CMMC Phase 2 vs. CMMC Level 2: What’s the Difference?
CMMC Phase 2 and CMMC Level 2 are not the same thing.
CMMC Phase 2 refers to the second stage of the Department’s planned implementation schedule for adding CMMC 3rd-party certification requirements to defense contracts.
CMMC Level 2 refers to a cybersecurity assessment level designed to verify that an organization has implemented the security requirements needed to protect Controlled Unclassified Information, or CUI.
That distinction became particularly important following the Department’s July 2026 decision to suspend the transition to CMMC Phase 2. According to the Department’s official CMMC Phase II suspension implementation memorandum, the suspension changed how certain assessment requirements may be placed into solicitations and contracts, but it did not eliminate CMMC Level 2, NIST SP 800-171 obligations, or existing requirements to protect CUI.
CMMC Phase 2 vs. Level 2 at a Glance
| Term | What it means | What it addresses | Current status |
|---|---|---|---|
| CMMC Phase 2 | The second stage of the CMMC contractual rollout | When and how CMMC 3rd-party assessment certification i required for applicable solicitations and contracts | The planned November 2026 transition is currently suspended |
| CMMC Level 2 | A cybersecurity assessment level | Protection of CUI using requirements aligned with NIST SP 800-171 Revision 2 | Still part of the CMMC framework; Level 2 self-assessments remain permitted during the suspension |
| Level 2 (Self) | An organization-conducted Level 2 assessment | Verification of applicable Level 2 security requirements, with results submitted to SPRS | Currently an allowed contract designation |
| Level 2 (C3PAO) | A third-party Level 2 certification assessment | Independent verification by an authorized or accredited C3PAO | Program offices may not designate this requirement during the current Phase 2 suspension |
The easiest way to remember the difference is:
A phase tells you when requirements are being introduced. A level tells you what cybersecurity standard an organization must meet.
What Is CMMC Phase 2?
CMMC Phase 2 was designed to be the second stage of the Department’s four-phase implementation schedule.
Under the official CMMC rollout schedule in 32 CFR § 170.3, Phase 1 began with the inclusion of CMMC Level 1 self-assessment and CMMC Level 2 self-assessment requirements in applicable contracts.
Phase 2 was intended to expand the use of CMMC Level 2 certification assessments performed by Certified Third-Party Assessment Organizations, commonly called C3PAOs.
The regulation originally described Phase 2 as beginning one calendar year after Phase 1. During this stage, the Department intended to include Level 2 C3PAO certification status as a condition of award for applicable solicitations and contracts, while retaining some discretion to delay the requirement until an option period.
Phase 2 therefore addresses the rollout of assessment requirements.
It is not a separate cybersecurity standard, and it does not replace CMMC Level 1, Level 2, or Level 3.
Is CMMC Phase 2 Currently Paused?
Yes.
On July 13, 2026, the Department announced the suspension of the planned November 10, 2026 transition to CMMC Phase 2 while it conducts a broader review of the program.
The Department’s official guidance implementing the CMMC Phase II suspension states that, during the suspension, program managers and requiring activities may include only:
- CMMC Level 1 (Self)
- CMMC Level 2 (Self)
During this period, they may not designate:
- CMMC Level 2 (C3PAO)
- CMMC Level 3 (DIBCAC)
The implementation memorandum also directs officials to address applicable active solicitations and contracts containing the suspended assessment requirements.
However, the Department explicitly stated that Phase 1 self-assessment requirements remain in place.
The Department’s official CMMC program information also explains that cybersecurity compliance aligned with NIST SP 800-171 Revision 2 continues to be enforced through self-assessments and selected government-led assessments.
For a closer look at what contractors must continue doing during the pause, see:
CMMC Phase I Requirements During the Phase II Pause: What Defense Contractors Must Still Do
and
CMMC Phase II Is Paused, but These 7 Compliance Mistakes Can Still Cost You Contracts
What Is CMMC Level 2?
CMMC Level 2 is the CMMC assessment level generally associated with protecting Controlled Unclassified Information on contractor information systems.
The Department’s CMMC program overview describes CMMC as a tiered model in which the required level depends on the type and sensitivity of the Federal Contract Information or CUI being handled.
Contractors and subcontractors may be required to achieve a specified CMMC status before contract award.
CMMC Level 2 is currently aligned with NIST Special Publication 800-171 Revision 2.
The official NIST SP 800-171 Revision 2 publication establishes security requirements for nonfederal systems and organizations that process, store, or transmit CUI or provide security protection for those systems.
