The certificate is not the hard part.
Phase 2 of the CMMC rollout moves third-party certification from something you plan for into something that gates the award itself. An assessor you do not employ walks your environment. Then a named person at your company signs a statement every year afterward saying it is all still true.
Most small defense suppliers are budgeting for the assessment. Very few are budgeting for the signature.
What actually changes in Phase 2, and when does the clock start?
Under 32 CFR § 170.3(e), "Implementation of CMMC Program requirements will occur over four (4) phases."
Phase 1 pegs its start to an external event. It "Begins on the effective date of the complementary 48 CFR part 204 CMMC Acquisition final rule" (§ 170.3(e)(1)). Phase 2 then "Begins one calendar year following the start date of Phase 1" (§ 170.3(e)(2)). There is no calendar date anywhere in the rule text. If someone hands you a month for Phase 2, they are quoting something other than part 170.
The substantive change is one sentence. In Phase 2, "DoD intends to include the requirement for CMMC Status of Level 2 (C3PAO) for applicable DoD solicitations and contracts as a condition of contract award."
Read "intends" literally. The same paragraph keeps DoD's discretion to "delay the inclusion of requirement for CMMC Status of Level 2 (C3PAO) to an option period instead of as a condition of contract award," and to include Level 3 (DIBCAC) where it chooses. Phase 2 is not a universal bar. It is the phase in which a solicitation can lawfully decline to award to you because a third party has not certified you.
Before award of any contract or subcontract carrying a Level 2 (C3PAO) requirement, § 170.17(b) requires two things: the Organization Seeking Certification has achieved either Conditional or Final Level 2 (C3PAO), and has submitted an affirmation of compliance.
Conditional counts. The affirmation is not closing paperwork; it is half the test.
Why can no defense subcontractor self-attest its way to Level 2 (C3PAO)?
Because the rule hands the assessment to someone else. § 170.17(a)(1) requires that the OSC "must obtain a Level 2 certification assessment from an authorized or accredited C3PAO." § 170.17(c)(1) says it again from the assessor side: "An authorized or accredited C3PAO must perform a Level 2 certification assessment."
Level 2 (Self) and Level 2 (C3PAO) are different objects in the rule. A solicitation naming the second is not satisfied by the first.
The independence is structural. C3PAOs must satisfy Accreditation Body Conflict of Interest and Ethics policies and reach ISO/IEC 17020:2012(E) compliance within 27 months of authorization (§ 170.9(b)(2)), assessment staff need a Tier 3 background investigation (§ 170.9(b)(3)), and the C3PAO must itself pass a Level 2 certification assessment run by DCMA DIBCAC (§ 170.9(b)(6)).
To reach the status, the OSC "must complete and achieve a MET result for all security requirements specified in § 170.14(c)(3)" (§ 170.17(a)(1)). Every requirement. The POA&M route below is the only relief, and it is narrow.
One thing works in your favor. Achieving Level 2 (C3PAO) "also satisfies the requirements for a CMMC Statuses of Level 1 (Self) and Level 2 (Self) ... for the same CMMC Assessment Scope" (§ 170.17(a)). One certification, three statuses, one scope.
Which subcontractors inherit the C3PAO requirement from the prime, and at which tier?
Every tier. § 170.23(a) is explicit: "CMMC requirements apply to prime contractors and subcontractors throughout the supply chain at all tiers that will process, store, or transmit any FCI or CUI on contractor information systems in the performance of the DoD contract or subcontract." Primes "shall comply and shall require subcontractors to comply with and to flow down CMMC requirements."
No tier cutoff, no exemption for being small. The trigger is the information, not your position in the chain.
The flow-down ladder in § 170.23(a) has four rungs:
→ FCI only, no CUI: "Level 1 (Self) is required for the subcontractor" (a)(1) → CUI: "Level 2 (Self) is the minimum requirement" (a)(2) → CUI, prime contract requires Level 2 (C3PAO): "the CMMC Status of Level 2 (C3PAO) is the minimum requirement for the subcontractor" (a)(3) → CUI, prime contract requires Level 3 (DIBCAC): "the CMMC Status of Level 2 (C3PAO) is the minimum requirement for the subcontractor" (a)(4)
Note what rung four does not say. A Level 3 (DIBCAC) prime does not push Level 3 down to you. It pushes Level 2 (C3PAO). Suppliers who read a DIBCAC-level prime as a DIBCAC-level obligation over-scope. Suppliers who assume self-assessment survives a C3PAO prime under-scope. Both are wrong in expensive directions.
Two facts decide your rung: whether CUI actually reaches your systems, and what the prime contract requires. The second is a question you can ask your prime before the solicitation lands.
Who is your Affirming Official, and what do they have to sign every year?
The rule requires a named human being, not a corporate signature block. An Affirming Official is "the senior level representative from within each Organization Seeking Assessment (OSA) who is responsible for ensuring the OSA's compliance with the CMMC Program requirements and has the authority to affirm the OSA's continuing compliance with the specified security requirements for their respective organizations" (§ 170.4).
Two attributes, both testable: responsibility for compliance, and authority to affirm. A coordinator without authority does not qualify, and neither does an executive with no line of sight into the control environment.
§ 170.22(a) sets four trigger points. The affirmation is submitted:
→ "Upon achievement of a Conditional CMMC Status, as applicable" → "Upon achievement of a Final CMMC Status" → "Annually following a Final CMMC Status Date" → "Following a POA&M closeout assessment, as applicable"
It binds you whether you are a prime or a sub: "An Affirming Official from each OSA, whether a prime or subcontractor, must affirm the continuing compliance of their respective organizations." Affirmations are entered electronically in SPRS, and the Department verifies submission (§ 170.22(a) and (b)).
This is the duty that outlives the certificate. The C3PAO assessment is a point in time. The affirmation is a recurring, personally attributed statement that the environment the assessor saw is still the environment you are running.
So the question is not who signs. It is what that person reads before signing. An annual attestation backed by a spreadsheet last touched at assessment time is a name on a filing with nothing underneath it.
What happens to a Conditional CMMC Status if the POA&M is not closed in 180 days?
It expires. § 170.21(b): "The closing of a POA&M must be confirmed by a POA&M closeout assessment within 180-days of the Conditional CMMC Status Date. If the POA&M is not successfully closed out within the 180-day timeframe, the Conditional CMMC Status for the information system will expire."
That closeout is not something you run yourself: "For Level 2 certification assessment, the POA&M closeout certification assessment must be performed by an authorized or accredited C3PAO" (§ 170.21(b)(2)). You are booking the assessor twice, inside a fixed window, in a market whose capacity you do not control.
If Conditional Level 2 (C3PAO) status expires during a period of performance, "standard contractual remedies will apply, and the OSC will be ineligible for additional awards with a requirement for the CMMC Status of Level 2 (C3PAO), or higher requirement, for the information system within the CMMC Assessment Scope until such time as a new CMMC Status is achieved" (§ 170.17(a)(1)(ii)(B)).
Some requirements can never sit on a POA&M. § 170.21(a)(2)(iii) bars six by name, including CA.L2-3.12.4 System Security Plan, AC.L2-3.1.20 External Connections (CUI Data), AC.L2-3.1.22 Control Public Information (CUI Data), and three physical access requirements.
The System Security Plan on that list is the one to internalise: no deferral path for the document that defines your scope.
How do you shrink what a C3PAO actually assesses before you book one?
Scope is the largest cost variable, and the rule lets you set it. "The CMMC Assessment Scope must be specified prior to assessment" (§ 170.19(a)(1)): "the set of all assets in the OSA's environment that will be assessed against CMMC security requirements" (§ 170.4).
Table 3 to § 170.19(c)(1) sorts Level 2 assets into categories with very different burdens:
→ CUI Assets are assessed "against all Level 2 security requirements" → Security Protection Assets are assessed against the requirements "relevant to the capabilities provided" → Contractor Risk Managed Assets get an SSP review; "if sufficiently documented, do not assess against other CMMC security requirements, except as noted," and any limited check "shall not materially increase the assessment duration nor the assessment cost" → Specialized Assets get an SSP review and are not assessed against other CMMC security requirements → Out-of-Scope Assets attract no assessment, but you must "prepare to justify" their inability to process, store or transmit CUI
The table closes the obvious loophole: "Assets that fall into any in-scope asset category cannot be considered an Out-of-Scope Asset." Scope reduction is an architecture exercise - separation, enclaving, documented asset treatment - not a labelling exercise.
Service providers are where scope quietly expands. Table 4 to § 170.19(c)(2)(i) sets the External Service Provider rule. Where a CSP processes, stores or transmits CUI, "The CSP shall meet the FedRAMP requirements in 48 CFR 252.204-7012." Where a non-CSP ESP does, "The services provided by the ESP are in the OSA's assessment scope and shall be assessed as part of the OSA's assessment."
§ 170.17(c)(5)(i) states the cloud baseline: the CSP offering must be "FedRAMP Authorized at the FedRAMP Moderate (or higher) baseline," or meet equivalent requirements per DoD Policy. For a non-CSP ESP, the services are assessed "against all Level 2 security requirements," and your on-premises infrastructure connecting to that provider "is part of the CMMC Assessment Scope, which will also be assessed" (§ 170.17(c)(6)).
All of it must be documented in your SSP and in the provider's customer responsibility matrix. One lever: § 170.19(c)(2)(ii) notes an ESP "may voluntarily undergo a CMMC certification assessment to reduce the ESP's effort required during the OSA's assessment."
What must you keep after the certificate is issued, and what can still take it away?
Three obligations survive the assessment.
Evidence, for six years. "The hashed artifacts used as evidence for the assessment must be retained by the OSC for six (6) years from the CMMC Status Date" (§ 170.17(c)(4)). You must hash the artifact files "using a NIST-approved hashing algorithm" and give the C3PAO the names, hash values and algorithm.
Re-certification, on a three-year cycle. "The Level 2 certification assessment must be completed within three years of the CMMC Status Date associated with the Conditional Level 2 (C3PAO)" (§ 170.17(a)(1)). Per § 170.4, the Conditional date "will remain as the CMMC Status Date after a successful POA&M closeout. A new date is not set for a Final that follows a Conditional." Your three-year clock started earlier than you think.
The affirmation, annually. As above.
And one thing overrides all of it. Under § 170.17(a)(1)(iv), DoD reserves the right to conduct a DCMA DIBCAC assessment. If the results show that adherence "have not been achieved or maintained, these DCMA DIBCAC results will take precedence over any pre-existing CMMC Status," and the OSC becomes "ineligible for additional awards with CMMC Status requirement of Level 2 (C3PAO), or higher requirement" for that scope until a new CMMC Status is achieved.
A certificate is a finding about a moment. A DIBCAC finding about a later moment beats it.
That is the design of Phase 2. The certificate opens the door. The affirmation, the artifact trail and the maintained scope keep it open. If your Affirming Official cannot see, on the day they sign, which requirements are met and which evidence supports each one, you are holding a certificate and an exposure at the same time.
Aigis GRC holds it the way an assessor reads it: every obligation traced to a verbatim quote from the source text, with asset categories, the ESP boundary and the affirmation cycle as structured data your Affirming Official can query before signing. Answer once. Assess everything. See how the obligation engine and the risk register fit together at https://agrc.ai.
FAQ: CMMC Phase 2, C3PAO certification, and annual affirmations
When does CMMC Phase 2 start? The rule gives a relative date, not a calendar one. Phase 2 "Begins one calendar year following the start date of Phase 1," and Phase 1 begins on the effective date of the complementary 48 CFR part 204 CMMC Acquisition final rule (§ 170.3(e)(1) and (2)).
Can we win a Phase 2 award while still on a POA&M? Yes, if the POA&M is a valid one. § 170.17(b) allows award where the OSC has achieved "either Conditional Level 2 (C3PAO) or Final Level 2 (C3PAO)" and has submitted the affirmation. The Conditional status then expires if closure is not confirmed within 180 days of the Conditional CMMC Status Date (§ 170.21(b)).
Our prime is Level 3 (DIBCAC). Do we need Level 3? No. Where a subcontractor handles CUI and the prime contract requires Level 3 (DIBCAC), "the CMMC Status of Level 2 (C3PAO) is the minimum requirement for the subcontractor" (§ 170.23(a)(4)). That is the floor; the contract may require more.
Who can sign the annual affirmation? A senior representative from inside your own organization who is responsible for CMMC compliance and has the authority to affirm continuing compliance (§ 170.4). It cannot be delegated to your C3PAO, prime, or service provider. Each OSA, prime or subcontractor, affirms for itself (§ 170.22(a)).


