CMMC 2.0: DoD Unveils Sweeping Changes Streamlining CMMC Requirements
Client Alert | 1 min read | 11.05.21
The Department of Defense (DoD) recently announced significant changes to its Cybersecurity Maturity Model Certification (CMMC) program intended to simplify the requirements and ease the compliance burden on contractors. Unlike its predecessor, the new CMMC 2.0 moves to three compliance levels rather than five; aligns the required security controls (known as practices) with National Institute of Standards and Technology (NIST) Special Publications (SP) 800-171 and 800-172; and eliminates entirely previously required maturity processes. The changes also include a shift to self-assessments for all but contractors supporting the most sensitive programs, as well as the return of Plans of Action and Milestones (POAMs) to demonstrate compliance and achieve certification.
The new requirements are summarized below:
- CMMC Level 1, Foundational – Contractors must implement the 17 controls from NIST SP 800-171 enumerated in FAR 52.204-21 and submit an annual self-assessment to the DoD through the Supplier Performance Risk System (SPRS).
- CMMC Level 2, Advanced – Contractors must implement the 110 controls in NIST SP 800-171 and submit an annual self-assessment or, if required to handle (as yet undefined) critical national security information, a triennial independent assessment performed by a CMMC Third Party Assessment Organization (C3PAO).
- CMMC Level 3, Expert – Contractors must implement the 110 controls in NIST SP 800-171 and a subset of controls from NIST SP 800-172 before undergoing a triennial government-led assessment. The DoD, however, is still in the process of developing the requirements for this Level.
CMMC 2.0 will be implemented through the rulemaking process, which the DoD estimates could take anywhere from nine months to two years. Thereafter, the DoD will begin to incorporate CMMC 2.0 requirements into contracts. In the meantime, the DoD has suspended its CMMC pilot program and will not approve the inclusion of CMMC requirements in any forthcoming DoD solicitations.
Contacts

Partner and Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 3 min read | 06.12.26
DOJ Guidance Backs Away From Disparate Impact Liability
On June 9, 2026, the U.S. Department of Justice (DOJ) issued a formal opinion concluding that the Equal Opportunity Employment Commission’s (EEOC) existing interpretations of Title VII of the Civil Rights Act of 1964 (Title VII) disparate-impact liability, including the Uniform Guidelines on Employee Selection Procedures (UGESP), are unconstitutional. According to the opinion, EEOC’s prior interpretations contemplate liability based on disproportionately adverse effects alone, without regard to an employer’s likely intent, rather than treating disparate impact as an evidentiary mechanism to “smoke out” intentional discrimination. DOJ found that this approach functions as a “qualified racial-proportionality mandate” that places “a racial thumb on the scales, often requiring employers to evaluate the racial outcomes of their policies, and to make decisions based on (because of) those racial outcomes.” The opinion fulfills one mandate of Executive Order 14281, which rejected disparate-impact liability insofar as it “creates a near insurmountable presumption that unlawful discrimination exists wherever there are any differences in outcomes among different [demographic groups].”
Client Alert | 4 min read | 06.12.26
Auto Dealers: The FTC Is Back in the Driver’s Seat — Warning Letters Signal Renewed Federal Scrutiny
Client Alert | 13 min read | 06.12.26
Client Alert | 4 min read | 06.12.26

