Insights › CMMC

CMMC Phase 2 starts November 10: what defense contractors need to do in the next eight weeks

On November 10, 2026, the second phase of the CMMC rollout begins. For most Department of Defense contracts that involve Controlled Unclassified Information (CUI), a self-assessment will no longer be enough: award will require a Level 2 certification issued after an assessment by a Certified Third-Party Assessment Organization (C3PAO). If you handle CUI and have not booked an assessor, this is the deadline that matters.

What actually changes on November 10

Phase 1, which began November 10, 2025, required Level 1 and Level 2 contractors to post a self-assessment score in the Supplier Performance Risk System (SPRS) and to submit an annual executive affirmation. Contracting officers could require a C3PAO assessment for certain contracts, but for most Level 2 work a self-assessment was accepted.

Phase 2 flips the default. For new solicitations that involve CUI issued on or after November 10, 2026, contracting officers are expected to require Level 2 (C3PAO) certification as a condition of award. The DoD's own estimates in the 32 CFR rule say roughly 93% of organizations that handle CUI will need the third-party version. Phase 3 (November 2027) extends the requirement to option periods on existing contracts and introduces Level 3, and Phase 4 (November 2028) applies it to everything.

Two points that catch people out:

  • It flows down. If your prime needs Level 2 certification and shares CUI with you, you need it too. Primes are already checking subcontractor SPRS status before sharing data.
  • There is no "catch up later." If a solicitation you want to bid on requires certification and you do not have it, you are ineligible before the technical evaluation begins.

Why eight weeks is tight but workable

A full Level 2 readiness effort for an organization starting from scratch usually takes six to twelve months. With eight weeks you will not finish that from zero, and you should be suspicious of anyone who promises you will. What you can do in eight weeks is get to a defensible position: a correctly scoped CUI environment, an accurate SPRS score with a Plan of Action & Milestones (POA&M) for the gaps, and a place in a C3PAO's queue. Assessor capacity is the real constraint. There are far fewer authorized C3PAOs than organizations that need them, and lead times are growing as the date approaches.

The eight-week checklist

Weeks 1–2: Confirm scope and where CUI actually lives

  • Inventory every contract clause (DFARS 252.204-7012, 7019, 7020, 7021) and confirm which contracts involve CUI versus only Federal Contract Information (FCI). Level 1 contracts do not need a C3PAO.
  • Map where CUI is stored, processed and transmitted: file shares, email, engineering workstations, ERP, cloud services, contractor laptops, and any vendor that touches it.
  • Decide whether to shrink the assessment boundary. Moving CUI into an enclave (for example a Microsoft 365 GCC High tenant with locked-down workstations) can cut the number of in-scope systems dramatically and is often the fastest route to a passing assessment.

Weeks 3–4: Gap assessment against NIST SP 800-171 Rev 2

  • Score all 110 practices using the DoD Assessment Methodology. Be honest; an inflated SPRS score is a False Claims Act exposure, not a shortcut.
  • Write or update the System Security Plan (SSP). Assessors read the SSP first, and a vague one is the most common reason for a failed assessment.
  • Build the POA&M. Note that under CMMC, Level 2 POA&M items must be closed within 180 days, and certain high-weighted practices (for example MFA and FIPS-validated encryption) cannot be on a POA&M at all.

Weeks 5–6: Close the gaps that block certification

  • Multi-factor authentication for all network and privileged access.
  • FIPS 140-validated encryption for CUI at rest and in transit.
  • Audit logging and log retention that you can actually show an assessor.
  • Formal access reviews, incident response plan, and evidence that staff have completed security awareness training.
  • Vendor and cloud services confirmed as FedRAMP Moderate (or equivalent) for anything that stores CUI.

Weeks 7–8: Get in the queue and rehearse

  • Engage a C3PAO now, even if your assessment date is months away. Booking is the step that protects your eligibility.
  • Run a mock assessment. Assessors want evidence, not intentions: screenshots, configurations, tickets, logs and signed policies for each practice.
  • Update SPRS with your current score and the affirmation, so primes doing due diligence see progress rather than silence.

What a Registered Provider Organization does in this process

An RPO like CorporateTech is not the assessor; C3PAOs are independent by design. The RPO's job is everything before the assessment: scoping, the gap assessment, writing the SSP and POA&M, implementing the technical controls, collecting evidence, and running the rehearsal so the real assessment holds no surprises. For many Orange County manufacturers and engineering firms, the most valuable decision we help make is the enclave question in week one, because it determines the size and cost of everything that follows.

If you only do one thing this week

Find out where you stand. A two-hour scoping call will tell you whether you are looking at an enclave project or a full-environment remediation, and whether your current SPRS score would survive contact with an assessor. That is enough to know whether November 10 is a manageable date or a problem.

Book a CMMC scoping call

  • CMMC
  • NIST 800-171
  • Defense contractors

‹ All insights