CMMC Phase 2 Requirements 2026 — What Defense Contractors Need to Know Before the November 10 Deadline
If you hold a DoD contract, hope to win one, or sit anywhere in a defense supply chain, the most consequential cybersecurity deadline of your career is now less than seven months away. November 10, 2026 — that’s when CMMC Phase 2 takes effect, and it changes the game for nearly every contractor handling Controlled Unclassified Information.
Phase 1 was a warm-up. The Department of Defense started embedding CMMC clauses into solicitations in November 2025, but most contractors could still self-attest to their NIST 800-171 compliance, post a score in SPRS, and bid on contracts. The honor system, more or less, still applied.
Phase 2 ends the honor system.
Starting November 10, 2026, contracting officers will require third-party certified Level 2 status by default for contracts involving CUI. An independent, Cyber AB-authorized assessor — a C3PAO — has to formally verify that you actually meet all 110 NIST SP 800-171 controls. A self-assessment won’t count. A binder of policies your IT lead wrote last quarter won’t count.
The DoD estimates more than 76,000 organizations need Level 2 C3PAO certification. As of February 2026, fewer than 1,100 had completed it. If you’re doing the arithmetic in your head right now, you’re seeing what we’re seeing.
What CMMC Phase 2 Actually Is
CMMC is the DoD’s framework for verifying that defense contractors actually protect the sensitive government information they handle. It replaces a decade of self-attestation under DFARS 252.204-7012 with a tiered, assessed certification model. As of February 2026, all assessment obligations route exclusively through CMMC under DFARS 252.204-7021.
The program rolls out across four phases:
- Phase 1 (November 10, 2025): Self-assessments accepted as a condition of award; DoD discretion to require C3PAO Level 2.
- Phase 2 (November 10, 2026): C3PAO-assessed Level 2 becomes the default for CUI contracts; Level 3 (DIBCAC) becomes available at DoD’s discretion.
- Phase 3 (November 10, 2027): C3PAO Level 2 becomes mandatory across the board, including option exercises on existing contracts.
- Phase 4 (November 10, 2028): Full implementation. CMMC requirements apply to all applicable DoD contracts above the micro-purchase threshold where FCI or CUI is handled.
Yes, This Affects Your DoD Contract — Here’s How to Tell
The deceptively simple test: if your contract requires you to process, store, or transmit Federal Contract Information or Controlled Unclassified Information on a non-federal information system, CMMC applies. The level depends on the data:
- Only FCI: Level 1 (annual self-assessment and affirmation)
- CUI on contractor systems: Level 2 (C3PAO assessment by Phase 2, with limited self-assessment exceptions)
- CUI for the DoD’s most sensitive programs: Level 3 (DIBCAC assessment)
Look for DFARS 252.204-7021 in your contracts and solicitations. That’s the binding clause. The clause specifies the required CMMC level and assessment type.
If you’re a subcontractor and your prime hasn’t said anything yet, that silence is not protection. Flow-down obligations under 32 CFR §170.23 require primes to vet sub compliance before sharing covered information. Those conversations are coming, and the primes who haven’t started them are the ones you should worry about most.
The Question to Ask Your Contracting Officer or Prime Today
“Will any of our active contracts, recompetes, or option exercises after November 10, 2026 require C3PAO-assessed Level 2 certification?” If the answer is yes — and you don’t have a C3PAO engagement booked or a clear path to one — you have a problem that grows worse every week you delay.
Download a FREE CMMC Scoping Book
The Bottleneck Nobody Planned For
This is the part of the Phase 2 conversation that gets glossed over in most compliance briefings, and it’s the part that’s actually going to determine who wins contracts in late 2026.
The math from the February 2026 Cyber AB Town Hall:
- 76,598 organizations are estimated to need Level 2 C3PAO certification
- ~1,042 organizations had completed certification as of February 2026
- ~80 to 100 authorized C3PAOs nationwide
- Under 800 Certified CMMC Assessors in the workforce; industry estimates need 2,000 to 3,000
- Wait times projected to exceed 18 months by Q3 2026 in defense corridor states
Even if every C3PAO worked nonstop, the pipeline cannot absorb the demand about to hit it. C3PAOs in aerospace and defense hubs are already booking into late 2026 and 2027.
And the assessment is not the start of the timeline — it’s the end. A typical readiness journey runs 12 to 14 months: gap analysis, remediation, documentation, pre-assessment review, then the C3PAO engagement itself. Add another 180 days if you receive a Conditional status. If you start gap analysis today, you’re realistically looking at certification in mid-to-late 2027 — well past the Phase 2 deadline.
Five Ways CMMC Phase 2 Will Catch Contractors Off Guard
These are the recurring patterns we see when contractors finally engage seriously with CMMC. Each is preventable. None is rare.
- Assuming a self-assessment score in SPRS will keep you eligible. It will, until your contract recompetes after November 10, 2026 — and then your bid is non-responsive. Self-attested compliance is being phased out as the default for CUI work.
- Confusing readiness with certification. A C3PAO cannot provide both consulting and assessment services to the same client — that separation is codified in 32 CFR Part 170. Contractors who hire one firm to “do CMMC for them” sometimes learn too late that the certifying firm has a six-month wait.
- Underestimating which controls cannot be on a POA&M. Conditional certification sounds like a generous fallback, but the rule prohibits POA&M items for fundamental safeguards — multi-factor authentication, FIPS-validated encryption, and basic FAR 52.204-21 controls. Miss those at assessment and you don’t get conditional status. You don’t get certified at all. You go to the back of the line.
- Forgetting that subcontractors flow down. If you’re a prime required to hold C3PAO Level 2, your subs handling CUI need to meet the same standard. If they can’t, you have to bring the work in-house, find a certified replacement, or restructure the data flow. None of those happens in 30 days.
- Treating cloud licensing as if it’s compliance. A GCC High tenant or a GovCloud subscription is a building block, not a certification. Your environment still has to be configured, documented, and assessed against all 110 controls.
The False Claims Act Exposure Most People Miss
Phase 2 creates two parallel records of your cybersecurity posture — your historical SPRS self-scores and your C3PAO assessment results. When those numbers don’t match, the Department of Justice now has a measurable trigger for investigation under the False Claims Act.
This isn’t theoretical. The enforcement precedent is on the books:
- MORSECORP — $4.6 million (March 2025). The defense AI software developer self-reported a NIST 800-171 score of 104 out of 110. A subsequent assessment put the actual score closer to negative 142. The case was filed by the company’s own head of security under qui tam provisions; the whistleblower received an $851,000 share.
- Raytheon and Nightwing — $8.4 million (May 2025). Allegations that a key internal network used in 29 DoD contracts had no System Security Plan in place, despite certifications of compliance. The whistleblower was a former Director of Engineering.
The pattern across these cases is what to internalize: enforcement was not triggered by data breaches. It was triggered by the gap between what was claimed and what was real. Phase 2 makes that gap dramatically easier for the government to discover, because the C3PAO assessment will produce an authoritative, independent measurement that can be compared to whatever you’ve been saying about yourself in SPRS.
If your historical self-scores were optimistic, that’s a conversation worth having with counsel before your C3PAO walks in the door.
What to Do Right Now
You don’t need to solve everything in a week. But you do need to start moving with intent:
- Inventory contracts and identify which require — or will require — CMMC Level 2. Flag every active contract, recompete, and option exercise scheduled after November 10, 2026.
- Run an honest gap assessment against NIST SP 800-171 Rev 2 using NIST 800-171A as the assessment guide. Document where you are, not where you wish you were.
- Engage a Registered Provider Organization (RPO) for readiness work — separately from your C3PAO. Remember the conflict-of-interest firewall.
- Book your C3PAO conversation now. Even if the formal assessment is months away, get on a calendar.
- Implement the controls that cannot be on a POA&M before assessment — MFA, FIPS-validated encryption, the basic FAR 52.204-21 safeguards. These are non-negotiable at the gate.
- Address your subcontractors. Identify who handles CUI on your behalf and confirm their certification path.
- Have a candid conversation with counsel about your historical SPRS submissions — particularly if your assessed score will diverge significantly from what’s currently posted.
Frequently Asked Questions
Will my existing contract be cancelled if I don’t have C3PAO certification by November 10, 2026?
Generally, no — Phase 2 is not retroactive to contracts already awarded. But option exercises, recompetes, task orders under existing IDCs, and any new contracts after the deadline will require the appropriate CMMC status. The practical effect is that your business pipeline starts shutting off, not that an existing contract is yanked.
Can I bid on a contract while my C3PAO assessment is pending?
You need a current CMMC status in SPRS at the level the contract requires at the time of award — not at bid submission. If you achieve Conditional or Final status before award, you’re eligible. If you’re still in remediation when the award comes around, you’re not.
Helpful Articles & Information
- CUI Scoping Workbook
- CMMC compliance services
- Managed IT for government contractors
- NIST SP 800-171 Rev. 2 — Protecting Controlled Unclassified Information
- DoD CMMC Official Program Page
- 32 CFR Part 170 — CMMC Program Final Rule
- DFARS 252.204-7021 Contract Clause
- Cyber AB Marketplace — Find Authorized C3PAOs
How Greypike Helps GovCons Get Phase 2 Ready
Greypike works with small and mid-sized Defense Industrial Base contractors every day, and the Phase 2 conversation is dominating our pipeline. Teams that started CMMC work two years ago are finalizing assessments. Teams just starting now are doing the hard math about whether they can realistically certify before the deadline.
We run NIST 800-171 gap assessments, build out technical controls, write the SSP and supporting policies, and get your environment to a defensible posture for assessment. Our Obolix compliance platform centralizes the evidence collection that makes the assessment day go smoothly rather than sideways. Greypike Enclave deploys a hardened, CUI-compliant VDI environment on Google or Microsoft government clouds, giving contractors a defensible technical boundary on day one. And GreypikeAI delivers AI capabilities inside a FedRAMP-aligned boundary — so the productivity gains your competitors are using don’t have to come with the compliance exposure that’s already getting other contractors named in DOJ settlements.
If you’re handling CUI and don’t yet have a clear, scheduled path to C3PAO Level 2 certification, that’s the conversation to start. Not after the deadline. Now.
Schedule a Consultation with Greypike
Visit greypike.com or call (703) 214-9246 to talk through your CMMC Phase 2 readiness.
Greypike Inc. — Veteran-Owned. Mission-Focused. Compliance-Ready.





