Executive summary:
CMMC Level 2 requires midsize DoD contractors handling CUI to implement all 110 NIST SP 800-171 Rev 2 controls. DoD has paused Phase 2 third-party assessments, but the underlying obligation is unchanged: DFARS 252.204-7012 still requires those controls, and you still self-assess and maintain your SPRS score. Scoping CUI into an enclave, prioritizing high-impact controls, and keeping your SSP current are the fastest ways to simplify the work.
CMMC Level 2, set out in 32 CFR Part 170 (CMMC Program rule), requires midsize defense contractors who handle Controlled Unclassified Information (CUI) to meet all 110 security controls in NIST SP 800-171 Rev 2. While Level 1 covers basic protections for Federal Contract Information (FCI), Level 2 is for systems that process or store CUI.
Even though the DoD has paused mandatory CMMC audits by Certified Third-Party Assessment Organizations (C3PAOs) during Phase 2, organizations still need to do self-assessments and keep their compliance records up to date.
Midsize contractors need to document their security measures in a System Security Plan (SSP) and record any gaps in a Plan of Action and Milestones (POA&M). Because they handle more sensitive defense data than many smaller firms, they face unique challenges. This makes it important to map controls and collect evidence regularly as part of daily compliance.
CMMC Level 2 covers 14 security areas, including access control, incident response, and configuration management. Executives need to clearly understand each technical safeguard. By checking how each requirement fits your systems, your team can make sure the right people are responsible for every safeguard. For more details, see our full guide on CMMC Level 2 requirements.
Leaders in the Defense Industrial Base should stay aware of possible program updates but continue their own work. The Department of Defense is collecting feedback and could extend the pause, change the assessment rules, end the CMMC framework, or move ahead with Phase 2.
Whatever regulators decide, your main responsibilities do not change. DFARS 252.204-7012 still requires you to fully apply NIST SP 800-171 controls to any system that stores or handles defense data. You also need to keep your Supplier Performance Risk System (SPRS) scores current, because incorrect CMMC self-assessments can cause serious legal and regulatory issues under federal contracting rules.
Federal agency decisions also affect the whole supply chain. Prime contractors often need strict cybersecurity checks to keep their contracts, and they may ask subcontractors for third-party proof that controls are in place. To learn how top defense companies apply these rules to their suppliers, see our section below on DFARS flow-down requirements for midsize DoD contractors.
"DFARS 7021 was not repealed. What's been suspended is phase two of the rollout plan and how the contractors implement that,” Therrien says. "The expensive part is implementing security. That part has been around for eight years. That part did not go away."
“I would say keep using it, keep pressing forward,” Arnold says. “Don't stop what you're doing, because this is the best framework that we know of. Maybe next year or maybe 60 days down the line, something will be clearer and smoother and more streamlined. But for now, this is the best of what we have.”
This interactive tool lets midsize DoD contractors see how the July 2026 CMMC pause affects them. Pick your role — prime or subcontractor — and a possible DoD decision to see your next move. Under every outcome, the core requirement holds: implement NIST 800-171, self-assess, and maintain your SPRS score.
NIST SP 800-171 sets the technical security controls, while DFARS 252.204-7012 makes these controls a legal requirement in contracts. DFARS 252.204-7021, known as the CMMC acquisition clause, adds CMMC Level 2 verification to contract solicitations. Changes in CMMC assessment policies do not change your core compliance responsibilities.
Since December 2017, DFARS 252.204-7012 has required defense contractors that handle Controlled Unclassified Information to protect such data in accordance with NIST SP 800-171. CMMC did not add new technical safeguards. Instead, it created a formal mechanism to verify that companies are following the rules.
If C3PAO audits are paused, the DFARS contract requirements still apply. Not following these rules is still a serious risk, and falsely claiming compliance can lead to False Claims Act liability, no matter what CMMC verification model is in place.
Right now, DFARS 252.204-7012 uses the version of NIST SP 800-171 that is current when the contract is offered, which is usually Rev. 2. This is also the version used in NIST SP 800-171A, the evaluation guide, and in the CMMC final rule.
Contractors should prepare for a future switch to Rev. 3 as defense standards evolve. Keeping your System Security Plan current and your Supplier Performance Risk System score accurate will help your organization stay compliant now and in the future.
The Federal Acquisition Regulations set rules for both prime contractors and subcontractors in defense supply chains. Prime contractors have to pass down DFARS 252.204-7012 requirements to any subcontractor that handles Controlled Unclassified Information.
This means large prime contractors cannot just secure their own networks. They also need to make sure your organization has put all the required NIST SP 800-171 security controls in place before they share sensitive defense data with you.
Since prime contractors risk heavy financial penalties and False Claims Act issues if there are supply chain problems, they often use stricter checks than the government requires. Even though the Department of Defense has paused mandatory third-party audits for CMMC, your enterprise customers might still ask for a C3PAO certification or do detailed evidence reviews to protect themselves. In the end, your timeline will mostly depend on what your prime contractor expects.
