R
RampReady
← Blog/CMMC

What Is a CMMC Level 2 Assessment? A Practitioner's Guide

A complete breakdown of CMMC Level 2 assessments — who conducts them, what they evaluate, how scoring works, and what the July 2026 Phase II suspension means for contractors. Written for practitioners, not policy readers.

⚠️ July 2026 Update: CMMC Phase II Suspended

On July 13, 2026, the Department of War (DoW) announced the immediate suspension of CMMC Phase II requirements, which had been scheduled to take effect on November 10, 2026. DoW CIO Kirsten Davies signed the memo citing prohibitive compliance costs and the assessor capacity gap — more than 100,000 DIB companies needing assessments against roughly 100 authorized C3PAOs.

What is suspended:

  • CMMC Level 2 C3PAO third-party assessments — no longer required as a contract condition until further notice
  • CMMC Level 3 DIBCAC assessments — also suspended
  • Future CMMC implementation milestones — frozen pending review
  • Active solicitations and contracts already containing Level 2 C3PAO or Level 3 requirements must be amended to remove those requirements

What remains fully in force:

  • DFARS 252.204-7012 — safeguarding obligations and 72-hour incident reporting
  • CMMC Phase I — CMMC Level 1 (Self) and Level 2 (Self) self-assessment requirements that took effect November 10, 2025
  • SPRS scores — contractors must still maintain and report NIST SP 800-171 self-assessment scores
  • 32 CFR Part 170 — the CMMC rule itself has not been repealed or amended; this is a policy pause, not a regulatory change

A CMMC Reform Task Force has been established and will report within 60 days. A public RFI is open through August 14, 2026 — contractors, especially small and mid-size businesses, should submit feedback on compliance burdens. DoW officials declined to rule out deeper restructuring or even cancellation of the program after the review.

What this means for contractors right now: NIST SP 800-171 compliance remains the contractual baseline regardless of what happens to CMMC. The self-assessment obligation and SPRS score requirement are unchanged. Contractors who have been building toward CMMC Level 2 should maintain their compliance posture — the underlying security requirements are not going away even if the certification mechanism changes.

The most important thing contractors can do during this pause is conduct or update their NIST SP 800-171 self-assessment to know exactly where they stand. The NIST SP 800-171 Self-Assessment Field Manual covers the complete OSA methodology — how to plan, conduct, score, document, and defend your self-assessment.


What Is CMMC Level 2?

CMMC Level 2 is the certification tier that applies to most defense contractors handling Controlled Unclassified Information (CUI). It maps directly to the 110 security practices in NIST SP 800-171 Revision 2, organized across 14 domains, and is codified in 32 CFR Part 170 — the final CMMC rule that took effect in December 2024.

If your organization receives, processes, stores, or transmits CUI in the performance of a DoD contract, and that contract contains DFARS clause 252.204-7021, you are subject to CMMC Level 2.

Under the current suspension, CMMC Level 2 self-assessment (Level 2 Self) remains required — meaning you must assess your own compliance against the 110 practices, document it, and report your SPRS score. What is suspended is the third-party C3PAO certification (Level 2 C3PAO) that was going to be required starting November 2026.

Who Conducts a C3PAO Assessment?

When Phase II was active — and may again be required after the reform review — CMMC Level 2 C3PAO assessments are conducted by a C3PAO (CMMC Third-Party Assessment Organization) certified by the Cyber AB. Your assessment team consists of Certified CMMC Assessors (CCAs) trained and certified to evaluate organizations against the CMMC assessment guide.

This is the critical distinction that the Phase II suspension affects: the self-assessment (which drives your SPRS score) is conducted by you. The C3PAO certification assessment is conducted by an independent third party. The former is still required; the latter is currently suspended.

What Does the Assessment Cover?

Whether self-assessed or C3PAO-assessed, the evaluation covers all 110 practices in NIST SP 800-171 Rev. 2, using the CMMC Assessment Guide Level 2 (CAG v2.13) as the standard. The CAG defines assessment objectives — specific outcomes to verify for each practice — along with the methods (Examine, Interview, Test) used to gather evidence.

