CMMC Phase 2 Countdown: Level 2 Audits From November

Elena Vasquez··5 min read
Engineer working in a defense manufacturing facility preparing for CMMC Level 2 assessment

The US defense supply chain is roughly 90 days from its biggest compliance shift in years. On November 10, 2026, Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program begins, and with it the era in which a contractor could attest to its own security posture starts to close. For contracts involving Controlled Unclassified Information (CUI), the Department of Defense may now require Level 2 certification by an authorized third-party assessment organization (C3PAO) instead of a self-assessment, as outlined in industry guidance on Phase 2.

For tens of thousands of small and mid-size suppliers, machine shops, software vendors, logistics firms and the MSPs that support them, this is the moment the paperwork exercise becomes an audit.

What Changes on November 10, 2026

Phase 2 does not flip a switch across the entire defense industrial base overnight. It applies contract by contract: as new solicitations and options include the Phase 2 requirement, affected contractors must hold a valid Level 2 certification from a C3PAO to be eligible. There is no blanket audit of the supply chain, but there is also no way to predict exactly when your next contract action will carry the clause. Once it does, certification is a gate, not a goal.

The practical consequence is that readiness timing is driven by your contracting pipeline, not by the calendar alone. A supplier whose key recompete lands in early 2027 effectively has a 2026 deadline, because assessments take months to schedule and complete. Prime contractors have already internalized this: Lockheed Martin, Boeing and Northrop Grumman are demanding compliance documentation from suppliers ahead of contractual requirements, pushing the deadline down the chain faster than the regulation itself.

80,000 Companies, About 80 Assessors

The arithmetic of Phase 2 is the story. DoD estimates that roughly 80,000 defense-industrial-base companies will need Level 2 certification through a C3PAO, while only about 80 authorized C3PAOs exist to perform those assessments, a capacity crunch documented in industry analyses. Even under optimistic throughput assumptions, demand exceeds supply by orders of magnitude, and assessment calendars are already booking out.

Waiting has two costs. First, the queue itself: companies that start scheduling in 2027 may find the earliest available assessment slots pushed well beyond their contract needs. Second, the remediation gap: organizations that begin readiness work late discover deficiencies with no runway left to fix them. An assessment you fail still consumes your slot, your budget and your credibility with primes.

In a market with 80,000 buyers and about 80 sellers, the scarce resource is not compliance knowledge. It is a confirmed date on an assessor calendar, backed by evidence that will hold up when they arrive.

Awareness and Training Is Assessed Evidence

Level 2 assesses the 110 security requirements of NIST SP 800-171 Revision 2, and that includes the Awareness and Training family, documented in the DoD CIO CMMC documentation. Three requirements sit squarely in scope:

  • 3.2.1: ensure that managers, systems administrators and users are made aware of the security risks associated with their activities and the applicable policies, standards and procedures.
  • 3.2.2: ensure personnel are trained to carry out their assigned information-security duties and responsibilities, which means role-based training, not one generic module for everyone.
  • 3.2.3: provide security awareness training on recognizing and reporting potential indicators of insider threat.

Under self-assessment, many organizations satisfied themselves with a policy document and good intentions. A C3PAO assessor works differently: they ask for objective evidence. Who was trained, on what content, on what date, and how do you know it covered insider-threat indicators? A security awareness training program with per-user completion records, dated content and role-based assignments turns those questions into a report export. Adding phishing simulation results strengthens the file further, because it demonstrates the training is exercised, not just delivered. Assessors distinguish quickly between programs that exist on paper and programs that leave a data trail.

There is a wider pattern here worth noting: the same evidence-grade training records are increasingly demanded by cyber insurers, as we covered in our look at 2026 cyber insurance requirements. Building the record-keeping habit once serves multiple audiences.

Stay on Rev 2: Do Not Implement Rev 3 Early

A counterintuitive trap is catching diligent teams. NIST published SP 800-171 Revision 3, and forward-leaning security staff are tempted to implement it now. For CMMC purposes, that can backfire: the program remains codified on Revision 2, and implementing Rev 3 controls in ways that diverge from the assessed Rev 2 baseline can actually cause findings in an assessment. Coverage at Federal News Network puts the Rev 3 transition no earlier than 2027-2028.

The right posture is to prepare, not to jump: track the delta between revisions, plan the migration, but assess and certify against Rev 2 as written. Configuration and documentation should tell one consistent story on the day the C3PAO arrives.

What This Means for Your Organization

Ninety days is not much runway, but it is enough to act deliberately. If you handle CUI anywhere in the defense supply chain:

  • Map your contract exposure. Identify which current and upcoming contracts involve CUI and when they are likely to carry a Level 2 certification requirement.
  • Book the assessment path now. Contact C3PAOs early; the capacity crunch means calendars, not budgets, are the binding constraint.
  • Run a gap assessment against 800-171 Rev 2, and resist the urge to build to Rev 3 before the program adopts it.
  • Make training assessable. Stand up role-based awareness and insider-threat training with per-user, dated completion records; make sure 3.2.1, 3.2.2 and 3.2.3 each map to concrete evidence.
  • Answer your primes proactively. Suppliers who show up with documentation before Lockheed, Boeing or Northrop ask for it stay on the preferred list.

Phase 2 rewards the organizations that treated the long CMMC rollout as preparation time. For everyone else, November 10 is when the deferred work starts pricing itself into lost contracts.

Share: