Updated August 6, 2026 — on July 13, 2026 the Department of War suspended CMMC Phase II and paused the Phase III and IV milestones pending a program review. This guide has been revised throughout to reflect that. DFARS 252.204-7012, NIST SP 800-171, SPRS scoring and annual affirmations are unaffected and remain conditions of doing defense work.
For years, CMMC lived comfortably in the future tense: a rule being drafted, a deadline being debated, a problem for next year. That ended on November 10, 2025, when the acquisition rule took effect and CMMC clauses began appearing in new Department of Defense solicitations. Suppliers now have to show their cybersecurity posture before award — and the requirement doesn't stop at the prime contractor. It flows down the supply chain to the machine shop, the software subcontractor, the logistics firm.
Southern California, with its dense aerospace and defense manufacturing base, is full of exactly the kind of small supplier this lands on hardest: companies with real DoD-adjacent work and a two-person (or zero-person) IT department. Here's what you actually need to know.
What CMMC 2.0 is — and isn't
The Cybersecurity Maturity Model Certification isn't a new rulebook. Contractors handling controlled unclassified information (CUI) have been contractually required to implement the NIST SP 800-171 safeguards since the DFARS clause took hold in 2017. The problem was that compliance ran on the honor system, and self-reported scores were often generous fiction.
CMMC 2.0 is the Department of Defense checking receipts. It takes requirements that already existed and adds verification: self-assessments with executive affirmations at the low end, independent third-party assessments in the middle, government-led assessments at the top. Two rules make it real: the program rule (32 CFR Part 170), effective December 16, 2024, and the acquisition rule (48 CFR), effective November 10, 2025, which puts CMMC requirements into contracts — both per the Federal Register.
The three levels, in plain terms
- Level 1 — Foundational. For companies that handle federal contract information (FCI) but not CUI. It requires the 15 basic safeguarding practices from FAR 52.204-21 — things like access control, malware protection, and secure disposal — verified by an annual self-assessment and an affirmation from a senior official.
- Level 2 — Advanced. For companies that handle CUI: drawings, specifications, technical data. It requires all 110 security requirements of NIST SP 800-171. For most contracts, verification means a certification assessment by an authorized C3PAO (CMMC Third-Party Assessment Organization) every three years; a smaller set of contracts will accept a self-assessment. This is where most defense suppliers land, and it's the heavy lift.
- Level 3 — Expert. For suppliers on the most sensitive programs: 134 requirements (the 110 from NIST SP 800-171 plus 24 from NIST SP 800-172), assessed by the government itself. A small share of the industrial base — but if it's you, you already know.
The timeline you should actually plan around
The rollout is phased over roughly three years, but two dates matter most:
- November 10, 2025 — Phase 1 (already live). New applicable solicitations require at least a current self-assessment, a score posted in the government's SPRS system, and a senior official's affirmation as a condition of award.
- November 10, 2026 — Phase 2 (suspended). Third-party C3PAO certification requirements were to begin appearing in applicable contracts involving CUI. On July 13, 2026 the Department of War suspended this phase, paused Phases 3 and 4, and directed contracting officers to remove Level 2 (C3PAO) and Level 3 (DIBCAC) requirements from existing contracts by modification — Level 1 (Self) and Level 2 (Self) stay, and waivers are suspended during the review. No replacement date has been announced.
Now the fine print that bites. First, primes aren't waiting for the government's schedule — many are already asking subcontractors for SPRS scores and remediation plans, because their own awards depend on a clean supply chain. Second, the suspension pauses a certification schedule, not a security requirement — DFARS 252.204-7012 predates CMMC, outlives it, and still obliges you to implement NIST SP 800-171. Third, an affirmation is a legal statement: the Department of Justice's Civil Cyber-Fraud Initiative has pursued contractors over misrepresented cybersecurity compliance. Guessing your score is not a strategy.