
If your DoD contracts reference DFARS 252.204-7012 or you handle Controlled Unclassified Information, you need to meet CMMC 2.0 Level 2, which means implementing all 110 NIST SP 800-171 controls. If you only handle Federal Contract Information, you likely fall under Level 1, covering just the 15 basic safeguards in FAR 52.204-21.
Here’s what to do this week, not next quarter:
- Pull your contract and check for the DFARS 252.204-7012 clause. That single clause is your signal.
- Scope your CUI. Know exactly where it lives and who touches it.
- Start your System Security Plan (SSP) now, even in draft form.
- Enter your score in SPRS through the PIEE portal when required.
Pro Tip: *Level 2 allows Plans of Action & Milestones (POA&Ms) with a hard 180-day closeout window, while Level 1 allows none. If you’re banking on a POA&M safety net at Level 1, that option is not available.
Assessor availability is tight, and if your contract has a near-term recompute or option year, you’re already behind if you haven’t started scoping.
Key Takeaways
Meeting CMMC 2.0 requirements comes down to correctly identifying your level, documenting every control in a real SSP, and starting your assessment prep well before your contract’s phase date arrives.
| Point | Details |
|---|---|
| Identify your level first | Check for DFARS 252.204-7012 in your contract; its presence signals Level 2, otherwise Level 1 likely applies. |
| POA&M rules differ by level | Level 2 allows POA&Ms with a 180-day closeout window; Level 1 permits none at all. |
| SSP is the longest-lead item | Build your System Security Plan with real evidence early since it drives every remediation decision. |
| Start before your phase date | C3PAO assessment queues have run 12 to 18 months in some regions, so waiting for enforcement is too late. |
| Managed support closes gaps faster | Architechmsp runs gap assessments, SSP drafting, and technical remediation for contractors short on internal capacity. |
CMMC 2.0 Requirements at a Glance: Levels, Legal Anchors, and When Each Applies
CMMC 2.0 has three levels, and which one applies to you is a legal question, not a preference.
- Level 1 covers Federal Contract Information (FCI) and requires the 15 practices in FAR 52.204-21. Annual self-assessment, no third party required.
- Level 2 covers Controlled Unclassified Information (CUI) and maps to all 110 controls in NIST SP 800-171 Revision 2. Many Level 2 contracts require a third-party assessment from a Certified Third-Party Assessment Organization (C3PAO); some allow self-assessment depending on DoD determinations of sensitivity.
- Level 3 covers the highest-sensitivity CUI facing advanced persistent threats. The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) handles these assessments, and the government, not the contractor, decides who needs it.
The determining factor is your contract language, not your company’s size or gut feeling about risk. If DFARS 252.204-7012 appears anywhere in your solicitation or contract, you’re almost certainly handling CUI, and that points you to Level 2. Prime contractors flow these requirements down to subcontractors through their own contract terms, so a subcontractor’s level often gets dictated by the prime, not negotiated independently.
Level 1 Requirements: The 15 Basic Safeguarding Practices
Level 1 is the entry point, and it’s more approachable than most contractors assume, but “approachable” doesn’t mean “optional.”
The 15 practices under FAR 52.204-21 fall into a handful of practical buckets:
- Limit system access to authorized users and processes.
- Verify and control connections to external systems.
- Control information posted on publicly accessible systems.
- Identify and authenticate users before granting access.
- Sanitize or destroy media containing FCI before disposal.
- Limit physical access to systems and facilities.
- Escort visitors and monitor visitor activity.
- Maintain audit logs of physical access.
- Control and manage physical access devices.
- Monitor and protect organizational communications at network boundaries.
- Implement subnetworks for publicly accessible components where applicable.
- Identify, report, and correct system flaws in a timely manner.
- Provide protection from malicious code at appropriate locations.
- Update malware protection when new releases are available.
- Perform periodic scans and real-time scans of files from external sources.
Level 1 requires an annual self-assessment and a senior official’s affirmation, recorded per DoD CIO guidance. Keep evidence simple: screenshots of your endpoint protection dashboard, a visitor log, patch management reports. No third party reviews this at Level 1, and critically, no POA&Ms are allowed. Every practice has to be fully in place at the time of affirmation, or you’re not compliant. Missing an affirmation deadline lets your status lapse, which can jeopardize contract eligibility immediately.
Level 2 Requirements in Practice: NIST 800-171, SSPs, and SPRS Scoring
Level 2 is where the real work happens. You’re implementing all 110 controls from NIST SP 800-171 Revision 2, spanning 14 control families: access control, incident response, configuration management, media protection, and more.
