Introduction
CMMC has moved from proposed policy to an enforceable contract requirement. Formalized into the Defense Federal Acquisition Regulation Supplement in November 2025, the Cybersecurity Maturity Model Certification now has a hard date attached to its next phase: from November 10, 2026, the Department of Defense can condition contract awards on third-party CMMC Level 2 certification for any work involving Controlled Unclassified Information, and Level 3 assessment for the highest-sensitivity contracts. This is not a US-only concern. Any organization in the defense supply chain - including European subcontractors, technology vendors, and service providers supporting US defense programmes - falls inside the requirement if CUI passes through their systems.
The Three Levels, Briefly
- Level 1: basic safeguarding of Federal Contract Information, verified by annual self-assessment
- Level 2: full alignment with all 110 controls in NIST SP 800-171, generally requiring third-party assessment by a Certified Third-Party Assessment Organization (C3PAO) from Phase 2 onward, with self-assessment permitted for a subset of contracts every three years plus annual affirmations
- Level 3: the highest tier, assessed by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), reserved for the most sensitive programmes
Why This Matters Outside the United States
CMMC flows down through the supply chain by contract clause, not by geography. A European systems integrator, cloud service provider, or component manufacturer supporting a US prime contractor is bound by the same requirement as a US-based subcontractor if Controlled Unclassified Information touches their environment. For European companies pursuing US defense-adjacent business - a stated growth objective for organizations expanding into the American market - CMMC readiness is no longer a distant US policy question. It is a prerequisite that determines whether a bid is even eligible for award consideration once Phase 2 takes effect.
The evidence problem inside 110 controls
NIST SP 800-171's 110 controls break down into 320 individual assessment objectives, each of which a C3PAO assessor expects to see supported by evidence, not attestation. Organizations preparing for Level 2 consistently report that documenting audit logs, access records, and configuration history across 14 control families is the heaviest lift of the entire certification - heavier than implementing the controls themselves. A control that exists but cannot produce a defensible evidence trail for the assessment window will not pass.
Building the evidence trail before Phase 2 lands
Organizations that treat CMMC evidence as something assembled in the weeks before a scheduled C3PAO assessment consistently underestimate the lift. Assessment objectives that reference access history, configuration change logs, and incident records require a continuous trail stretching back through the assessment period - not a snapshot manufactured retroactively. Starting that trail now, ahead of the November 2026 deadline, is the difference between an assessment that draws on existing evidence and one that requires reconstructing months of history from memory and disconnected systems.
For European organizations pursuing US defense-adjacent contracts, CMMC readiness is now a market-access requirement, not a future consideration. See how ROOTKey builds continuous, audit-ready evidence trails for compliance frameworks including NIST SP 800-171.
Erhalten Sie Einblicke zur Cyber-Resilienz per E-Mail
Praktische, auditfähige Hinweise zu Datenintegrität, Compliance und Kontinuität – sobald wir veröffentlichen.





