US GOVERNMENT / DEPARTMENT OF WAR

CMMC 2.0

Cybersecurity Maturity Model Certification · 32 CFR Part 170 · Final Rule published November 2023 · Phase II suspended July 13, 2026

CMMC 2.0 is the Department of War's cybersecurity certification framework for defense contractors. It establishes three maturity levels built on top of NIST SP 800-171, adding an assessment and certification layer to what was previously a self-attestation requirement. The framework's core purpose is to ensure contractors protecting Controlled Unclassified Information (CUI) actually implement the 110 security controls in NIST SP 800-171 Rev 2 — not just promise to.

Phase II suspension (July 13, 2026): The Department of War suspended Phase II CMMC requirements — which would have mandated third-party assessments for Level 2 contracts. Phase I self-assessment requirements remain in place. The suspension means contractors handling CUI still must implement 800-171 controls and self-assess, but the third-party certification apparatus is paused. The DoW has not indicated when or whether Phase II will resume. This creates uncertainty: contractors who invested in certification preparation are left with sunk costs, while the underlying compliance obligation (800-171 implementation) remains.

Three Maturity Levels Levels 1–3

Level 1 (Foundational): 17 basic safeguarding requirements derived from FAR 52.204-21. Self-assessment with annual affirmation by a company executive. Applicable to contractors handling Federal Contract Information (FCI) that is not CUI. No third-party assessment required.

Level 2 (Advanced): All 110 requirements from NIST SP 800-171 Rev 2. Third-party assessment required for contracts designated as requiring higher assurance (Phase II — now suspended). For non-high-assurance contracts, self-assessment with annual affirmation suffices. This is the level most AI-relevant contractors would fall into, since AI systems processing CUI trigger the full 800-171 control set.

Level 3 (Expert): NIST SP 800-171 Rev 2 plus enhanced requirements from NIST SP 800-172. Government assessment only — no third-party assessors. Reserved for contractors handling the most sensitive CUI. Approximately 24 additional controls beyond the 800-171 baseline.

AI IMPACT

The three-tier structure creates a compliance cost ladder. A contractor running AI models locally on their own infrastructure must implement all 110 controls at Level 2 — or 134+ at Level 3. A contractor using a FedRAMP-authorized cloud AI service inherits the cloud provider's certification and only needs to cover their own access controls. The framework structurally favors cloud AI over self-hosted AI by making local deployment carry the full compliance burden.

Level 3's government-only assessment is a gatekeeping mechanism. The government decides which contractors qualify for the most sensitive work. If AI systems are involved in processing Level 3 CUI, the government assesses whether your AI deployment meets 800-172 enhanced controls — you don't get to choose your assessor, and there's no appeal structure equivalent to the third-party market.

NIST SP 800-171 Foundation 800-171

CMMC is not an independent standard — it is an enforcement layer on top of NIST SP 800-171 Rev 2. The core security requirements ARE 800-171. CMMC adds the assessment/certification mechanism. Contractors were always required to implement 800-171 under DFARS 252.204-7012; CMMC adds the verification that they actually did.

The 110 controls in 800-171 cover 14 families: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity.

For AI systems processing CUI, the relevant controls span the entire catalog: access control (who can query the model), audit and accountability (logging all AI interactions with CUI), system and communications protection (encrypting CUI in transit to/from AI systems), and media protection (sanitizing storage that held CUI training data).

AI IMPACT

Every 800-171 control applies to AI systems handling CUI. If you train, fine-tune, or run inference on a model using CUI, that model's infrastructure is in scope. Access control means managing who can interact with the model. Audit means logging every prompt and response. Media protection means securely erasing CUI from training datasets. The compliance burden is identical whether you're running a database or an LLM — but AI systems are harder to audit because model weights may encode CUI in opaque ways.

The "CUI in model weights" problem is unresolved. 800-171 requires protection of CUI at rest and in transit. But if CUI is used to fine-tune a model, the information may be embedded in the model's weights — not easily separable, not easily sanitizable. CMMC doesn't address this. Contractors face a choice: don't use CUI in AI training (losing capability), or accept the risk that CUI persists in model artifacts (violating 800-171).

Source: DoD CIO · NIST SP 800-171 Rev 2 · DFARS 252.204-7012
Phase II Suspension — July 2026 Suspension

On July 13, 2026, the Department of War suspended Phase II of CMMC 2.0 implementation. Phase II would have required third-party C3PAO assessments for Level 2 contracts handling higher-assurance CUI. The suspension indefinitely pauses the certification ecosystem that had been building around CMMC — certified assessors (C3PAOs), the Cyber AB marketplace, and contractor preparation investments.

Phase I remains active: contractors must still self-assess against the applicable requirements and submit annual affirmations. The underlying DFARS 252.204-7012 obligation to implement NIST SP 800-171 has not changed. The suspension affects only the verification mechanism, not the substantive security requirements.

The DoW has not provided a timeline for Phase II resumption or indicated whether the program will be restructured. This leaves the defense industrial base in a state of regulatory uncertainty — compliant with 800-171 but without the certification framework that was supposed to validate that compliance.

