What is Needed for CMMC 2.0 Level 1 Compliance?

The Cybersecurity Maturity Model Certification (CMMC) was created by the U.S. Department of Defense (DoD) to protect sensitive information in the Defense Industrial Base (DIB). Its goal is to ensure contractors handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) meet specific cybersecurity standards.

If you aren’t familiar with CMMC, check out our blog, CMMC for Manufacturers: What Phase 2 Means and How to Get Ready, to learn what it is and why you’ll have to do it.

The original CMMC framework included five levels of compliance, each with increasing cybersecurity requirements. However, CMMC 2.0 (introduced in 2021 and finalized in October 2024) simplifies this framework by reducing the levels to three (Foundational, Advanced, and Expert) and aligning closely with established standards like NIST SP 800-171 and NIST SP 800-172.

Level 1 (Foundational)
Self-assessment with 15 practices focused on basic cyber hygiene.

Level 2 (Advanced)
Alignment with 110 controls from NIST SP 800-171, requiring third-party assessments for most organizations.

Level 3 (Expert)
Based on NIST SP 800-172, requiring government-led assessments.

To ensure you’re on the easiest path to success, check out our on-demand webinar, How to Streamline Your CMMC 2.0 Compliance.

The CMMC 2.0 Implementation Timeline—Key Dates to Know

The CMMC 2.0 implementation is being rolled out in phases, giving manufacturers time to prepare.

Update (July 2026): On July 13, 2026, the Department of War suspended CMMC Phase 2 — the November 10, 2026 deadline — along with all pending and future CMMC rollout milestones, and opened a 60-day review of the program. Phase 1 self-assessment requirements remain firmly in place. For Level 1 shops, this changes almost nothing: Level 1 was always self-assessed, never third-party assessed, so your path is intact. You still self-assess against the 15 requirements below.

Here’s where each phase stands now:

  • Phase 1 — November 10, 2025 (in effect): CMMC clauses appear in new DoD solicitations and contract awards. Level 1 and Level 2 self-assessments are required as a condition of award for applicable contracts. This is the piece that’s still live.
  • Phase 2 — was November 10, 2026 (suspended): Would have made third-party (C3PAO) Level 2 the default for CUI contracts and stopped self-assessments from counting. Suspended July 13, 2026, pending the reform review. No replacement date has been set.
  • Phase 3 — was November 10, 2027 (suspended): Would have made C3PAO Level 2 a condition for option exercises on existing contracts, and made Level 3 (DIBCAC) mandatory in applicable solicitations. Swept up in the suspension of future milestones.
  • Phase 4 — was November 10, 2028 (suspended): Full implementation across all applicable DoD contracts above the micro-purchase threshold. Also on hold.

What applies in the meantime: During the review, the DoW is enforcing cybersecurity through NIST SP 800-171 Rev 2 self-assessments and DFARS 252.204-7012 — the safeguarding obligation that never went away. A CMMC Reform Task Force will report to the DoW CIO within 60 days, drawing on a public request for information due August 14, 2026.

FREE Self-Assessment Tool

DoD contracts issued after November 10, 2025, may include the new CMMC clauses, and most contracts that touch FCI or CUI will eventually. To complete a CMMC 2.0 Level 1 self-assessment*, manufacturers should:

  1. Understand the CMMC 2.0 Level 1 Requirements
    Review the 15 requirements and ensure they are implemented across your systems.
  2. Prepare Your Documentation
    Maintain clear records of how your company addresses each practice.
  3. Conduct the Assessment
    Use tools like Carbide’s CMMC 2.0 Level 1 Assessment Questionnaire to evaluate your compliance.
  4. Submit Your Results
    Enter your assessment results in the Supplier Performance Risk System (SPRS).

If you’re preparing for CMMC 2.0 Level 1 compliance, Carbide has a free self-assessment tool to help you navigate the process. This tool provides step-by-step guidance and generates a report identifying gaps that must be addressed to meet the Level 1 requirements.

*For more guidance, consult resources such as the DoD’s CMMC documentation and self-assessment guides.

The G-code piece of your CMMC plan. Traceability, compliance, and control — all in a GovCloud-hosted platform.

The G-code piece of your CMMC plan. Traceability, compliance, and control — all in a GovCloud-hosted platform.

Similar Posts