Atom Cybersecurity — two practices, one standard
Reference • CMMC 2.0 rollout • Phase 2

November 10, 2026: the self-assessment door closes.

CMMC 2.0 phases in over three years. Phase 1 (from Nov 10, 2025) let most contractors meet Level 2 with a self-assessment at award. Phase 2, beginning November 10, 2026, changes that: for contracts involving CUI, a Level 2 third-party certification by a C3PAO becomes a condition of award. A real assessment takes months to prepare for — which is why this date is a planning date, not a start date.

What actually changes

From “we assessed ourselves” to “a C3PAO assessed us.”

Under Phase 1, a contractor could satisfy a Level 2 requirement with a self-assessment recorded in SPRS — a claim you make about your own environment. From November 10, 2026, Phase 2 requires that Level 2 be verified by a Certified Third-Party Assessment Organization for acquisitions involving CUI, and the certification becomes a condition of award.

Nothing about the underlying standard changes — it is still the 110 requirements of NIST SP 800-171 under DFARS 252.204-7021. What changes is who checks, and how much slack the government extends. Self-attestation gives way to independent verification.

  • Before Phase 2 — Level 2 met by self-assessment in SPRS.
  • From Nov 10, 2026 — Level 2 met by C3PAO third-party certification.
  • Trigger — acquisitions involving CUI; certification required at award.
  • Standard unchanged — still the 110 requirements of NIST SP 800-171.
The rollout

Four phases, one per year, each raising the bar.

DoD is phasing CMMC in rather than switching it on at once. Each phase raises what a contracting officer must require at award. Phase 2 is the one most of the Defense Industrial Base is racing, because it is where self-assessment stops being enough for CUI work.

Find the phase that lands on your contract →

  • Phase 1 • Nov 10, 2025

    Self-assessment at award

    Level 1 or Level 2 self-assessment required at award. DoD may include Level 2 certification at its discretion on selected acquisitions.

  • Phase 2 • Nov 10, 2026

    Level 2 C3PAO certification

    Level 2 third-party certification by a C3PAO required at award for contracts involving CUI. Self-assessment is no longer sufficient here.

  • Phase 3 • Nov 10, 2027

    Option exercises & Level 3

    Level 2 certification extends to option exercises, not just new awards. Level 3 requirements — adding NIST SP 800-172, assessed by DIBCAC — are introduced at award on the highest-priority programs.

  • Phase 4 • Nov 10, 2028

    Full implementation

    CMMC requirements apply across all applicable DoD contracts. The ramp is complete.

Between now and the date

What contractors should do before Phase 2.

C3PAO assessment capacity is finite and remediation is slow. Working backward from November 10, 2026 with several months of runway is the difference between eligible and sidelined.

01

Confirm your level & scope

Establish whether your contracts touch CUI (Level 2) or only FCI (Level 1), and draw a tight CUI boundary. A smaller enclave is fewer controls to prove.

02

Get an honest SPRS score

Assess against all 110 requirements and record a truthful score. Know where you stand before a prime or a C3PAO does.

03

Remediate & document

Close the gaps for real, author the SSP, and track the rest in a POA&M with owners and dates an assessor will accept.

04

Book the C3PAO early

Assessment slots are limited and demand is climbing toward the date. Engage an authorized C3PAO before the calendar fills.

05

Run a mock assessment

Rehearse against the same objectives your assessor will use, tighten the evidence package, and fix findings before they count.

06

Sustain the controls

Keep the controls operating and file your annual affirmation, so the environment still passes on assessment day, not just at setup.

Where Atom fits

We prepare you. The C3PAO certifies you.

Atom is not a C3PAO and does not issue the Level 2 certification — that would be a conflict of interest and it is not our role. What we do is the readiness and remediation work that makes the certification pass: scope the boundary, close the 110 controls, write the SSP and POA&M, run the mock assessment, and stand beside you through the real one.

The clean separation is the point. We build the environment; an independent, authorized assessor verifies it. Starting that work well before November 10, 2026 is what keeps you eligible on the contracts that matter.

See the full CMMC 2.0 readiness path →

  • Readiness & remediation — scope, close controls, build evidence.
  • SSP & POA&M — the documents a C3PAO will read.
  • Mock assessment — rehearse before the graded one.
  • Not the assessor — the C3PAO certifies; we prepare.
Keep reading

Related reading.

The clock is running

Be certifiable before Phase 2, not scrambling after.

Request a readiness assessment. We’ll scope your CUI boundary, score you against all 110 controls, and hand you a dated plan that reaches C3PAO-ready before November 10, 2026.

Request a Readiness Assessment