CMMC Phase 2 starts November 10, 2026: what small defense contractors should do about their network
On November 10, 2026, CMMC enters Phase 2. From that date, Defense Department contracts that involve Controlled Unclassified Information (CUI) can require a third-party CMMC Level 2 assessment before award. If you're a small manufacturer, machine shop or subcontractor in the Defense Industrial Base, here's what that means and where your network fits in.
What changes on November 10
Phase 1 began on November 10, 2025, when CMMC requirements started showing up in new solicitations, mostly as self-assessments. Phase 2 adds the big one: for contracts that call for it, a Certified Third-Party Assessment Organization (C3PAO) has to assess your Level 2 practices. Level 2 is built on NIST SP 800-171, which has 110 security requirements.
It doesn't only apply to primes. If your customer shares CUI with you, CMMC requirements flow down to you too. That can mean drawings, specs or contract data.
Your network is one part of the picture
Most of those 110 requirements are about people, policies and computers: training, access control, multi-factor sign-in, patching, logging, incident response and your System Security Plan (SSP). A handful sit at the network layer. In plain terms, an assessor will want to see that:
- Your network boundary is protected, with traffic from the internet controlled.
- The computers that handle CUI are separated from everything else, like guest Wi-Fi, printers and smart devices.
- You control which devices can join your network, especially over Wi-Fi.
- Your wireless network is protected with authentication and encryption.
Five practical steps before November
- Find where CUI lives. List the people, computers and services that touch it. That list shapes your assessment scope.
- Separate CUI machines. Put them on their own network segment so a flat network doesn't pull every device in your building into scope. Your assessor decides the final scope, but a clear boundary makes their job, and yours, easier.
- Control what joins. New devices shouldn't get onto your network just because someone knows the Wi-Fi password.
- Write it down. Record your network layout, which devices sit in the CUI segment and how they're protected. Your SSP needs it.
- Don't stop at the network. Multi-factor sign-in, endpoint protection, policies and training cover far more of the 110 requirements than any router can. If you haven't already, talk to a Registered Practitioner Organization (RPO) or a C3PAO early. Assessment calendars fill up.
Where Rio fits, honestly
Rio is a router built for small businesses that can't afford an enterprise security stack. It helps with the network layer:
- SecureRooms give you up to 16 isolated network segments, so CUI machines can sit apart from guests and everything else.
- Device approval lets you hold new devices until an admin approves them in the Rio app, and block anything you don't recognize.
- A firewall at the internet boundary blocks unsolicited inbound traffic from day one.
We publish a full NIST SP 800-171 control mapping so you know exactly where Rio fits. Out of the 110 requirements, it rates Rio as supporting 2 and partially covering 13, all at the network layer. The other 95 need other tools, policies or procedures, and the mapping says so plainly.
A few limits are worth knowing up front. Rio VPN is a privacy VPN for outbound traffic, not a remote-access VPN, so it doesn't cover remote-access requirements. FIPS validation of Rio's encryption is not confirmed, so don't rely on Rio for requirements that need FIPS-validated cryptography. And no product makes a company CMMC compliant. Your assessor reviews your whole program.
Read the NIST 800-171 control mapping, or see Rio for Defense: the same Rio router with priority support and one free replacement if it fails or is damaged in the first year.
The short version
November 10, 2026 is close. Start with where your CUI lives, put a clear boundary around it, control what joins your network, and document it. The network piece is one of the most visible parts of an assessment, and one of the easiest to get in place early.
This post is general information, not legal or compliance advice. Check your contract requirements and work with a qualified CMMC professional.
