1. Home
  2. |Insights
  3. |CMMC 2.0: DoD Unveils Sweeping Changes Streamlining CMMC Requirements

CMMC 2.0: DoD Unveils Sweeping Changes Streamlining CMMC Requirements

Client Alert | 1 min read | 11.05.21

The Department of Defense (DoD) recently announced significant changes to its Cybersecurity Maturity Model Certification (CMMC) program intended to simplify the requirements and ease the compliance burden on contractors.  Unlike its predecessor, the new CMMC 2.0 moves to three compliance levels rather than five; aligns the required security controls (known as practices) with National Institute of Standards and Technology (NIST) Special Publications (SP) 800-171 and 800-172; and eliminates entirely previously required maturity processes.  The changes also include a shift to self-assessments for all but contractors supporting the most sensitive programs, as well as the return of Plans of Action and Milestones (POAMs) to demonstrate compliance and achieve certification. 

The new requirements are summarized below:

  • CMMC Level 1, Foundational – Contractors must implement the 17 controls from NIST SP 800-171 enumerated in FAR 52.204-21 and submit an annual self-assessment to the DoD through the Supplier Performance Risk System (SPRS).  
  • CMMC Level 2, Advanced – Contractors must implement the 110 controls in NIST SP 800-171 and submit an annual self-assessment or, if required to handle (as yet undefined) critical national security information, a triennial independent assessment performed by a CMMC Third Party Assessment Organization (C3PAO). 
  • CMMC Level 3, Expert – Contractors must implement the 110 controls in NIST SP 800-171 and a subset of controls from NIST SP 800-172 before undergoing a triennial government-led assessment.  The DoD, however, is still in the process of developing the requirements for this Level.

CMMC 2.0 will be implemented through the rulemaking process, which the DoD estimates could take anywhere from nine months to two years.  Thereafter, the DoD will begin to incorporate CMMC 2.0 requirements into contracts.  In the meantime, the DoD has suspended its CMMC pilot program and will not approve the inclusion of CMMC requirements in any forthcoming DoD solicitations.

Contacts

Insights

Client Alert | 5 min read | 12.12.25

Eleventh Circuit Hears Argument on False Claims Act Qui Tam Constitutionality

On the morning of December 12, 2025, the Eleventh Circuit heard argument in United States ex rel. Zafirov v. Florida Medical Associates, LLC, et al., No. 24-13581 (11th Cir. 2025). This case concerns the constitutionality of the False Claims Act (FCA) qui tam provisions and a groundbreaking September 2024 opinion in which the United States District Court for the Middle District of Florida held that the FCA’s qui tam provisions were unconstitutional under Article II. See United States ex rel. Zafirov v. Fla. Med. Assocs., LLC, 751 F. Supp. 3d 1293 (M.D. Fla. 2024). That decision, penned by District Judge Kathryn Kimball Mizelle, was the first success story for a legal theory that has been gaining steam ever since Justices Thomas, Barrett, and Kavanaugh indicated they would be willing to consider arguments about the constitutionality of the qui tam provisions in U.S. ex rel. Polansky v. Exec. Health Res., 599 U.S. 419 (2023). In her opinion, Judge Mizelle held (1) qui tam relators are officers of the U.S. who must be appointed under the Appointments Clause; and (2) historical practice treating qui tam and similar relators as less than “officers” for constitutional purposes was not enough to save the qui tam provisions from the fundamental Article II infirmity the court identified. That ruling was appealed and, after full briefing, including by the government and a bevy of amici, the litigants stepped up to the plate this morning for oral argument....