CMMC 2.0 wasn’t a minor update to CMMC 1.0 — it was a deliberate simplification, built in direct response to industry feedback that the original framework was too costly and too complex for the small and mid-sized businesses that make up most of the Defense Industrial Base. Understanding exactly what changed, and why, is useful both for contractors who built compliance programs around the original 1.0 structure and for anyone trying to make sense of CMMC references that don’t specify which version they mean.

Executive Summary

Main Idea: CMMC 2.0 reduced five certification levels to three, aligned each level directly with existing NIST standards rather than a CMMC-specific control set, and reopened self-assessment as an option at Levels 1 and (for some contracts) Level 2 — reversing 1.0’s universal third-party assessment requirement.

Why You Should Care: If you’re working from documentation, a vendor’s marketing material, or a colleague’s understanding of “CMMC” without a version specified, you may be working from CMMC 1.0’s assumptions — which are no longer how the program operates. Knowing the five specific changes prevents that kind of confusion and clarifies what your organization actually needs to do today.

CMMC 1.0 vs. CMMC 2.0

Key Takeaways

  1. CMMC 2.0 cut five certification levels down to three. The original framework’s Levels 1 through 5 were consolidated into Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert) — removing two levels of granularity that DIB feedback found added complexity without adding meaningful security value.
  2. CMMC 2.0 tied each level directly to existing NIST standards instead of a separate CMMC-specific control catalog. Level 2 now maps directly to NIST SP 800-171’s 110 controls, and Level 3 builds on NIST SP 800-172 — replacing 1.0’s independent, CMMC-only control structure with alignment to standards many contractors already had experience implementing under DFARS 252.204-7012.
  3. CMMC 2.0 reopened self-assessment as an option, reversing 1.0’s universal third-party requirement. Under 1.0, every certification level required a third-party assessment. Under 2.0, Level 1 is always self-assessed, and even Level 2 permits self-assessment for contracts that don’t involve the most critical national security information — a significant cost and timeline reduction for the majority of the DIB.
  4. CMMC 2.0 introduced limited, time-bound POA&Ms — something 1.0 didn’t allow at all. Under the original framework, an organization had to have every required control fully implemented before certification. CMMC 2.0 permits a Plan of Action and Milestones for a subset of controls, with a defined remediation timeline, giving organizations a more realistic path to certification without requiring perfection on day one.
  5. These changes were a direct response to cost and complexity concerns raised by the DIB itself. Small and mid-sized businesses — the majority of the defense supply chain — reported that CMMC 1.0’s assessment costs and universal third-party requirement were disproportionately burdensome relative to their size, and CMMC 2.0’s streamlining was designed specifically to address that feedback without weakening the underlying security standard.

Why CMMC 2.0 Happened

CMMC 1.0, published in January 2020, established the first version of the Department of Defense’s cybersecurity certification framework — five levels, each requiring third-party assessment, with a CMMC-specific set of controls layered on top of existing NIST requirements. In practice, DIB contractors — particularly small and mid-sized businesses — found the framework more expensive and more procedurally complex than its security benefit justified. Assessment costs, assessor availability, and the sheer granularity of five distinct levels created friction that DoD determined was undermining, rather than supporting, its goal of raising cybersecurity standards across the defense supply chain.

CMMC 2.0, announced in November 2021 and finalized through 32 CFR Part 170 in late 2024, was built specifically to address that feedback: fewer levels, direct alignment with standards contractors already needed to meet under DFARS, and a return to self-assessment where the risk profile supports it.

The Five Changes, Side by Side

Element CMMC 1.0 CMMC 2.0
Certification levels Five levels (1–5) Three levels: Foundational, Advanced, Expert
Control source CMMC-specific control catalog, independent of existing standards Directly aligned to NIST SP 800-171 (Level 2) and NIST SP 800-172 (Level 3)
Assessment type Third-party assessment required at every level Self-assessment permitted at Level 1 always, and at Level 2 for many contracts
Plans of Action and Milestones Not permitted — full implementation required before certification Permitted for a limited subset of controls, with a defined remediation timeline
Design intent Uniform rigor applied broadly across the DIB Risk-based rigor scaled to program criticality and contractor size

What Stayed the Same

It’s worth being clear about what CMMC 2.0 didn’t change, since some of the framework’s core substance carried over directly. The underlying goal — verifying that DIB contractors protect Federal Contract Information and Controlled Unclassified Information appropriately — didn’t change. The data-sensitivity basis for determining required level didn’t change: FCI still maps to the foundational tier, CUI still maps to the advanced tier. And DFARS 252.204-7012’s underlying requirement to implement NIST SP 800-171 predates both versions of CMMC and remains the standard either version is ultimately verifying compliance against.

