Five Months to CMMC Phase 2: What Small Contractors Need to Know

CMMC Phase 2 arrives November 10, 2026, bringing third-party certification requirements where applicable for contractors handling CUI. With fewer than 600 assessors serving 80,000+ contractors, wait times stretching to 18 months, and certification costs reaching $300,000, the window for preparation is closing fast.

Five Months and Counting

CMMC Phase 1 enforcement has been active since November 2025. The CMMC 2.0 program rule (32 CFR Part 170) took effect in December 2024, and the companion DFARS acquisition rule became effective on November 10, 2025. CMMC clauses have been appearing in new DoD solicitations for months now, and companies without a valid SPRS score are already being disqualified from awards.

The next inflection point is Phase 2 on November 10, 2026, less than five months away. Phase 2 introduces third-party certification assessments where applicable for contractors handling Controlled Unclassified Information (CUI), replacing self-assessment for most CUI-handling Level 2 contracts. Phase 3, bringing Level 3 DIBCAC assessments for high-priority programs, follows on November 10, 2027. Full implementation across all applicable DoD solicitations and contracts arrives November 10, 2028.

The readiness picture has not improved. According to CyberSheath’s 2025 State of the DIB report, only 1% of defense industrial base organizations feel fully prepared for CMMC assessments, down from 8% in 2023 and 4% in 2024. Out of roughly 80,000 defense contractors that need Level 2 certification, only about 270 hold final CMMC certificates.

Those numbers represent a compliance gap so large it threatens to reshape the defense industrial base itself.

What CMMC 2.0 Actually Requires

CMMC 2.0 collapsed the original five-level framework into three tiers, each mapping to a distinct category of information and a different verification mechanism.

Level 1 (Foundational) applies to contractors handling Federal Contract Information (FCI) only. It requires 15 practices aligned with FAR 52.204-21, organized across six domains. Verification is an annual self-assessment, with results entered into the Supplier Performance Risk System (SPRS). No third-party assessor is required. For most small contractors handling only FCI, Level 1 compliance is straightforward and inexpensive, typically $5,000 to $15,000.

Level 2 (Advanced) is where the burden concentrates. It applies to contractors handling Controlled Unclassified Information (CUI) and requires full implementation of the 110 security controls from NIST SP 800-171 Rev. 2, organized across 14 control families. Access Control alone carries 22 requirements. System and Communications Protection adds 16. Identification and Authentication contributes 11.

Level 2 accounts for approximately 98% of defense contractor certifications needed. Depending on the contract and the phase of implementation, verification requires either a self-assessment or a third-party certification assessment conducted by a CMMC Third-Party Assessment Organization (C3PAO).

Level 3 (Expert) targets the most sensitive programs, requiring additional controls from NIST SP 800-172 and verification through Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) assessments. Most small contractors will not face Level 3 requirements in the near term, though the Phase 3 timeline beginning in November 2027 will expand its reach.

The 110 Controls in Practice

The 110 NIST 800-171 controls are not abstract cybersecurity principles. They are specific, auditable requirements that touch every aspect of how a company manages its information systems. The 14 control families cover access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.

For a 50-person defense subcontractor running a mix of on-premise and cloud infrastructure, implementation means deploying multi-factor authentication across all systems accessing CUI, establishing continuous audit logging with tamper-evident storage, segmenting networks to isolate CUI from general business traffic, encrypting CUI at rest and in transit using FIPS-validated cryptographic modules, and documenting every control with sufficient evidence to survive a third-party assessment.

Many small contractors discover that their existing IT environments were never designed with these controls in mind. The gap between “we have antivirus and a firewall” and “we implement all 110 controls with documented evidence” is where the cost and complexity reside.

What Certification Actually Costs

The Department of Defense estimated the cost of Level 2 C3PAO certification at $104,670 over three years. The SBA Office of Advocacy has formally stated that this estimate understates the small-business cost burden.

The DoD figure covers assessment, certification, and affirmation fees. It does not cover the implementation work required to actually pass the assessment.

Realistic first-year total costs, including preparation, gap remediation, technology upgrades, and the assessment itself, range from $98,000 to $305,000. The median small business first-year spend is approximately $116,000. C3PAO assessment fees alone run $35,000 to $80,000, representing only 25 to 35% of total first-year costs. Regional variation adds another layer: West Coast organizations pay up to 54% more than Midwest contractors for equivalent assessments.

For contractors with DoD revenue under $500,000, compliance costs can consume an entire year’s profit. This is not a compliance exercise. It is an existential financial decision that determines whether a company can continue competing for defense work.

Conditional Certification and POA&M Realities

CMMC 2.0 includes a conditional certification pathway, but its constraints are tighter than many contractors expect.

A contractor can receive conditional CMMC status if it achieves at least an 80% score on its Level 2 assessment while documenting the remaining gaps in a Plan of Action and Milestones (POA&M). But the rules on what can appear on a POA&M are strict.

For Level 1, POA&Ms are not permitted at all. Every requirement must be fully met before self-assessment submission.

