CMMC 2.0 Is Here — What Every Small GovCon Needs to Know Right Now
The DoD's revised Cybersecurity Maturity Model Certification is being written into solicitations now. Here's what changed, what it costs, and how to prepare without burning a year of revenue.
What changed from CMMC 1.0
The Cybersecurity Maturity Model Certification was overhauled in late 2021 and finalized through rulemaking in 2024. CMMC 2.0 replaces the original five maturity levels with three, drops the unique CMMC-only practices, and aligns Level 2 directly with NIST SP 800-171's 110 security requirements. Most importantly, it brings back limited self-assessment at Level 1 and for a subset of Level 2 contracts.
If you bid on DoD cyber or IT work — or you're a sub to anyone who does — CMMC is no longer optional. The DFARS clauses implementing it are now appearing in solicitations and will be phased in across the entire DIB through 2028.
The three levels, in plain English
Level 1 — Foundational. 17 basic safeguards from FAR 52.204-21. Self-assessed annually. Required if you handle Federal Contract Information (FCI) — which, for most prime contracts, is everyone.
Level 2 — Advanced. All 110 requirements from NIST SP 800-171 Rev 2. Most contracts at this level require a third-party assessment by a C3PAO every three years. Required if you handle Controlled Unclassified Information (CUI).
Level 3 — Expert. Level 2 plus a subset of NIST SP 800-172 requirements. Government-led assessment. Reserved for the most sensitive programs.
Most small cyber and IT firms will land at Level 2. A small number — typically those doing IT support that doesn't touch CUI — can stay at Level 1.
Self-assessment is not the loophole you think it is
Level 1 and a narrow slice of Level 2 contracts allow annual self-assessment with a senior official affirmation in SPRS. The affirmation is a personal attestation. Under the DOJ's Civil Cyber-Fraud Initiative, a knowingly false SPRS score is a False Claims Act exposure — treble damages and per-claim penalties. Several settlements have already cited inflated SPRS scores. Self-attest accurately or don't bid.
What it actually costs
Real-world numbers from small DIB firms that have gone through Level 2:
Gap assessment: $8K–$25K. Remediation (tools, MDR, GCC High migration, policies): $40K–$250K depending on starting posture. C3PAO assessment: $20K–$100K depending on scope. Annual maintenance: $30K–$150K.
If those numbers feel high, they are — but the alternative is being shut out of a contract category that will be worth tens of billions through the decade. Build the cost into your bid rates, not your overhead.
A realistic timeline
If you start today and you're not already running on a 800-171-aligned stack, plan on 6–9 months to be assessment-ready and another 2–4 months in the C3PAO queue. The two phases that consistently blow up timelines:
Writing the System Security Plan (SSP). 110 requirements, each with implementation detail, mapped to your actual environment. Most firms underestimate this by a factor of three.
Migrating to a CUI-capable environment. If your shop runs on commercial M365, you're moving to GCC High or an equivalent. That migration is not a weekend project.
How to compete while you're getting certified
Until your C3PAO certificate is in hand, focus your bidding on Level 1 work, non-CUI IT support, civilian (non-DoD) cybersecurity opportunities, and teaming as a sub under a CMMC-certified prime. Civilian agencies — DHS, VA, Treasury, HHS — are running enormous cyber buys that don't require CMMC today.
See The Hidden SAM.gov Opportunities Your Competitors Are Missing for civilian categories worth watching, and The 5 Federal Cybersecurity Contract Vehicles Every Small Business Should Know for the IDIQs to pursue while you certify.
Finding federal cyber contracts just got easier.
Daily SAM.gov scans matched to your NAICS codes, set-asides, and keywords — delivered before your competitors notice.