09/08/2025
CMMC 2.0 is coming β are you ready?
Starting October 1, 2025, the Department of Defense will begin requiring contractors to comply with CMMC 2.0 in order to compete for contracts. Full implementation will roll out in phases through 2028.
CMMC 2.0 is designed to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) across the defense supply chain. If your business supports the DoD, compliance will be a contract requirement.
What is CMMC 2.0?
Streamlined from 5 levels to 3
Aligns with NIST SP 800-171
Scales requirements based on the sensitivity of data handled
Levels of CMMC 2.0
Level 1 (Foundational): Basic cyber practices, annual self-assessments
Level 2 (Advanced): 110 NIST SP 800-171 controls, triennial third-party assessments for critical CUI
Level 3 (Expert): Based on NIST SP 800-172, government-led assessments
Key Timeline
October 2025: Self-assessments required for new DoD contracts
2026β2027: Third-party certification requirements begin for Level 2
2028: Full enforcement for all applicable contracts
The time to prepare is now. Waiting until deadlines hit may put your contracts and your competitive edge at risk.
At Simple Helix, we help DoD contractors assess their current security posture, identify compliance gaps, and build a roadmap to achieve and maintain CMMC certification.
For more information, reach out to Danny Sevrick, Katie Host, or Drina Black our account managers.