• Home
  • Business
  • CMMC Level 2 Certification: What Applies and How to Achieve It
CMMC Level 2 Certification: What Applies and How to Achieve It

CMMC Level 2 Certification: What Applies and How to Achieve It

On July 13, 2026, the Department of War suspended Phase II of the CMMC program, the mandate that would have required third-party (C3PAO) Level 2 certification starting November 10, 2026. A newly formed Reform Task Force now has 60 days to review the program’s future, which means the requirement no longer applies to most defense contractors in its original form. However, important exceptions apply.

This guide outlines who CMMC Level 2 certification applies to today, what obligations persist regardless, and how to prepare for whatever comes next.

Who Does CMMC Level 2 Certification Apply To?

CMMC Level 2 certification currently applies to one group: contractors whose prime requires it as a condition of the subcontract. That obligation is set by contract language, not federal rulemaking, but it isn’t fully insulated from the federal timeline. As the DoW removes Level 2 (C3PAO) and Level 3 requirements from primes’ own government contracts, a prime’s certification demand on its subcontractors may eventually follow suit.

Most other contractors handling Controlled Unclassified Information fall under the paused track. NIST SP 800-171 Rev. 2 still defines the security posture the department expects, but the independent assessment that would have confirmed it against that standard is on hold while the review is underway.

How to Achieve CMMC Level 2 Certification

For contractors still bound by a prime’s requirement, certification work doesn’t pause with the federal timeline. Getting there involves a sequence of concrete steps:

  1. Scope the environment where CUI is stored, processed, or transmitted, since certification only covers systems within that boundary.
  2. Run a gap analysis against all 110 NIST SP 800-171 Rev. 2 controls to identify what’s missing.
  3. Close Plan of Action and Milestones (POA&M) items, prioritizing controls tied to access management and incident response.
  4. Build out a System Security Plan (SSP) that documents how each control is implemented.
  5. Confirm assessment requirements directly with the prime, since flow-down clauses may change as the DoW removes C3PAO requirements from the prime’s own contracts.

Each step builds on the last; a thin SSP or unresolved POA&M item is often what stalls an assessment once it’s scheduled.

See also: The Doctor Who Might Tell You No: What Every Man on TRT Should Know Before Buying Anastrozole

What Still Applies While Phase II Is Paused?

Contractors outside a prime’s mandate still have obligations. These include an accurate self-assessment against NIST SP 800-171 scored and posted to SPRS, plus ongoing compliance with DFARS 252.204-7012, including incident reporting. Senior official affirmations are also required, both annually and at key contract milestones, to confirm the score reflects current practice.

Documentation supporting every control claimed in the score matters as much as the score itself. Inaccurate claims about cybersecurity compliance have already resulted in False Claims Act investigations and settlements involving government contractors.

Pursue CMMC Level 2 Certification with Confidence

If your organization is still working toward CMMC Level 2 certification, consider reaching out to a provider who combines a CMMC compliance platform with expert advisory support. Together, they can help close gaps in your documentation and keep you current as the Reform Task Force review develops.

Contractors outside that requirement still have self-assessment scores, affirmations, and SPRS submissions to get right, and the same kind of advisory support helps confirm which obligations apply and where documentation needs work. Either way, an experienced team can help you stay ahead of the task force’s decision rather than reacting to it once it lands.

Related Post

Leave a Reply

Your email address will not be published. Required fields are marked *