.
By Cyber Inspect Editorial Board
The three levels
Level 1 (Foundational): 15 basic safeguards, annual self-assessment. Level 2 (Advanced): NIST SP 800-171 alignment, third-party assessment for prioritized contracts. Level 3 (Expert): NIST SP 800-172 subset, government assessment.
The rollout curve
CMMC 2.0 is being phased into DoD solicitations. Most contractors handling Controlled Unclassified Information will require Level 2 certification within the current contract cycle.