What Do the Latest DFARS Changes Require for CMMC Level 2?
The May 7, 2026 DFARS update makes current CMMC Level 2 status an award and performance requirement when the solicitation includes it.
AI-assisted and automatically checked against the linked primary sources.
What is the latest DFARS policy on CMMC Level 2?
According to DFARS Subpart 204.75, the current rule set ties CMMC Level 2 directly to award eligibility when the program office or requiring activity identifies that level for the solicitation. Contracting officers must include the required CMMC level in the solicitation, and they may not award a contract, task order, or delivery order to an offeror that does not have a current CMMC status at the level required by the solicitation. For information systems used in performance that will process, store, or transmit FCI or CUI, the contractor must have the specified level or higher at time of award and keep that status current throughout the life of the contract. The policy also allows award with a conditional Level 2 status, but only for a period not to exceed 180 days from the CMMC status date. For final Level 2 self or C3PAO assessments, “current” means not older than 3 years, with no changes in compliance since the status date and a corresponding affirmation of continuous compliance.
Can a contractor win a Level 2 award with a conditional status?
- Review the solicitation first: the required CMMC level must be identified by the contracting officer if the program office or requiring activity provides it.
- For Level 2, award depends on having a current status at the required level or higher for systems that process, store, or transmit FCI or CUI.
- Conditional Level 2 can support award, but only for up to 180 days from the CMMC status date.
- Final Level 2 self and C3PAO assessments are current for up to 3 years, subject to the stated compliance and affirmation conditions.
Process
- 1
Confirm the required CMMC level in the solicitation
Verify whether the program office or requiring activity has identified Level 2 for the procurement.
- 2
Check whether your status is current
Confirm that the relevant Level 2 status is current and matches the solicitation requirement for every in-scope system.
- 3
Track the conditional or final status window
If you rely on a conditional Level 2 status, monitor the 180-day limit; if you rely on a final Level 2 assessment, confirm the 3-year current-status rule and the affirmation requirement.
Important note
The subpart applies to unclassified contractor information systems and does not replace other security requirements, including other contractor security obligations that continue to apply.
Ready to Win Government Contracts?
Use Gov Contract Finder to discover relevant federal opportunities and prepare stronger bids.
Related Articles
What should contractors verify in “SP 800-92, Guide to Computer Security Log Management and Use Logging on Business Systems | CISA”?
A primary-source checklist for reviewing “SP 800-92, Guide to Computer Security Log Management and Use Logging on Business Systems | CISA” without relying on unsupported legacy claims.
Read more →What should contractors verify in “SP 1353, NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF…”?
A primary-source checklist for reviewing “SP 1353, NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF…” without relying on unsupported legacy claims.
Read more →What should contractors verify in “Crypto Agility | CSRC”?
A primary-source checklist for reviewing “Crypto Agility | CSRC” without relying on unsupported legacy claims.
Read more →