What Is CMMC 2.0 and How Is It Different from the Original CMMC Framework?

If your organization works with the U.S. Department of Defense — or is pursuing contracts that require handling federal contract information or controlled unclassified information — CMMC compliance is no longer a future consideration. It’s a present requirement. But for many organizations encountering the framework for the first time, or those who tracked the original version and stepped away during the revision process, the current state of CMMC can feel like a moving target.

This post breaks down what CMMC 2.0 actually is, how it differs from the original framework, and what your organization needs to understand before pursuing certification.

What Is CMMC?

The Cybersecurity Maturity Model Certification (CMMC) is a framework developed by the Department of Defense to verify that defense contractors and subcontractors adequately protect sensitive federal information within their environments. Unlike many compliance frameworks that operate on a self-attestation model, CMMC requires independent verification for most organizations — meaning you can’t simply declare yourself compliant. You have to prove it.

The framework applies to any organization in the Defense Industrial Base (DIB) that handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). That includes prime contractors, subcontractors, and suppliers throughout the DoD supply chain.

What Was Wrong with the Original CMMC?

CMMC 1.0, introduced in 2020, established five maturity levels with 171 practices spanning 17 domains. While the intent was sound, the framework drew significant criticism for its complexity, cost burden on small and mid-sized contractors, and the logistical challenges of standing up a certified third-party assessor ecosystem quickly enough to meet demand.

The DoD responded by going back to the drawing board, releasing CMMC 2.0 in late 2021 and finalizing the rulemaking in late 2024.

How CMMC 2.0 Is Different

The most significant structural change in CMMC 2.0 is the reduction from five maturity levels to three. Understanding those levels is essential for any organization trying to determine where they fall and what’s required of them.

Level 1, called Foundational, applies to organizations that handle FCI but not CUI. It requires compliance with 17 basic cybersecurity practices drawn from FAR 52.204-21, and it is the only level that permits annual self-attestation by a senior company official.

Level 2, called Advanced, applies to organizations that handle CUI. It aligns directly with the 110 security requirements in NIST SP 800-171 and requires a triennial third-party assessment conducted by a CMMC Third Party Assessment Organization (C3PAO) for most organizations — though some may qualify for self-attestation depending on the sensitivity of the programs involved.

Level 3, called Expert, applies to organizations working on the DoD’s highest-priority programs. It builds on NIST SP 800-171 and incorporates a subset of NIST SP 800-172 requirements. Assessments at this level are conducted by the Defense Contract Management Agency (DCMA) rather than a C3PAO.

Another meaningful change in 2.0 is the elimination of the maturity process requirements that existed in the original framework. CMMC 2.0 focuses on practice implementation and evidence — not on demonstrating organizational maturity processes as a separate layer of compliance.

What Hasn’t Changed

The underlying intent of CMMC has not changed. The DoD still expects contractors to protect federal information with verifiable controls, and the consequences of non-compliance — including loss of contract eligibility — remain serious. The NIST SP 800-171 alignment at Level 2 means that organizations already working toward that standard have a meaningful head start, but alignment is not the same as certification readiness.

What Your Organization Should Be Doing Now

If your organization is subject to CMMC requirements, the time to assess your readiness is before a contract requires it. That means understanding your CUI environment, identifying gaps against the applicable NIST controls, remediating those gaps with documented evidence, and — for Level 2 — preparing for a C3PAO assessment.

Steadfast Partners supports defense contractors throughout this process through Steadfast Accelerate. Our CMMC Accelerator Program is designed to move organizations from gap identification through audit-ready preparation efficiently — without overengineering a program that doesn’t fit your size or operational reality.

If you’re unsure where your organization stands against CMMC 2.0 requirements, contact Steadfast Partners at 737-210-5503 to schedule a readiness conversation.

Call Us Today   737-210-5503