Updates to CMMC 2.0 policy for defense awards

News for Researchers

Posted September 4, 2026 by Ashley Washburn

A new rule applying to Department of Defense awards took effect Nov. 10, 2025. This rule launched a tiered three-year rollout of cybersecurity requirements called Cybersecurity Maturity Model Certification 2.0. Originally introduced in 2020, CMMC is a pre-award assessment required to ensure potential awardees have implemented required cybersecurity protections. The new rule, CMMC 2.0, is a simpler version that more closely aligns with existing standards such as NIST SP 800-171. 

In practice, to apply for or receive new awards from DOD, UNL is required to implement specified requirements. CMMC 2.0 has three levels, with increasing controls depending on the security level needed for the work being done. The required security level is determined by the contract.

It was anticipated that DOD solicitations would start requiring Level 2 certifications starting in November 2026 as part of Phase II implementation. As of July 13, 2026, Phase II has been suspended for 60 days to allow DOD to review and address concerns from potential awardees. The self-assessment requirements have not been suspended. 

University of Nebraska leadership, research offices for each campus and Information Technology Services have been working to assess and prepare for CMMC 2.0 requirements since January 2024, almost a year before the final rule was published. The university has completed its self-assessments, is conducting mock assessments with external assessors, and is working to contract with a C3PAO. The intended timeline for Level 2 certification is by the end of 2026 and/or in conjunction with the recent DOD suspension. 

Researchers in the DOD space can expect significant changes compared to prior requirements. To implement the required cybersecurity controls for Level 2, a transition into a new secure environment (enclave) will be needed.

Additional information will be shared with impacted faculty and their departments and colleges as it becomes available.

For questions, contact the Research Compliance, Integrity and Security office via email or at 402-472-4491.


Back to News for Researchers