CMMC 2.0: What Primes Need to Know About the Final Rule
CMMC 2.0 is now codified in the CFR. For primes, the practical question is no longer 'is it coming' but 'how do I flow it down and prove it across my supply chain.'
After years of draft guidance, the Cybersecurity Maturity Model Certification (CMMC) 2.0 final rule is codified in the Code of Federal Regulations (32 CFR Part 170). For primes, the practical question is no longer "is it coming" but "how do I flow it down and prove it across my supply chain." Official program information is available from the DoD CMMC pages.
The three levels and what each requires
CMMC 2.0 collapses to three levels mapped to the protection of Controlled Unclassified Information (CUI):
- Level 1 (Foundational) — 15 practices from FAR 52.204-21, annual self-assessment with a senior company official affirmation. Required where only Federal Contract Information (FCI) is handled.
- Level 2 (Advanced) — aligns to NIST SP 800-171. Most CUI contracts require it. A subset of Level 2 contracts require a third-party assessment by a C3PAO.
- Level 3 (Expert) — aligns to NIST SP 800-171 plus a subset of NIST SP 800-172. Assessment by DoD assessors.
The flow-down problem for primes
A prime's own CMMC posture is necessary but not sufficient. The contract clause set will flow CMMC requirements to subcontractors handling CUI. That means the prime needs a defensible view of every subcontractor in the CUI chain, their level, their assessment status, and their gaps. A subcontractor that cannot attest to its level is a contract-execution risk.
Self-assessment is still real
For Level 1 and many Level 2 contracts, self-assessment with senior-official affirmation is the mechanism — but "self-assessment" is not a checkbox. An affirmation signed without an underlying SSP, POA&M, and evidence trail is a personal-liability exposure for the affirming official. Treat the self-assessment as an auditable artifact: scope boundary, asset inventory, practice implementation, and a POA&M for open gaps.
What to do now
- Inventory every contract and subcontract that touches CUI and map the required CMMC level.
- Build or refresh your System Security Plan against NIST SP 800-171 and identify open practices.
- Establish a POA&M with realistic close dates and budget.
- Stand up a supply-chain attestation process so flow-downs are documented before award, not after.
GovCon Architect supports CMMC self-assessment, system profiling, evidence management, PO&M tracking, and policy generation so primes can run this as a managed program rather than a one-time scramble.
The GovCon Architect editorial team writes practitioner guidance on federal capture, compliance, and proposal operations. GovCon Architect is an AI-powered federal government contracting platform for opportunity intelligence, capture, compliance, competitive intelligence, and proposal workflows.
