CMMC Level 2 for Leadership in 2026: Executive Accountability and Budget Ownership
Executive Brief
Cybersecurity Maturity Model Certification (CMMC) Level 2 was built as a technical framework, but the accountability behind it has never lived in IT alone. That is truer in 2026 than it was a year ago.
On July 13, 2026, the Department of War (DoW) paused mandatory third-party (C3PAO) certification requirements while a Reform Task Force reviews the program. Some executives are reading that pause as a reason to step back. It’s actually a reason to lean in, since self-assessment puts more of the accountability directly on leadership.
- CMMC Level 2 self-assessment, and all other CMMC levels, requires a senior company official, known as an Affirming Official, to personally certify the results in the Supplier Performance Risk System (SPRS)
- Budget decisions for CMMC readiness cannot be made on a single fiscal-year cycle if they’re tied to multi-year contract pipelines
- Organizations that pass assessments consistently share the same leadership pattern: executive sponsorship, cross-functional ownership, and budget tied to contract exposure rather than a single deadline
- None of this changes because a certification mechanism is under review. The underlying obligation, and the accountability for it, still sits with leadership.
Dig deeper below to learn more.
Why Leadership Accountability Matters More Right Now
The certification mechanism under review is the third-party (C3PAO) assessment, not the standard itself. National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 2 and Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 remain fully in force during this review period.
- A C3PAO is an outside check between a documentation gap and a submitted score, and now that check is on hold
- Self-assessment still requires certifying that all 110 NIST SP 800-171 controls are met, and that certification is signed by a person, not a department
- False Claims Act exposure applies to a certification that the signer knew, or had reason to believe, was false. It’s not triggered by an honest mistake, but it’s a real risk when leadership treats the signature as a formality rather than a verified claim
Understanding the Affirming Official Role
Under CMMC 2.0, a senior official inside your organization, known as the Affirming Official, personally certifies your self-assessment results in the Supplier Performance Risk System (SPRS). For most contractors, that is the CEO, another senior executive, or, where the role exists, the Facility Security Officer (FSO).
- Many organizations delegate the signature without delegating real oversight of what’s being signed
- The Affirming Official is in the strongest position when they have reviewed the evidence behind the score, not just the summary
- They should also be present during the self-assessment itself, and the same expectation applies to any future C3PAO assessment or Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) review. They do not need to lead it, especially when working with a Managed Service Provider (MSP), but they need a solid working understanding of what is being assessed
- This is the same gap behind most failed assessments: a System Security Plan (SSP) that describes controls an organization intends to have in place, or a self-assessment score built from assumptions, instead of a verified account of what is implemented in the environment today
A signature carries more weight when there is a documented Shared Responsibility Matrix (SRM) behind it, showing exactly which controls your organization owns and which a provider owns. That clarity is what protects the person signing, and it’s a reasonable thing for leadership to ask for before anyone puts their name on an attestation.
Budget Ownership: Why This Cannot Sit with IT Alone
CMMC readiness isn’t a single line item on an annual IT budget. CMMC readiness isn't a single line item on an annual IT budget. For government contracting businesses, it deserves its own dedicated line item: a multi-year commitment that must be planned against your contract pipeline, not against a certification deadline that can move.
- Budgeting after a solicitation drops is the most expensive way to fund CMMC readiness, since it forces rushed remediation instead of planned investment
- Outsourced compliance models can meaningfully reduce upfront costs compared to building an equivalent capability in-house, particularly for small and mid-sized contractors
- Budget cycles that don’t account for recompetes, option years, and prime flow-down timing consistently underfund readiness when it’s needed most
Our Compliance Without Compromise guide breaks down where compliance costs concentrate, how outsourced and in-house models compare, and why early budgeting consistently outperforms reactive spending. It’s worth a look before your next budget cycle locks in.
What Good Looks Like from the Top Down in 2026
"If CMMC only shows up on the leadership agenda when news drops, you're already behind. The contractors who pass consistently treat it as a standing business risk, reviewed with the same rigor as revenue forecasts and signed by an executive who understands and verifies the evidence and process," says Ketan Patel, MBA, CISA, ISI Senior Vice President, Compliance.
- Executive sponsorship that treats CMMC as a standing business risk item, not a project that gets revisited only when a contract requires it
- A cross-functional steering group that includes legal, finance, HR, operations, and IT, not just IT reports to leadership after the fact
- Budget aligned to contract exposure and renewal timing, reviewed at least annually against the actual pipeline, not against a single regulatory date
- Gap assessment results reviewed directly by leadership, not summarized down to a single pass or fail number before they reach the top
- An Affirming Official who has seen the evidence behind the score they are about to sign
None of this requires waiting for the CMMC Reform Task Force to finish its review. The standard, the attestation, and the accountability for both are already in place, and they will most likely still be in place whatever the Task Force recommends. The organizations that treat 2026 as a leadership problem, not just a technical one, are the ones that will be ready regardless of what changes next.
FAQs
Who must sign the CMMC Level 2 self-assessment attestation?
A senior official inside your organization, known as the Affirming Official, personally certifies your self-assessment results in SPRS. That’s typically the CEO, another senior executive, or, where the role exists, the FSO, and the requirement is unaffected by the Phase II suspension.
Does the C3PAO requirements pause increase personal liability for executives?
It doesn’t change the underlying standard. False Claims Act exposure applies when a certification was known, or reasonably believed, to be false, not from an honest mistake. Removing the third-party check means that verification now must happen internally before anyone signs.
How should budget planning for CMMC differ from typical IT budgeting?
It needs to be planned against your contract pipeline over multiple years, not a single fiscal year or a single regulatory deadline. Waiting until a solicitation requires certification is consistently the most expensive path.
Should leadership wait for the Task Force review before budgeting for CMMC?
No. DFARS 252.204-7012 and NIST SP 800-171 Revision 2 obligations are unchanged, and readiness work completed now remains applicable under any outcome of the review.



