The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

CMMC Remediation Services: How to Close Your Gaps Without Hiring the Wrong Provider

The Defense Compliance Report Editorial TeamIndependent CMMC and DIB compliance research
Published: Last reviewed:
Editorial research — not formally reviewed by a CMMC Subject Matter Advisor. Verify scope and applicability with a Registered Practitioner before acting.

The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance — not affiliated with, endorsed by, or acting on behalf of the Department of Defense, the Cyber AB, the CAICO, DCMA DIBCAC, NIST, or any U.S. government agency. This is educational content, not legal, contractual, cybersecurity, or compliance advice. Please don't submit CUI, contract numbers, system diagrams, vulnerability details, or any sensitive security information through any form on this site.

CMMC remediation servicesare the hands-on work of closing the gap between your current security posture and the cybersecurity your defense contracts actually require — implementing missing controls, writing your System Security Plan (SSP) and Plan of Action & Milestones (POA&M), standing up tools, and raising your score in the Supplier Performance Risk System (SPRS), the Department of Defense database that stores CMMC statuses and self-assessment results. If you handle Controlled Unclassified Information (CUI), you're in Level 2 territory: 110 requirements across 14 control families, verified by self-assessment or a third-party C3PAO assessment depending on your contracts.

Here's the part most vendors won't say out loud, and it's the single most expensive mistake we see: for a Level 2 certification assessment, the firm that prepared you generally can't be the firm that certifies you — for three years. We'll show you exactly what that rule says and what to do about it, below.

The answer changes if you only handle Federal Contract Information (FCI) under Level 1(15 requirements from FAR 52.204-21, self-assessed annually, all requirements MET, no POA&Ms), or if you already score 88 or higher and simply need an assessor. Use the table below to find yourself fast.

Start here: find your situation

If this is youYou probably need firstDon't start withYour next move
You handle only FCI (Level 1)An internal owner, light readiness help if anyA C3PAOConfirm the 15 FAR 52.204-21 safeguards and file your annual affirmation
You handle CUI but have no real SSPAn RPO / readiness leadA C3PAOLock scope, build the SSP, POA&M, and an evidence map
Your SPRS score is low, negative, or staleA readiness lead + technical remediationA certification assessorTurn gaps into a prioritized, owner-assigned plan
Your MSP says "we do CMMC" but can't show evidenceA CMMC-capable MSP/MSSP + readiness leadA software-only fixVerify they map work to NIST 800-171 objectives
CUI is scattered across email, drives, endpointsA scoping/enclave strategyMigrating everything before scopingDecide whether to shrink scope before you buy tools
You already score 88+ and are ready to certifyA separate, authorized C3PAOThe same consultant who prepped youRun final independence and evidence checks

Not sure which row you're in?

Tell us your level, scope, environment, and timeline — without submitting any CUI — and we'll match you with source-checked CMMC provider options that fit.

Find my remediation path →

What are CMMC remediation services?

CMMC remediation services close the gaps that stand between your current environment and a passing CMMC status — bad scoping, missing NIST SP 800-171 controls, thin SSP and POA&M documentation, weak evidence, and the wrong environment for CUI. It's the doing phase. It sits between the gap assessment (which finds the problems) and the formal assessment (which verifies they're fixed). For Level 2, “done” means you've actually implemented the 110 NIST SP 800-171 Revision 2 requirements, documented them in an SSP, and produced evidence an assessor can verify.

Remediation is not one service. It's a sequence — scope, document, implement, prove, operate — and different parts of that sequence are best handled by different kinds of providers. Treating it as a single thing you buy from one vendor is how budgets blow up and certifications get delayed.

Where remediation fits in the CMMC process

PhaseWhat happensWho typically leadsWhat you walk away with
1. Gap assessmentMap your CUI/FCI, score against NIST 800-171, identify findingsRPO / readiness consultantA scored gap register and a baseline SPRS score
2. RemediationFix the findings: controls, SSP, POA&M, tooling, evidenceRPO + MSP/MSSP / enclave / GRCA defensible environment and an evidence package
3. AssessmentSelf-assessment, or a formal C3PAO assessment if requiredYou, or a separate C3PAOA CMMC status posted in SPRS
The mistake we see most often is jumping from a vague sense of “we need CMMC” straight to either buying a tool or scheduling a C3PAO. Both skip the part that actually moves your score: closing the findings and producing evidence that maps to the requirements.

