No CMMC Level 2, No DoD Contract
For the Defense Industrial Base, the self-attestation era is over. CMMC 2.0 turns cybersecurity from something you assert into something an independent assessor verifies — and the consequence of failing is ineligibility, not a fine.
Most compliance regimes penalise you after the fact. CMMC is different: it operates as a gate. Without the required certification level, the contract is not available to bid. There is no remediation period, no negotiated settlement. There is simply a bid you cannot submit. That reframing matters for how the programme gets funded internally — this is not a risk-mitigation spend; it is a revenue-access spend.
What Level 2 actually requires
CMMC Level 2 is built on NIST SP 800-171 — 110 security requirements across fourteen families. The requirements themselves are not exotic. What catches organisations out is the evidentiary standard. Under self-attestation, "we have multi-factor authentication" was an assertion. Under third-party assessment, it is a claim that must be demonstrated across every in-scope system, with policy, implementation, and evidence of ongoing operation.
The two documents that decide the outcome
The System Security Plan describes the boundary and how each of the 110 requirements is met. The Plan of Action and Milestones records what is not yet met, with owners and dates. The common failure is an SSP written as aspiration — documenting the target state, not the current one. A shorter, honest SSP with a credible POA&M consistently outperforms a comprehensive, optimistic one.
The supply-chain effect
CMMC requirements flow down. If you supply a prime that handles CUI, your certification requirement is set by their contract, not yours. Organisations that have never thought of themselves as defence contractors are discovering that a single flow-down clause has made them one. The question is not whether CMMC applies — it is whether you find out from your own assessment or from a customer's.