· CMMC  · 7 min read

CMMC 2.0 Final Rule: What 32 CFR Part 170 Means for DIB Contractors

The CMMC 2.0 final rule in 32 CFR Part 170 ties defense contract assessments to NIST SP 800-171 and DFARS 252.204-7012, and DoD has suspended Phase II third-party certifications while those obligations remain in force.

The CMMC 2.0 final rule in 32 CFR Part 170 ties defense contract assessments to NIST SP 800-171 and DFARS 252.204-7012, and DoD has suspended Phase II third-party certifications while those obligations remain in force.

CMMC 2.0 in 32 CFR Part 170 operationalizes contractor cybersecurity by aligning assessments to NIST SP 800-171 and DFARS 252.204-7012, and DoD has paused Phase II certification while keeping those underlying duties in place.

32 CFR Part 170 structure and intent

32 CFR Part 170 establishes three program levels and an assessment model that the Department of Defense can reference in solicitations and contracts. The rule frames who performs each assessment type, how organizations scope systems, and how assessors document results. DoD built the program to use named guides and the Cyber AB process as the procedural backbone.

DoD CIO guidance anchors the practical work. The Level 2 Assessment Guide describes how assessors test NIST SP 800-171 Rev. 2 requirements for environments that handle CUI. The Level 2 Scoping Guide ties scoping expectations to section 170.19 and explains how Organizations Seeking Assessment and Organizations Seeking Certification should bound systems.

DoD CIO maintains a public index of CMMC resources. That index consolidates the current guides. It gives contractors and assessors a common reference set.

Alignment with NIST SP 800-171 and DFARS 252.204-7012

CMMC Level 2 rides on NIST SP 800-171 Rev. 2. DoD states in the Level 2 Assessment Guide that Level 2 incorporates the 800-171 Rev. 2 security requirements for CUI. The control identifiers and assessment objectives in 800-171 drive the evidence and tests.

DFARS 252.204-7012 remains the floor for covered defense information and incident reporting. DoD CIO guidance on the Phase II pause underscores that point. The clause requires encryption, incident reporting to DoD within 72 hours, and media preservation, among other elements. CMMC does not replace those contract terms. It layers an assessment program over the same baseline.

The following 800-171 Rev. 2 controls illustrate how CMMC Level 2 ties to concrete safeguards and evidence:

  • AC.L2-3.1.1. Limit system access to authorized users, processes acting for authorized users, or devices.
  • IA.L2-3.5.1. Identify users, processes acting for users, or devices.

You should show proof that your identity and access design enforces these requirements in the CUI boundary. That proof sits in your System Security Plan and your technical configuration.

Two more controls drive core monitoring and configuration practice:

  • AU.L2-3.3.1. Create, protect, and retain audit records to monitor and investigate unauthorized activity.
  • CM.L2-3.4.1. Establish and maintain baseline configurations and inventories of systems.

Assessors use your logging design, retention settings, and baseline documentation to score these. A final example touches boundary defense:

  • SC.L2-3.13.1. Monitor, control, and protect communications at the external boundary and key internal boundaries.

You should present how you segment, filter, and inspect traffic that can touch CUI.

For program planning, align your policies, procedures, and control implementations to 800-171, then map that evidence to the CMMC Level 2 assessment objectives. Our overview of NIST 800-171 to CMMC Level 2 expands on this approach. Pair that with a review of your contract set for DFARS 252.204-7012, which we covered in DFARS 252.204-7012 requirements.

CMMC levels and assessment types with CAP v2.0

CMMC defines three levels. Level 1 targets FCI practices and uses a self-assessment. Level 2 targets CUI and uses assessments against NIST SP 800-171 Rev. 2. Level 3 covers a subset of advanced practices for programs with heightened risk.

The Cyber AB CMMC Assessment Process v2.0 explains how assessors and contractors run through an engagement. CAP v2.0 defines four phases that align to roles and artifacts in 32 CFR Part 170.

  • In Phase 1, the C3PAO reviews the System Security Plan, validates scope, and checks evidence readiness before uploading a pre-assessment form into eMASS.
  • In Phase 2, the team assesses conformity to the security requirements and records objective evidence and findings.

Phases 3 and 4 then cover reporting and closeout. The Level 2 Assessment Guide mirrors those stages and gives assessors the test methods. Contractors who prepare a current, accurate SSP and asset inventory reduce churn across all four phases.

July 2026 suspension and current contracting impact

DoD CIO announced a suspension of CMMC Phase II on July 13, 2026. That action paused the rollout that would have added third-party CMMC Level 2 certification as a condition in many awards. During the suspension, DoD states that solicitations and contracts may include only Level 1 self-assessments or Level 2 self-assessments, not Level 2 C3PAO certifications or Level 3 DIBCAC assessments.

DoD also states that DFARS 252.204-7012 safeguarding and incident reporting obligations remain in effect. Contractors still need a current 800-171 self-assessment and a posted SPRS score when clauses require it. Our guide to SPRS scoring for NIST 800-171 covers score calculation and posting steps.

Plan against two tracks in this suspension window:

  • Maintain NIST SP 800-171 Rev. 2 conformity with evidence that supports a Level 2 self-assessment and any future certification.
  • Keep DFARS 252.204-7012 controls, incident reporting, and cyber incident response aligned to current contract language.

You gain schedule risk if you pause remediation during the suspension. You reduce risk if you fix plan of action items and validate scope and evidence now.

Using official guides and Microsoft references in CUI environments

Contractors on Microsoft 365 can plan effectively with official CMMC guides and Microsoft references. DoD CIO labels the Level 2 Assessment Guide and the Level 2 Scoping Guide as approved for public release to support organizations and assessors. The Scoping Guide also notes that it does not carry the force and effect of law. Use these guides to bound your CUI system, define in-scope assets, and structure evidence.

Microsoft publishes two documents that help map cloud capabilities to CMMC practices.

  • The Microsoft Product Placemat for CMMC 2.0 provides a Preview mapping between Microsoft cloud services and CMMC practices.
  • The Microsoft Technical Reference Guide for CMMC Level 2 provides Preview technical guidance and references the Placemat as a companion.

Treat both as references. Neither document functions as authorization or a compliance determination. You still need an SSP that names your tenant, labels the CUI boundary, and records control implementations, exceptions, and shared responsibilities.

A focused Microsoft plan should cover two workstreams:

  • Scope and boundary. Define the tenant, enclaves, and interconnections that can store, process, or transmit CUI. The Scoping Guide and our take on CUI boundary scoping can help shape that picture.
  • Control evidence. Map configurations and logs to 800-171 control identifiers and CMMC assessment objectives. Include identity controls like AC.L2-3.1.1 and IA.L2-3.5.1, monitoring controls like AU.L2-3.3.1, configuration controls like CM.L2-3.4.1, and boundary controls like SC.L2-3.13.1.

Microsoft 365 customers who handle ITAR or export-controlled CUI should assess whether GCC High fits program needs. Our GCC High migration decision framework discusses drivers and tradeoffs. The right tenancy choice does not, by itself, meet 32 CFR Part 170 or DFARS 252.204-7012. Your SSP, procedures, and technical configuration do that work.

Practical next steps under the final rule

You can move with confidence if you anchor work in current DoD guidance and NIST 800-171.

  • Pull the Level 2 Assessment Guide, the Level 2 Scoping Guide, CAP v2.0, and the NIST 800-171 Rev. 2 catalog. Build your checklist from those sources.
  • Confirm contract clause flowdown and 800-171 self-assessment status across your portfolio. Align SPRS scores, SSP updates, and POA&M closures to the contracts that matter most.

Hold Phase II planning loosely while the suspension stays in place. Keep remediation on track so you do not face a compressed schedule if DoD resumes certification requirements in future updates.

Sources

CMMC (Department of Defense CIO)

CMMC Assessment Guide Level 2, Version 2.13 (Department of Defense CIO)

CMMC Scoping Guide Level 2, Version 2.13 (Department of Defense CIO)

CMMC Resources and Documentation (Department of Defense CIO)

CMMC Assessment Process v2.0 (Cyber AB)

NIST SP 800-171 Rev. 2 (NIST)

Microsoft Product Placemat for CMMC 2.0 (Preview) (Microsoft)

Microsoft Technical Reference Guide for CMMC Level 2 (Preview) (Microsoft)

Want a structured starting point?

Our 27-question CMMC technical readiness self-survey covers tenant, identity, endpoint, data protection, audit logging, documentation, and the 72-hour DFARS reporting plan. The score is produced in your browser from your answers alone. Nothing is verified or stored.

Back to Blog

Related Posts

View All Posts »