Back to all posts

July 29, 2026

CMMC 2.0 Levels Explained: What Small and Mid-Sized Contractors Need to Know









Why this matters right now

If your company sells to the Department of Defense (DoD), or you supply a company that does, CMMC 2.0 is still worth tracking closely but the timeline just changed. The rule took effect on November 10, 2025, and Phase 1 self-assessment requirements are already showing up in applicable contracts involving FCI or CUI. On July 13, 2026, the Department of War suspended the Phase II requirements that were due to begin that November, and opened a 60-day review of the entire program. Contracts limited to commercial-off-the-shelf (COTS) items are generally exempt, but where CMMC is specified, the applicable certification level remains a condition of eligibility to bid or win that work.

This guide breaks CMMC 2.0 down in plain words. No jargon. Just what small and mid-sized contractors need to know to stay in the game, including what the suspension does and does not change.


What is CMMC 2.0?

CMMC stands for Cybersecurity Maturity Model Certification. It is a security check-up that the DoD uses to make sure contractors are actually protecting sensitive information, instead of just saying they are.

The old version, CMMC 1.0, had five levels and confused a lot of people. CMMC 2.0 simplified this down to three levels, each one built on cybersecurity rules that already exist and are widely used.





The three CMMC 2.0 levels





Most small and mid-sized contractors will land at Level 1 or Level 2. Level 2 makes up the large majority of all assessments, so if you handle anything beyond routine paperwork, plan for Level 2.


The rollout: four phases, one now suspended

CMMC 2.0 was designed to roll out in four phases over three years, with each phase applying where the DoD specifies CMMC requirements in a given contract. As of July 13, 2026, that timeline is no longer fully in effect. Here is where things stand:





How much does it cost, and how long does it take?

Costs vary depending on your size and how much security work you have already done. These figures reflect the full Level 2 program as designed; with Phase II suspended, the outside-audit costs below are not an immediate near-term requirement, but the underlying security work is still worth budgeting for. A few numbers to plan around:

  • A Level 2 outside audit alone typically costs about $20,000 to $40,000 for small and mid-sized companies.

  • The full cost of Level 2 - including preparation, fixing gaps, the audit, and yearly check-ins, usually runs about $105,000 to $118,000, according to DoD cost estimates.

  • Other estimates put the full three-year cost of Level 2 between $150,000 and $400,000, when technology, training, and upkeep are included.

  • Most companies need 6 to 12 months to get ready for their assessment.

  • Level 2 certification stays valid for three years once you earn it.


Why small and mid-sized contractors should still stay ready

The suspension eases the nearest-term deadline, but it does not remove the underlying obligation to protect FCI and CUI, and the program is only paused, not cancelled.

  • Phase 1 self-assessment requirements remain in force today, and the DoD continues to enforce the NIST SP 800-171 Rev 2 standard through self-assessments and select government-led assessments.

  • The Department of War has opened a Request for Information (RFI) and ordered a CMMC Reform Task Force review, due back within 60 days of July 13, 2026. That review could bring back a revised Phase 2, change the assessment model, or adjust timelines so this is a good moment to watch official channels rather than assume the requirement is gone for good.

  • If you are a subcontractor, your required level still depends on the information you handle, not automatically on your prime contractor's level. Check this yourself instead of assuming.

  • Companies that keep their NIST SP 800-171 practices current and their SPRS score up to date will be in the strongest position whenever the reformed program takes effect, rather than starting from scratch under a new deadline.



FAQ

Got Questions? We've Got Answers

Quick, straightforward answers about CMMC 2.0 from understanding its three levels to what the Phase II suspension means and what defense contractors should do next.

Quick, straightforward answers about CMMC 2.0 from understanding its three levels to what the Phase II suspension means and what defense contractors should do next.

Has CMMC been suspended or cancelled?

Do I get to choose which CMMC level applies to my company?

Is self-assessment enough, or do I need an outside auditor?

What happens if I am not certified in time?

I'm a subcontractor, does my prime contractor's level cover me?

Related resources

Related resources

Explore More

Explore More