Your System Security Plan is the backbone of this effort. It’s not a formality. It describes how each of the 110 controls is implemented across your environment, and assessors expect it backed by real evidence: firewall configuration exports, multi-factor authentication (MFA) enrollment reports, access control lists, security awareness training logs, and incident response test results. Contractors consistently underestimate how much time the SSP itself takes to build properly, since it has to reflect your actual environment, not a generic template.
Scoring works through SPRS. You calculate a score based on which controls are implemented (a perfect score is 110; each unmet control subtracts points based on its weight), then submit that score through the PIEE portal. Contracting officers pull these scores when evaluating bids and monitoring active contracts, so an outdated or inflated score is a real liability.
Here’s the part that trips people up: POA&Ms are permitted at Level 2, but only for a subset of lower-weighted controls, and every POA&M has a strict 180-day closeout window. It’s not a permanent exemption. Assessors and contracting officers want a named owner, a cost estimate, and demonstrable progress, not a vague promise to “fix it eventually.”
- MFA scope gaps: many contractors deploy MFA on cloud logins but miss privileged local accounts.
- Logging and SIEM coverage: NIST 800-171 expects audit log review, not just log collection.
- Encryption at rest and in transit: often assumed to be handled by a cloud provider when it isn’t fully.
Pro Tip: Run your gap assessment against the actual control language, not a vendor’s marketing checklist. A surprising number of “compliant” self-assessments fall apart the moment a C3PAO asks for the underlying evidence.
How Long Does a CMMC 2.0 Assessment Take to Schedule?
Assessment type depends on your level and the sensitivity of your CUI. Organizations Seeking Assessment (OSAs) at Level 1 self-assess annually. Most Level 2 contracts require a C3PAO-led third-party assessment, renewed on a triennial cycle with annual affirmations in between. DIBCAC handles Level 3 assessments directly for the government.
- Confirm which assessment type your contract requires. Don’t assume; check the clause.
- Track the official phase dates published through the CMMC final rule, since enforcement ties directly to solicitation and award language during each phase.
- Build in lead time for scheduling. Reported C3PAO demand has created assessment queues resulting in long wait times in some regions.
- Check DoD CIO and CISA guidance regularly. The program has seen rollout pauses and clarifications before, and missing an update can cost you months.
If your contract has an option year or recompete inside the next 18 months, you’re already at the point where waiting is the riskiest move on the table.
Your CMMC 2.0 Compliance Checklist: Six Steps to Follow Now
Getting from “we think we’re okay” to “we’re assessment-ready” follows a predictable sequence.
- Confirm your level. Check your contract clauses and ask your prime or contracting officer directly if it’s ambiguous.
- Scope your CUI. Map every place CUI enters, moves through, and leaves your environment. Isolating CUI to specific systems keeps your compliance boundary small and manageable.
- Run a gap assessment. Compare your current environment against every applicable NIST 800-171 control and rank gaps by risk and remediation cost.
- Draft your SSP and POA&Ms. Assign a named owner and a real cost estimate to every open item, and set 180-day countdown clocks the moment a POA&M opens.
- Fix the highest-impact gaps first. MFA across all privileged and remote access, centralized logging, and encryption at rest and in transit tend to close the most risk per dollar spent.
- Submit your SPRS score and schedule your assessment. Don’t wait for a perfect score. Submit, document your POA&Ms, and get in the assessor queue.
Pro Tip: If your internal IT team is stretched thin, bringing in outside help for steps three through five is usually cheaper than the delay caused by doing it alone the first time.
What Cybersecurity Practices Does Each CMMC 2.0 Level Actually Require?
Level 1 is about basic cyber hygiene: controlling who accesses your systems, keeping malware protection current, and physically securing your facilities. There’s no formal process documentation requirement, and no maturity component. You either do the 15 things or you don’t.
Level 2 adds process maturity on top of technical controls. NIST 800-171 doesn’t just ask whether you have a firewall; it asks whether you have a documented configuration management process, whether you review audit logs on a defined schedule, and whether your incident response plan has actually been tested. That’s the practical difference between Level 1 and Level 2 that catches contractors off guard: Level 2 assessors want to see that your security program runs on a repeatable process, not just working hardware.
Encryption requirements get stricter too. Level 2 expects CUI encrypted both at rest and in transit using validated cryptographic modules, not just “we use HTTPS.” Access control moves from basic authentication at Level 1 to role-based access, session termination policies, and least-privilege enforcement at Level 2. Incident response shifts from informal awareness to a documented, tested plan with defined reporting timelines tied to your DFARS 252.204-7012 obligations.

