Cybersecurity · By KSG Team · September 2026
Who needs CMMC Level 2*? Since the Department of War (DoW) suspended CMMC Phase 2 on July 13th, 2026, two questions have dominated conversations across the Defense Industrial Base (DIB): which contractors need Level 2, and whether the suspension means that requirement can now be deferred.
The answers are unrelated to each other, which is the source of most of the confusion. The level a contractor needs is determined by the information it handles. The suspension changed how one of those levels is verified. It did not change who the requirement applies to.
This article covers both questions in order. It sets out how a contractor determines its required level, how that requirement reaches subcontractors, and why enforcement activity during the suspension window makes the case for treating this period as preparation rather than relief.
The Required Level Is Determined by Information, Not by Company Size
A common assumption is that CMMC Level 2* applies to large contractors and Level 1 applies to small ones. That is incorrect. Under 32 CFR Part 170.23, the requirement attaches to the information that enters a contractor's environment during contract performance. A ten-person machine shop that receives controlled technical drawings carries the same obligation as a large manufacturer that receives the same drawings.
Two categories of information drive the determination.
| Information type | What it covers | Typical examples |
|---|---|---|
| Federal Contract Information (FCI) | Information provided by or generated for the government under a contract that is not intended for public release. It applies broadly across DoW contracts. | Delivery schedules, purchase order detail, unit pricing on a government order, a statement of work that cannot be published. |
| Controlled Unclassified Information (CUI) | A narrower and more sensitive category defined by federal law or policy, requiring safeguarding by regulation. | Technical drawings, engineering specifications, test results, export-controlled information, process detail that would assist reverse engineering. |
The Information Security Oversight Office (ISOO) describes the relationship between the two categories directly: all CUI in the possession of a government contractor is FCI, but not all FCI is CUI. Correct classification of the data comes before correct scoping of the environment, and scoping is where most CMMC outcomes are decided.
CMMC Level 1 vs Level 2: the determination in practice
| What enters the environment | Required level | Assessment type |
|---|---|---|
| FCI only. No CUI at any point during performance. | Level 1 (Foundational) | Annual self-assessment against 15 basic safeguarding requirements drawn from FAR 52.204-21. A Plan of Action and Milestones is generally not permitted. |
| CUI, in any quantity, processed, stored or transmitted. | Level 2 (Advanced) | Assessment against all 110 security requirements in NIST SP 800-171 Revision 2. The contract specifies whether a self-assessment or a third-party C3PAO certification is required. |
| CUI associated with the highest-priority national security programs. | Level 3 (Expert) | Government-led assessment conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). It applies to a narrower set of contracts. |
The detail that most coverage omits is in the middle row. Level 2 is not a single requirement. It has two assessment types, and the contract determines which one applies. Level 2 (Self) requires an annual self-assessment. Level 2 (C3PAO) requires certification by an accredited third-party assessor organization every three years.
That distinction is the reason the suspension changed less than the headlines suggested. Only the C3PAO route was paused. Level 2 (Self) was not.
How the Requirement Reaches Subcontractors
A frequent question from lower-tier suppliers is whether the Prime contractor's compliance covers them. It does not. Under 32 CFR Part 170.23, CMMC applies to Prime contractors and subcontractors at every tier that will process, store or transmit FCI or CUI in performance of the work, and Prime contractors are required to flow the requirement down.
The flow-down follows the information, not the relationship. A subcontractor's level is determined by what actually reaches its environment:
A subcontractor receiving FCI only requires Level 1 (Self).
A subcontractor receiving CUI requires at least Level 2 (Self).
Where the associated prime contract requires Level 2 (C3PAO), that is the stated minimum for a subcontractor handling CUI.
Where the prime contract requires Level 3, Level 2 (C3PAO) is the stated minimum for a subcontractor handling CUI, subject to specific government direction.
An important consequence follows. A Prime contractor holding a Level 2 obligation does not automatically place every supplier at Level 2. If CUI does not reach a supplier's environment during performance, the higher level may not apply to that supplier.
This matters commercially. Some Prime contractors issue broad flow-down letters requiring every supplier to obtain the highest status regardless of what information that supplier receives. That is a conversation worth having rather than an expense worth accepting without question. The appropriate starting point is the work itself: what information does the lower tier genuinely need to perform, and can the deliverable be produced without transferring CUI at all? Reducing the information that flows reduces both scope and risk.
Where scoping most often goes wrong
Scoping errors run in both directions, and both are expensive.
Under-scoping is the more dangerous of the two. A team draws a boundary around the obvious servers and laptops and declares everything else out of scope. The real workflow then appears. FCI moves through email. CUI lands in a backup. An external provider administers identity. A monitoring platform protects the enclave. A printer produces paper. A subcontractor receives a file. The boundary was never where the diagram said it was.
Over-scoping is more common and is usually driven by caution rather than analysis. A contractor that could isolate CUI work inside a purpose-built enclave instead applies Level 2 controls across the entire business, and pays for controls the contract does not require.
The enclave route is legitimate and is worth evaluating. Where CUI handling is genuinely isolated in a separate environment, Level 2 scope is limited to that enclave while the remainder of the business operates under Level 1 requirements. This requires real technical separation rather than an organizational assertion that the environments are different. For contractors working across both commercial and defense programs, it is frequently the most cost-effective architecture available.
A documented, deliberate scope determination protects a contractor from both failure modes. Defaulting upward to Level 2 without analysis is not a conservative choice. It is an undocumented one.
Four steps to determine the required level
Read the contract documents directly. The Statement of Work and applicable clauses will typically reference FAR 52.204-21 for FCI, or identify the requirement to protect CUI. DFARS 252.204-7025 appears in solicitations and states the required level and assessment type.
Map the information, not the organization. Trace where FCI and CUI are processed, stored and transmitted, including email, backups, external service providers and physical media.
Confirm with the Contracting Officer. The Contracting Officer is the authoritative source for the level required by an acquisition. For subcontractors, the Prime contractor holds the flow-down obligation and knows what the subcontract carries.
Document the determination and the reasoning behind it. A scope decision that exists only as an assumption cannot be defended later.
Why the Pause Is Not a Pass
Having established which level applies, the second question follows. If Phase 2 is suspended, can the requirement be deferred?
The evidence from the suspension window itself answers this more clearly than any regulatory analysis could.
Enforcement did not pause with the program
The Department of Justice (DOJ) has announced two cybersecurity False Claims Act settlements since the CMMC review began, and a third in the preceding year. Each one involved NIST SP 800-171 non-compliance, and none of them depended on CMMC certification existing at all.
| Settlement | Amount | What it demonstrates |
|---|---|---|
| Honeywell Aerospace Inc. announced September 1st, 2026 | $2,042,518 | Allegations covered April 2020 through December 2023 and concerned NIST SP 800-171 non-compliance on one network. The case originated in a 2022 whistleblower complaint by a former employee, who received $375,823 as a relator's share. No security breach was alleged. The allegations remain allegations, with no determination of liability. |
| LOGZONE Inc. announced June 2026 | $507,144 | The contractor had submitted a self-assessment score of 110 out of 110. A later DIBCAC assessment produced a score of negative 170, against an applicable range of negative 203 to 110. This matter was not whistleblower-driven. It arose from the government's own assessment process. |
| MORSECORP Inc. announced March 2025 | $4,600,000 | Alleged failures to comply with cybersecurity requirements across Army and Air Force contracts. Establishes that this enforcement pattern predates the suspension by more than a year. |
Three points follow from these cases, and each one applies to a contractor at any level.
A breach is not required. The Honeywell allegations concerned the gap between required controls and implemented controls. Cybersecurity representations made in connection with a government contract are treated as material to the government's payment decision, which means a compliance gap can generate liability even where no data loss occurred.
Exposure accumulates quietly. The Honeywell allegations span nearly four years of billing cycles before surfacing through litigation. A gap that goes unexamined does not stay static. It compounds across every invoice submitted during the period.
There are two independent routes to enforcement. The first is a whistleblower complaint filed under the False Claims Act by an employee or former employee, which is what occurred in the Honeywell and MORSECORP matters. The second is a government-initiated assessment, which is what occurred with LOGZONE when DIBCAC assessed an environment that had been self-reported as fully compliant. Neither route requires the CMMC program to be operating.
Self-assessment is now the only attestation in the process
This is the consequence of the suspension that receives the least attention and carries the most risk.
When a C3PAO validates an environment, an independent party shares responsibility for the judgment. With that step paused, the only party attesting to a contractor's security posture is the contractor. The score posted in the Supplier Performance Risk System (SPRS) and the annual affirmation signed by a senior official are the complete attestation.
Those obligations were not suspended. A current SPRS score has been required under DFARS 252.204-7019 since November 2020, independently of the CMMC clause. DFARS 252.204-7012, which requires adequate security and cyber incident reporting within 72 hours, remains fully in force. The annual affirmation remains a condition of award eligibility.
The practical position is straightforward. Removing the third-party assessment did not remove accountability from the process. It concentrated accountability on the contractor's own signature.
What the Reform Task Force report can and cannot change
The CMMC Reform Task Force delivered its recommendations to the DoW Office of the Chief Information Officer (OCIO) in the middle of September 2026. Public release of the report is expected between late September and early October 2026.
Two constraints apply to whatever it recommends.
A report is advice, not law. Only a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170 changes a contractual obligation. Until one of those instruments is issued, DFARS 252.204-7012, NIST SP 800-171 Revision 2, SPRS scoring and the annual affirmation all remain in force exactly as they are today.
No plausible outcome removes NIST SP 800-171. The stated purpose of the review was to reduce compliance cost and administrative burden, particularly for small and non-traditional companies, not to lower the security standard. The Under Secretary of War for Acquisition and Sustainment framed the intent at the time of the announcement as removing the bureaucracy of the third-party assessment while expecting contractors to continue meeting the NIST standards.
One more requirement that is not paused
Contractors holding both defense and civilian federal work should track a separate regulatory thread. On June 23rd, 2026, the FAR Council published a proposed rule that would extend safeguarding and incident reporting requirements to CUI handled under all federal contracts, not only DoW contracts. That rulemaking is unaffected by the CMMC suspension.
For a mixed portfolio, the practical implication is that narrowing CMMC scope on the defense side may produce no meaningful relief, because a comparable obligation could arrive government-wide through a different regulatory instrument.
How KSG Approaches Scoping and Level Determination
Kaizen Solutions Group has secured federal and state government systems since 2016. We are an SBA 8(a)-certified small disadvantaged business, ISO 27001:2022, ISO 9001:2015 and ISO 20000-1:2018 certified, and we hold GSA HACS designations across all five categories: Risk and Vulnerability Assessment, High Value Asset assessment, Penetration Testing, Incident Response, and Cyber Hunt.
Our position on scoping is that the determination should be made on the basis of the information a contractor actually handles, and should be documented. A contractor that has been told to pursue Level 2 without an analysis of what enters its environment may be preparing for a requirement it does not carry. A contractor that has drawn a boundary without tracing its own data flows may be preparing for a narrower requirement than the one it does carry. Both positions are avoidable.
Where we typically begin
CUI boundary scoping and level determination: We map where FCI and CUI are processed, stored and transmitted across systems, external service providers and physical media, then document the level determination and the reasoning behind it.
Gap assessment against all 110 NIST SP 800-171 controls: We assess the environment against the full control set and reconcile the result against the score currently posted in SPRS. Where those two figures disagree, we address that first.
System Security Plan and Plan of Action and Milestones development: We produce documentation that describes the environment, the boundary and the deficiencies accurately enough to hold up under a DoW audit or a DIBCAC review.
Risk Management and POA&M analytics: We deliver continuous monitoring, vulnerability and patch management, Cybersecurity Supply Chain Risk Management, and Key Risk Indicator and Key Performance Indicator dashboards so that remediation progress is visible to leadership.
Security operations and remediation delivery: We support Security Operations Center monitoring, SIEM and SOAR, penetration testing, incident response, Identity and Access Management, endpoint detection and response, and DevSecOps. This is the technical work behind the controls, not only the assessment of them.
Governance, Continuous ATO and Continuous Monitoring: For contractors that also carry FISMA and Assessment and Authorization obligations across the civilian side of their portfolio.
Our CMMC Level 2* readiness practice is built around control implementation rather than certificate acquisition. That is the reason the July suspension did not change how we scope engagements. The work is required today and will remain a requirement under any reformed framework.
Talk to our team · Download our capability statement · Explore CMMC Level 2* readiness
Frequently Asked Questions
Who needs CMMC Level 2*?
Any organization in the Defense Industrial Base that processes, stores or transmits Controlled Unclassified Information (CUI) during performance of a DoW contract. The requirement attaches to the information, not to company size or position in the supply chain. A contractor handling only Federal Contract Information (FCI) requires Level 1. Level 3 applies to a narrower set of contracts tied to the highest-priority national security programs.
Do subcontractors need CMMC?
Yes, where FCI or CUI reaches their environment. Under 32 CFR Part 170.23 the requirement applies at every tier, and the Prime contractor is required to flow it down. The subcontractor's level follows the information it actually receives: FCI only requires Level 1 (Self), and CUI requires at least Level 2 (Self). A Prime contractor holding a Level 2 obligation does not automatically place every supplier at Level 2 — if CUI does not reach that supplier during performance, the higher level may not apply.
Is CMMC still required in 2026?
Yes. CMMC Phase 2, the rollout milestone that would have made third-party C3PAO certification a condition of award, was suspended on July 13th, 2026. Phase 1 self-assessment requirements remain in force, as do DFARS 252.204-7012, NIST SP 800-171 Revision 2, SPRS score submission and the annual affirmation. The program rule at 32 CFR Part 170 was not repealed.
What is the difference between Level 2 self-assessment and C3PAO certification?
Level 2 has two assessment types and the contract specifies which applies. Level 2 (Self) requires an annual self-assessment against the 110 requirements in NIST SP 800-171 Revision 2, with results posted in SPRS. Level 2 (C3PAO) requires certification by an accredited third-party assessor organization every three years. The July 2026 suspension paused the C3PAO route. It did not pause Level 2 (Self).
What is a CUI enclave, and does it reduce scope?
A CUI enclave is a purpose-built environment in which CUI handling is isolated from the general business infrastructure. Where the separation is genuine, Level 2 scope is limited to the enclave while the remainder of the business operates under Level 1 requirements. This requires real technical separation rather than an organizational assertion that the environments are different, and it is frequently the most cost-effective architecture for contractors working across both commercial and defense programs.
Does CMMC Level 2* assess against NIST SP 800-171 Revision 2 or Revision 3?
Revision 2. NIST published Revision 3 in May 2024, and the June 2026 FAR CUI proposed rule references the newer baseline, but CMMC Level 2* continues to map to Revision 2. Transition to Revision 3 would require separate rulemaking. Contractors may adopt Revision 3 voluntarily, but assessments currently test against Revision 2.
What happens if a posted SPRS score does not match the actual environment?
This is the live enforcement risk. The score is a legal representation of a contractor's compliance posture, and the annual affirmation is signed by a senior official. In June 2026 the DOJ settled a False Claims Act matter in which a contractor had self-reported a score of 110 and a subsequent DIBCAC assessment produced a score of negative 170. Correcting an inaccurate score is the first action to take, and it is substantially less costly than having the discrepancy identified by an investigation or a whistleblower complaint.
Does a Plan of Action and Milestones allow deferral of Level 2 requirements?
Partially, and within limits. A contractor must meet a minimum score threshold before conditional status can be granted, and outstanding items must be closed out within 180 days to reach final status. The highest-weighted requirements are not eligible for deferral and must be implemented. Level 1 generally does not permit a Plan of Action and Milestones at all.