AI IMPACT — CRITICAL

The suspension creates a window — but the compliance burden remains. Without third-party assessments, contractors don't need to prove 800-171 compliance to a C3PAO. But they still must implement all 110 controls. The practical effect: contractors who were deferring AI adoption until they achieved CMMC certification can now proceed without that gate — but they still carry the underlying 800-171 obligation, and the government can audit at any time.

The compliance burden still pushes contractors toward cloud AI. Even without C3PAO assessments, implementing 800-171 for self-hosted AI infrastructure is expensive and complex. FedRAMP-authorized cloud providers offer inherited compliance — the contractor's scope shrinks to access management rather than full infrastructure security. The suspension of Phase II doesn't change this dynamic; it just removes the certification checkpoint that would have forced the issue.

Regulatory uncertainty favors large cloud providers. When the rules might change, organizations hedge by choosing the safest option — which is a cloud provider with existing authorizations. Small contractors can't justify building compliant local AI infrastructure when CMMC might resume with new requirements. The suspension, paradoxically, accelerates the cloud migration it was supposed to relieve pressure from.

Source: DoD CIO CMMC · business.defense.gov · 32 CFR Part 170
Assessment Ecosystem C3PAO/AB

CMMC 2.0 created a new assessment industry: Certified Third-Party Assessment Organizations (C3PAOs), licensed by the Cyber AB (the accreditation body for CMMC). C3PAOs conduct Level 2 assessments; the Department of War conducts Level 3 assessments directly. Individual Certified CMMC Assessors (CCAs) and Certified CMMC Professionals (CCPs) staff the assessment teams.

The ecosystem was designed to scale: hundreds of C3PAOs and thousands of assessors would be needed to evaluate the estimated 300,000+ companies in the defense industrial base. Training and certification programs were established, and contractors began investing in pre-assessment readiness — gap assessments, control implementation, documentation.

With Phase II suspended, this ecosystem is in limbo. C3PAOs that invested in accreditation have limited assessment demand. The Cyber AB marketplace still exists but with no mandatory assessments to drive volume. The infrastructure remains in place — ready to reactivate if Phase II resumes.

AI IMPACT

The assessment ecosystem is a compliance tax on AI innovation. Every dollar spent on C3PAO assessments, pre-assessment gap analysis, and documentation is a dollar not spent on AI capability. For defense contractors, the compliance overhead directly competes with AI R&D budgets. The suspension temporarily relieves this, but the ecosystem's existence means the tax can be reimposed at any time.

C3PAOs assess the infrastructure, not the AI. Current CMMC assessment methodology evaluates whether 800-171 controls are implemented — not whether AI systems operating within that infrastructure are secure. A contractor could have a perfectly documented 800-171 implementation while running AI models that leak CUI through inference. The assessment framework hasn't caught up to AI-specific risks.

Cloud AI and FedRAMP Nexus FedRAMP

Contractors using cloud services to process CUI must use FedRAMP-authorized cloud providers. CMMC doesn't create a separate cloud certification — it inherits FedRAMP's existing authorization framework. A contractor running AI on AWS GovCloud, Azure Government, or Google Cloud for Government inherits those providers' FedRAMP authorizations for the infrastructure layer.

The contractor remains responsible for controls within the cloud environment: access management, encryption configuration, audit logging, and any AI-specific configurations. But the underlying infrastructure controls (physical security, hypervisor isolation, network segmentation) are inherited from the cloud provider's FedRAMP package.

This inheritance dramatically reduces the compliance scope for cloud-hosted AI versus self-hosted AI. A self-hosted AI deployment requires the contractor to implement all 110 controls across their infrastructure. A cloud-hosted deployment requires the contractor to implement perhaps 40-60 controls, with the rest inherited.

AI IMPACT

The FedRAMP inheritance creates a structural bias toward cloud AI. Self-hosting AI on contractor infrastructure means owning the full 800-171 control set. Using a FedRAMP-authorized cloud AI service means inheriting the provider's controls and owning only the access layer. For most contractors, this isn't a close calculation — cloud AI is the economically rational choice under CMMC, even with Phase II suspended.

FedRAMP-authorized AI services are limited to a few large providers. Only AWS, Azure, Google, and a handful of others have FedRAMP authorizations that cover AI services. Contractors who want to use smaller AI providers, open-source models, or self-hosted solutions face the full compliance burden. CMMC + FedRAMP effectively narrows the AI supplier market for defense contractors to a handful of government-approved cloud platforms.

Source: DoD CIO · FedRAMP.gov · NIST SP 800-171 Rev 2

Related frameworks: NIST SP 800-171 Rev 2 (the control set CMMC enforces) · NIST SP 800-53 (the federal control catalog 800-171 derives from) · FedRAMP (cloud authorization inherited by CMMC contractors) · EO 14409 (directs CISA to deploy AI to critical infrastructure)

Investigation tracks: The Compliance Trap (how certification requirements narrow AI access) · The Infrastructure Play (FedRAMP inheritance as cloud AI leverage) · The Asymmetry (large contractors vs small — compliance cost gap)