Achieving compliance without a dedicated security team requires treating CMMC Level 2 as an operational sequence rather than a large IT project. Midsize contractors can streamline this process by isolating sensitive data, focusing on high-impact remediation, and leveraging automation tools to reduce the administrative burden of maintaining 110 controls.
"Midsize companies get overwhelmed because they look at CMMC as 110 separate investigations," Spieler says. "But controls aren't 110 unique tasks—they're mostly queries against a smaller handful of data objects: assets, identities, configurations, and data flows."
He emphasizes that while control ownership remains with the contractor, maintaining live data transforms daily operations. "Even with an asset repository, you'll still own controls. But the difference between a chaotic IT project and a manageable daily workflow is whether you're managing compliance operations against live data in a repository, or trying to reconstruct historical reality from scratch every time your auditor has an ask."
Midsize contractors can follow these steps to simplify their CMMC Level 2 compliance:
Map exactly where Controlled Unclassified Information enters, travels, and rests within your infrastructure, categorizing data against the official CUI Registry. Instead of attempting to secure your entire corporate network, deploy a dedicated CUI enclave to isolate this sensitive data. Containing the footprint reduces your CMMC assessment scope, which dramatically lowers implementation costs, simplifies administrative overhead for internal IT teams, and accelerates your overall project timeline significantly.
With your assessment boundary strictly defined, evaluate your technical safeguards and documented policies against the 110 security requirements. Internal IT teams should utilize the NIST SP 800-171A assessment procedures to verify actual operational practices rather than relying on assumptions. Identifying specific deficiencies early prevents wasted spending on unnecessary software tools and provides a realistic, objective baseline for an accurate CMMC Level 2 self-assessment.
Address your most critical security vulnerabilities immediately, focusing heavily on access control mechanisms and incident response protocols. For any non-critical requirements you cannot resolve right away, create a formal CMMC Plan of Action and Milestones. Keep in mind that certain highly weighted controls cannot be deferred, and regulators require all documented action items to be fully resolved within a strict 180-day window.
Consolidate your security policies, system architecture diagrams, and specific control implementations into a comprehensive System Security Plan. This core document serves as the primary evidence during any compliance review and must accurately reflect your daily operational reality. A midsize organization should explicitly detail how each of the 14 NIST control families functions within the defined boundary, linking directly to verified technical evidence.
Calculate your final assessment score and submit it to the federal registry alongside an annual affirmation signed by a senior corporate executive. Compliance requires persistent ongoing maintenance once this baseline is firmly established. Implement continuous monitoring processes, conduct routine internal reviews, and update your security documentation regularly to ensure your operational posture remains audit-ready whenever enterprise prime contractors request verification.
Before taking action, executive leaders should make key decisions that help reduce compliance overhead. Setting assessment boundaries, deciding whether to manage compliance internally or work with outside partners, and focusing on remediation efforts that most affect your score will shape your program’s cost and timeline.
Midsize contractors can try these strategies to simplify CMMC Level 2 compliance:
Many midsize organizations struggle with compliance because they treat important administrative steps as minor technical tasks. To avoid common mistakes like scope creep, unrealistic plans, and inaccurate reporting, approach these requirements with discipline.
Here are common CMMC Level 2 compliance challenges and practical strategies to address them:
CMMC Level 2 requires implementing the 110 NIST SP 800-171 controls, proving each with concrete evidence, and maintaining continuous operational readiness. Managing this complex lifecycle manually through spreadsheets quickly consumes hundreds of internal engineering hours and creates severe vulnerabilities during federal or prime contractor audits.
Spieler explains that shifting from manual tracking to a centralized platform changes the entire compliance dynamic. "When you centralize those (data objects) into a single source of truth, the scope almost inverts and becomes deterministic instead of full of guesswork," Spieler says. "Technical controls become derived properties you evaluate continuously, and evidence becomes a byproduct of normal operations. It shrinks your daily job from re-proving the entire environment to triaging the handful of assets or configs that drifted."
Strike Graph’s AI-native compliance management platform consolidates this entire workflow into a single operational hub well-suited for midsize organizations. Instead of organizing files manually, teams execute guided self-assessments directly within the system, tracking identified deficiencies through integrated Plan of Action and Milestones ticketing. The platform connects directly with existing enterprise systems to automate ongoing evidence collection efficiently.
Beyond mere tracking, Strike Graph dynamically generates your essential System Security Plan while its Verify AI technology constantly validates evidence against active NIST requirements. This automated validation helps reduce compliance drift and supports ongoing audit readiness.
Visit the Strike Graph CMMC compliance platform to streamline your assessment process, eliminate redundant manual work, and protect your defense supply chain revenue.