CMMC 2.0 is live: what the November 2026 deadline actually means for your contracts
The rule took effect on November 10, 2025. Phase 2 brings the C3PAO certification requirement for CUI — here is what to do with the months you have left.
Notes from the readiness work — CMMC 2.0, NIST SP 800-171, ITAR, and CUI enclave design, written for the engineers, compliance leads, and program managers who actually have to stand the controls up. No hype, no acronym soup for its own sake.
The rule took effect on November 10, 2025. Phase 2 brings the C3PAO certification requirement for CUI — here is what to do with the months you have left.
Why GCC High became the default for ITAR technical data, when the §120.54 encryption carve-out is a real alternative, and the scoping mistakes that quietly widen your boundary.
The DoD Assessment Methodology, why a control can cost you 3 or 5 points, and how a POA&M affects the number your prime sees.
What a System Security Plan has to prove, how the POA&M is supposed to be used, and the gaps that turn a document review into a finding.
DFARS 252.204-7012 and the CMMC clause do not stop at the prime. Where the obligations pass through, and how to answer the questionnaire honestly.
Walkthroughs, interviews, and evidence sampling across all 110 controls. What "MET / NOT MET / NOT APPLICABLE" means and how to prepare your team.
A readiness assessment tells you where you actually stand against NIST SP 800-171 and what it will take to reach the level your contracts require. We prepare and remediate; we do not certify.
Request a Readiness Assessment →