01

How do I know if my organization needs CMMC Level 2 certification?

The short answer: it depends on the type of government information you handle, and what your contract says. Those two things, in that order.

One note before we start, because it is the question we are hearing most. The Department paused part of the CMMC rollout in July 2026 for a review, which has left a lot of organizations unsure whether any of this still applies to them. It does. Your obligations under your contract have not gone away, and the requirements below are the ones you will be measured against whenever your assessment happens.

Start with the data, not the certification

CMMC levels exist to protect different kinds of information, so the first question is not which level you want. It is what the government has actually entrusted you with.

Federal Contract Information, or FCI, is information provided by or generated for the government under a contract that is not intended for public release. Organizations that handle FCI but not CUI generally fall under Level 1, which covers 15 basic requirements.

Controlled Unclassified Information, or CUI, is information the government owns or creates that requires safeguarding under law, regulation, or government-wide policy. If you store, process, or transmit CUI, you are in Level 2 territory, assessed against the 110 requirements of NIST SP 800-171.

Then read your contract, because it decides

Your contract is the authority, not your best guess. A few places to look:

  • DFARS 252.204-7012. If this clause is in your contract, the government expects CUI to be involved and expects you to protect it.
  • Any CMMC requirement clause specifying a level and whether a self-assessment or a certification assessment applies.
  • Flow-down language from your prime. Subcontractors inherit requirements, and many organizations discover their obligations through a prime rather than directly from the government.

Two assumptions that get organizations in trouble

The first is assuming you do not handle CUI because nothing arrived with a marking on it. Marking practices are inconsistent across the Defense Industrial Base. Technical drawings, specifications, and data packages are frequently CUI whether or not anyone labeled them that way. If you are unsure what you have received, ask the contracting officer or your prime rather than assuming.

The second is assuming you are too small or too far down the supply chain to be in scope. Requirements flow down. A three-person shop machining a part from a controlled drawing is handling CUI.

Level 2 does not always mean the same thing

Within Level 2 there is a distinction that matters commercially. Some contracts are satisfied by a self-assessment. Others call for a certification assessment conducted by an authorized third party. Which one applies to you is determined by your contract, not by your preference, and it changes both your timeline and your cost.

Where the program stands right now, and what it means for you

The CMMC program is being implemented in phases. In July 2026 the Department paused the phase that would have introduced third-party assessment requirements, pending a review of the program. Self-assessment obligations remain in effect, and DFARS 252.204-7012 continues to apply.

Three things follow from that, and they matter more than the pause itself.

Your underlying obligations did not change. The requirement to protect CUI comes from your contract, not from the assessment schedule. An organization that is not meeting NIST SP 800-171 today is not compliant today, regardless of when anyone comes to check.

The determination of what you need has not changed either. Whether you handle CUI, and what your contract requires, are questions with the same answers this month as last month.

And the capacity problem is still coming. There are roughly a hundred authorized assessment organizations serving a market of tens of thousands of companies. Organizations already report waits measured in months. When third-party assessments resume, the constraint will not be your readiness, it will be whether anyone is available to assess you.

Which is why we tell people the same thing we would have told them in June: use this time. An organization that arrives at the front of the queue ready is in a very different position from one that starts preparing when the queue forms.

If you are still not sure

Most organizations that call us are not sure, and that is a normal place to start. A short conversation about what data you receive and what your contract says will usually settle it in under an hour.

Book an intro call and we will tell you what your contract actually requires.