The CMMC Level 2 Cliff: 80,000 Contractors Don't Know They're Behind
CMMC Phase 2 was suspended on July 13, 2026, weeks before it was due to start. Most Tier-2 and Tier-3 defense subcontractors were already behind — and the underlying NIST 800-171 obligations never paused. Here is what the gap looks like.
CMMC Phase 2 is suspended — the 110 controls are not
On July 13, 2026 the Department of War suspended Phase 2 — which was to begin November 10, 2026 and make a C3PAO Level 2 assessment a condition of award — and froze the later phases pending a reform review. Level 2 and Level 3 assessment requirements are being removed from active solicitations and contracts. DFARS 252.204-7012, Phase 1 self-assessments, NIST SP 800-171 Rev 2, SPRS score posting and annual affirmations all still apply, and a prime contractor's own supplier requirements are unaffected by the suspension.
The scale of the problem
The Defense Industrial Base (DIB) has approximately 220,000 companies. Of those, roughly 80,000 are Tier-2 and Tier-3 subcontractors that handle Controlled Unclassified Information (CUI) and were in scope for CMMC Level 2 certification under the suspended Phase 2. What a reformed program will require of them is the subject of the current review.
As of Q3 2026, the number of companies with a completed C3PAO Level 2 assessment is in the low thousands. The gap between requirement and readiness is enormous — and most companies in that gap don't know it yet.
They will find out one of two ways: when their prime contractor asks for proof of certification, or when they lose a contract they expected to keep.
What Level 2 actually requires
CMMC Level 2 requires implementation of all 110 security requirements in NIST SP 800-171 Rev 2. (Not Rev 3 — DoD Class Deviation 2024-O0013 indefinitely defers Rev 3.) The assessment methodology uses the SPRS scoring system: each control has a point value, and you lose points for each unimplemented control.
The maximum possible SPRS score is 110. The conditional certification floor — the minimum score at which you can receive a Level 2 certification with a Plan of Action and Milestones — is 88.
The 6 controls you cannot defer
Under 32 CFR 170.21, the following controls cannot be placed on a POA&M. They must be fully implemented before certification:
- 3.1.20 — Verify and control/limit connections of external systems
- 3.1.22 — Control CUI posted or processed on publicly accessible systems
- 3.10.3 — Escort visitors and monitor visitor activity
- 3.10.4 — Maintain audit logs of physical access
- 3.10.5 — Control and manage physical access devices
- 3.12.4 — Develop, document, and periodically update a system security plan
If you're using a compliance tool that lets you put any of these on a POA&M, the tool is wrong. This is one of the most common errors in self-managed CMMC prep.
Where most companies are actually failing
Based on self-assessment data submitted to SPRS.mil, the control families with the highest non-implementation rates in the DIB are:
System and Communications Protection (SC)
FIPS 140-2 encryption (3.13.11) requires GCC High or equivalent — standard M365 commercial does not qualify. Many contractors don't realize this.
Identification and Authentication (IA)
MFA requirement (3.5.3) has a partial-credit rule — you get 3 points (not 5) for partial implementation. Misunderstanding this creates score errors.
Audit and Accountability (AU)
Log retention and review requirements (3.3.1–3.3.9) require active monitoring, not just enabling logs. "We have logs" is not the same as "we review logs."
Configuration Management (CM)
Baseline configuration documentation (3.4.1–3.4.2) requires written, enforced standards — not IT team tribal knowledge.
The False Claims Act exposure
Since 2021, DoJ's Civil Cyber-Fraud Initiative has actively pursued False Claims Act (31 U.S.C. §3729) cases against defense contractors who falsely certified NIST 800-171 compliance. Penn State settled for $1.25M in October 2024 over cybersecurity non-compliance affecting DoD and NASA contracts. Aerojet settled for $9M in 2022. This is not hypothetical.
Any company that submits a CMMC affirmation to DoD knowing it contains materially false representations is exposed to FCA liability — including individual liability for the CEO or compliance officer who signs the affirmation. The affirmation is never auto-submitted. You sign it. You are accountable for it.
The realistic timeline to Level 2
Gap assessment
Understand your current SPRS score and which controls need remediation. Tool-assisted assessment is faster than manual.
Remediation
Implementing missing controls, especially infrastructure changes (GCC High migration, MFA enforcement, SIEM implementation). This is the long phase.
Documentation
System Security Plan, DPIA, evidence package. Can be parallelized with late-stage remediation.
C3PAO assessment
C3PAO capacity is constrained — queue times are growing as Phase 2 deadline approaches. Book your C3PAO before you finish remediation.
In total: 6–14 months from a standing start to Level 2 certification. If you haven't started, the math is uncomfortable.
What to do right now
- Run a free SPRS gap analysis to know your current score and exact gap
- Identify your POA&M-prohibited controls — they need immediate remediation, not deferral
- Check your CUI hosting environment — if it's commercial M365 (not GCC High), flag it now
- Book your C3PAO before you finish remediation — queue times are growing
- Generate your SSP from your actual evidence, not from a template
Know your SPRS score today
Free CMMC Level 1 assessment — see your exact gap against all 17 FAR 52.204-21 controls. No account required.
This article is informational and does not constitute legal advice. CMMC certification decisions are made by authorized C3PAOs, not by Aegis Firma. NIST 800-171 Rev 2 control information sourced from NIST SP 800-171 Rev 2 (2021) and DoD Assessment Methodology v1.2.1. Last updated: April 2026.