Where CMMC Level 2 Stands Right Now
Status note, updated September 2026. In July 2026 the Department of Defense suspended the transition to CMMC Phase 2. During the suspension, new solicitations are limited to Level 1 (Self) and Level 2 (Self) assessments, third-party Level 2 and Level 3 assessments are on hold, and program offices were directed to amend requirements packages that had called for them.
What has not changed is the underlying obligation. DFARS 252.204-7012 remains in force. If you handle Controlled Unclassified Information, you are still required to implement NIST SP 800-171 and to keep an accurate self-assessment score in SPRS. The certification regime is paused; the duty to protect CUI is not.
That distinction matters for planning. Everything below is what Level 2 asks for and what it takes to be ready — and readiness is still the right thing to build, because the requirement underneath it never went away and assessments are expected to resume.
What CMMC Level 2 Actually Requires
CMMC Level 2 aligns with the 110 security practices defined in NIST SP 800-171. These practices span 14 domains including access control, incident response, media protection, and system and communications protection. Under the program as designed, a third-party assessment organization (C3PAO) validates compliance for most CUI contracts rather than self-attestation — and that third-party step is the part currently on hold.
The Three Things Most Contractors Underestimate
1. Scope definition. Before any assessment, you must define exactly which systems, people, and facilities touch CUI. Scope creep is the most common reason assessments run over time and budget.
2. System Security Plan (SSP). Your SSP is the foundation of the assessment. It must document every control, describe how it is implemented, and account for any gaps via a Plan of Action and Milestones (POA&M).
3. Evidence collection. Assessors require documented evidence for each practice — screenshots, logs, policies, and procedures. Organizations that have implemented controls but haven't documented them will fail practices they technically pass operationally.
How Long Does CMMC Level 2 Take?
Most organizations need 6 to 18 months from gap assessment to certification, depending on their current security posture. Organizations with an existing NIST 800-171 program in place can often compress this to 3 to 6 months. The current pause is worth using rather than waiting out — the preparation is unchanged, and the queue for assessors will not get shorter when they resume.
Start With a Gap Assessment
The fastest path to CMMC Level 2 readiness begins with a structured gap assessment against all 110 NIST 800-171 controls. This gives you a clear remediation roadmap, a realistic timeline, and a defensible self-assessment score — which you are already required to keep current in SPRS.
If a CMMC clause just showed up in a contract you're negotiating, book a confidential deal-readiness call to understand exactly what's required.