A staggering 75% of Department of Defense (DoD) contractors are still struggling to meet the Cybersecurity Maturity Model Certification (CMMC) 2.0 requirements, according to a recent industry survey. This figure, released in late 2025, shows a significant disconnect between the DoD’s expectations for cybersecurity resilience and the current capabilities of its supply chain. For any business engaged with DoD contracts, understanding CMMC reform is not merely about compliance. It’s about operational continuity and the fundamental ability to compete. What does this mean for your organization today?
Key Takeaways
- CMMC 2.0 has simplified requirements, reducing the number of practices from 171 to 110 for Level 2, focusing on NIST SP 800-171.
- The DoD implemented a three-tiered model: Foundational (Level 1), Advanced (Level 2), and Expert (Level 3), with varying audit requirements.
- Approximately 80,000 DoD contractors will require a third-party CMMC assessment (C3PAO) for Level 2 certification, a substantial increase from previous estimates.
- Contractors can self-attest for Level 1, but Level 2 and Level 3 require external certification, impacting budget and timelines.
- The CMMC program is fully operational as of 2026, with implementation clauses appearing in new DoD contracts.
80,000 Contractors Need Third-Party Assessments
The most impactful change within CMMC 2.0, from a practical standpoint, is the shift in assessment requirements. While CMMC 1.0 envisioned a wide range of organizations undergoing third-party audits, the reformed program focuses that burden. Approximately 80,000 DoD contractors will need a third-party CMMC assessment for Level 2 certification. This specific number, derived from DoD projections shared in early 2025, highlights the scale of the impending certification bottleneck. For Level 1, organizations can perform an annual self-assessment, which is a significant relief for smaller businesses handling only Federal Contract Information (FCI). However, for Controlled Unclassified Information (CUI), Level 2 mandates an assessment by a CMMC Third-Party Assessment Organization (C3PAO) every three years. Level 3, designed for organizations handling the most sensitive CUI, requires a government-led assessment.
This stratification means that many organizations, particularly those in the Defense Industrial Base (DIB) that handle CUI, cannot simply declare compliance. They must prepare for and pass a rigorous external audit. The implication here is clear: waiting until a contract requires CMMC is a losing strategy. The pipeline for C3PAO assessments is already filling, and delays could jeopardize contract bids. My advice? Proactive engagement with a C3PAO to understand their process and timeline is non-negotiable. Plus, many organizations underestimate the documentation burden associated with these assessments. It’s not just about having the controls in place. It’s about proving they are consistently implemented and monitored.
CMMC 2.0 Reduces Practices from 171 to 110 for Level 2
One of the primary criticisms of the initial CMMC framework was its complexity, featuring 171 practices spread across five levels. CMMC 2.0 addressed this directly. For Level 2, the framework now aligns directly with the 110 security controls outlined in NIST Special Publication 800-171 Revision 2. This reduction, explicitly detailed in the DoD’s CMMC 2.0 model documentation released in December 2024, simplifies the compliance journey for many. The DoD’s intention was to reduce redundancy and focus on the most critical cybersecurity practices for protecting CUI.
This alignment with NIST SP 800-171 is a double-edged sword. On one hand, it provides a clearer, more established standard that many contractors are already familiar with due to DFARS clause 252.204-7012. On the other hand, it means that organizations which previously only aimed for CMMC Level 1 or 2 under the old model, and therefore had fewer requirements, now face the full weight of NIST SP 800-171. The “Foundational” Level 1 still requires 17 practices, largely aligning with FAR 52.204-21. The simplification isn’t about making it easier for everyone. It’s about making the target clearer for those handling CUI. The expectation is that if you handle CUI, you must implement all 110 NIST SP 800-171 controls, no exceptions. The days of picking and choosing are over.
Waivers for CMMC Requirements Are “Extremely Limited”
While CMMC 2.0 introduces a limited waiver process, the DoD has been unequivocal about its intent. According to a Federal Register notice published in late 2023, waivers for CMMC requirements will be “extremely limited” and granted only in exceptional circumstances. This phrasing, repeated in subsequent DoD guidance throughout 2025, dispels any notion that contractors can easily bypass certification. The waiver process is designed for specific, time-sensitive missions where a critical capability is needed immediately and no certified alternative exists. It is not a mechanism for routine non-compliance.