Where Things Stand Now

The most consequential recent chapter in CMMC’s evolution isn’t a 1.0-to-2.0 framework change — it’s the Department of War’s July 13, 2026 suspension of Phase 2’s third-party certification requirement, pending a Reform Task Force review expected to report around mid-September 2026.

Kiteworks’ own August 2026 survey of 273 confirmed DoW-business organizations found the DIB did not simply wait out the pause: 98% of respondents took at least one concrete action in response, and budget reallocation moved toward compliance infrastructure rather than away from it. The same research also surfaced a real confidence gap worth knowing about — 96% of respondents said they were confident their self-attested SPRS score would hold up under review, but only 60% of that group actually had a current SPRS submission, and just 29% had both a current score and a FedRAMP-authorized platform behind it. For the full findings, including the DOJ’s June 2026 LOGZONE False Claims Act settlement and a self-scoring readiness checklist, see State of CMMC 2.0 Preparedness in the DIB.

For the current status of the pause itself and what it does and doesn’t affect, see CMMC Phase II Is Suspended. Your DFARS Obligations Are Not.

How Kiteworks Supports CMMC 2.0 Compliance

Kiteworks supports nearly 90% of CMMC 2.0 Level 2 requirements out of the box — the tier most DIB organizations need under the current framework — through a unified Data Policy Engine that consolidates access controls, encryption, and audit logging across secure email, secure file sharing, managed file transfer, and SFTP.

AES-256 encryption with FIPS 140-3 validated cryptographic modules addresses NIST SP 800-171’s System and Communications Protection requirements directly, and a single, consolidated, immutable audit trail gives contractors the kind of real-time evidence — the exact capability 47% of respondents in Kiteworks’ DIB survey said would most increase their confidence in their own self-attestation — that self-assessment and C3PAO certification alike depend on. Kiteworks also holds FedRAMP Moderate Authorization, independently assessed since June 2017, addressing the single weakest readiness indicator in that same survey: only 35% of respondents were already using a FedRAMP-authorized platform.

To see how Kiteworks supports your organization’s CMMC 2.0 compliance, whichever level applies, schedule a custom demo.

Frequently Asked Questions

CMMC 2.0 reduced five certification levels to three (Foundational, Advanced, Expert); aligned each level directly to existing NIST standards (NIST SP 800-171 for Level 2, NIST SP 800-172 for Level 3) rather than a separate CMMC-specific control catalog; reopened self-assessment as an option at Level 1 and, for many contracts, Level 2, reversing 1.0’s universal third-party assessment requirement; introduced limited, time-bound Plans of Action and Milestones, which 1.0 didn’t permit at all; and shifted the framework’s overall design philosophy from uniform rigor to risk-based rigor scaled to program criticality and contractor size.

CMMC 2.0 was a direct response to feedback from the Defense Industrial Base, particularly small and mid-sized businesses, that CMMC 1.0’s universal third-party assessment requirement and five-level structure imposed disproportionate cost and complexity relative to the security benefit gained. The Department determined that streamlining the framework — fewer levels, direct alignment with standards many contractors already needed to meet under DFARS, and restored self-assessment where appropriate — would improve compliance rates without weakening the underlying cybersecurity standard.

No. CMMC 2.0, finalized through 32 CFR Part 170 in late 2024 and enforced through 48 CFR amendments effective November 10, 2025, replaced CMMC 1.0 entirely. Any current or new DoD contract referencing CMMC certification requirements is referencing the 2.0 framework’s three-level structure, not the original five-level version.

A substantial amount. The underlying security controls contractors implemented under CMMC 1.0 — particularly anything aligned to NIST SP 800-171 — carry over directly, since CMMC 2.0’s Level 2 is built on that same standard. What changes is largely procedural: which assessment type applies (self-assessment may now be available where third-party certification was previously mandatory), which level your organization falls under given the framework’s three-tier consolidation, and whether a documented POA&M can now cover gaps that CMMC 1.0 would have required fully closed before certification.

 

Back to Risk & Compliance Glossary

Get started.

It’s easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

Share
Tweet
Share
Explore Kiteworks