Cornelius Digital Request Consultation
HomeInsightsAboutFAQCareersCapabilitiesFree Assessment Request Consultation

CMMC 2026: What You Need to Know

One-page reference for defense contractors. Print it, share it, bookmark it.

Which CMMC Level Do I Need?

→ Does your contract involve Controlled Unclassified Information (CUI)?

    → Yes → You need CMMC Level 2 (110 controls, third-party assessment)

    → No, just Federal Contract Information (FCI) → You need CMMC Level 1 (15 controls, self-assessment)

    → Not sure? → Check your contract for DFARS 252.204-7012. If it's there, assume Level 2.

CMMC LEVEL 1

Basic Safeguarding (FCI)

  • 15 controls from FAR 52.204-21
  • Self-assessment (no third-party required)
  • Annual SPRS submission + senior official affirmation
  • POA&Ms NOT allowed — all controls must be MET
  • Applies to all DoD contractors handling FCI
CMMC LEVEL 2

Advanced Protection (CUI)

  • 110 controls from NIST SP 800-171 Rev 2
  • Third-party assessment by authorized C3PAO
  • System Security Plan (SSP) required
  • Limited POA&Ms allowed (180-day remediation window)
  • 3-year certification cycle with annual affirmations

Key Dates

Nov 2025
Phase 1 (Active Now): CMMC Level 1 and Level 2 self-assessments required in applicable contracts
Nov 2026
Phase 2: Level 2 C3PAO assessments required in all applicable new solicitations
Nov 2027
Phase 3: CMMC Level 2 for all option periods on existing contracts
Nov 2028
Phase 4 (Full): CMMC required across all applicable DoD contracts

What It Costs

  • Level 1 (self-assessment): Minimal direct cost — primarily internal time to verify 15 controls and submit SPRS score
  • Level 2 consulting (readiness): $55,000–$95,000 for boutique firms, $120,000–$285,000+ for Big Four firms
  • Level 2 C3PAO assessment: $30,000–$100,000+ depending on scope (separate from consulting)
  • Technology upgrades: Varies — GCC High migration, MFA, SIEM, encryption ($5,000–$50,000+)
  • Cost of non-compliance: Lost contracts, lost revenue, potential False Claims Act liability

The 3 Documents You Must Have

  • SPRS Score — Your numerical compliance score submitted to the DoD. Without it, you cannot win contracts requiring CMMC. Check your readiness →
  • System Security Plan (SSP) — Documents how you implement each of the 110 NIST 800-171 controls. This is the single most critical artifact in a C3PAO assessment.
  • Plan of Action & Milestones (POA&M) — Your roadmap for addressing identified gaps. Must demonstrate credible, time-bound remediation plans. (Level 2 only)

Free Tools — No Login Required

Official Sources

Talk to a CMMC Expert

Free, confidential 30-minute conversation. No obligation — just an honest assessment of where you stand.