Those requirements address areas including:
- Access control
- Audit and accountability
- Configuration management
- Identification and authentication
- Incident response
- Media protection
- Physical protection
- Personnel security
- Risk assessment
- Security assessment
- System and communications protection
- System and information integrity
Although NIST has published Revision 3 of SP 800-171, contractors should not assume that publication of a newer NIST revision automatically changes the requirements incorporated into their contracts.
The Department’s July 2026 CMMC Phase II suspension guidance continues to reference NIST SP 800-171 Revision 2 in connection with the current CMMC implementation framework.
Contractors should therefore follow the requirements incorporated into their contracts and the applicable CMMC regulations.
Does CMMC Level 2 Require a Self-Assessment or a C3PAO Assessment?
CMMC Level 2 can have two different assessment designations.
CMMC Level 2 (Self)
For Level 2 (Self), the organization conducts its own assessment using the applicable assessment methodology and submits the results to the Supplier Performance Risk System, or SPRS.
Under the requirements established in 32 CFR § 170.16, a Level 2 self-assessment must generally be performed every year.
An authorized affirming official must affirm compliance when the assessment is submitted and annually thereafter.
The assessment record can include information such as:
- The organization’s assessment score
- CMMC assessment scope
- Applicable CAGE codes
- POA&M status, when applicable
CMMC Level 2 (C3PAO)
For Level 2 C3PAO, an authorized or accredited Certified Third-Party Assessment Organization performs the assessment.
The requirements for these assessments are established in 32 CFR § 170.17.
A final Level 2 C3PAO status is generally valid for three years, subject to annual affirmation of continuous compliance.
The assessment organization submits the assessment results through the designated CMMC systems for transmission to SPRS.
Under the July 2026 Phase II suspension guidance, contracting activities may currently designate Level 2 (Self), but not Level 2 (C3PAO), for covered procurement requirements during the suspension period.
Did the Phase 2 Pause Eliminate CMMC Level 2?
No.
The pause affects the implementation schedule and the use of certain assessment designations.
It does not suspend or erase CMMC Level 2 from the CMMC model.
In fact, the Department’s Phase II suspension memorandum specifically permits CMMC Level 2 self-assessment requirements during the suspension.
The Department also describes Level 2 self-assessments as a mechanism for evaluating an offeror’s implementation of requirements designed to protect CUI.
Defense contractors should therefore not interpret the Phase 2 suspension as permission to:
- Stop implementing NIST SP 800-171 requirements
- Discontinue CUI safeguards
- Allow required SPRS assessments to expire
- Ignore annual affirmation requirements
- Remove physical or electronic access controls
- Stop training employees who handle CUI
- Abandon preparation for future third-party assessments
The distinction matters because a contractor can be operating during a Phase 2 pause while still needing to maintain CMMC Level 2 readiness.
What Requirements Remain in Effect During the Pause?
The Department’s CMMC Phase II suspension memorandum states that cybersecurity obligations contained in DFARS 252.204-7012 remain in effect.
The official DFARS 252.204-7012 clause addresses safeguarding covered defense information and cyber incident reporting.
Depending on the contract and the information involved, current obligations may include:
- Protecting covered defense information and CUI.
- Implementing applicable NIST SP 800-171 security requirements.
- Maintaining an accurate System Security Plan.
- Conducting and submitting required assessments.
- Maintaining a current SPRS record.
- Submitting required affirmations of continuous compliance.
- Reporting covered cyber incidents.
- Flowing applicable requirements down to subcontractors.
- Controlling access to physical and electronic CUI.
- Following applicable CUI marking, storage, transmission, and destruction procedures.
The DFARS 252.204-7021 CMMC clause also establishes requirements associated with maintaining the CMMC status specified by an applicable contract and flowing appropriate requirements down through the supply chain.
Why Are Phase 2 and Level 2 So Commonly Confused?
The terms sound similar, and both involve the number two, but they describe completely different parts of the program.
“Phase 2” answers a scheduling question:
At what stage of the CMMC rollout will the Department begin requiring 3CPAO (3rd-party) assessments more broadly?
“Level 2” answers a cybersecurity question:
What security and assessment standard applies to the contractor information system?
This means a solicitation introduced during Phase 1 could require Level 2 (Self).
Before the suspension, Phase 2 was expected to expand the use of Level 2 C3PAO requirements.
The phase and the level are related, but they are not interchangeable.
What Should Defense Contractors Do Now?
Contractors that handle or expect to handle CUI should continue building and maintaining their compliance programs.
Confirm What Information You Handle
Determine whether your organization receives, creates, processes, stores, or transmits FCI, CUI, or covered defense information.
The information involved will influence the safeguarding and assessment requirements that apply.
Review Every Contract and Solicitation
Do not rely solely on general CMMC announcements.
