CMMC Ready Now
Back to Knowledge Center
Getting Started5 min read

CMMC 2.0: What Changed from Version 1.0

The 2021 overhaul collapsed five levels to three, eliminated 20 unique CMMC practices, reintroduced POA&Ms, and aligned the model directly with NIST standards. Here's what changed and why.

When DoD published CMMC 2.0 in November 2021, it was a significant course correction designed to reduce burden on small businesses, align more tightly with existing NIST standards, and address industry criticism of the original five-level model.

DimensionCMMC 1.0CMMC 2.0
Number of levels5 (Basic → Advanced)3 (Foundational / Advanced / Expert)
Total practices171 (across all levels)110 at Level 2, 130+ at Level 3
Unique CMMC practices20 beyond NIST0 (aligned entirely to NIST)
POA&M allowed?No — all controls must be metYes — conditional certification possible
Waivers allowed?NoYes — limited circumstances (national security)
Level 2 assessmentThird-party required for all Level 2C3PAO for prioritized; self-assess for non-prioritized

Why the 20 unique practices were removed

The original CMMC 1.0 included 20 practices that had no basis in any existing NIST or other federal standard. Industry feedback was that these practices were unclear, duplicative, or technically impractical. CMMC 2.0 removed all 20, aligning Level 2 exactly to NIST SP 800-171 Rev 2 (110 controls) and Level 3 to NIST SP 800-172 practices on top of Level 2.

The POA&M reintroduction — and its limits

CMMC 2.0 allows contractors to receive a “conditional” certification with an active Plan of Action and Milestones (POA&M) for controls not yet fully implemented. However, not all controls can be placed in a POA&M. Certain high-value controls — such as multi-factor authentication, encryption of CUI at rest and in transit, and incident response capabilities — must be fully implemented before certification. Open POA&M items must be closed within 180 days of certification.

What stayed the same

The underlying security controls did not change. All 110 NIST SP 800-171 Rev 2 requirements still apply to Level 2. CMMC 2.0 changed how compliance is verified and by whom, not what contractors are required to implement.

Ready to start your CMMC journey?

Book a free 30-minute call with Rick to get a straight answer on where you stand and what to do next.