CMMC Compliance Checkby Agent Trust Cloud

CMMC 2.0 compliance explained

The Cybersecurity Maturity Model Certification (CMMC) program checks that defense contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). "CMMC 2.0" is the streamlined model that became the rule in 32 CFR Part 170, CMMC Program (eCFR).

Status checked on 1 October 2026: Phase 1 of the CMMC rollout is in effect (Level 1 and Level 2 self-assessments, SPRS entry and annual affirmations where a contract requires them). On 13 July 2026 the Department suspended Phase 2, the planned start of required third-party (C3PAO) Level 2 certifications on 10 November 2026, pending a review. No new Phase 2 date has been published. Status and sources.

The three levels

LevelInformationRequirementsAssessment
Level 1FCIThe 15 requirements of FAR 52.204-21Self-assessment every year, plus an annual affirmation
Level 2CUIThe 110 requirements of NIST SP 800-171 Rev 2Self-assessment or C3PAO certification assessment every three years, plus annual affirmations; which one depends on the contract
Level 3CUI in the highest-priority programsLevel 2, plus selected NIST SP 800-172 requirementsGovernment assessment (DCMA DIBCAC), after a Level 2 certification

What changed from the first CMMC model

The original model had five levels and its own practices. CMMC 2.0 cut that to three levels mapped straight to existing federal requirements: FAR 52.204-21 for Level 1 and NIST SP 800-171 Rev 2 for Level 2. It also allows a limited plan of action and milestones (POA&M) at Level 2, with a 180-day deadline to close it (POA&M rules).

How the rule is being phased in

The program rule (CMMC Program final rule, 89 FR 83092 (15 October 2024)) took effect in December 2024, and contract clauses began requiring CMMC status in a four-phase rollout. Phase 1 (self-assessments) started on 10 November 2025. Phase 2 (C3PAO certifications for many Level 2 contracts) was due on 10 November 2026 but was suspended on 13 July 2026; see the CMMC status page for the latest dated position.

What a self-assessment involves

  1. Scope the systems that process, store or transmit FCI or CUI (32 CFR 170.19, CMMC scoping).
  2. Write or update the System Security Plan.
  3. Assess every requirement against its NIST SP 800-171A objectives with final, not draft, evidence.
  4. Score it (Level 2) and enter the result in the Supplier Performance Risk System (SPRS).
  5. Have a senior official affirm compliance (32 CFR 170.22, affirmation), and repeat on schedule.

Run the free CMMC self-check

Sources