CMMC 2.0 is the DoD's mandatory cybersecurity certification framework with three levels: Level 1 (17 practices, self-assessed) for all DoD contractors, Level 2 (110 NIST 800-171 practices, C3PAO-assessed) for contractors handling CUI, and Level 3 for critical defense programs. Phase 2 enforcement begins October 2026.
CMMC 2.0 Certification Requirements 2026: Small Business Guide | AIGovBid
CMMC 2.0 is the DoD's mandatory cybersecurity certification framework with three levels: Level 1 (17 practices, self-assessed) for all DoD contractors, Level 2 (110 NIST 800-171 practices, C3PAO-assessed) for contractors handling CUI, and Level 3 for critical defense programs. Phase 2 enforcement begins October 2026.
CMMC 2.0 Certification Requirements 2026: Small Business Guide | AIGovBid
CMMC 2.0 is the DoD's mandatory cybersecurity certification framework with three levels: Level 1 (17 practices, self-assessed) for all DoD contractors, Level 2 (110 NIST 800-171 practices, C3PAO-assessed) for contractors handling CUI, and Level 3 for critical defense programs. Phase 2 enforcement be
CMMC 2.0 is the DoD's mandatory cybersecurity certification framework with three levels: Level 1 (17 practices, self-assessed) for all DoD contractors, Level 2 (110 NIST 800-171 practices, C3PAO-assessed) for contractors handling CUI, and Level 3 for critical defense programs. Phase 2 enforcement begins October 2026.
This AIGovBid guide covers compliance for small business government contractors and explains the next steps contractors should take.
Frequently asked questions
What is CMMC 2.0 and who does it apply to?
CMMC 2.0 (Cybersecurity Maturity Model Certification) is the DoD's mandatory cybersecurity framework for all contractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). It applies to every DoD prime contractor and subcontractor in the supply chain. CMMC 2.0 streamlined the original five-level model to three levels: Level 1 (17 practices), Level 2 (110 practices based on NIST SP 800-171), and Level 3 (110+ practices based on NIST SP 800-172).
When do small businesses need to be CMMC certified?
The CMMC phased rollout began in October 2025 (Phase 1). Phase 2 starts in October 2026, when Level 2 C3PAO third-party assessments become required for all prioritized DoD programs. Small businesses that handle CUI and want to compete on DoD contracts in 2026 need to begin their CMMC compliance process immediately — remediation and C3PAO assessment typically take 12–18 months combined.
How much does a CMMC Level 2 assessment cost?
C3PAO (CMMC Third-Party Assessment Organization) assessment costs typically range from $30,000 to $100,000 or more, depending on the size and complexity of your environment. Smaller companies with a well-scoped CUI enclave and mature documentation can expect costs toward the lower end of that range. Remediation costs — purchasing compliant tools, configuring controls, updating policies — are additional and vary widely.
What is the difference between CMMC Level 1 and Level 2?
CMMC Level 1 covers 17 basic cybersecurity practices derived from FAR 52.204-21 and applies to contractors handling Federal Contract Information (FCI) but not CUI. It requires only an annual self-assessment. Level 2 covers all 110 security requirements in NIST SP 800-171 and applies to contractors handling Controlled Unclassified Information (CUI). Most DoD contracts involving technical data, design specs, or sensitive program information require Level 2, which in many cases requires a triennial third-party C3PAO assessment.
Does CMMC apply to subcontractors?
Yes. DFARS clause 252.204-7021 requires prime contractors to flow CMMC requirements down to all subcontractors that handle CUI or FCI. If a subcontractor stores, processes, or transmits CUI as part of a DoD program, it must achieve the same CMMC level required of the prime. Primes are responsible for verifying that their subcontractors are CMMC-compliant before award of any subcontract involving CUI.
Canonical URL: https://www.aigovbid.com/blog/cmmc-2-0-certification-requirements-small-business-2026