For Level 2, POA&Ms are allowed only for 1-point requirements, the lower-weight controls in the scoring methodology. Requirements worth 3 or 5 points must be fully implemented before the assessment. There is one narrow exception: SC.L2-3.13.11 (CUI Encryption) may appear on a POA&M if encryption is employed but not yet FIPS-validated.

The clock on conditional status is tight. All POA&M items must be resolved and verified within 180 days of the conditional status date. If the contractor cannot close the gaps within six months, the conditional status expires and the certification fails.

This means that a contractor banking on conditional certification as a way to defer hard work has, at best, a six-month runway. If the remaining controls require infrastructure changes, procurement, or workforce training, 180 days can evaporate quickly.

The Assessor Bottleneck

Even contractors that are ready for certification face a practical constraint: there are not enough assessors to meet demand.

Approximately 100 C3PAOs are currently authorized nationwide, served by fewer than 600 certified CMMC assessors. Industry estimates suggest 2,000 to 3,000 assessors are needed to process the pipeline of 80,000+ contractors requiring Level 2 certification.

The math does not work. Wait times for a C3PAO engagement are currently 6 to 18 months, with some assessors booked through 2027. Contractors that have not initiated the engagement process are already behind.

This assessor shortage creates a secondary risk: price inflation. As Phase 2 approaches and demand spikes, assessment costs will likely rise above current ranges. Contractors who delay are paying more for less scheduling flexibility.

The Cost of Non-Compliance

The consequences of failing to achieve CMMC certification are not theoretical. They are contractual, financial, and increasingly legal.

Contract ineligibility. Proposals submitted without the required CMMC status are deemed non-responsive and removed from consideration. No CMMC status in SPRS means no award. For contractors whose revenue depends on DoD work, losing eligibility is a business-ending event.

False Claims Act exposure. Inaccurate SPRS scores or CMMC affirmations trigger False Claims Act liability. Since launching its Cyber-Fraud Initiative, the DOJ has reached 16 settlements totaling over $80 million. In February 2025, Health Net Federal Services and Centene Corporation paid $11.25 million for falsely certifying cybersecurity compliance on a TRICARE contract. In December 2025, DOJ brought its first-ever FCA action against a subcontractor, a precision machining company that settled for approximately $421,000 for failing to provide adequate cybersecurity protections.

Operational disruption. One Maryland defense subcontractor with $5 million in annual DoD revenue lost a contract representing 40% of its revenue when it could not meet Level 2 requirements within 90 days, then incurred $180,000 in emergency compliance costs compared to an estimated $80,000 had the work been planned.

The enforcement trajectory is clear. The DOJ is pursuing cybersecurity compliance fraud with increasing frequency and expanding scope, from primes to subcontractors, from large firms to small shops.

What Small Contractors Should Do Now

The path from “not started” to “certified” typically takes 12 to 18 months. With Phase 2 enforcement less than five months away, contractors who have not started are already past the ideal preparation window. Those who begin today are operating on a severely compressed timeline.

Determine your required level. Review your current and anticipated contracts for DFARS 252.204-7021 clauses. If you handle CUI, you need Level 2. If you handle only FCI, Level 1 suffices. If you are unsure, assume Level 2 and confirm with your contracting officer.

Run a gap assessment against NIST 800-171 Rev. 2. Score yourself honestly against all 110 controls using the DoD assessment methodology. Enter your score in SPRS. Forty-two percent of contractors have submitted SPRS scores, but 17% of those still report negative scores against the 110-point target.

Engage a C3PAO early. Given the 6 to 18 month wait times, the assessment engagement should start immediately, even if remediation work is still underway. A C3PAO can conduct a readiness assessment that identifies gaps before the formal certification assessment begins.

Budget realistically. Plan for $100,000 to $300,000 in first-year costs, not the DoD’s $104,000 three-year estimate. Factor in technology upgrades, managed security services, documentation development, and staff training alongside the assessment fee.

Watch for financial relief. The Senate NDAA for FY2027 proposes a CMMC grant program offering up to $100,000 per small business to offset Level 2 C3PAO assessment costs, capped at $50 million total. A separate House draft bill proposes a CMMC tax credit for small businesses. Neither is enacted yet, but both signal recognition that the compliance burden is unsustainable for the smallest contractors.

The Bigger Picture

CMMC 2.0 is the most significant compliance mandate to hit the defense industrial base in a generation. Industry estimates project that 33,000 to 44,000 companies, roughly 15 to 20% of the DIB, will exit the defense market between 2025 and 2027 because of certification costs and complexity.

That attrition is not evenly distributed. It will fall hardest on small contractors, the same firms that comprise 73% of the defense industrial base and receive 25% of all DoD prime contracts. The companies least able to absorb a six-figure compliance cost are the ones most likely to leave the market entirely.

The contractors that survive will be the ones that treated CMMC not as a checkbox exercise but as an infrastructure investment, one that protects both their competitive eligibility and the sensitive information that the program was designed to safeguard. The ones that waited for clarity already have it. The enforcement dates are set. The assessor pipeline is constrained. The cost of delay compounds monthly.

The only remaining variable is whether you start now or start too late.

Want to discuss this further?