The 14 domains covered are:

  • AC — Access Control (22 practices)
  • AT — Awareness and Training (3 practices)
  • AU — Audit and Accountability (9 practices)
  • CA — Security Assessment (4 practices)
  • CM — Configuration Management (9 practices)
  • IA — Identification and Authentication (11 practices)
  • IR — Incident Response (3 practices)
  • MA — Maintenance (6 practices)
  • MP — Media Protection (9 practices)
  • PE — Physical Protection (6 practices)
  • PS — Personnel Security (2 practices)
  • RA — Risk Assessment (3 practices)
  • SC — System and Communications Protection (16 practices)
  • SI — System and Information Integrity (7 practices)

How Does Scoring Work?

Each of the 110 practices is assessed as either MET or NOT MET. There is no partial credit at the practice level. A practice is MET only when all associated assessment objectives are satisfied.

For SPRS self-assessment scoring, the DoD scoring methodology assigns a starting value of 110 and deducts points for each unmet practice based on severity weighting. Your SPRS score is reported to the Supplier Performance Risk System and is visible to contracting officers.

For C3PAO certification (when applicable), achieving CMMC Level 2 certification requires all 110 practices scored as MET, with limited POA&M allowances under specific conditions defined in 32 CFR Part 170.

The Self-Assessment Obligation Right Now

During the Phase II suspension, the self-assessment obligation is the operative compliance requirement for most contractors. Under CMMC Phase I (in effect since November 2025):

  • Contractors must conduct a NIST SP 800-171 self-assessment
  • Results must be entered into SPRS
  • A senior company official must affirm the accuracy of the score
  • Annual affirmations are required

Conducting a rigorous, well-documented self-assessment is not just a compliance checkbox — it is your defensible record of where you stand and what you are working to fix. Regulators, contracting officers, and eventually C3PAOs (if the program resumes) will look at your assessment documentation.

The NIST SP 800-171 Self-Assessment Field Manual covers the complete process: planning the assessment, applying the OSA methodology practice by practice, calculating your SPRS score correctly, documenting findings, building your POA&M, and defending your score to contracting officers and auditors.

System Boundary and Scoping

Before any assessment begins, you must define the scope — specifically, what assets are in the assessment boundary. Your System Security Plan (SSP) defines this boundary, identifying which assets are in-scope for CMMC.

CUI scope is determined by following the CMMC scoping guidance:

  • Assets that process, store, or transmit CUI are CUI Assets — always in scope
  • Assets that provide security protection to CUI Assets are Security Protection Assets — always in scope
  • Assets that do not interact with CUI or security systems may be Out of Scope if properly isolated

Poor scoping is one of the most common self-assessment and C3PAO assessment failures. Getting scoping right is foundational to everything else.

Preparing While the Program Is Under Review

The Phase II suspension does not mean contractors should stand down on CMMC preparation. The Reform Task Force may recommend changes to the assessment model — potentially simplifying requirements for small businesses — but the underlying NIST SP 800-171 security requirements are not going away.

Contractors who use this period wisely will:

  1. Conduct or update their self-assessment using the formal OSA methodology and document findings properly in SPRS
  2. Build or update their SSP — the primary documentation artifact that any assessment, self or third-party, will reference
  3. Work their POA&M — closing gaps identified in the self-assessment positions you well regardless of what the reform produces
  4. Monitor the RFI and 60-day review — the Reform Task Force report (due mid-September 2026) will indicate the program's direction
  5. Engage the RFI if you have feedback on compliance burdens; the August 14, 2026 deadline is the rare opportunity for contractor input to directly shape policy

What to Watch For

Three developments will determine what comes next:

The 60-day Reform Task Force report — Due approximately mid-September 2026. This will indicate whether CMMC is restructured, simplified, or fundamentally changed. Watch for changes to the assessment model, particularly for small businesses.

A class deviation, DFARS rule, or amendment to 32 CFR Part 170 — The July 13 memo changes policy discretion, not the underlying regulation. A formal regulatory change would be a significantly more durable development. Until then, the CMMC rule is still on the books.

The FAR CUI rule — The June 2026 FAR Overhaul rulemaking folded CUI requirements into the civilian acquisition framework. Mixed defense and civilian contractors get no reprieve from the CMMC Phase II pause on their civilian contracts — the CUI safeguarding obligation exists independently of CMMC.


The RampReady CMMC catalog covers every angle of CMMC compliance — from the CMMC Level 2 Assessment Field Guide (C3PAO Edition) for assessors, to the NIST SP 800-171 Self-Assessment Field Manual for contractors conducting their own assessments under the current Phase I requirements.

← Back to all posts