← All insights

CMMC Phase 2 Starts November 10: What Defense Contractors Need to Do Now

On November 10, 2026, third-party CMMC Level 2 certification becomes a condition of award for many DoD contracts involving CUI. Here's what changes, who is affected, and a practical readiness checklist.

For most of the past year, defense contractors could satisfy the Cybersecurity Maturity Model Certification (CMMC) program with a self-assessment. That changes on November 10, 2026, when CMMC enters Phase 2 and independent, third-party Level 2 certification starts appearing as a condition of contract award.

If your organization handles Controlled Unclassified Information (CUI) for the Department of Defense, as a prime or anywhere in the supply chain, this is the milestone to plan around.

A quick recap of the CMMC rollout

CMMC is being phased into DoD contracts over four years:

Phase Start date What it adds
Phase 1 November 10, 2025 Level 1 and Level 2 self-assessments required in applicable solicitations
Phase 2 November 10, 2026 Level 2 certification by an authorized C3PAO required for applicable contracts
Phase 3 November 10, 2027 Level 3 assessments by the DoD's DIBCAC begin to apply
Phase 4 November 10, 2028 Full implementation across applicable contracts

Phase 1 established the basics: affirmations and scores in the Supplier Performance Risk System (SPRS). Phase 2 is where an outside assessor must verify that your controls are actually in place.

What changes in Phase 2

Independent verification replaces self-attestation for many CUI contracts. An authorized CMMC Third-Party Assessment Organization (C3PAO) will evaluate all 110 security requirements of NIST SP 800-171 Rev. 2. Each requirement is either met or not met, backed by documentation, interviews and technical evidence.

Certification is a condition of award. When a solicitation specifies CMMC Level 2 (C3PAO), you need a current certification status before award. Starting the process after the RFP drops is too late.

It flows down. Primes must ensure subcontractors that handle CUI hold the appropriate CMMC status. Expect your larger customers to start asking for your certification status and timeline, if they haven't already.

Conditional certification and POA&Ms

Not every gap is fatal, but the rules are tight:

  • You may achieve conditional Level 2 status with a score of at least 88 of 110 points, with remaining items documented in a Plan of Action and Milestones (POA&M).
  • POA&M items must be closed out within 180 days, verified by a follow-up assessment. Otherwise the conditional status expires.
  • Certain higher-weighted requirements cannot be deferred to a POA&M at all. They must be met at the time of assessment.

In practice, a POA&M is a safety net for a few minor gaps, not a strategy.

Your readiness checklist

If you expect Level 2 (C3PAO) requirements in upcoming contracts, here is where to focus now:

  1. Define your CUI boundary. Identify exactly where CUI is stored, processed and transmitted, and which people, systems and service providers touch it. A well-scoped enclave can dramatically reduce cost and assessment effort.
  2. Finish (or refresh) your System Security Plan. Assessors start with the SSP. It must describe how each of the 110 requirements is implemented in your environment, not just that a policy exists.
  3. Run an honest gap assessment. Score yourself the way an assessor would, using the NIST SP 800-171A assessment objectives. Confirm that the score in SPRS reflects reality.
  4. Prioritize the requirements that can't be POA&M'd. Multi-factor authentication, FIPS-validated encryption for CUI, boundary protection and audit logging are common stumbling blocks.
  5. Review your cloud and managed service providers. Cloud services that store or process CUI generally need FedRAMP Moderate authorization or equivalency, and your MSP's responsibilities belong in a shared-responsibility matrix.
  6. Collect evidence as you go. Screenshots, configurations, logs, training records and signed policies. If it isn't documented, assessors treat it as not implemented.
  7. Schedule your assessment early. Demand for C3PAO assessments is high heading into Phase 2. Getting on an assessor's calendar now protects your pipeline.

The bottom line

Phase 2 turns CMMC from a paperwork exercise into a verified requirement. Organizations that treat it as a deadline-driven sprint usually end up with expensive surprises. Those that start with a clear scope, an accurate SSP and an honest gap assessment get through certification faster and keep winning work.

Security Best Practices helps defense contractors scope CUI environments, close NIST SP 800-171 gaps and prepare for C3PAO assessments. If November 10 is on your radar, let's talk.