Starting November 10, 2026, DoD contracts above $10 million require a C3PAO-certified assessment for CMMC Level 2. Companies scoring below 80 on the SPRS assessment faceFalse Claims Act liability. The window to self-certify is closing. This guide covers all 110 NIST SP 800-171 Rev 2 controls, the Phase 2 rule mechanics, and the 90-day roadmap to compliance.
DoD's CMMC Phase 2 marks the full activation of the Cybersecurity Maturity Model Certification program. Unlike Phase 1 (Oct 2023–Oct 2026), where CMMC requirements appeared in contracts but assessments were not contract-gated, Phase 2 makes certification a binding contract requirement.
| Date | Milestone | What It Means for Contractors |
|---|---|---|
| Oct 1, 2023 | Phase 1 begins | CMMC requirements appear in RFIs and RFPs. Self-assessment permitted. No contract-gating. |
| Nov 10, 2026 | Phase 2 begins — contract-gating active | Contracts above $10M require C3PAO assessment or approved POA&M. Self-assessment no longer sufficient for Level 2. |
| Nov 10, 2027 | Phase 2 full enforcement | All DoD contracts flowing down DFARS 252.204-7012 will gate CMMC Level 2 certification at award. |
| Ongoing | DIBCAC random audits | Defense Contract Audit Agency conducts random supplier audits. Failed DIBCAC = contract termination risk + FCA liability. |
A C3PAO (Certified Third-Party Assessor Organization) conducts the official CMMC Level 2 assessment. The assessor reviews all 110 NIST SP 800-171 controls and issues a certified score. A company with a POA&M (Plan of Action and Milestones) may receive conditional certification, but only if the POA&M is approved by the contracting officer and all mandatory controls are in place.
Self-attestation is dead for Level 2 on contracts above $10M. DFARS 252.204-7012 still requires self-assessment results posted to SPRS, but the Phase 2 rule mandates C3PAO certification for Level 2 award eligibility.
A Plan of Action and Milestones shows where your security program has gaps. Under Phase 2 conditional status rules:
Mandatory controls (no POA&M exception): AC.1.001, AC.2.016, AC.3.020, IA.1.077, IR.2.093, IR.3.098, RM.2.143, RM.3.144
All other controls may be covered by an approved POA&M if the contracting officer agrees. However, a POA&M that is not kept current or not adequately resourced will fail a DIBCAC audit. CoreRecon Fortress and Command clients receive continuous POA&M tracking as part of their compliance program.
Each domain below maps to NIST SP 800-171 Rev 2. The common DIBCAC failure modes listed are the gaps that sank Texas defense subcontractors in prior assessments. Use this to prioritize remediation before your C3PAO assessment.
Reference: NIST SP 800-171 Rev 2 — 110 security requirements across 14 domains. CMMC Level 2 requires assessment against all 110. The 14 CMMC domains (AC, AT, AU, CM, IA, IR, MA, MP, PS, PE, RA, CA, SC, SI) are the organizing structure for all requirements.
Starting from zero? Three months to a C3PAO-ready posture. CoreRecon Command clients get this roadmap delivered as a co-managed engagement — you own the business decisions, we own the technical execution.
The Supplier Performance Risk System (SPRS) is DoD's central database for contractor cybersecurity self-assessments. Every company doing work under DFARS 252.204-7012 must submit a SPRS score before contract award — and primes are increasingly checking it before awarding subcontracts.
| SPRS Score Range | Risk Level | What It Means for Contract Awards |
|---|---|---|
| Below 0 | Critical | Major gaps across all domains. Primes will not award. DoD contract eligibility at risk. |
| 0 – 49 | High | Significant gaps. POA&M required. CMMC Level 2 certification unlikely without remediation. |
| 50 – 79 | Medium | Partial compliance. C3PAO assessment will reveal gaps. Most Texas DIB subs score here. |
| 80 – 110 | Low / Compliant | Target score. Eligible for CMMC Level 2 certification. C3PAO assessment can proceed. |
Based on DIBCAC audit findings across Texas defense subcontractors:
1. Flat network architecture — No CUI isolation. All systems on same VLAN. Easy DIBCAC finding.
2. MFA gaps on privileged accounts — Service accounts, admin accounts, and remote access paths without MFA. Score killers.
3. Log retention under 1 year — Many companies have SIEM but only retain 30-90 days. NIST 800-171 requires 1 year minimum.
4. SSP not updated in 12 months — CoreRecon Fortress and Command clients receive quarterly SSP reviews as part of their tier.
5. Personnel Security — same-day access revocation skipped — Departing employees often retain access 24-48 hours longer than policy allows.
The False Claims Act (31 U.S.C. § 3729) creates major liability for contractors who misrepresent their cybersecurity posture. If you self-certify a SPRS score of 80+ but a DIBCAC audit finds critical gaps, DoD can pursue:
Civil penalties: Up to $13,946 per false claim (inflation-adjusted), plus three times the damages suffered by the government.
Termination for cause: Contract termination + barred from future DoD awards.
Qui tam (whistleblower) exposure: Employees who report cybersecurity misrepresentation can file qui tam actions on behalf of the government.
The bottom line: self-assess honestly, maintain your POA&M, and work with a MSSP that gives you documented evidence for every control claim.
Texas has over 1,800 defense subcontractors across the Dallas-Fort Worth Metroplex, Houston Energy Corridor, and San Antonio-Austin corridor. CMMC Level 2 enforcement directly impacts these companies and their supply chain.