Implementation Guide  •  Defense Contractors  •  CMMC Level 2

CMMC L2 Phase 2 Is Live Nov 2026.
Self-Attestation Is Dead.

Starting November 10, 2026, DoD contracts above $10 million require a C3PAO-certified assessment for CMMC Level 2. Companies scoring below 80 on the SPRS assessment faceFalse Claims Act liability. The window to self-certify is closing. This guide covers all 110 NIST SP 800-171 Rev 2 controls, the Phase 2 rule mechanics, and the 90-day roadmap to compliance.

CoreRecon Intelligence  |  June 11, 2026  |  CMMC Level 2 / NIST SP 800-171 Rev 2

What Changed in November 2026

DoD's CMMC Phase 2 marks the full activation of the Cybersecurity Maturity Model Certification program. Unlike Phase 1 (Oct 2023–Oct 2026), where CMMC requirements appeared in contracts but assessments were not contract-gated, Phase 2 makes certification a binding contract requirement.

Date Milestone What It Means for Contractors
Oct 1, 2023 Phase 1 begins CMMC requirements appear in RFIs and RFPs. Self-assessment permitted. No contract-gating.
Nov 10, 2026 Phase 2 begins — contract-gating active Contracts above $10M require C3PAO assessment or approved POA&M. Self-assessment no longer sufficient for Level 2.
Nov 10, 2027 Phase 2 full enforcement All DoD contracts flowing down DFARS 252.204-7012 will gate CMMC Level 2 certification at award.
Ongoing DIBCAC random audits Defense Contract Audit Agency conducts random supplier audits. Failed DIBCAC = contract termination risk + FCA liability.
C3PAO Assessment vs. Self-Attestation

A C3PAO (Certified Third-Party Assessor Organization) conducts the official CMMC Level 2 assessment. The assessor reviews all 110 NIST SP 800-171 controls and issues a certified score. A company with a POA&M (Plan of Action and Milestones) may receive conditional certification, but only if the POA&M is approved by the contracting officer and all mandatory controls are in place.

Self-attestation is dead for Level 2 on contracts above $10M. DFARS 252.204-7012 still requires self-assessment results posted to SPRS, but the Phase 2 rule mandates C3PAO certification for Level 2 award eligibility.

POA&M Conditional Status — What Assessors Check

A Plan of Action and Milestones shows where your security program has gaps. Under Phase 2 conditional status rules:

Mandatory controls (no POA&M exception): AC.1.001, AC.2.016, AC.3.020, IA.1.077, IR.2.093, IR.3.098, RM.2.143, RM.3.144

All other controls may be covered by an approved POA&M if the contracting officer agrees. However, a POA&M that is not kept current or not adequately resourced will fail a DIBCAC audit. CoreRecon Fortress and Command clients receive continuous POA&M tracking as part of their compliance program.

All 110 NIST 800-171 Controls Across 14 CMMC Domains

Each domain below maps to NIST SP 800-171 Rev 2. The common DIBCAC failure modes listed are the gaps that sank Texas defense subcontractors in prior assessments. Use this to prioritize remediation before your C3PAO assessment.

Domain 1
22 controls
Access Control
AC
Common DIBCAC Failure Mode
MFA not enforced on all CUI-accessible accounts; flat network with no CUI segmentation; overly broad remote access permissions
Domain 2
3 controls
Awareness & Training
AT
Common DIBCAC Failure Mode
No documented role-based training completion records; insider threat awareness not updated annually
Domain 3
9 controls
Audit & Accountability
AU
Common DIBCAC Failure Mode
Logs not retained 1+ year; insufficient log review cadence; user account reviews not performed quarterly
Domain 4
9 controls
Configuration Management
CM
Common DIBCAC Failure Mode
Baseline configurations not documented; change control not enforced; unauthorized software on CUI systems
Domain 5
11 controls
Identification & Authentication
IA
Common DIBCAC Failure Mode
Shared/service accounts without MFA; PIV/CAC enforcement gaps; password complexity not enforced
Domain 6
3 controls
Incident Response
IR
Common DIBCAC Failure Mode
IR plan not tested in 12 months; evidence of 72-hour reporting drill not documented; tabletop exercise not conducted
Domain 7
6 controls
Maintenance
MA
Common DIBCAC Failure Mode
Off-site maintenance without sanitizing CUI from media; maintenance tool malware checks not logged
Domain 8
9 controls
Media Protection
MP
Common DIBCAC Failure Mode
CUI on unencrypted USB/removable media; FIPS-validated encryption not applied; media sanitization logs missing
Domain 9
2 controls
Personnel Security
PS
Common DIBCAC Failure Mode
Departing employee access not revoked within same business day; NDAs not updated for new contract CUI
Domain 10
6 controls
Physical Protection
PE
Common DIBCAC Failure Mode
Laptop left in vehicle; badge sharing; visitor logs not retained 1+ year
Domain 11
3 controls
Risk Assessment
RA
Common DIBCAC Failure Mode
Supply chain risk assessment not documented; threat landscape not updated; risk register not reviewed annually
Domain 12
4 controls
Security Assessment
CA
Common DIBCAC Failure Mode
SSP not reviewed/updated in 12 months; penetration test not conducted; POA&M not kept current
Domain 13
16 controls
System & Communications Protection
SC
Common DIBCAC Failure Mode
Flat network with no boundary enforcement; split tunneling not blocked; FIPS-validated crypto gaps; VPN bypass paths unmitigated
Domain 14
7 controls
System & Information Integrity
SI
Common DIBCAC Failure Mode
Malicious code protection gaps; scan/update not performed; flaw remediation not current; spam/malware filters weak

Reference: NIST SP 800-171 Rev 2 — 110 security requirements across 14 domains. CMMC Level 2 requires assessment against all 110. The 14 CMMC domains (AC, AT, AU, CM, IA, IR, MA, MP, PS, PE, RA, CA, SC, SI) are the organizing structure for all requirements.

90-Day CMMC L2 Implementation Roadmap

Starting from zero? Three months to a C3PAO-ready posture. CoreRecon Command clients get this roadmap delivered as a co-managed engagement — you own the business decisions, we own the technical execution.

Month 1
Foundation & Gap Analysis
Run SPRS self-assessment — score every one of the 110 controls; identify score gap to 80+
Identify CUI data flows — where is Controlled Unclassified Information stored, processed, transmitted?
Document System Security Plan (SSP) — map controls to current architecture; identify gaps against NIST 800-171 Rev 2
Establish identity management — enforce MFA on all CUI-accessible accounts; disable inactive accounts
Begin media inventory — identify all systems and removable media that touch CUI

CoreRecon Role
SPRS scorecard review, CUI data flow mapping workshop, gap analysis against all 14 domains. Deliver initial POA&M with resourcing estimate.

Client Role
Provide system inventory, identify contract scope (DFARS 252.204-7012 applicability), assign a security champion to own documentation.
Month 2
Technical Control Implementation
Implement boundary protection — segment CUI network from corporate; enforce VPN + FIPS 140-2 validated crypto
Configure audit logging — enable centralized log collection, 1-year retention, quarterly account reviews
Activate endpoint detection — deploy EDR on all CUI-accessible endpoints; configure malicious code protection
Encrypt all CUI media — apply FIPS-validated encryption to all removable media; implement media sanitization procedures
Conduct incident response tabletop — document 72-hour reporting procedure; test IR plan with current team

CoreRecon Role
Architect CUI network segmentation, deploy Sentinel/Fortress EDR and log collection, configure FIPS-validated encryption controls. Conduct IR tabletop as a facilitated exercise.

Client Role
Provide network diagrams and system access for engineering. Identify all sub-contractors who touch CUI data. Begin personnel security screening for employees with CUI access.
Month 3
Assessment Readiness & POA&M Closeout
Update SSP and POA&M — document all implemented controls; close out or document all remaining gaps
Run internal penetration test — validate that boundary controls, access controls, and logging meet CMMC L2 requirements
Complete role-based security training — document all training completions; update insider threat awareness records
Finalize SPRS score — confirm score of 80+ or documented POA&M for all non-mandatory gaps; submit to SPRS
Select C3PAO and schedule assessment — engage a certified assessor; confirm contracting officer acceptance of POA&M if applicable

CoreRecon Role
Execute internal pen test, produce evidence packages for all 14 domains, finalize POA&M with remediation timelines, prepare client for C3PAO interview process.

Client Role
Review and approve final SSP. Confirm budget for C3PAO assessment ($40K–$80K typically). Designate Point of Contact for assessment day. Update procurement records to reflect CMMC Level 2 certification status.

SPRS Score Mechanics

The Supplier Performance Risk System (SPRS) is DoD's central database for contractor cybersecurity self-assessments. Every company doing work under DFARS 252.204-7012 must submit a SPRS score before contract award — and primes are increasingly checking it before awarding subcontracts.

SPRS Score Range Risk Level What It Means for Contract Awards
Below 0 Critical Major gaps across all domains. Primes will not award. DoD contract eligibility at risk.
0 – 49 High Significant gaps. POA&M required. CMMC Level 2 certification unlikely without remediation.
50 – 79 Medium Partial compliance. C3PAO assessment will reveal gaps. Most Texas DIB subs score here.
80 – 110 Low / Compliant Target score. Eligible for CMMC Level 2 certification. C3PAO assessment can proceed.
Common SPRS Gaps That Sink Texas Defense Subs

Based on DIBCAC audit findings across Texas defense subcontractors:

1. Flat network architecture — No CUI isolation. All systems on same VLAN. Easy DIBCAC finding.

2. MFA gaps on privileged accounts — Service accounts, admin accounts, and remote access paths without MFA. Score killers.

3. Log retention under 1 year — Many companies have SIEM but only retain 30-90 days. NIST 800-171 requires 1 year minimum.

4. SSP not updated in 12 months — CoreRecon Fortress and Command clients receive quarterly SSP reviews as part of their tier.

5. Personnel Security — same-day access revocation skipped — Departing employees often retain access 24-48 hours longer than policy allows.

False Claims Act Liability

The False Claims Act (31 U.S.C. § 3729) creates major liability for contractors who misrepresent their cybersecurity posture. If you self-certify a SPRS score of 80+ but a DIBCAC audit finds critical gaps, DoD can pursue:

Civil penalties: Up to $13,946 per false claim (inflation-adjusted), plus three times the damages suffered by the government.

Termination for cause: Contract termination + barred from future DoD awards.

Qui tam (whistleblower) exposure: Employees who report cybersecurity misrepresentation can file qui tam actions on behalf of the government.

The bottom line: self-assess honestly, maintain your POA&M, and work with a MSSP that gives you documented evidence for every control claim.

Texas Defense Contractor Landscape

Texas has over 1,800 defense subcontractors across the Dallas-Fort Worth Metroplex, Houston Energy Corridor, and San Antonio-Austin corridor. CMMC Level 2 enforcement directly impacts these companies and their supply chain.

InterConnect Wiring
Fort Worth, TX • FPD-S2
F-35 avionics wiring harness sub-tier supplier. DFARS 252.204-7012 flow-down from Lockheed Martin Fort Worth. SPRS score visibility required for sub-prime award.
Lockheed Martin Fort Worth
Fort Worth, TX • DFW Metroplex
F-35 main assembly. CMMC Level 2 certified prime. Flowing down CMMC requirements to all sub-tier suppliers. SPRS checks on all new subcontract awards.
L3Harris Technologies
London, TX • DFW Metroplex
Communication systems for DoD. Multi-flow-down of CMMC Level 2 requirements. CJIS and ITAR add additional compliance complexity for Texas sub-tier suppliers.
BAE Systems Austin
Austin, TX • Austin/San Antonio Corridor
Precision-guided munitions and defense electronics. DoD contractor with active CMMC Level 2 certification. Actively recruiting SDVOSB sub-tier suppliers who can meet compliance.
SDVOSB Advantage for Texas Sub-Tier Suppliers
Service-Disabled Veteran-Owned Small Businesses receive preferential scoring on DoD subcontract awards under the VETS Smart program. CoreRecon is a Texas-based SDVOSB — we have navigated the CMMC Level 2 certification process ourselves. For sub-tier defense suppliers who are SDVOSB or working with SDVOSB primes, CoreRecon's Command tier provides the documented evidence trail, continuous POA&M management, and C3PAO-ready SSP that primes like BAE and L3Harris require from their supply chain.
Free CMMC L2 Gap Assessment
Know your SPRS score before your prime does.
14-domain scorecard, SPRS estimate, POA&M starter mapped to NIST SP 800-171 Rev 2. Delivered in 5 business days — no cost, no obligation.
Book your free gap assessment →
CMMC Level 2 pre-selected in your assessment form
Co-Prime Opportunity
Need a vCISO to own this?
CoreRecon's fractional vCISO engagement covers the 90-day roadmap, C3PAO coordination, POA&M management, and SPRS score maintenance — for less than a full-time hire. See the ROI →
Book Your Free Gap Assessment →
14-domain gap assessment — mapped to NIST SP 800-171 Rev 2