76,000+
Contractors need Level 2
The DoD estimates more than 76,000 organizations require Level 2 C3PAO certification. As of February 2026, fewer than 1,100 had completed it.
On November 10, 2026, C3PAO-certified Level 2 becomes the default for DoD contracts handling CUI — and with 76,000+ contractors chasing ~80 assessors, the queue is the real deadline. We get you certification-ready before the line gets longer.
Book a CMMC Strategy Call →// WHY CMMC, WHY NOW
76,000+
The DoD estimates more than 76,000 organizations require Level 2 C3PAO certification. As of February 2026, fewer than 1,100 had completed it.
NOV 10 2026
C3PAO-assessed Level 2 becomes the default condition of award for most CUI contracts. A self-assessment no longer counts.
6–12 MO
Preparation typically takes 6 to 12 months, and C3PAO scheduling backlogs already run past a year. Starting late means missing solicitations.
// THE HONOR SYSTEM IS OVER
For a decade, DFARS 252.204-7012 let contractors self-attest to the 110 NIST 800-171 controls — and the DoD Inspector General repeatedly found a defense base claiming compliance it hadn't achieved. CMMC exists to close that gap. As of February 2026, all assessment obligations route exclusively through DFARS 252.204-7021, and the senior-official affirmation now carries False Claims Act exposure. After Phase 2, only a C3PAO can verify you actually meet all 110 controls.
// THE THREE CMMC CERTIFICATION LEVELS
CMMC 2.0 collapses what used to be five levels into three, each tied to the sensitivity of the information you handle, the contract type, and how the certification is assessed. The level you need is determined by the contract — not by what you'd prefer to spend.
~145K CONTRACTORS
~80K CONTRACTORS · 35% OF DIB
FEW HUNDRED · MOST SENSITIVE
// LEVEL 01
17 PRACTICES · FAR 52.204-21
FCI ONLY · NO CUI HANDLING
ANNUAL SELF-ASSESSMENT
// LEVEL 02
110 PRACTICES · NIST SP 800-171
CUI HANDLING · 14 CONTROL FAMILIES
C3PAO TRIENNIAL ASSESSMENT
// LEVEL 03
~134 PRACTICES · +NIST SP 800-172
SENSITIVE CUI · APT-TARGETED
DIBCAC TRIENNIAL (GOV-LED)
// LEVEL 01
17 practices · FAR 52.204-21
FCI only · no CUI handling
Annual self-assessment
~145K contractors
// LEVEL 02
110 practices · NIST SP 800-171
CUI handling · 14 control families
C3PAO triennial assessment
~80K contractors · 35% of DIB
// LEVEL 03
~134 practices · +NIST SP 800-172
Sensitive CUI · APT-targeted
DIBCAC triennial (gov-led)
Few hundred · most sensitive programs
// FCI = Federal Contract Information · CUI = Controlled Unclassified Information · C3PAO = Certified Third-Party Assessment Organization · DIBCAC = Defense Industrial Base Cybersecurity Assessment Center
// THE DOD ROLLOUT CALENDAR
The DoD published the 48 CFR CMMC Acquisition Rule on September 10, 2025; it became effective sixty days later, triggering a four-phase rollout that concludes with full implementation across all applicable DoD contracts.
CMMC Program Rule takes effect. Framework codified.
Self-assessments active in new DoD solicitations. C3PAO assessments optional.
C3PAO Level 2 certification mandatory for most CUI contracts.
Level 3 DIBCAC government-led assessments enforced.
Full implementation. CMMC required on all applicable DoD contracts and option periods.
// IS THIS YOU?
// 01 // CUI
If covered defense information, technical drawings, or controlled data touch your environment, you're at Level 2 — and Phase 2 puts a C3PAO assessment between you and your next award.
// 02 // FLOW-DOWN
Lockheed, Boeing, and Northrop are pre-positioning their supply base. Under DFARS 252.204-7021, the requirement flows down to every tier handling CUI — and they expect you already in the queue.
// 03 // SELF-SCORE
A posted self-assessment got you through Phase 1. After Phase 2 it won't — and an inaccurate affirmation now carries False Claims Act exposure. The fix is a verified, defensible position.
// WHAT WE DO
// Phase 01 · Assess
We measure you against all 110 NIST 800-171 controls and draw the line around what's actually in scope — the work that determines everything downstream.
// Phase 02 · Certify
We build the artifacts a C3PAO reads first, remediate the gaps, and rehearse the assessment so the fieldwork holds no surprises.
// Phase 03 · Sustain
Certification is a posture, not a moment. We keep it true between assessments and help you carry the requirement down to your own subcontractors.
// THE QUEUE IS FILLING
// FREQUENTLY ASKED
November 10, 2026 is the start of CMMC Phase 2. On that date, C3PAO-assessed Level 2 certification becomes the default condition of award for most DoD contracts involving CUI. The self-assessment many contractors relied on under Phase 1 no longer suffices — an independent, Cyber AB-authorized C3PAO has to verify you implement all 110 NIST SP 800-171 controls before award.
The reason it dominates the conversation is the math: the DoD estimates more than 76,000 organizations need Level 2 certification, and as of February 2026 fewer than 1,100 had completed it — against roughly 80 authorized assessors. The deadline isn't the problem; the queue in front of it is.
Three levels, each tied to the sensitivity of the information you handle. Level 1 (Foundational) covers FCI only, requires the 17 FAR 52.204-21 practices, and is verified by annual self-assessment. Level 2 (Advanced) covers CUI, requires all 110 controls of NIST SP 800-171 across 14 families, and is assessed by a C3PAO every three years — this is where most of the Defense Industrial Base sits. Level 3 (Expert) covers the most sensitive CUI, adds NIST SP 800-172 enhancements, and is assessed by the government through DIBCAC.
The level you need is set by the contract, not by preference.
Yes. CMMC flows down through the entire supply chain under DFARS 252.204-7021. If a prime contract requires Level 2, every subcontractor handling CUI on that contract must hold the appropriate level before CUI can be shared — regardless of subcontract value.
Major primes including Lockheed Martin, Boeing, and Northrop Grumman have issued supplier directives and begun pre-positioning their base, with some FY2026 contracts already carrying C3PAO requirements. Waiting for the prime to ask is waiting too late. The senior-official affirmation in SPRS also carries False Claims Act exposure for inaccurate statements.
Plan on 6 to 12 months of preparation before a C3PAO assessment — longer without documented policies or with legacy systems that can't implement the controls. A realistic engagement runs a gap assessment, scopes the CUI boundary, authors the SSP, develops the POA&M, and rehearses a mock assessment before fieldwork.
On gaps: a close-but-imperfect result can yield a Conditional certification with 180 days to close every open POA&M item — miss that window and it expires. POA&M latitude is narrow, and certain high-weight controls can't be on a POA&M at all. The safe path is to close gaps before fieldwork, not to lean on the 180-day window.
// THE NEXT MOVE
Book a 30-minute CMMC strategy call with a WatchUr6 advisor. Bring the contract or solicitation driving this, your current SPRS score if you have one, and the level you think you need. You'll walk away with an honest read on your real position, the gaps between you and a C3PAO assessment, and a realistic timeline to certification — whether you hire us or not.
Book a CMMC Strategy Call →SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED