What Is CMMC 2.0?

The Cybersecurity Maturity Model Certification (CMMC) is a Department of Defense program requiring contractors and subcontractors in the Defense Industrial Base (DIB) to demonstrate cybersecurity compliance before receiving contracts involving Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). CMMC 2.0, which took effect in late 2024, defines three levels of certification:

  • Level 1 (Foundational) — 17 basic practices protecting FCI. Annual self-assessment. No penetration testing required.
  • Level 2 (Advanced) — 110 practices from NIST SP 800-171 for CUI. Third-party assessment every three years, annual self-affirmation. Penetration testing not explicitly required but often identified as a practice to implement.
  • Level 3 (Expert) — 110+ practices from NIST SP 800-172 for the most sensitive CUI. Government-led assessments. Penetration-type testing is effectively required through the comprehensive control set.

The October 2026 Deadline

Full CMMC 2.0 implementation takes effect for DoD contracts in October 2026. From that point, contractors must demonstrate the appropriate certification level before contract award. Contracts already in place will require compliance on a rolling basis as they renew. Organizations that have not begun their compliance journey face real risk of being locked out of DoD contracting.

How Penetration Testing Applies to CMMC

For Level 2, NIST SP 800-171 includes control CA-8, which requires penetration testing be conducted periodically and upon significant changes. While Level 2 assessments focus primarily on documentation and implementation evidence, CMMC assessors are trained to verify that security controls actually work — not just that policies exist on paper. Network penetration testing provides the most defensible evidence that access controls, segmentation, and detection capabilities are functioning as claimed.

For Level 3, the comprehensive NIST SP 800-172 control set includes more advanced requirements around adversary simulation, red team exercises, and continuous monitoring that effectively require penetration-type assessments.

The Flow-Down Problem

CMMC requirements flow down the supply chain. If a prime contractor is subject to CMMC Level 2, any subcontractor that handles CUI on their behalf is also subject to Level 2. Many small and mid-size defense suppliers are discovering that their prime contractor relationships require CMMC compliance they did not anticipate. This is driving significant demand for independent security testing among companies that have never conducted formal pentesting before.

Working toward CMMC compliance?

Grid32 provides network and application penetration testing that supports CMMC Level 2 and Level 3 evidence requirements. Don't wait until 2026.

Get a Quote →