If your company handles Controlled Unclassified Information (CUI) for the Department of Defense, CMMC 2.0 is no longer a future problem. Phase 2 makes a third-party (C3PAO) assessment mandatory for Level 2 — and because preparation realistically runs nine to twelve months, the runway for the 2026 milestone has already narrowed.
What actually changes
Level 1 (basic, FCI) stays self-assessed. Level 2 is the one that bites: it maps to the 110 controls of NIST SP 800-171, and for most CUI-handling contracts it now requires an independent assessment rather than a self-attestation. A shortfall isn't a fine — it's contract ineligibility.
The gap most generalist IT teams have
CMMC is a governance problem wearing a technical costume. The 800-171 controls touch access control, audit logging, incident response, media protection, and documented policy — areas a break-fix IT shop rarely owns. The common failure is treating it as a checklist to buy tools for, when the assessors are looking for evidence that the controls operate.
A realistic runway
- Scope the CUI boundary — what systems, what data, who touches it.
- Gap-assess against all 110 controls and build a System Security Plan (SSP) with a POA&M for what's not yet met.
- Remediate the technical and policy gaps — this is the 6–9 month middle.
- Pre-assess with fresh eyes before the C3PAO arrives.
You don't have to be certified to offer readiness
Only organizations that handle CUI need certification themselves — but the managed-compliance work of getting a contractor there is where a security partner earns its keep. See our vCISO & risk-advisory services for how the readiness path works.


