← All articles
CMMCNIST 800-171Defense

No CMMC Level 2, No DoD Contract

For the Defense Industrial Base, the self-attestation era is over. CMMC 2.0 turns cybersecurity from something you assert into something an independent assessor verifies — and the consequence of failing is ineligibility, not a fine.

11 Jul 2026·4 min read

Most compliance regimes penalise you after the fact. CMMC is different: it operates as a gate. Without the required certification level, the contract is not available to bid. There is no remediation period, no negotiated settlement. There is simply a bid you cannot submit. That reframing matters for how the programme gets funded internally — this is not a risk-mitigation spend; it is a revenue-access spend.

What Level 2 actually requires

CMMC Level 2 is built on NIST SP 800-171 — 110 security requirements across fourteen families. The requirements themselves are not exotic. What catches organisations out is the evidentiary standard. Under self-attestation, "we have multi-factor authentication" was an assertion. Under third-party assessment, it is a claim that must be demonstrated across every in-scope system, with policy, implementation, and evidence of ongoing operation.

The scoping decision is the single highest-leverage move in a CMMC programme. Get it wrong and you have committed to assessing an estate three times larger than the contract requires.

The two documents that decide the outcome

The System Security Plan describes the boundary and how each of the 110 requirements is met. The Plan of Action and Milestones records what is not yet met, with owners and dates. The common failure is an SSP written as aspiration — documenting the target state, not the current one. A shorter, honest SSP with a credible POA&M consistently outperforms a comprehensive, optimistic one.

The supply-chain effect

CMMC requirements flow down. If you supply a prime that handles CUI, your certification requirement is set by their contract, not yours. Organisations that have never thought of themselves as defence contractors are discovering that a single flow-down clause has made them one. The question is not whether CMMC applies — it is whether you find out from your own assessment or from a customer's.

Ready to build AI systems the world can trust?

Book a complimentary 45-minute AI Governance Readiness Assessment with our Senior Lead Auditor team.

contact@gnaan.ai +91 6282 552 995