CMMC 2.0 is live: what the November 2026 deadline actually means for your contracts
By the Atom Cybersecurity team
For years the honest answer to "when does CMMC actually bite?" was "soon, probably." That answer expired. The 48 CFR acquisition rule took effect on November 10, 2025, and the CMMC clause — DFARS 252.204-7021 — now flows into new Department of Defense contracts. The requirement is real, it is phased, and the phase most of the Defense Industrial Base is watching lands on November 10, 2026.
The rule is in effect — that part is settled
CMMC is no longer a proposal working its way through rulemaking. The acquisition rule is final and operative. In practical terms that means contracting officers are directed to specify a required CMMC level in solicitations, and meeting that level is a condition of award. If your contract calls for a level you cannot demonstrate, you are ineligible — and that applies whether you are a prime or a subcontractor receiving the requirement through flow-down.
It helps to keep two long-standing obligations in view, because CMMC sits on top of them rather than replacing them. DFARS 252.204-7012 already requires contractors handling CUI to implement NIST SP 800-171 and to report cyber incidents to the DoD within 72 hours through DIBNet. CMMC is the mechanism that verifies you are doing what 7012 has asked of you all along.
The phased rollout, and where November 2026 fits
The rule ramps in over three years so the assessor ecosystem can keep up. Here is the schedule, with the exact effective dates.
-
Phase 1 • Nov 10, 2025
Self-assessment at award
Level 1 and Level 2 self-assessment requirements begin appearing in contracts, backed by an annual affirmation in SPRS.
-
Phase 2 • Nov 10, 2026
Level 2 C3PAO certification for CUI
Contracts involving CUI begin requiring Level 2 third-party certification by a C3PAO at award. This is the deadline driving the current scramble.
-
Phase 3 • Nov 10, 2027
Option exercises & Level 3
Level 2 certification extends to option exercises, and Level 3 requirements — government-assessed by DIBCAC — arrive on the highest-priority programs.
-
Phase 4 • Nov 10, 2028
Full implementation
CMMC requirements apply across all applicable DoD contracts. The ramp is complete.
Which level applies to you
The level is tied to the sensitivity of the information you handle, not to your size.
- Level 1 — 17 controls, for Federal Contract Information (FCI). Annual self-assessment.
- Level 2 — the full 110 NIST SP 800-171 controls, for CUI. Certified by a C3PAO on a three-year cycle. This is the level most CUI-handling contractors need.
- Level 3 — Level 2 plus a subset of NIST SP 800-172, assessed directly by the government (DIBCAC), for the highest-risk programs.
Why "November 2026" is really "now"
A Level 2 certification is not a form you file the week it is due. The honest path from an unassessed environment to a passing C3PAO result runs through scoping, remediation, documentation, and a period of operating the controls long enough to produce evidence. That work is measured in months, not weeks. Add to that a finite number of authorized C3PAOs and a queue that lengthens as the deadline approaches, and the calendar tightens further.
There is also a subtlety worth stating plainly: even before your own contracts name a level, your primes can require it earlier. Flow-down is contractual, and a prime racing its own Phase 2 obligation will push the requirement down to the subcontractors who touch its CUI. Many companies first learn they need Level 2 from a prime's questionnaire, not from a solicitation.
What to do with the months you have
The sequence below is the one we run, and it is deliberately front-loaded on the truth: you cannot plan a remediation you have not scoped.
- Scope the CUI boundary first. Identify exactly where CUI is stored, processed, and transmitted. Everything else — cost, timeline, and your SPRS score — follows from where you draw this line.
- Score honestly against 800-171. Run a gap assessment against all 110 controls and compute your SPRS score using the DoD Assessment Methodology. A padded self-score helps no one and does not survive a C3PAO.
- Write the SSP and stand up the POA&M. The System Security Plan describes how each control is met; the POA&M tracks the ones that are not, with owners and dates.
- Remediate in priority order. Close the highest-value gaps first and put the controls into genuine operation — logging, MFA, access reviews — so there is real evidence to sample.
- Sustain it. CMMC is continuous. You affirm annually in SPRS and must notify the relevant officials when a CUI system materially changes. Treat compliance as an operating posture, not a one-time event.
Where Atom fits — and where we do not
We take contractors from "not sure where we stand" to assessment-ready: scoping, gap analysis, SSP and POA&M, remediation, and the managed operations that keep the controls running between affirmations. We are direct about one boundary: Atom is not a C3PAO and does not issue CMMC certifications. The certifying assessment is performed by an authorized third party. Our job is to make that assessment a formality rather than a gamble.
If November 2026 is on your horizon — or a prime has already put it on your desk — the most useful next step is knowing your real score. Everything after that is a plan.
Know where you stand before your prime asks.
Request a readiness assessment. We scope your CUI environment, score it against NIST SP 800-171, and hand you a prioritized path to the level your contracts require.
Request a Readiness Assessment →