Review the actual clauses, statements of work, security requirements, and flowdown provisions contained in each contract or subcontract.
Maintain Level 2 Readiness
A temporary restriction on Level 2 C3PAO designations does not mean contractors should dismantle the controls, documentation, and evidence needed to demonstrate compliance.
Continue maintaining:
- Your System Security Plan
- Policies and procedures
- Network and data-flow diagrams
- Asset inventories
- Access-control records
- Training records
- Incident-response procedures
- Assessment evidence
- POA&M documentation, where permitted
- Physical CUI handling procedures
Keep Your SPRS Information Accurate
The requirements for Level 2 self-assessments and affirmations are detailed in 32 CFR § 170.16.
Organizations subject to those requirements should ensure that required assessment information and affirmations remain accurate and current.
Continue Protecting Physical CUI
CMMC is not limited to firewalls, passwords, and cloud environments.
Level 2 includes physical protection and media protection requirements, while the broader CUI program requires organizations to control how CUI is accessed, handled, stored, transmitted, and destroyed.
Physical CUI products can support a documented handling program, but signs, labels, cover sheets, storage products, and other physical safeguards do not independently create CMMC compliance.
They must be used as part of a properly implemented organizational security program.
Frequently Asked Questions
Is CMMC Phase 2 the Same as CMMC Level 2?
No.
CMMC Phase 2 is an implementation stage.
CMMC Level 2 is a cybersecurity assessment level associated with protecting CUI.
Was CMMC Level 2 Suspended?
No.
The Department temporarily suspended the transition to Phase 2 and restricted the designation of Level 2 C3PAO and Level 3 DIBCAC requirements during the review period.
Level 2 self-assessment requirements remain available and may still be included in applicable procurements.
The details are outlined in the Department’s official Phase II suspension implementation memorandum.
Is a Level 2 C3PAO Assessment Currently Required?
During the current suspension, program managers and requiring activities may not designate Level 2 C3PAO requirements in the manner originally planned for Phase 2.
Active solicitations and existing contracts containing affected requirements are to be addressed according to the Department’s July 2026 CMMC implementation guidance.
Contractors should always review their individual contracts, solicitations, and official amendments to determine what applies to them.
How Often Is a Level 2 Self-Assessment Required?
Under 32 CFR § 170.16, a Level 2 self-assessment is generally required every year; an affirmation at the time of assessment and annually thereafter.
How Often Is a Level 2 C3PAO Assessment Required?
Under 32 CFR § 170.17, a final Level 2 C3PAO status is generally valid for three years, subject to required annual affirmations and continued compliance.
Does the Phase 2 Pause Eliminate NIST SP 800-171 Requirements?
No.
The Department’s official CMMC information explains that it continues to enforce cybersecurity requirements aligned with NIST SP 800-171 Revision 2 through self-assessments and selected government-led assessments.
Existing DFARS cybersecurity requirements also remain in effect where applicable.
Does CMMC Level 2 Apply Only to IT Systems?
No.
Level 2 assessments focus heavily on the systems and environments that process, store, or transmit CUI, as well as components that provide security protection for those systems.
However, the underlying security requirements also address personnel, physical protection, media handling, policies, procedures, and organizational processes.
The scope of those requirements can be reviewed directly in NIST SP 800-171 Revision 2.
The Bottom Line
CMMC Phase 2 and CMMC Level 2 serve different purposes.
Phase 2 is a point in the CMMC implementation schedule. Level 2 is a cybersecurity and assessment level associated with protecting CUI.
The Department’s suspension of Phase 2 delayed the planned expansion of Level 2 C3PAO assessment requirements, but it did not eliminate Level 2, NIST SP 800-171 responsibilities, or the obligation to safeguard CUI.
Defense contractors should use the additional time to strengthen—not abandon—their compliance programs.
Organizations that maintain accurate documentation, effective cybersecurity controls, current assessments, and consistent physical CUI handling practices will be better positioned for current contract requirements and whatever implementation structure follows the Department’s review.
- #C3PAO
- #CMMC
- #CMMC 2.0
- #CMMC Assessment
- #CMMC Compliance
- #CMMC Level 2
- #CMMC Phase
- #CMMC Phase 2
- #CMMC Phase II
- #CUI
- #CUI Protection
- #Cybersecurity Compliance
- #Defense Contractors
- #Defense Contracts
- #Defense Industrial Base
- #DFARS 252.204-7012
- #DFARS 252.204-7021
- #DoW Compliance
- #Level 2 Self Assessment
- #NIST
- #NIST 800-171
- #NIST SP 800-
- #NIST SP 800-171
- #SPRS
Share

