Cipher Defense Research
CMMC 2.0 consolidated the model into three levels and moved much of the defense industrial base from aspirational compliance to contractual requirement. For most contractors handling controlled unclassified information, the practical question is no longer whether certification applies, but which level, and by which contract cycle.
The move from five levels to three simplified the map but raised the stakes: Level 2 aligns directly with NIST 800-171, and for many programs it requires third-party assessment rather than self-attestation. Documentation that used to sit unexamined in a self-assessment now has to survive an assessor's review.
Certification is not the long pole — remediation is. Closing gaps in access control, logging, and incident response takes quarters, not weeks, and assessor availability adds its own queue. Teams that start from their contract dates and work backward almost always find less runway than they expected.
A gap assessment against 800-171 control families tells you the real distance to your required level. From there, a prioritized remediation roadmap, sequenced by contract exposure rather than by ease, is what turns a compliance deadline into a project plan.