Gov Contract Finder LogoGov Contract Finder Logo
  • ⭐
    AI Bidding Assistant
    Analyze RFPs and draft faster
    Apps
    Browser ExtensionMobile App
    Features
    Email AlertsInsights & AnalyticsProcurement Officers
    Overview →
    OverviewBrowser ExtensionMobile AppEmail AlertsInsights & AnalyticsAI Bidding Assistant
  • Pricing
  • Contracts
  • Learn
    Knowledge BaseGuidesGlossaryQ&ABlogDocumentation
    Comparisons
    Compare PlatformsSAM.gov Alternative
    Solutions
    Why Gov Contract FinderFor Small BusinessFor Capture TeamsSupport
    Proof
    Customer StoriesData Coverage
    Knowledge BaseGuidesGlossaryQ&ABlogDocumentationSupportWhy Gov Contract FinderFor Small BusinessCompare Platforms
  • Services
  • Login
  • Schedule Demo
Gov Contract Finder LogoGov Contract Finder Logo
  • Product
  • AI Bidding Assistant
  • Browser Extension
  • Mobile App
  • Email Alerts
  • Insights & Analytics
  • Pricing
  • Knowledge Base
  • Guides
  • Glossary
  • Q&A
  • Documentation
  • Blog
  • For Small Business
  • For Capture Teams
  • Compare Platforms
  • Services
  • Workflow Automation
  • Support
  • Contact Us
© Copyright 2026 Gov Contract Finder.
  • Terms Of Service
  • Privacy Policy
  • Editorial Policy
Home / Resources / Cybersecurity & CMMC
Cybersecurity & CMMC

What Do the Latest DFARS Changes Require for CMMC Level 2?

Published February 6, 2026

The May 7, 2026 DFARS update makes current CMMC Level 2 status an award and performance requirement when the solicitation includes it.

What Do the Latest DFARS Changes Require for CMMC Level 2 editorial illustration
Gov Contract Finder Editorial Team
•2 min read•Updated August 26, 2026•Information as of August 26, 2026

AI-assisted and automatically checked against the linked primary sources.

Get more Gov Contract Finder updates in Google

Open Google source preferences

What is the latest DFARS policy on CMMC Level 2?

According to DFARS Subpart 204.75, the current rule set ties CMMC Level 2 directly to award eligibility when the program office or requiring activity identifies that level for the solicitation. Contracting officers must include the required CMMC level in the solicitation, and they may not award a contract, task order, or delivery order to an offeror that does not have a current CMMC status at the level required by the solicitation. For information systems used in performance that will process, store, or transmit FCI or CUI, the contractor must have the specified level or higher at time of award and keep that status current throughout the life of the contract. The policy also allows award with a conditional Level 2 status, but only for a period not to exceed 180 days from the CMMC status date. For final Level 2 self or C3PAO assessments, “current” means not older than 3 years, with no changes in compliance since the status date and a corresponding affirmation of continuous compliance.

[1][2]

Can a contractor win a Level 2 award with a conditional status?

Yes. DFARS 204.7502 allows award when the contractor’s Level 2 status is conditional, as long as the status is equal to or higher than the solicitation requirement and the conditional period does not exceed 180 days.
Sources: [2] 204.7502 Policy.

  • Review the solicitation first: the required CMMC level must be identified by the contracting officer if the program office or requiring activity provides it.
  • For Level 2, award depends on having a current status at the required level or higher for systems that process, store, or transmit FCI or CUI.
  • Conditional Level 2 can support award, but only for up to 180 days from the CMMC status date.
  • Final Level 2 self and C3PAO assessments are current for up to 3 years, subject to the stated compliance and affirmation conditions.

Process

  1. 1
    Confirm the required CMMC level in the solicitation

    Verify whether the program office or requiring activity has identified Level 2 for the procurement.

  2. 2
    Check whether your status is current

    Confirm that the relevant Level 2 status is current and matches the solicitation requirement for every in-scope system.

  3. 3
    Track the conditional or final status window

    If you rely on a conditional Level 2 status, monitor the 180-day limit; if you rely on a final Level 2 assessment, confirm the 3-year current-status rule and the affirmation requirement.

Important note

The subpart applies to unclassified contractor information systems and does not replace other security requirements, including other contractor security obligations that continue to apply.

Sources & Citations

1. Subpart 204.75 - Cybersecurity Maturity Model Certification [Link ↗](government site)Accessed 8/26/2026
2. 204.7502 Policy. [Link ↗](government site)Accessed 8/26/2026
3. 204.7503 Procedures. [Link ↗](government site)Accessed 8/26/2026

Tags

#2026#CMMC#compliance#cybersecurity#DoD

Ready to Win Government Contracts?

Use Gov Contract Finder to discover relevant federal opportunities and prepare stronger bids.

Get StartedSchedule Demo

Related Articles

What should contractors verify in “SP 800-92, Guide to Computer Security Log Management and Use Logging on Business Systems | CISA”?

A primary-source checklist for reviewing “SP 800-92, Guide to Computer Security Log Management and Use Logging on Business Systems | CISA” without relying on unsupported legacy claims.

Read more →

What should contractors verify in “SP 1353, NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF…”?

A primary-source checklist for reviewing “SP 1353, NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF…” without relying on unsupported legacy claims.

Read more →

What should contractors verify in “Crypto Agility | CSRC”?

A primary-source checklist for reviewing “Crypto Agility | CSRC” without relying on unsupported legacy claims.

Read more →
Next Step

Check each in-scope information system’s current CMMC status date and affirmations before award or option exercise.