What a real remediation engagement includes

Remediation breaks into a handful of workstreams. A credible provider can tell you which ones they own, which ones they don't, and what proof each one produces.

WorkstreamExamples of the workEvidence it producesBest-fit provider
ScopingCUI/FCI data-flow mapping, asset inventory, defining the boundaryData-flow diagram, asset inventory, SSP scopeRPO / readiness lead
DocumentationSSP, POA&M, policies, proceduresUpdated SSP, control narratives, POA&MRPO / RP-led consultant
Technical controlsMFA, logging, EDR, configuration, vulnerability managementConfigs, screenshots, log reports, ticketsMSP / MSSP
CUI environmentGCC High, AWS GovCloud, enclave, secure collaborationArchitecture, responsibility matrix, SSP updatesEnclave / cloud implementer
Evidence workflowEvidence collection, owner tracking, recurring reviewsEvidence repository, task history, affirmation calendarGRC / workflow software
Assessment readinessMock assessment, objective-by-objective reviewReadiness findings, remediation punch listRPO / readiness lead
Notice what's noton this list as a standalone fix: “buy a platform.” Software supports several of these workstreams. It implements none of them on its own.

Do you actually need CMMC remediation right now?

You need CMMC remediation when a gap assessment, a low or stale SPRS score, a prime's flow-down, a solicitation clause, or an internal CUI review shows your environment doesn't meet the CMMC level your contracts require. Under the program rule — 32 CFR Part 170, effective December 16, 2024 — CMMC applies to any contractor information system that processes, stores, or transmits FCI or CUI, and the required level is written into the solicitation and the contract.

Here's the detail that surprises people, and the reason “we'll deal with it when our prime asks” is a dangerous plan: the eligibility decision happens before you're awarded anything. A solicitation provision called DFARS 252.204-7025 (“Notice of Cybersecurity Maturity Model Certification Level Requirements,” effective November 10, 2025)tells offerors which level the contract requires. Per 48 CFR 252.204-7025, if you don't have the current required CMMC status at the time of offer, you are ineligible for award — full stop. Remediation isn't something you do after you win; it's what determines whether you can compete.

Which DFARS clauses matter during remediation?

ClauseWhat it doesWhy it matters during remediationPrimary source
252.204-7012Safeguarding covered defense information and cyber incident reporting; baseline obligation to implement NIST SP 800-171This is the underlying duty CMMC verifies; FedRAMP-equivalency for cloud handling CUI traces hereAcquisition.gov
252.204-7019Requires a current (within 3 years) NIST SP 800-171 DoD Assessment posted in SPRS to be eligible for awardYour baseline SPRS score lives here; remediation raises itAcquisition.gov
252.204-7020Government access for higher-level assessments; flow-down of the assessment requirement to subcontractorsSets up DoD/DIBCAC's right to verify your workAcquisition.gov
252.204-7021The CMMC contract clause: requires holding the required CMMC status and affirmation during performance, and flow-downThe ongoing obligation once you winAcquisition.gov
252.204-7025Solicitation provision notifying offerors of the required CMMC level; no current status = ineligible for awardThe gate you must clear before awardAcquisition.gov / 48 CFR 252.204-7025

The timing math you can't argue with

Two dated facts make the urgency real, not manufactured:

Put those together with a 6-to-12-month remediation timeline, and the picture is simple: if you need a certified posture for a 2027 opportunity, mid-2026 is not early. It's about right — and possibly tight.

What just happened that sent you here

TriggerWhat it meansFirst remediation move
New solicitation with DFARS 252.204-7025The contracting officer has named a required level; no status = no awardConfirm the exact level and assessment type, then scope
Prime flowed down CMMC languageYour status now gates your subcontractGet the required level and information type in writing
Low / negative / stale SPRS scoreYour documented posture fails the thresholdConvert findings into a prioritized plan
Gap assessment deliveredYou have a punch list, not a planSequence the work and assign owners
You scheduled a C3PAO too soonYou may pay for an assessment you'll failPause; build readiness first
You found CUI in email, drives, or endpointsYour scope is bigger than you thoughtMap data flows before buying anything

One honest disqualifier

If you handle only FCI and your contracts require Level 1, you likely don't need a remediation program in the sense this page describes. Level 1 is 15 requirements from FAR 52.204-21, self-assessed annually with an affirmation, all of which must be MET — and POA&Ms aren't permitted at Level 1 at all. Confirm your basics, file your affirmation, and skip the six-figure conversation. See our CMMC Level 1 vs Level 2 guide if that's you.

Get matched before the queue tightens

If you handle CUI and have open gaps, the smart move is to start now. Send us the non-sensitive basics — level, scope, environment, timeline — and we'll point you to source-checked provider categories that fit, so you don't lose weeks guessing.

Find my remediation path →

How much do CMMC remediation services cost in 2026?

For CMMC Level 2, remediation typically runs $10,000 to $150,000+, and it's the single largest and most variable cost in the whole effort. Your number depends on your starting SPRS score, the size of your CUI scope, your environment (commercial Microsoft 365 vs. GCC High vs. an enclave), and how much of the work you can do in-house. Small businesses generally land near $50,000–$130,000 all-in for Level 2; mid-size firms, $100,000–$200,000.

We'll be straight with you: there is no honest flat price for remediation. Anyone who quotes you a fixed number before mapping your CUI and scoring your gaps is guessing. The cost lives in what's broken, and nobody knows that until someone looks. That's not a dodge — it's the reason a gap assessment comes first.

What remediation actually costs, by component

DCR market-planning estimate, last verified June 3, 2026. Compiled from multiple 2026 cost analyses and DoD's own published estimates. Planning ranges, not quotes.

Cost componentTypical 2026 rangeNotes
Gap / readiness assessment$3,500 – $40,000RPO small-business work often $5K–$10K; complex environments $15K–$25K+
SSP + documentation$5,000 – $60,000DIY $5K–$15K; consultant-built $15K–$40K; full packages higher
Control implementation (the labor)$10,000 – $150,000+The big variable; some complex Level 2 efforts reach $250K
Tooling / licensing (MFA, SIEM, EDR, scanning, encryption)$10,000 – $50,000+ /yrRecurring, not one-time
CUI enclave / secure collaboration$300–$400 /user/mo, or $3,000–$4,000+ /mo managedScales with users or managed scope
vCISO / fractional compliance lead (if used)$250–$400 /hr; $50K–$300K full programsDirection and accountability
Ongoing maintenance~15–30% of initial, annuallyAffirmations, monitoring, renewals
DoD's own assessment-fee estimates(from the program rulemaking, charged every three years): Level 1 self ~$4,000–$6,000; Level 2 self ~$37,000–$49,000; Level 2 C3PAO ~$104,000–$118,000. For many organizations, remediation and recurring tooling end up larger than the assessment fee — which is exactly why the assessment shouldn't be your first purchase. See our full CMMC certification cost breakdown.

Level 3 is not a simple add-on

It requires reaching Final Level 2 (C3PAO) status first, then a government DIBCAC assessment against 24 additional requirements selected from NIST SP 800-172. Budget it as its own program, not a line item.

A few things that genuinely move your number, up or down:

Free and lower-cost help for small businesses

Before you spend, check the free or lower-cost help that exists for the DIB: APEX Accelerators (DoD-funded procurement assistance), Project Spectrum (a DoD-sponsored cybersecurity readiness platform), and the NIST Manufacturing Extension Partnership (MEP) network support small-business cybersecurity readiness. See also our guide to CMMC for small defense contractors.

Request scoped quotes by category, not guesswork

Tell us what you already have — an SSP, a POA&M, your current environment, your provider, and your deadline — and we'll help you identify source-checked options in the right category so the quotes you collect are actually comparable.

