xmodoxmodo

Frameworks · Americas

CMMC 2.0

The Cybersecurity Maturity Model Certification (CMMC) 2.0 is the US Department of Defense programme for verifying that contractors protect federal contract information and Controlled Unclassified Information. The DFARS final rule took effect on 10 November 2025, with phased implementation. Level 1 covers 15 requirements aligned with FAR 52.204-21 and is self-assessed annually. Level 2 covers the 110 requirements of NIST SP 800-171 Revision 2, and is self-assessed or certified by a C3PAO depending on the contract. Level 3 adds 24 requirements from NIST SP 800-172.

Who it applies to

It applies to defence contractors and subcontractors that handle federal contract information or Controlled Unclassified Information. The contract sets the required level.

Main requirements

Level 1

Level 1 has 15 basic safeguarding requirements, with an annual self-assessment and affirmation.

Level 2

Level 2 has the 110 requirements of NIST SP 800-171 Rev. 2. It is self-assessed or C3PAO-certified on a three-year cycle, as the contract specifies.

Level 3

Level 3 adds 24 requirements from NIST SP 800-172 to Level 2, and the Department carries out the assessment.

Phasing

Self-assessments apply from 10 November 2025. Contracts require C3PAO Level 2 certifications from Phase 2, which begins on 10 November 2026.

How xmodo supports it

  • 1

    Each level is a scope over the NIST SP 800-171 pack, so moving from Level 1 to Level 2 adds requirements to the same programme.

  • 2

    xmodo generates the system security plan, plan of action and affirmation evidence from the status of your controls, for the self-assessment or the C3PAO.

  • 3

    Assessors get portal access limited to the relevant evidence. The rule's phased dates are stored as structured fields and checked against the rule.

Related frameworks

CMMC 2.0 shares requirements with the frameworks below. Controls you already run for any of them count towards CMMC 2.0 as well.

Frequently asked questions

Does CMMC use NIST SP 800-171 Revision 3?

No. The CMMC rule ties Level 2 to the 110 requirements of Revision 2. xmodo keeps Revision 2 as the CMMC edition, with Revision 3 beside it for customers who cite the current publication.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo