Skip to content
Back to blog

CMMC Level 2 Certification: What Executives Need to Know

CMMC Level 2 Certification: What Executives Need to Know

Last Updated: September 25, 2026 | Reviewed for accuracy based on latest CMMC information.

For defense contractors that handle Controlled Unclassified Information, CMMC Level 2 is becoming a contract eligibility requirement. As the Department of Defense continues its phased rollout, more solicitations and contracts will require either Level 2 self-assessment or Level 2 certification through an authorized C3PAO.Sera Brynn is authorized by The Cyber AB to conduct CMMC Level 2 assessments and is also an accredited FedRAMP 3PAO and GovRAMP 3PAO, giving our team direct experience with the assessment standards federal contractors must navigate.

The Department of War (DoW) suspended Phase 2 requirements on July 13, 2026, pending a 60-day program review. Phase 1 obligations remain in force, and NIST SP 800-171 Rev. 2 compliance is still contractually required. Contractors that pause preparation now will restart under pressure when certification requirements return.

This article explains what CMMC Level 2 requires, where the phased rollout stands after the suspension, where POA&M flexibility applies, and the path to a formal C3PAO assessment. 

CMMC Phase Timeline and the 2026 Suspension

CMMC requirements were introduced through a phased implementation plan.

Phase 1 began on November 10, 2025, when the DFARS acquisition rule became effective and CMMC requirements began appearing in applicable DoD solicitations and contracts. Phase 1 requirements remain fully in place. Contracts may require Level 1 self-assessment, Level 2 self-assessment, or, at the Department's discretion, Level 2 C3PAO certification.

Phase 2 was scheduled to begin on November 10, 2026 and would have expanded Level 2 C3PAO certification as a condition of award. On July 13, 2026, the DoW suspended Phase 2 and all pending CMMC implementation milestones, pending a 60-day review of the program.

The suspension does not pause cybersecurity obligations. During the review period, the Department will enforce NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments. DFARS 252.204-7012 remains a binding contract requirement, and contractors must continue to safeguard covered defense information.

For executives, the calculus has shifted but not reversed. The 110 security requirements of NIST SP 800-171 still apply. Certification requirements may return in revised form after the review concludes, and CMMC readiness still takes months for organizations that need to define CUI scope, remediate gaps, and prepare evidence. Contractors that achieve Level 2 certification now enter that environment with independent verification already in hand. Contractors that stop preparing will start over when requirements resume.

FAQ since the July 2026 Suspension

Is CMMC cancelled?

No. The Department of War suspended Phase 2 requirements and pending implementation milestones on July 13, 2026, pending a 60-day program review. Phase 1 self-assessment requirements remain in force. The Department is collecting industry feedback through a public RFI, with responses due August 14, 2026, and a CMMC Reform Task Force will recommend the program’s path forward. The review may revise the program. It has not ended it.

Does the suspension change our obligation to protect CUI?

No. All defense contractos and subcontractors remain contractually obligated to safeguard covered defense information under DFARS 252.204-7012. During the review, the Department will enforce NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments. The suspension paused a verification mechanism. The 110 security requirements still apply.

What happens to contracts that already include a Level 2 C3PAO requirement?

Contracting officers have been directed to amend active solicitation and modify existing contracts to remove Level 2 C3PAO and Level 3 assessment requirements. Contractors should verify that the modification reaches each affected contract rather than assume it.

What happens after the 60-day review?

The Task Force's internal deadline to deliver its report to the DoW CIO was on or about September 11, 2026. As of this writing, no report has been made public and the Department has not issued further guidance or a revised timeline. Sera Brynn will update this article as soon as the Department releases its findings. 

Should we pause CMMC preparation?

That depends on the organization’s contract mix and risk tolerance. The 110 NIST SP 800-171 requirements remain contractually binding, self-assessment accuracy now carries the enforcement weight, and readiness timelines have not shortened. Organizations that continue preparing keep their options open regardless of what the review concludes.

Is our existing Level 2 certification still worth anything?

Yes. A completed Level 2 C3PAO assessment provides independent verification that a self-assessment cannot. Prime contractors continue to weigh verified compliance when selecting subcontractors, and certification held now positions the organization ahead of the market if third-party requirements return after the review.

Do SPRS scores still matter?

Yes, and arguably more than before. Self-assessment is now the primary enforcement mechanism, and SPRS scores and annual affirmations remain required. The Department of Justice continues to pursue contractors over misrepresented cybersecurity compliance under the Civil Cyber-Fraud Initiative, and an inflated score or false affirmation carries False Claims Act exposure. Accuracy in SPRS is a legal obligation, not an administrative formality.

Understanding the Three CMMC Levels

CMMC has three levels. Each level is tied to the type of information a contractor handles and the security requirements included in the contract.

Level 1: Foundational

Level 1 applies to contractors that handle Federal Contract Information. It includes basic safeguarding requirements and is completed through self-assessment. Level 1 does not require a C3PAO.

Level 2: Advanced

Level 2 applies to contractors that handle Controlled Unclassified Information. It is based on the 110 security requirements in NIST SP 800-171 Rev. 2.

Some Level 2 contracts require self-assessment. Under the current suspension, new C3PAO certification requirements are paused, though the required CMMC status for any contract will be identified in the solicitation or contract.

A final Level 2 C3PAO status is valid for three years, with annual affirmations required in SPRS.

Level 3: Expert

Level 3 applies to contractors that handle the most sensitive DoD programs. It adds selected requirements from NIST SP 800-172 and is assessed by DCMA DIBCAC. Phase 3 was scheduled to begin one year after Phase 2 and is also affected by the July 2026 suspension of pending implementation milestones.

What CMMC Level 2 Actually Requires

CMMC Level 2 requires implementation of the 110 security requirements in NIST SP 800-171 Rev. 2. These requirements are evaluated using the CMMC assessment process and related assessment objectives.

The 14 Level 2 domains are:

#
Domain
Number of Controls
1.
 Access Control (AC)
22 controls
2.
Audit and Accountability (AU)
9 controls
3.
Awareness and Training (AT)
3 controls
4.
Configuration Management (CM)
9 controls
5.
Identification and Authentication (IA)
11 controls
6.
Incident Response (IR)
3 controls
7.
Maintenance (MA)
6 controls
8
Media Protection (MP)
9 controls
9.
Personnel Security (PS)
2 controls
10.
Physical Protection (PE)
6 controls
11.
Risk Assessment (RA)
3 controls
12.
Security Assessment (CA)
4 controls
13.
System and Communications Protection (SC)
16 controls
14.
System and Information Integrity (SI)
7 controls

 

Executives should understand that CMMC Level 2 is not only a technology exercise. Assessors review documentation, technical settings, system boundaries, policies, procedures, artifacts, and interviews. The organization must show that requirements are implemented and operating within the defined CMMC assessment scope.

SPRS, Scoring, and Conditional Certification

Before a CMMC Level 2 assessment, organizations should understand how scoring and POA&M rules can affect the final assessment outcome.

For Level 2, organizations are assessed against the 110 requirements in NIST SP 800-171. A final certification requires all applicable requirements to be met. In some cases, a conditional certification may be available if the organization meets the minimum score requirement and any remaining items are eligible for a POA&M.

Not every requirement can be placed on a POA&M, and all approved POA&M items must be closed within 180 days. This is why organizations should review scoring, evidence, and remediation priorities before entering the formal assessment process.

For C3PAO assessments, assessment results are submitted through the official CMMC reporting process and reflected in SPRS.

Executive takeaway: POA&M flexibility exists, but it is limited. Organizations should not treat conditional certification as the plan. The safest path is to enter the assessment with scope, evidence, and key requirements ready for review.

Preparing for Your Third-Party Assessment

The suspension removed the deadline, not the work. NIST SP 800-171 Rev. 2 still governs, and the preparation sequence below positions contractors to certify on their own timeline rather than the government's.

1. Engage an Authorized C3PAO

If your contract requires CMMC Level 2 certification, your official assessment must be conducted by an Authorized C3PAO. Even if remediation is still underway, engaging a C3PAO early can help your organization begin assessment planning, understand timing and documentation expectations, and secure a place on the assessment schedule before capacity becomes more constrained.

2. Confirm Your CUI Scope

Start by identifying every system, application, user, process, facility, and external service provider that stores, processes, or transmits CUI.

Scope matters because it determines the size and complexity of the assessment. A poorly defined scope can increase cost, delay readiness, and create assessment issues that could have been addressed earlier. 

3. Conduct a Gap Assessment

Compare your current environment against the 110 requirements in NIST SP 800-171 Rev. 2 and the applicable CMMC assessment objectives.

A strong gap assessment should identify:

  • Requirements that are fully met
  • Requirements that are partially met
  • Requirements that are not met
  • Evidence gaps
  • Documentation gaps
  • Items that may affect POA&M eligibility
  • Remediation priorities

4. Build and Validate the SSP and Evidence Package

The System Security Plan is a core CMMC document. It must accurately describe the assessment scope, system boundaries, control implementation, roles, responsibilities, and related documentation.

The SSP should not be created at the end of the process. It should be developed and updated as remediation progresses.

Your evidence package should include approved policies, procedures, screenshots, configurations, logs, diagrams, training records, access reviews, and other artifacts that show how requirements are implemented.

Entering the assessment process with a clear scope, accurate documentation, organized evidence, and an Authorized C3PAO already engaged can help reduce delays and give your organization a clearer path toward CMMC Level 2 certification.

Schedule Your CMMC Level 2 Assessment with Sera Brynn

Sera Brynn is authorized by The Cyber AB to conduct CMMC Level 2 assessments. Our assessment team helps defense contractors understand what to expect, prepare for assessment logistics, and complete the formal C3PAO process when they are ready.

 

Sera Brynn provides:

  1. Formal CMMC Level 2 C3PAO assessments
  2. Assessment planning and scoping discussions
  3. Assessment logistics and evidence readiness coordination
  4. Assessment execution by credentialed CMMC professionals
  5. Reporting aligned with CMMC program requirements

Sera Brynn also provides CMMC readiness advisory services under conflict-of-interest rules. Advisory and assessment services cannot be provided for the same client environment when doing so would create a conflict.

If your organization handles CUI under current or future DoW contracts, the review period is the window to confirm scope, close gaps, and certify ahead of the market. Certification completed now stands ready when requirements resume.

Contact Sera Brynn at 877-701-8000 to discuss CMMC Level 2 assessment availability.

 

Know Your CMMC Assessment Pricing

Need a clearer estimate before scheduling your CMMC Level 2 assessment? Use Sera Brynn’s pricing and scheduling form to share basic details about your environment, assessment scope, and timeline.

Our team will review your information and help you understand assessment pricing, scheduling availability, and the next steps for engaging Sera Brynn as your C3PAO.

 

FAQ: CMMC Level 2 Fundamentals

What is CMMC Level 2 certification?

CMMC Level 2 certification is a cybersecurity assessment status for defense contractors that handle Controlled Unclassified Information. It is based on the 110 security requirements in NIST SP 800-171 Rev. 2.

Some Level 2 contracts allow self-assessment. Others require a formal third-party assessment by an authorized C3PAO. 

Do I need a C3PAO or can I self-assess?

During the Phase 2 suspension, new DoW solicitations may require Level 1 or Level 2 self-assessment only. A follow-on implementation memo directs agencies to amend active solicitations and contracts that already carry Level 2 C3PAO or Level 2 assessment requirements to remove them. Contractors should confirm whether that amendment reaches their specific contracts. If certification requirements return after the program review, the required CMMC status will again be identified in the solicitation or contract.

How long does CMMC Level 2 readiness take?

Timeline depends on the maturity of your current security program, the complexity of your CUI environment, the quality of your documentation, and the amount of remediation required.

Organizations with defined scope, mature controls, and current evidence may move faster. Organizations starting with unclear scope or major control gaps should plan for a longer readiness period.

What is an SPRS score?

The Supplier Performance Risk System (SPRS) score reflects the organization’s implementation of NIST SP 800-171 requirements using the DoD assessment methodology. The score starts at 110 and subtracts points for unmet requirements.

For CMMC Level 2 C3PAO assessments, results are entered into the CMMC instantiation of eMASS and transmitted to SPRS. 

Which Level 2 requirements cannot be placed on a POA&M?

The Level 2 POA&M exclusions are:

  1. External Connections
  2. Control Public Information
  3. System Security Plan
  4. Escort Visitors
  5. Physical Access Logs
  6. Manage Physical Access

CUI Encryption has a limited exception when encryption is employed but is not yet FIPS-validated.

What happens if we fail or receive conditional certification?

A Conditional Level 2 status may be granted when the organization meets the CMMC POA&M rules. For Level 2, the assessment score must be at least 80 percent, which is 88 out of 110, and the POA&M cannot include prohibited requirements. Any allowed POA&M items must be closed within 180 days through a POA&M closeout assessment. If the POA&M is not successfully closed within that timeframe, the Conditional CMMC Status expires. Organizations that do not qualify for conditional status must remediate the gaps before achieving certification.

How long is CMMC Level 2 certification valid?

A final Level 2 C3PAO status is valid for three years. Annual affirmations of continued compliance are required in SPRS.

Is Sera Brynn authorized to conduct CMMC Level 2 assessments?

Yes. Sera Brynn is authorized by The Cyber AB to conduct CMMC Level 2 assessments. Formal assessments are conducted according to CMMC program requirements and applicable conflict-of-interest rules.