Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

CMMC 2.0 vs CMMC 1.0: What Changed and Why It Matters

If you have been following CMMC since its introduction, you may remember a more complex framework with five maturity levels and additional practices beyond NIST standards. That was CMMC 1.0. The program you see today—CMMC 2.0—is significantly different, streamlined based on industry feedback and practical implementation concerns.

CMMC stands for Cybersecurity Maturity Model Certification—the DoD’s mandatory cybersecurity program for defense contractors.

Understanding what changed helps you interpret older guidance correctly and appreciate why the current framework works the way it does.

The Original CMMC 1.0 Framework

When the DoD first announced CMMC in 2019 and released version 1.0 in January 2020, it featured:

Five Maturity Levels

LevelNameControlsFocus
Level 1Basic17 practicesBasic cyber hygiene
Level 2Intermediate72 practicesIntermediate cyber hygiene
Level 3Good130 practicesGood cyber hygiene (NIST 800-171)
Level 4Proactive156 practicesProactive security
Level 5Advanced171 practicesAdvanced/progressive security

CMMC-Unique Practices

CMMC 1.0 included practices beyond NIST SP 800-171, adding requirements the DoD considered important but that were not in existing standards.

Maturity Processes

Each level included “process maturity” requirements beyond technical practices, requiring documented processes, policies, and management oversight at increasing levels of sophistication.

Third-Party Assessment for All Levels

Every level required third-party assessment by a C3PAO—even Level 1, which covers basic safeguarding.

C3PAO stands for Certified Third-Party Assessment Organization—companies authorized to conduct CMMC assessments.

No Self-Assessment Option

Contractors could not self-assess and self-attest. All certifications require external verification.

No POA&M Allowed

Plans of Action and Milestones were not permitted. Contractors had to fully implement all controls before assessment—no gaps allowed.

POA&M stands for Plan of Action and Milestones—documents tracking security gaps and remediation plans.

Why CMMC 1.0 Faced Criticism

Industry feedback on CMMC 1.0 was significant:

Cost Concerns

Requiring third-party assessment for all contractors, including small businesses at Level 1, created substantial cost burdens. Many small contractors questioned whether they could afford compliance.

Complexity

Five levels with unique practices beyond established standards created confusion. Contractors struggled to understand requirements that did not map to existing frameworks.

Assessment Bottleneck

Requiring C3PAO assessment for everyone raised concerns about whether enough assessors would be available to certify the entire defense industrial base.

Rigidity

No self-assessment option and no POA&M allowance meant contractors either achieved perfect compliance or received nothing—no middle ground for organizations making genuine progress.

Timeline Concerns

The aggressive implementation timeline, combined with the above issues, led many to question the feasibility.

The DoD listened to this feedback and initiated a comprehensive review in 2021.

The CMMC 2.0 Overhaul

In November 2021, the DoD announced CMMC 2.0 with fundamental changes:

Three Levels Instead of Five

LevelNameControlsAssessment Type
Level 1Foundational15 (FAR 52.204-21)Self-assessment
Level 2Advanced110 (NIST 800-171)Self or C3PAO
Level 3Expert110+ (800-171 + 800-172)Government-led

The intermediate levels (old Levels 2 and 4) were eliminated. The framework now aligns directly with existing standards.

Alignment with Existing Standards

CMMC 2.0 eliminated unique practices:

  • Level 1 maps exactly to FAR 52.204-21 (15 requirements)
  • Level 2 maps exactly to NIST SP 800-171 (110 requirements)
  • Level 3 adds NIST SP 800-172 requirements

No more CMMC-unique controls that contractors had to learn separately.

Self-Assessment Options

Level 1 allows annual self-assessment with executive affirmation. Level 2 allows self-assessment for some contracts (those without critical CUI) with C3PAO assessment required only for prioritized acquisitions involving critical national security information.

CUI stands for Controlled Unclassified Information—sensitive government data requiring protection.

POA&M Allowed

Conditional certification is now possible when contractors meet 80% or more of the requirements. Remaining gaps can be documented in a POA&M with 180 days to remediate.

Reduced Assessment Burden

By allowing self-assessment for Level 1 and some Level 2 situations, the assessment bottleneck concern was addressed. Third-party assessment is reserved for higher-risk situations.

Key Differences Summary

AspectCMMC 1.0CMMC 2.0
Levels53
Level 1 assessmentC3PAO requiredSelf-assessment
Level 2 assessmentC3PAO requiredSelf or C3PAO (contract-dependent)
Unique practicesYesNo (aligns to NIST)
Process maturityRequiredRemoved
POA&MNot allowedAllowed (80% threshold)
Conditional certificationNot availableAvailable

What This Means for Contractors

If You Were Preparing for CMMC 1.0

Your preparation is not wasted:

  • NIST SP 800-171 controls remain the core of Level 2
  • Documentation and evidence you developed still apply
  • Security investments remain valuable
  • You may have less to do than originally planned

If You Are Starting Fresh

CMMC 2.0 is more approachable:

  • Clear alignment with established NIST standards
  • Self-assessment options reduce initial costs
  • POA&M provides flexibility for achieving compliance
  • Resources and guidance are more readily available

Level Selection

Understand which level applies to you:

  • Level 1: You handle only FCI (Federal Contract Information), not CUI
  • Level 2 Self-Assessment: You handle CUI, but contracts are not designated as requiring C3PAO assessment
  • Level 2 C3PAO: You handle CU,I and contracts require third-party assessment
  • Level 3: Rare; only for highest-sensitivity programs

FCI stands for Federal Contract Information—information provided by or generated for the government under contract.

Most contractors handling CUI will need Level 2. The question is whether self-assessment or C3PAO assessment applies—this is determined by contract requirements, not contractor choice.

The Regulatory Journey to CMMC 2.0

CMMC 2.0 required formal rulemaking:

Interim Rule (2020)

DFARS interim rule introduced CMMC 1.0 requirements into contracts.

DFARS stands for Defense Federal Acquisition Regulation Supplement—contract clauses for DoD acquisitions.

CMMC 2.0 Announcement (November 2021)

DoD announced the CMMC 2.0 framework changes but noted that rulemaking would be required.

Proposed Rules (2023-2024)

The DoD published proposed rules for both 32 CFR (program rule) and 48 CFR (DFARS acquisition rule) for public comment.

Final Rule (October 2024)

32 CFR Part 170 (CMMC Program Rule) was finalized, establishing the official CMMC 2.0 requirements.

DFARS Final Rule (2025)

The acquisition rule adding CMMC requirements to contracts was finalized, enabling enforcement.

Common Misconceptions

“CMMC was canceled.”

CMMC was not canceled—it was revised. CMMC 2.0 is the current, active framework now being enforced.

“I can choose self-assessment.”

For Level 2, the contract determines assessment type, not the contractor. If your contract requires C3PAO assessment, self-assessment does not satisfy the requirement.

“CMMC 2.0 is easier.”

CMMC 2.0 is simpler and more aligned with existing standards, but the security requirements are not easier. Level 2 still requires all 110 NIST SP 800-171 controls.

“I can wait until contracts require it.”

While CMMC appears in contracts through phased implementation, compliance with NIST SP 800-171 has been required since 2017 under DFARS 252.204-7012. Waiting is risky.

Looking Ahead

CMMC 2.0 is now the established framework, but evolution continues:

NIST SP 800-171 Revision 3

NIST has released Revision 3 of SP 800-171. The DoD will eventually update CMMC to reference the new revision, though timing is not yet determined.

Continuous Refinement

The DoD continues refining implementation guidance, assessment procedures, and program operations based on experience.

Expansion Beyond DoD

Other federal agencies are watching CMMC as a potential model for their own contractor cybersecurity requirements.

Stay current with DoD announcements and regulatory updates as the program matures.

Key Takeaways

CMMC 2.0 dramatically simplified the original framework by reducing five levels to three, eliminating unique practices, allowing self-assessment for lower-risk situations, and permitting POA&M for conditional certification.

The core security requirements—implementing NIST SP 800-171 controls—remain unchanged. CMMC 2.0 makes the path to compliance more practical, not less secure.

If you prepared for CMMC 1.0, your work still applies. If you are starting now, you benefit from a clearer, more achievable framework aligned with established standards.

Related Articles:

Official Sources: This article is based on DoD CMMC announcements, 32 CFR Part 170, and the evolution of the CMMC program from 2019-2025.

Confused by CMMC versions and changes? Contact Greypike for clear guidance on what applies to your business today. Ready to get started? Obolix is built for CMMC 2.0 Level 1—our platform gets you compliant in a week or less with the current requirements.

Table of Contents