Find my remediation path →

Who should do your CMMC remediation: RPO, MSP/MSSP, vCISO, enclave, GRC software, or C3PAO?

The right provider depends on the bottleneck, not the marketing label. Scope and documentation problems need advisory help (an RPO or readiness lead). Missing technical controls need an implementer (a CMMC-capable MSP/MSSP). CUI spread everywhere may need an enclave strategy. Scattered evidence may need GRC software. And formal certification needs a separateC3PAO. Match the provider to the gap that's actually blocking you.

The CMMC Remediation Provider-Fit Matrix

DCR editorial conclusion based on verified regulatory facts — reflects how we'd sequence the work, not a regulatory ordering of providers.

Your actual problemBest first provider categoryWhat they should produceWhat they should not claimHow to verify
You don't know if your data is FCI, CUI, or bothScoping-led RPO / readiness consultantCUI/FCI data-flow map, asset inventory, boundary recommendation, SSP scope"We can certify you" or "just buy this platform"CMMC applies to systems handling FCI/CUI; the contract names the level (32 CFR Part 170)
You handle CUI and have no defensible SSPRPO / readiness consultantSSP, POA&M, gap register, evidence map, control-owner mapA formal certification assessmentNIST SP 800-171 Rev. 2 requires documented implementation; DFARS 7019/7020 govern SPRS scoring
Technical controls are missing or weakCMMC-capable MSP/MSSP + a readiness leadMFA, logging, EDR, configuration, vulnerability, backup, incident-response evidence"Installing the tool means you're CMMC-ready"Level 2 = 110 requirements across 14 families; evidence must map to objectives (NIST SP 800-171A)
CUI is sprawled across email, drives, endpoints, vendorsCUI enclave / GCC High / GovCloud provider + a scoping leadReduced-scope design, responsibility matrix, data-flow map, SSP updates"An enclave is a shortcut to certification"Level 2 scoping defines asset categories per 32 CFR §170.19
Evidence is scattered and tasks slipGRC / evidence software + a readiness ownerEvidence repository, POA&M workflow, owner accountability, affirmation calendar"The software implements the controls for you"Artifacts, SSP, POA&M, and affirmations must be supportable in SPRS
You already score 88+ and are assessment-readyA separate authorized / accredited C3PAOFormal Level 2 assessment, findings report, status in SPRSHelping you prepare for the same assessment it will conductC3PAO must be current on the Cyber AB Marketplace
You hold Conditional Level 2 with an open POA&MYour remediation owner + the applicable closeout pathClosed POA&M items, updated evidence, closeout package"A POA&M can cover anything, indefinitely"Conditional status requires POA&M closeout within 180 days (32 CFR 170.21)

A quick tour of the categories

Registered Provider Organization (RPO)

A consultancy listed on the Cyber AB Marketplace whose people (Registered Practitioners, or RPs, and often Certified CMMC Professionals/Assessors) provide preparation and advisory services. RPOs are your scope, SSP, POA&M, and readiness leads. They cannot issue your certification. See our comparison of RPOs vs. C3PAOs.

CMMC-capable MSP / MSSP

A managed service or managed security provider that actually builds and runs the technical controls — identity, logging, endpoint protection, configuration. Important: an MSP that handles your CUI becomes an External Service Provider (ESP) in your scope, with documentation and assessment obligations. Evaluate MSPs by what they can access, not their marketing category.

vCISO / fractional compliance lead

Strategy, prioritization, and accountability when you have IT but lack direction. Often the cheapest way to keep a program from drifting.

GRC / compliance software

Tools that automate documentation, evidence collection, and POA&M tracking. A genuine help — and a genuine trap if you mistake it for the whole solution. Software doesn't implement controls or pass assessments.

CUI enclave / secure collaboration

GCC High, AWS GovCloud, or a purpose-built CMMC enclave — the most powerful scope-reduction lever available to most companies. Isolating CUI into a controlled environment can shrink what must be protected and assessed. It doesn't eliminate the need for an SSP, evidence, or control implementation.