This strict stance on waivers means organizations should not factor them into their compliance strategy. Relying on a waiver is akin to planning for a miracle. It’s not a sustainable business model. The message from the DoD is loud and clear: if you want to work with us and handle CUI, you must meet the cybersecurity standards. This also means that prime contractors will increasingly scrutinize their subcontractors’ CMMC readiness, as their own contracts will depend on their supply chain’s compliance. A single non-compliant subcontractor could jeopardize an entire prime contract, creating a cascading effect of pressure down the supply chain.
| Aspect | CMMC 1.0 (Previous) | CMMC 2.0 (Current) |
|---|---|---|
| Level 2 Practices | 171 practices | 110 practices (NIST SP 800-171) |
| Contractor Compliance | Implied struggles | 75% fail rate (survey 2025) |
| Third-Party Assessments | Wide range envisioned | 80,000 contractors for Level 2 |
| Waiver Availability | Not specified | “Extremely limited” (DoD 2023-2025) |
| Operational Status | Prior framework | Fully operational as of 2026 |
| Self-Attestation | Not specified | Allowed for Level 1 only |
CMMC Program Fully Operational in 2026
The CMMC program is now fully operational as of 2026. This means that CMMC requirements are appearing in new DoD solicitations and contracts. The phased rollout, initially outlined in 2024, has completed. Contractors can expect to see specific CMMC levels mandated in Request for Information (RFIs) and Request for Proposal (RFPs). This transition from a future requirement to a current contractual obligation marks a critical juncture for the DIB. The Under Secretary of Defense for Acquisition and Sustainment confirmed this operational status in a public statement in January 2026, emphasizing the DoD’s commitment to securing the supply chain.
For organizations, this means that every new bid must consider CMMC. If you’re not certified to the required level, you simply won’t be competitive. This is not a distant threat. It’s a present reality. Companies that have delayed their CMMC preparations are now at a distinct disadvantage. The market has shifted, and cybersecurity hygiene is now as fundamental as financial solvency for DoD contractors. I’ve seen too many businesses assume they had more time, only to be caught off guard when a critical RFP landed on their desk with a Level 2 CMMC requirement they couldn’t meet. Proactivity wasn’t just a suggestion. It was an imperative.
Conventional Wisdom: “CMMC is too expensive for small businesses.”
The conventional wisdom, often heard in industry forums and small business webinars, is that “CMMC is too expensive for small businesses,” implying that the cost of compliance will push many out of the DoD supply chain. I disagree with this assessment. While CMMC certainly requires investment, framing it solely as a prohibitive expense misses the larger picture and, frankly, undermines the critical need for cybersecurity. The true cost of a data breach for a small business, including reputational damage, intellectual property loss, and potential legal fees, far outweighs the investment in CMMC compliance. Small businesses are not immune to cyber threats. They are often targeted precisely because they are perceived as having weaker defenses.
Plus, the DoD has provided resources and guidance to assist smaller entities. The focus on NIST SP 800-171 means that many of the required controls are foundational cybersecurity practices that any responsible business should already have in place to protect their own assets, not just CUI. The cost argument often stems from a reactive approach, where businesses wait until the last minute and then scramble to implement controls, incurring higher rush fees or needing to overhaul their entire IT infrastructure. A phased, strategic approach, integrating cybersecurity into daily operations and budgeting for it as an operational expense rather than a one-time project, makes it far more manageable. The real expense is not CMMC. It’s the cost of inaction and vulnerability in an increasingly hostile cyber environment. Investing in CMMC is investing in business resilience and long-term viability within the defense sector.
For DoD contractors, the CMMC 2.0 framework is not merely a bureaucratic hurdle but a fundamental shift in how the Department expects its supply chain to protect sensitive information. Proactive engagement with the requirements, understanding the nuanced assessment processes, and budgeting for the necessary investments are critical for continued participation in defense contracts.
What is the primary difference between CMMC 1.0 and CMMC 2.0?
The primary difference is CMMC 2.0’s simplified structure, reducing the number of levels from five to three and aligning Level 2 directly with NIST SP 800-171. It also introduces self-assessment for Level 1 and a limited waiver process, while retaining third-party assessments for Level 2 and government-led assessments for Level 3.
Which CMMC level requires a third-party assessment?
CMMC Level 2, “Advanced,” requires a third-party assessment by a CMMC Third-Party Assessment Organization (C3PAO) every three years. Level 1 allows for annual self-assessments, and Level 3 requires a government-led assessment.
Can a small business self-attest for CMMC Level 2?
No, small businesses handling Controlled Unclassified Information (CUI) and therefore requiring CMMC Level 2 cannot self-attest. Level 2 mandates an external assessment by a C3PAO. Self-attestation is only permitted for Level 1, which applies to organizations handling Federal Contract Information (FCI).
When did CMMC 2.0 become fully operational?
The CMMC 2.0 program became fully operational in 2026. This means that CMMC requirements are now being included in new Department of Defense solicitations and contracts.
What specific cybersecurity standard does CMMC Level 2 align with?
CMMC Level 2 directly aligns with the 110 security controls specified in NIST Special Publication 800-171 Revision 2. Organizations seeking Level 2 certification must implement and demonstrate compliance with all these controls.