CMMC Phase 2 Starts in November and Arizona Suppliers Are Not Ready
The 17 practices behind CMMC Level 1, who they apply to, how the self-assessment and SPRS affirmation work, and what changes when Phase 2 begins.
The short answer
CMMC phased implementation began in November 2025 with Level 1 and Level 2 self-assessments appearing in solicitations, and Phase 2 begins in November 2026 when third-party assessed Level 2 certifications start becoming a condition of award. Level 1 covers 17 practices, permits no plans of action, and requires an annual self-assessment with a senior official's affirmation in SPRS.
Arizona has a deep defense manufacturing and services base, and a large share of it consists of small firms two or three tiers down from a prime. Those firms are the ones most likely to discover a CMMC requirement in a solicitation they were planning to bid, three weeks before it is due.
Here is the state of play and what a small supplier needs to do.
Where the program stands
Phased implementation began on November 10, 2025, with the first phase focused primarily on CMMC Level 1 and Level 2 self-assessments. Where applicable, solicitations in this phase require a Level 1 or Level 2 self-assessment, and the phase-in runs over three years. Phase 2 begins in November 2026, when third-party assessed Level 2 certifications start becoming a condition of award for many contracts.
For a small supplier, the practical translation is that the window in which a self-assessment is sufficient for Level 2 work is closing, and Level 1 obligations are already live.
Verify current status before you rely on any of this. The program has moved several times and dates have shifted.
Which level applies to you
The determining factor is the information that touches your systems.
Federal contract information is information provided by or generated for the government under a contract, not intended for public release. Purchase orders, statements of work, delivery schedules. If that is all you handle, you are Level 1.
Controlled unclassified information is more sensitive and specifically marked. Technical drawings, specifications, export controlled data. If CUI touches your systems, you are Level 2, and that is a substantially larger undertaking built on the 110 requirements in NIST SP 800-171.
A great many small suppliers assume they handle only FCI and are wrong, because a drawing came through in an email attachment years ago and now lives on the file server. Determine this by looking, not by assuming.
The 17 practices of Level 1
Level 1 maps to the basic safeguarding requirements in the FAR clause and is genuinely achievable for a small shop. In plain terms:
Limit system access to authorized users and to the types of transactions those users are permitted. Control the flow of federal contract information on your systems and at their boundaries. Verify and control external connections and publicly accessible systems.
Identify users and devices, and authenticate them before granting access.
Sanitize or destroy media containing federal contract information before disposal or reuse.
Limit physical access to facilities and equipment, escort visitors, maintain audit logs of physical access, and control physical access devices such as keys and badges.
Monitor and protect communications at your network boundaries, and separate publicly accessible systems from your internal network.
Identify and correct flaws in a timely manner, provide protection from malicious code, keep that protection updated, and scan systems and files.
None of that requires expensive tooling. Most of it requires configuration you can do with what you already own, plus written documentation that you did it.
The self-assessment and the affirmation
You conduct the assessment annually, against every practice, and every practice must be met. Plans of action and milestones are not permitted at Level 1, so partial credit does not exist. A practice is met or your status is not achieved.
Results go into the Supplier Performance Risk System, and a senior official at your company submits an affirmation of compliance. That affirmation is a representation to the government. Affirming compliance you do not have carries False Claims Act exposure, and there have been settlements on exactly this theory. Do not sign a document that says you meet controls you have not verified.
Where small suppliers get stuck
Scope. The assessment applies to the systems that process, store, or transmit the covered information. Narrowing your scope deliberately, by keeping government work in a defined enclave rather than scattered across everything, is the single biggest cost reduction available. Do this before you assess, not after.
Documentation. Small firms usually do most of the technical controls and document none of them. The assessment expects evidence.
Email. Government-related information in a general-purpose mailbox pulls your entire mail system into scope. This is a common and expensive discovery.
The Level 2 jump. Firms that will eventually handle CUI should plan for it now rather than at solicitation time, because Level 2 certification involves a third-party assessment with scheduling lead times measured in months.
Get the workbook
The CMMC Level 1 Self-Assessment Workbook walks all 17 practices with the assessment objective, plain-language guidance on what meeting it looks like for a small business, an evidence column, a met or not met determination, a scope definition sheet, and the affirmation preparation checklist.
Run it once and you will know whether November is a deadline or a formality for your firm.
Frequently asked questions
What is the difference between CMMC Level 1 and Level 2?
The determining factor is the information touching your systems. Federal contract information, such as purchase orders and delivery schedules, means Level 1 and its 17 practices. Controlled unclassified information, such as technical drawings and export controlled data, means Level 2 and the 110 requirements in NIST SP 800-171.
Can I use a plan of action for CMMC Level 1?
No. Level 1 does not permit plans of action and milestones or partial credit. Every practice must be met before affirmation, so remediation occurs before the status is achieved.
What is the biggest cost driver in CMMC compliance?
Scope. The assessment applies to the systems that process, store, or transmit covered information, so narrowing scope deliberately by keeping government work in a defined enclave rather than scattered across everything is the single biggest cost reduction available. Do this before you assess, not after.
What are the risks of affirming CMMC compliance incorrectly?
The affirmation submitted in SPRS is a representation to the government. Affirming compliance you do not have carries False Claims Act exposure, and there have been settlements on exactly this theory. The senior official signing should have seen the evidence file.
