WATCHUR6 // CMMC // PHASE 2 COUNTDOWN

The self-attestation era is ending.
Certification is the new condition of award.

On November 10, 2026, C3PAO-certified Level 2 becomes the default for DoD contracts handling CUI — and with 76,000+ contractors chasing ~80 assessors, the queue is the real deadline. We get you certification-ready before the line gets longer.

Book a CMMC Strategy Call
CMMC 2.0 LEVEL 2 110 NIST 800-171 CONTROLS DFARS 7021 ALIGNED VETERAN-LED

// WHY CMMC, WHY NOW

The deadline is fixed. The capacity to meet it isn't.

76,000+

Contractors need Level 2

The DoD estimates more than 76,000 organizations require Level 2 C3PAO certification. As of February 2026, fewer than 1,100 had completed it.

NOV 10 2026

Phase 2 goes live

C3PAO-assessed Level 2 becomes the default condition of award for most CUI contracts. A self-assessment no longer counts.

6–12 MO

To get ready — before the queue

Preparation typically takes 6 to 12 months, and C3PAO scheduling backlogs already run past a year. Starting late means missing solicitations.

// THE HONOR SYSTEM IS OVER

We self-attested in SPRS, so we're compliant.
After Phase 2, a self-assessment isn't proof — it's a liability.

For a decade, DFARS 252.204-7012 let contractors self-attest to the 110 NIST 800-171 controls — and the DoD Inspector General repeatedly found a defense base claiming compliance it hadn't achieved. CMMC exists to close that gap. As of February 2026, all assessment obligations route exclusively through DFARS 252.204-7021, and the senior-official affirmation now carries False Claims Act exposure. After Phase 2, only a C3PAO can verify you actually meet all 110 controls.

// THE THREE CMMC CERTIFICATION LEVELS

The Level Ladder. Find your tier.

CMMC 2.0 collapses what used to be five levels into three, each tied to the sensitivity of the information you handle, the contract type, and how the certification is assessed. The level you need is determined by the contract — not by what you'd prefer to spend.

// FCI = Federal Contract Information  ·  CUI = Controlled Unclassified Information  ·  C3PAO = Certified Third-Party Assessment Organization  ·  DIBCAC = Defense Industrial Base Cybersecurity Assessment Center

// THE DOD ROLLOUT CALENDAR

Five years, four phases. The next deadline is closer than it looks.

The DoD published the 48 CFR CMMC Acquisition Rule on September 10, 2025; it became effective sixty days later, triggering a four-phase rollout that concludes with full implementation across all applicable DoD contracts.

DEC 16 2024

32 CFR EFFECTIVE

CMMC Program Rule takes effect. Framework codified.

NOV 10 2025

PHASE 1

Self-assessments active in new DoD solicitations. C3PAO assessments optional.

NOV 10 2026

PHASE 2

C3PAO Level 2 certification mandatory for most CUI contracts.

NOV 10 2027

PHASE 3

Level 3 DIBCAC government-led assessments enforced.

NOV 10 2028

PHASE 4

Full implementation. CMMC required on all applicable DoD contracts and option periods.

// IS THIS YOU?

Three signs you need to move now.

// 01 // CUI

You handle CUI on a DoD contract

If covered defense information, technical drawings, or controlled data touch your environment, you're at Level 2 — and Phase 2 puts a C3PAO assessment between you and your next award.

// 02 // FLOW-DOWN

A prime is asking about your status

Lockheed, Boeing, and Northrop are pre-positioning their supply base. Under DFARS 252.204-7021, the requirement flows down to every tier handling CUI — and they expect you already in the queue.

// 03 // SELF-SCORE

You're relying on an SPRS self-score

A posted self-assessment got you through Phase 1. After Phase 2 it won't — and an inaccurate affirmation now carries False Claims Act exposure. The fix is a verified, defensible position.

// WHAT WE DO

Readiness, certification, and the years after.

// Phase 01 · Assess

Gap Assessment & Scoping

We measure you against all 110 NIST 800-171 controls and draw the line around what's actually in scope — the work that determines everything downstream.

