Services Threat Intel Blog Company Contact Contact Sales
← Back to Threat Intel Compliance

CMMC 2.0: what changes for contractors, and when

Cipher Defense Research


CMMC 2.0 consolidated the model into three levels and moved much of the defense industrial base from aspirational compliance to contractual requirement. For most contractors handling controlled unclassified information, the practical question is no longer whether certification applies, but which level, and by which contract cycle.

The structural changes that matter

The move from five levels to three simplified the map but raised the stakes: Level 2 aligns directly with NIST 800-171, and for many programs it requires third-party assessment rather than self-attestation. Documentation that used to sit unexamined in a self-assessment now has to survive an assessor's review.

The timeline risk most teams underestimate

Certification is not the long pole — remediation is. Closing gaps in access control, logging, and incident response takes quarters, not weeks, and assessor availability adds its own queue. Teams that start from their contract dates and work backward almost always find less runway than they expected.

What to do now

A gap assessment against 800-171 control families tells you the real distance to your required level. From there, a prioritized remediation roadmap, sequenced by contract exposure rather than by ease, is what turns a compliance deadline into a project plan.

Working against a CMMC deadline?

Contact Sales