C3PAO

A CMMC Third-Party Assessment Organization, authorized by the Cyber AB to conduct Level 2 certification assessments. This is the only entity that can certify you for a Level 2 (C3PAO) contract — and, as you'll see next, it generally cannot also be the firm that prepared you. See our guide to finding an authorized C3PAO.

Compare provider categories before you spend a dollar

Send only the non-sensitive basics — level, scope, current environment, timeline — and we'll point you to the remediation category that fits your bottleneck, so you're not paying a documentation specialist to fix firewalls.

Find my remediation path →

Can one company handle both your remediation and your assessment?

No — and this is the most important rule on this page. Federal regulation bars the firm that prepared you from sitting on your Level 2 certification assessment. Specifically, 32 CFR §170.8(b)(17)(ii)(G) prohibits CMMC Ecosystem members from participating in the Level 2 certification assessment process for any assessment in which they previously served as a consultant to prepare that organization — for three years. The Cyber AB's Code of Professional Conduct (CoPC v2.0) quotes this directly and confirms it applies to the C3PAO as an organization and to all of its assessment team members.

Why the firewall exists

The logic is simple: a firm that assessed a client it had just consulted for would be grading its own homework. Impartiality is the whole point of a third-party certification. If the line blurs, the certification means nothing — and an assessment performed in a conflict can be challenged, which is far more expensive than doing it right the first time.

What this actually means for choosing a partner — and why it's good for you

The dream of “one vendor does everything” is exactly the wrong instinct here. Instead:

Reframed, the firewall is a feature. It's the reason a CMMC certification carries weight with a contracting officer — and it's why a readiness partner who respects the boundary is showing you competence, not a limitation.

Separate readiness from assessment the right way

Want it handled end-to-end without tripping the conflict rule? We'll match you with a readiness partner to close your gaps and help you line up an independent C3PAO for the assessment — two clean engagements, one path.

Find my remediation path →

What should a CMMC remediation plan look like?

A real CMMC remediation plan maps every gap to a specific requirement, the system it affects, an owner, the evidence that will prove it's fixed, a due date, and the consequence if it's not closed. It is not a wish list. A POA&M only counts under strict rules — Conditional Level 2 and Level 3 status depend on closing valid POA&M items within 180 days, and Level 1 doesn't permit POA&Ms at all (32 CFR 170.21). If your “plan” is a spreadsheet of vague intentions, it won't survive an assessment.

The difference between a punch list and a plan is ownership and evidence. Here's the structure we recommend, and what a few rows look like in practice.

Remediation plan template

GapRequirement familyAffected systemFix ownerEvidence neededPOA&M-eligible?Closeout risk
MFA not enforced for privileged accessAccess Control / Identification & AuthenticationIdentity providerMSP/MSSPConfig screenshots, policy, user sampleDepends on the specific requirement and scoreHigh
SSP missing a system boundarySecurity AssessmentWhole CUI environmentRPO / readiness leadSSP section, architecture diagramNo — the SSP itself cannot be deferredHigh
Logs not centralizedAudit & AccountabilityServers / endpoints / cloudMSP/MSSPSIEM/log reports, retention settingsDepends on assessment statusMedium–High
CUI in unmanaged file sharesMedia Protection / Access ControlFile sharesEnclave/cloud + readinessData-flow map, migration evidenceScope-dependentHigh

The sequence that works

  1. 1. Scope your CUI/FCI boundary first

    Misjudging your CUI footprint is one of the most expensive mistakes in the entire program. Shrink before you fix. See our guide on the enclave-vs-enterprise decision.

  2. 2. Baseline your SPRS score

    Know your real starting point before committing to a timeline or a provider.

  3. 3. Build the SSP

    The document an assessor asks for first. CA.L2-3.12.4 (the SSP requirement) cannot go on a POA&M — it must be in place.

  4. 4. Prioritize the POA&M

    Sequence around impact and the items you can't defer. The six prohibited requirements must be fully implemented; everything else flows from there.

  5. 5. Implement controls and deploy tools

    Where most of the cost and time live. Match technical implementation to an MSP that can map work to NIST 800-171A evidence objectives.

