Regulatory update — July 13, 2026: The DoD has suspended CMMC Phase 2, pausing the mandatory third-party (C3PAO) certification milestone pending a 60-day reform review. Your obligations have not gone away: NIST SP 800-171, DFARS 252.204-7012 safeguarding, Level 2 self-assessment, and SPRS scoring all remain in force. What this means for you →
Resources for DIB Contractors

Navigating CMMC 2.0 Level 2

Clear, technical resources for Defense Industrial Base contractors processing Controlled Unclassified Information. If your organization handles CUI — as a prime or subcontractor — safeguarding obligations under DFARS 252.204-7012 and NIST SP 800-171 remain a current requirement, even with third-party CMMC certification now paused.

Meet Certalo — our CMMC app → Explore free resources
Reality Check

Who Needs a Third-Party Audit?

Updated July 2026: With Phase 2 suspended, Level 2 self-assessment is the operative path right now — no C3PAO certification is currently required for contract award. That said, the program as designed makes third-party assessment the default for any contract involving CUI, and it may return following the DoD's 60-day review. Building your architecture and documentation toward that standard remains the safe assumption.

~80,000
DIB Contractors Needing Level 2 (C3PAO)

DoD estimates approximately 80,000 contractors across the Defense Industrial Base will require Level 2 third-party (C3PAO) certification — effectively any organization that stores, processes, or transmits CUI under a DoD contract.

  • Performed by an accredited C3PAO
  • Required prior to contract award once 7021 applies
  • Default path for CUI-handling contracts

Don't stand down — the certification is suspended, the standard is not. Keep preparing your architecture and documentation to the full 800-171 bar: it keeps you eligible for award today and ready if third-party certification returns after the review.

DFARS 48 CFR Rollout

The Enforcement Timeline

The phased rollout is active. Compliance is a current requirement for winning and maintaining defense contracts.

Active Now Since November 10, 2025

Phase 1 — Level 2 Self-Assessment

The DoD is inserting Level 2 Self-Assessment requirements into new solicitations. Contractors must have an active SPRS score prior to contract award. If you have not submitted a score, you are already at risk.

Suspended Paused July 13, 2026

Phase 2 — C3PAO Certification (Suspended)

The mandatory Level 2 third-party (C3PAO) certification milestone — originally set for November 10, 2026 — was suspended on July 13, 2026 pending a 60-day DoD reform review, citing compliance cost and assessor-capacity concerns. Third-party certification is not currently a condition of contract award. The underlying NIST SP 800-171 standard and your self-assessment obligations are unchanged, so continuing to prepare your SSP and SPRS score is the prudent hedge while the review is underway. Accredited assessors remain listed in the Cyber AB Marketplace.

Upcoming 2027

Phase 3 — Expansion to All Applicable New Contracts

C3PAO requirements expand to cover all applicable new contracts across the DIB, regardless of CUI classification tier.

Upcoming 2028

Phase 4 — Option Periods on Existing Contracts

C3PAO requirements apply to option periods on existing contracts, completing the transition to universal implementation across the defense supply chain.

Open Resources

What You'll Find Here

Technical guidance on building, documenting, and maintaining a CMMC 2.0 Level 2 compliance posture — without decoding regulatory jargon.

Introducing Certalo

Turn a months-long self-assessment into days of work

Certalo is our AI CMMC assistant — it drafts your SSP from real environment evidence, scores SPRS in real time, builds your POA&M, and prepares the policy and procedure documentation an assessor expects.

Request a demo See what it does
About Methodical Security

Our Mission

To help Defense Industrial Base organizations reduce the cost and time of CMMC assessments while measurably improving their security posture — through plain-language guidance today and agentic tooling soon.

Open Content

Free, technical resources covering the 110 NIST SP 800-171 controls, SSP and POA&M architecture, scoping decisions, C3PAO selection, and the assessment lifecycle — written for practitioners, not auditors.

Certalo

The Methodical app

AI agents that draft your SSP from real environment evidence, score gaps against SPRS, and keep your POA&M current as your environment changes — built to compress months of manual assessment work into days. Explore Certalo →

110
NIST SP 800-171 Rev 2
Security Requirements
14
Control Families
covered by Level 2
~80K
DIB contractors estimated
to require Level 2 (C3PAO)
Paused
Phase 2 C3PAO mandate
suspended (60-day review)