Level 3, while rare, adds enhanced requirements aimed at advanced persistent threats, including deeper monitoring and threat-hunting capabilities. Very few contractors will ever need it, but if the government designates you for Level 3, it’s not negotiable.
How CMMC 2.0 Requirements Differ From the Original CMMC 1.0
CMMC 1.0 launched with five maturity levels and its own set of practices layered on top of NIST 800-171, plus additional requirements unique to the framework itself. It required third-party assessment at nearly every level, which created cost and scheduling bottlenecks that hit small and mid-sized suppliers hardest.
CMMC 2.0 cut that down to three levels and aligned Level 2 directly with the existing 110 NIST SP 800-171 controls instead of adding a parallel set of practices. That single change removed a lot of duplicate work contractors had been bracing for under 1.0.
The bigger shift is flexibility. CMMC 1.0 offered no formal path for a documented remediation plan; you were compliant or you weren’t, full stop, at every level. CMMC 2.0 introduced POA&Ms at Level 2 with that 180-day closeout window, giving contractors breathing room to fix lower-weighted gaps without losing eligibility entirely. It also expanded self-assessment options for some Level 2 contracts rather than mandating third-party review across the board, though many Level 2 contracts still require a C3PAO.
For contractors who were tracking CMMC 1.0 timelines and shelved their prep when the rules changed, treat 2.0 as a real reset. The control set is largely familiar if you already worked from NIST 800-171, but the assessment structure, the POA&M rules, and the phased enforcement dates are new enough that old project plans need a rewrite, not a dusting off.
How CMMC 2.0 Affects Subcontractors and Flow-Down Requirements
Subcontractors don’t get to opt out of CMMC 2.0 just because they’re not the prime signing the contract. Requirements flow down through the supply chain, and primes are responsible for confirming their subcontractors meet the applicable level before CUI or FCI ever reaches them.
This creates a real practical problem for small subcontractors: a prime may require Level 2 compliance from a supplier that only handles a narrow slice of CUI, simply because separating that data cleanly wasn’t part of the original contract design. If you’re a subcontractor, ask your prime directly what level they’re requiring and why, and push back if the answer seems disconnected from what data you actually touch.
The upside is that flow-down also limits scope in the right circumstances. A subcontractor that never receives CUI and only handles FCI can often stay at Level 1, even if the prime above them is Level 2, as long as the contractual boundary and dataflows are cleanly documented. That documentation is exactly where scoping errors cause trouble: subcontractors who let CUI touch systems assumed to be Level 1 create scope creep that can drag the entire chain into a failed assessment.
Primes increasingly build CMMC status checks into vendor onboarding and annual reviews. If you’re a subcontractor without a current SPRS score or affirmation on file, expect that gap to surface in a prime’s due diligence long before your next contract renewal.
What Does CMMC 2.0 Compliance Cost to Budget For?
Costs break into three buckets: assessment fees, remediation spending, and ongoing maintenance. Level 1 self-assessment costs are largely internal labor since no third party is involved. Level 2 assessments through a C3PAO carry direct fees on top of whatever internal or contracted labor goes into preparation.
Remediation is usually the bigger number, and it varies enormously based on where you’re starting. A contractor with modern cloud infrastructure and MFA already deployed might face a modest bill for logging upgrades and documentation. A contractor running legacy on-premises systems with minimal access controls could face a much larger investment in hardware, software licensing, and configuration work.
Budget for these categories:
- SSP development and gap assessment, whether done internally or through outside support.
- Technical remediation, covering MFA rollout, centralized logging, encryption upgrades, and endpoint protection.
- C3PAO assessment fees for Level 2 contracts requiring third-party review.
- Ongoing maintenance, including annual affirmations, continuous monitoring, and staff training.
The mistake contractors make most often is budgeting for the assessment fee and forgetting that remediation and ongoing monitoring are recurring costs, not one-time projects. A POA&M with a 180-day clock also means remediation spending sometimes gets compressed into a tight window rather than spread comfortably across a fiscal year, so building contingency into your budget matters more here than in most compliance projects.
Who Owns CMMC 2.0 Compliance Inside Your Organization?
Compliance fails quietest when nobody clearly owns it. Someone in your organization needs to be the senior official responsible for the annual affirmation, and that person’s name is the one going on record with the DoD, so it shouldn’t be assigned casually.
Below that senior official, effective programs usually split responsibility three ways: an IT or security lead who owns technical control implementation, a compliance or quality lead who owns the SSP and POA&M documentation, and a contracts or business lead who tracks which contracts trigger which level and flags upcoming assessment deadlines. Small contractors often combine these roles into one or two people, which works fine as long as that person has real authority to require changes, not just document gaps.