  • 110-control gap assessment, scored to the DoD methodology
  • CUI boundary definition and asset inventory
  • Honest current SPRS score and prioritized gap list

// Phase 02 · Certify

Documentation & C3PAO Readiness

We build the artifacts a C3PAO reads first, remediate the gaps, and rehearse the assessment so the fieldwork holds no surprises.

  • System Security Plan (SSP) authored control by control
  • POA&M development and remediation execution
  • C3PAO selection, evidence packaging, mock assessment

// Phase 03 · Sustain

Affirmation & Flow-Down

Certification is a posture, not a moment. We keep it true between assessments and help you carry the requirement down to your own subcontractors.

  • Annual affirmation and SPRS maintenance
  • 180-day conditional POA&M closure support
  • DFARS 7021 flow-down coordination to subcontractors

// THE QUEUE IS FILLING

Every month you wait, the C3PAO line gets longer.

Book a CMMC Strategy Call

// FREQUENTLY ASKED

The CMMC questions teams keep asking.

What changes on November 10, 2026, and why is everyone talking about it?

November 10, 2026 is the start of CMMC Phase 2. On that date, C3PAO-assessed Level 2 certification becomes the default condition of award for most DoD contracts involving CUI. The self-assessment many contractors relied on under Phase 1 no longer suffices — an independent, Cyber AB-authorized C3PAO has to verify you implement all 110 NIST SP 800-171 controls before award.

The reason it dominates the conversation is the math: the DoD estimates more than 76,000 organizations need Level 2 certification, and as of February 2026 fewer than 1,100 had completed it — against roughly 80 authorized assessors. The deadline isn't the problem; the queue in front of it is.

What's the difference between CMMC Level 1, Level 2, and Level 3?

Three levels, each tied to the sensitivity of the information you handle. Level 1 (Foundational) covers FCI only, requires the 17 FAR 52.204-21 practices, and is verified by annual self-assessment. Level 2 (Advanced) covers CUI, requires all 110 controls of NIST SP 800-171 across 14 families, and is assessed by a C3PAO every three years — this is where most of the Defense Industrial Base sits. Level 3 (Expert) covers the most sensitive CUI, adds NIST SP 800-172 enhancements, and is assessed by the government through DIBCAC.

The level you need is set by the contract, not by preference.

We're a subcontractor. Does CMMC actually flow down to us?

Yes. CMMC flows down through the entire supply chain under DFARS 252.204-7021. If a prime contract requires Level 2, every subcontractor handling CUI on that contract must hold the appropriate level before CUI can be shared — regardless of subcontract value.

Major primes including Lockheed Martin, Boeing, and Northrop Grumman have issued supplier directives and begun pre-positioning their base, with some FY2026 contracts already carrying C3PAO requirements. Waiting for the prime to ask is waiting too late. The senior-official affirmation in SPRS also carries False Claims Act exposure for inaccurate statements.

How long does it take to get Level 2 certified, and what if we have gaps?

Plan on 6 to 12 months of preparation before a C3PAO assessment — longer without documented policies or with legacy systems that can't implement the controls. A realistic engagement runs a gap assessment, scopes the CUI boundary, authors the SSP, develops the POA&M, and rehearses a mock assessment before fieldwork.

On gaps: a close-but-imperfect result can yield a Conditional certification with 180 days to close every open POA&M item — miss that window and it expires. POA&M latitude is narrow, and certain high-weight controls can't be on a POA&M at all. The safe path is to close gaps before fieldwork, not to lean on the 180-day window.

// THE NEXT MOVE

Get in the queue before the queue gets longer.

Book a 30-minute CMMC strategy call with a WatchUr6 advisor. Bring the contract or solicitation driving this, your current SPRS score if you have one, and the level you think you need. You'll walk away with an honest read on your real position, the gaps between you and a C3PAO assessment, and a realistic timeline to certification — whether you hire us or not.

Book a CMMC Strategy Call

SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED