<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=1732033&amp;fmt=gif">
Skip to content

Updated 17 August 2026: On 13 July 2026 the Department of War suspended the CMMC Phase 2 requirements. The mandatory assessment by an accredited C3PAO, scheduled from 10 November 2026, will not take place for the time being. Phase 3 with the DIBCAC assessments is suspended as well. The Phase 1 self-assessment and the 110 controls of NIST SP 800-171 Rev. 2 remain in force. So do DFARS 252.204-7012, DFARS 252.204-7021 with annual affirmation and the obligation to post a score in SPRS. A Reform Task Force is reviewing the program; recommendations are expected in September 2026. Source: DoD CIO, CMMC.

Last updated: 17 August 2026

CMMC 2.0 | Cybersecurity Maturity Model Certification

CMMC 2.0 is the binding cybersecurity framework of the US Department of Defense. Every company in the DoD supply chain, including German and European suppliers, must prove compliance with defined security controls. Contracts that involve CUI require the 110 controls of NIST SP 800-171 Rev. 2, a self-assessment under DFARS 252.204-7021 with annual affirmation and a current score in SPRS. ISEC7 has supported defense suppliers on this path for years, with ready-to-use IT solution modules, readiness assessment and audit preparation across all three levels.

At a glance

  • 3 levels: Level 1 (Foundational, 17 controls), Level 2 (Advanced, 110 NIST SP 800-171 controls), Level 3 (Expert, NIST SP 800-172).
  • FCI vs. CUI: Level 1 protects Federal Contract Information, Level 2 and 3 protect Controlled Unclassified Information.
  • Assessment by an accredited C3PAO from Level 2 onward was scheduled from 10 November 2026 and has been suspended since 13 July 2026. Level 1 and Level 2 run on self-assessment under Phase 1.
  • Rollout paused in Phase 1. Contracting officers remove Phase 2 and Phase 3 requirements by contract modification.
  • Typical Level 2 project duration: 6 to 12 months for scoping, gap closure and documentation. The C3PAO assessment step is suspended.
SUPPLIER TO THE US DEPARTMENT OF DEFENSE? TAKE ACTION NOW.
 

Why CMMC?

Without documented implementation of the 110 controls and a current score in SPRS, eligibility for US defense contracts is at risk. The additional assessment by an accredited C3PAO was scheduled from 10 November 2026 and has been suspended since 13 July 2026. Because the standard cascades across the entire supply chain, subcontractors and suppliers in DACH and the EU are directly affected. Implementing the controls protects sensitive defense data (CUI and FCI) from industrial espionage by closing critical gaps in access control, encryption, monitoring and incident response. Companies that achieve compliance secure market access in one of the largest defense markets in the world and position themselves as a credible global partner.

CMMC 2.0 Cybersecurity Maturity Model Certification logo

The three CMMC levels

The CMMC 2.0 model has three levels, each tied to the sensitivity of the data being handled. Each level builds on the previous one and adds further security controls. Which level applies to your company depends directly on your DoD contract and the type of data you process.

CMMC L1 | Foundational

CMMC Level 1 protects Federal Contract Information (FCI). It requires 17 basic cyber hygiene practices from FAR 52.204-21, including access control, authentication and media protection. Proof is by annual self-assessment and can be achieved within a few weeks.

CMMC L2 | Advanced

CMMC Level 2 applies to companies that process Controlled Unclassified Information (CUI). It requires the 110 controls of NIST SP 800-171 Rev. 2 in 14 families. For most CUI contracts, an assessment by an accredited C3PAO was scheduled from 10 November 2026. That step has been suspended since 13 July 2026. The formal self-assessment with annual affirmation and a current score in SPRS remains mandatory.

CMMC L3 | Expert

CMMC Level 3 is for companies that manage CUI in highly critical defense programs. It adds selected controls from NIST SP 800-172 on top of Level 2 and targets defense against Advanced Persistent Threats (APTs). Assessment by a government body (DIBCAC) was planned as Phase 3 and has been suspended since 13 July 2026.

CMMC level pyramid graphic showing L1, L2, L3
HOW DO I ACHIEVE CMMC COMPLIANCE?
 

