Skip to content
Back to Compliance Academy

Product context is educational relevance, not a feature-status or compliance claim.

Context: Visitor
Context: Regulated Access
CMMC / FCI / CUI
Controlled Access
Front Desk
Compliance Manager
Admin
Executive

What is CMMC (Level 1 vs Level 2)?

The Department’s cybersecurity assessment program for defense contractors and subcontractors handling FCI or CUI; implementation is currently paused in Phase 1.

Last Reviewed: 2026-09-19Plain-English reference · not legal advice

Plain-English Summary

CMMC is the Department’s program for verifying implementation of cybersecurity requirements tied to Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). As of September 2026, implementation is paused in Phase 1 after the Department suspended Phase II on July 13, 2026. Current Phase I requirements focus on Level 1 and Level 2 self-assessments; the previously scheduled November 10, 2026 Phase II expansion of Level 2 certification requirements is not currently proceeding.

Why This Matters

Defense contractors still have to protect FCI and CUI under the applicable contract clauses even while Phase II is suspended. Current CMMC Phase I can make the relevant self-assessment status a condition of contract award, and the Department says it will continue enforcing NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments during the review.

Explanation Depth

Concept Explanation

CMMC is one way the Department checks whether defense contractors are protecting government information. Right now the rollout is paused in Phase 1. Level 1 and Level 2 self-assessments still matter, but the broader Phase II move to Level 2 third-party certification that had been scheduled for November 10, 2026 was suspended in July 2026. Always check the current contract and CMMC guidance instead of relying on the old timeline.

When You'll See This in SecurePoint

SecurePoint Visitor can help document selected physical-access activities relevant to a customer’s visitor and physical-protection procedures, such as access history and configured escort workflows. Those records may support the customer’s evidence, but SecurePoint does not determine CMMC scope, grant CMMC status, perform the assessment, or replace the customer’s SSP and other required cybersecurity controls.

What You Should Do Next

Check the current CMMC phase and the exact clauses in your solicitations and contracts before planning an assessment. For FCI, review the Level 1 requirements derived from FAR 52.204-21. For CUI under the current Phase I posture, review the Level 2 self-assessment requirements based on NIST SP 800-171 Rev. 2. Do not schedule or market a C3PAO assessment as universally required based on the old November 10, 2026 rollout date; verify the current Department guidance first.

What Can Go Wrong

The biggest current risk is using a stale implementation timeline. Phase II was suspended on July 13, 2026, so material that still says Level 2 certification broadly becomes mandatory on November 10, 2026 is out of date. A separate mistake is assuming a visitor-management or cybersecurity product can confer CMMC status by itself. CMMC status depends on the contractor’s scoped environment, required controls, assessment type, affirmations, and contract requirements.
What is CMMC (Level 1 vs Level 2)? | Compliance Academy | SecurePoint USA