  6. 6. Collect and organize evidence

    Evidence that can't be produced at assessment time is evidence that doesn't exist. Build your evidence repository before you schedule the C3PAO.

The 6 requirements that can never go on a POA&M

Under 32 CFR §170.21(a)(2)(iii), these six Level 2 requirements must be fully implemented to achieve any CMMC status. Missing any one of them means no Conditional pass — just no status:

  • AC.L2-3.1.20 — Verify and control all connections to external systems
  • AC.L2-3.1.22 — Control CUI posted or processed on publicly accessible systems
  • CA.L2-3.12.4 — The SSP itself — your environment description must exist
  • PE.L2-3.10.3 — Escort visitors and monitor visitor activity
  • PE.L2-3.10.4 — Maintain audit logs of physical access
  • PE.L2-3.10.5 — Control and manage physical access devices

How we built this guide

The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We built this guide by separating three kinds of claims: regulatory facts (cited to primary sources), market facts like cost and assessor capacity (cited and dated, because they change), and editorial judgmentslike which provider category fits a situation (clearly framed as our conclusions). We don't sell remediation. We route readers to the right category.

What we actually verified

What we could not independently verify

Disclosure and independence

The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. We update this page quarterly and after rulemaking changes. Read our editorial standards and corrections policy. Last verified: June 3, 2026. Next scheduled review: September 2026.

CMMC remediation services: frequently asked questions

What are CMMC remediation services?

CMMC remediation services help a defense contractor close the gaps between its current cybersecurity, documentation, and evidence and the CMMC status its contracts require. For Level 2, that means implementing the 110 NIST SP 800-171 Revision 2 requirements and proving it.

Is CMMC remediation the same as CMMC consulting?

Not quite. Consulting can include advice, gap assessments, and readiness planning. Remediation is the actual closure of gaps and the production of evidence — the work that moves your SPRS score and prepares you to pass.

Do I need a gap assessment before remediation?

Usually, yes — unless your gaps are already mapped. Without a gap register, “remediation” tends to become random tool buying. Scope and assess first. See our CMMC gap assessment guide.

Can an RPO certify us?

No. The Cyber AB describes Registered Provider Organizations as advisory and consultative. Only an authorized C3PAO can conduct a Level 2 certification assessment.

Can a C3PAO remediate our gaps?

Treat assessment and remediation as separate. Under 32 CFR §170.8(b)(17)(ii)(G), a firm that prepared you cannot participate in your Level 2 certification assessment for three years. The firm that fixes your gaps generally cannot be the one that certifies you.

What's the difference between a POA&M and remediation?

A POA&M records planned corrective actions; remediation is the work that closes them and produces evidence. Conditional Level 2 and Level 3 require closing valid POA&M items within 180 days. Level 1 doesn't allow POA&Ms.

How many CMMC Level 2 requirements are there?

110, drawn from NIST SP 800-171 Revision 2 and organized into 14 control families. Level 2 is verified by a self-assessment or a C3PAO assessment depending on the contract, plus an annual affirmation. See our CMMC levels guide.

Does CMMC Level 2 use NIST SP 800-171 Rev. 2 or Rev. 3?

For the current rule, Level 2 maps to Revision 2 unless and until DoD amends the rule. The Department confirmed this via FAQ under a class deviation.

What SPRS score do I need to pass Level 2?

An assessment score of at least 88 out of 110, calculated after subtracting the 1-, 3-, and 5-point values of each NOT MET requirement. Below 88, a POA&M can't help; you have to implement first. See our full SPRS score guide.

Which CMMC requirements can never go on a POA&M?

Six Level 2 requirements, under 32 CFR §170.21(a)(2)(iii): AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4 (the SSP), PE.L2-3.10.3, PE.L2-3.10.4, and PE.L2-3.10.5. Missing any of them results in no CMMC status, not a Conditional pass.

What documents should remediation produce?

At minimum: an updated SSP, a POA&M (where applicable), an asset inventory, a data-flow diagram, policy and procedure updates, technical evidence, a control-owner map, and assessment-readiness evidence.