Your path to CMMC

ISEC7 guides defense suppliers through the structured build-out of a CMMC-compliant infrastructure. We combine experience from our own ISEC7 certification with customer projects in DACH, the EU and the US. The work follows a clear step model in which the security controls (Controls) sit at the center, with documentation, tooling and staff training running in parallel.

STEP 1

Preparation and readiness assessment

First we define the scope: where in your organization FCI or CUI flows. A gap analysis against the controls of the target level follows, for example the 110 controls of Level 2 in 14 families such as access control, configuration management and system integrity. The output is a prioritized action plan with effort estimates.

STEP 2

Closing the gaps

Identified gaps are systematically closed with ready-to-use IT solution modules that cover up to 90 % of the technical controls in our customer projects. For each open requirement we produce a Plan of Action and Milestones (POAM) and a System Security Plan (SSP), both required for the self-assessment and for any later C3PAO assessment.

STEP 3

Institutionalization and test run

Controls do not exist only on paper. In this step the new security policies become part of day-to-day operations, employees are trained, and processes are validated through internal test audits. We simulate the assessment day including interview questions and evidence collection, so your evidence holds up in the self-assessment and in any later C3PAO assessment.

STEP 4

Evidence and continuous monitoring

The final step is the formal self-assessment with annual affirmation and a current score in SPRS. The official assessment by an accredited C3PAO for Levels 2 and 3 was scheduled from 10 November 2026 and has been suspended since 13 July 2026. Our managed services then take over continuous monitoring, so your score stays evidenced at any time.

Frequently asked questions about CMMC 2.0

What is CMMC 2.0 and who needs it?

CMMC 2.0 (Cybersecurity Maturity Model Certification) is the cybersecurity framework of the US Department of Defense. Every partner in the DoD supply chain must prove compliance with defined security controls. Any company that handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) for a US defense contract, directly or as a subcontractor, must meet the requirements of the level specified in the contract and provide the corresponding evidence.

What is the difference between FCI and CUI?

Federal Contract Information (FCI) is non-public information provided by or generated for the US government under a contract. Controlled Unclassified Information (CUI) is more sensitive and covers information that requires safeguarding under specific laws, regulations or government-wide policies. CMMC Level 1 protects FCI; Levels 2 and 3 protect CUI.

How long does a CMMC assessment typically take?

Timelines vary with the target level and the organization's starting maturity. Level 1 self-assessments can be achieved within a few weeks if basic cyber hygiene is in place. For Level 2, six to twelve months are realistic for scoping, gap closure and documentation (POAM, SSP). The C3PAO assessment has been suspended since 13 July 2026 and is out of that calculation for the time being. Level 3 engagements run longer because of the additional NIST SP 800-172 controls.

What is a C3PAO and when is it required?

A C3PAO (CMMC Third Party Assessment Organization) is an accredited body that performs the formal CMMC assessment and issues the certification. This assessment was scheduled for Level 2 (for most CUI contracts) and Level 3 from 10 November 2026. It has been suspended since 13 July 2026. Until further notice, Level 1 and Level 2 rely on the formal self-assessment with annual affirmation and a current score in SPRS.

How does ISEC7 help with CMMC compliance?

ISEC7 supports defense-industry customers along the full CMMC journey, from readiness assessment and scoping to a gap analysis against the relevant controls. Ready-to-use IT solution modules cover up to 90 % of the technical controls, with documentation support for POAM and SSP. Audit preparation with C3PAO partners and continuous monitoring after the self-assessment follow. See the ISEC7 CyberRisk Check as an entry point for a structured security assessment. Our NIS2 Compliance Services cover EU-side obligations, and our ISEC7 Managed Mobility Services handle ongoing operations.

CMMC MADE STRAIGHTFORWARD
 

Secure CMMC

Infrastructures

Implement CMMC compliance now, with ISEC7 expertise drawn from our own certification and defense customer projects across DACH, the EU and the US.

  • Ready-made CMMC modules & monitoring
  • Solution components for up to 90% compliance
  • CMMC from the FedRAMP cloud