Governance also means a recurring review cadence, not a one-time project. NIST 800-171 controls degrade in practice as staff change, systems get added, and configurations drift. Building a quarterly internal review into your calendar, even informally, catches drift before an assessor does.
When Do CMMC 2.0 Requirements Actually Take Effect for Your Contracts?
The CMMC final rule establishes the program’s legal basis and phased rollout, with enforcement tied to when CMMC requirements appear in new solicitations and contract modifications rather than a single flip-the-switch date across the entire industry. That means your actual deadline depends on your specific contract’s solicitation date, not a fixed calendar milestone everyone shares.
This is where the gap between regulatory timing and practical readiness gets dangerous. Even if your contract’s CMMC requirement doesn’t kick in for another year, the C3PAO assessment queue has reportedly been running 12 to 18 months in some regions. If you wait until the requirement is contractually live to start scheduling, you may miss your own award or option-year window entirely.
The practical move is to treat the phase date as your absolute last resort deadline, not your starting line. Work backward from it: assume a 12 to 18 month assessment queue, then add the months you’ll need for gap assessment, remediation, and SSP development before you’re even ready to request an assessment. For most contractors that means starting now, regardless of what phase your specific contract is technically in.
Monitor DoD business site updates periodically. The program has already seen guidance clarifications and rollout adjustments, and a pause or update can shift your planning window with little advance notice.
The Gap Between Regulatory Deadlines and Assessment Reality
The conventional advice on CMMC 2.0 treats phase dates like they’re the whole story. They’re not. The regulatory timeline tells you when a requirement becomes contractually enforceable. It says nothing about whether you can actually get assessed by then, and that’s the part most contractors get wrong.
If C3PAO queues really are running 12 to 18 months in some regions, a contractor who starts remediation the month their phase date hits is already a year behind, possibly more. The smarter contractors I’d point to as models aren’t the ones who technically meet the letter of the requirement first. They’re the ones who worked backward from queue times and started their gap assessment while their competitors were still debating whether Level 1 or Level 2 applied to them.
The other place conventional wisdom falls short is treating the SSP as paperwork. It’s not. It’s the single longest-lead item in most Level 2 preparations, and contractors who delegate it to whoever has spare time usually end up rebuilding it before an assessor will accept it. Prioritize the SSP and your gap assessment before anything else on your checklist, even before buying new security tools. You can’t remediate what you haven’t accurately scoped.
Get Help Meeting CMMC 2.0 Requirements Without Missing Your Deadline
Architechmsp is the alternative to building a CMMC compliance program from scratch with stretched internal IT staff: we run the gap assessment, draft the SSP, manage your POA&Ms against the 180-day clock, and implement the technical controls, MFA, centralized logging, and encryption, that assessors actually check.

Our six-step security framework was built for exactly this kind of regulated, evidence-heavy compliance work, not bolted on after the fact. For contractors juggling SPRS submissions, PIEE entries, and a C3PAO queue that doesn’t care about your recompete date, having a team that already lives in this world closes the gap between “we’re working on it” and “we’re ready” a lot faster than doing it solo.
If you’re not sure whether you’re Level 1 or Level 2, or you know you’re behind and need a realistic remediation timeline, start with a free cybersecurity assessment or review our cybersecurity services for defense contractors to see exactly how the work maps to your requirements.
Frequently Asked Questions
Do I need CMMC Level 1 or Level 2? If your contract includes DFARS 252.204-7012 or you handle Controlled Unclassified Information, you need Level 2. If you only handle Federal Contract Information, Level 1 likely applies.
Are POA&Ms allowed under CMMC 2.0? Yes, but only at Level 2, and only for a subset of lower-weighted controls. Every POA&M carries a mandatory 180-day closeout window. Level 1 permits no POA&Ms at all.
Where do I submit my CMMC score? Level 2 self-assessment scores get submitted to the Supplier Performance Risk System (SPRS) through the PIEE portal, where contracting officers can review them during bid evaluation and contract monitoring.
How long does it take to get a CMMC assessment scheduled? Reported C3PAO queue times have run roughly 12 to 18 months in some regions, so starting your gap assessment and remediation well ahead of your contract’s phase date matters more than the phase date itself.
Does CMMC 2.0 apply to subcontractors? Yes. Requirements flow down through prime contracts, and primes are responsible for verifying subcontractors meet the applicable level before sharing CUI or FCI.
Sources
- 32 CFR § 170.21 — Plan of action and milestones (POA&M) and assessment reporting requirements
- About CMMC - DoD CIO
- Cybersecurity Maturity Model Certification 2.0 Program (CISA)
- Federal Register — Cybersecurity Maturity Model Certification (CMMC) Program (final rule)