When should we schedule a C3PAO?

After scope, SSP, controls, evidence, and independence are stable. A C3PAO should not be your first call if you still have major remediation ahead — and with limited assessor capacity before the November 10, 2026 Phase 2 milestone, booking early matters once you're genuinely ready. See our guide to choosing the best C3PAO for CMMC Level 2.

Can our MSP handle CMMC remediation?

Sometimes — but only if it can map technical implementation to NIST 800-171 evidence and work alongside a readiness lead. And remember: an MSP that handles your CUI is an External Service Provider (ESP) in your scope, documented in your SSP and Customer Responsibility Matrix and assessed within your assessment.

Are CUI enclaves a shortcut to certification?

No. They can reduce or clarify scope — often the biggest cost lever you have — but you still need an SSP, a responsibility matrix, implemented controls, and evidence. Read our enclave vs. enterprise compliance guide for the full picture.

What if we only handle FCI?

Level 1 focuses on FCI: 15 requirements from FAR 52.204-21, self-assessed annually with an affirmation, all of which must be MET, and no POA&Ms. You likely don't need a full remediation program. See our Level 1 vs. Level 2 guide.

What if our prime flowed down CMMC but didn't explain the level?

Get the required CMMC level, assessment type, and information type in writing before you buy anything. Scope your remediation to the flowed-down information, not your whole business. See our guide on CMMC for subcontractors.

How do we get matched with the right provider category?

Use the Path Finder with non-sensitive inputs only — level, scope, environment, current artifacts, provider status, and timeline — and we'll point you to source-checked options that fit.

The bottom line

CMMC remediation isn't one purchase — it's a sequence, and the order matters more than the brand on the invoice. Scope before you fix. Build the SSP before you buy a tool. Implement before you schedule an assessor. And keep the firm that fixes your gaps separate from the firm that certifies you — that's not red tape, it's what makes your certification mean something.

The companies that move now have options. The ones that wait until they see a CMMC clause in a solicitation they want are usually already out of time.

Need help deciding what type of CMMC provider you need?

Tell us your level, scope, and timeline and we'll match you with source-checked CMMC provider options. Already at 110 and just need the assessment? See our guide to finding and verifying a C3PAO instead.

Find my remediation path →

Dropdowns and general descriptions only — please don't paste contract numbers, system details, or anything sensitive. We screen each provider category before routing. Provider-matching may generate referral compensation for us. Matching is not an endorsement or certification guarantee.

Primary and authoritative sources

  • CMMC Program Rule — 32 CFR Part 170 (Federal Register, Oct. 15, 2024; effective Dec. 16, 2024)
  • POA&M requirements — 32 CFR §170.21 (ecfr.gov)
  • CMMC Scoring Methodology — 32 CFR §170.24
  • CMMC Level 2 certification assessment and ESP/CSP handling — 32 CFR §170.17; scoping at §170.19
  • Application to subcontractors (flow-down) — 32 CFR §170.23
  • Conflict of interest — 32 CFR §170.8(b)(17)(ii)(G) and the Cyber AB Code of Professional Conduct v2.0
  • C3PAO roles — 32 CFR §170.9; CMMC Assessment Process (CAP) v2.0 (Cyber AB / CAICO)
  • DFARS 252.204-7012, -7019, -7020, -7021, and -7025 — Acquisition.gov; DFARS Case 2019-D041
  • CMMC levels and model — DoD CIO: dodcio.defense.gov/cmmc
  • NIST SP 800-171 Revision 2 and NIST SP 800-171A; NIST SP 800-172 — NIST CSRC: csrc.nist.gov
  • Cyber AB Marketplace (assessor/ecosystem directory and counts): cyberab.org
  • SBA Office of Advocacy — CMMC small-business cost comments and roundtable reporting (2026): advocacy.sba.gov
  • 2025 State of the DIB Report (Merrill Research, commissioned by CyberSheath) — DIB readiness/SPRS data

Last verified: June 3, 2026. Next scheduled review: September 2026.