The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base
Find My Path

How the CMMC path router works

The routing logic, decision rules, and outputs — documented as plain text so you can evaluate the reasoning before you use the tool.

The Defense Compliance Report

Publisher policy page — maintained by The Defense Compliance Report. This page explains our editorial, privacy, advertising, or contact practices and is not CMMC, legal, contractual, cybersecurity, or compliance advice.

CUI safety note. Do not enter CUI, classified information, contract numbers, solicitation details, personally identifiable information, or sensitive technical data into the routing tool. The tool asks only about your CMMC level, data scope, environment type, current maturity stage, and timeline. No input to the tool is transmitted to DoD, the Cyber AB, or any government agency.

What the tool does

The CMMC path router asks a short set of plain-language questions and maps your answers to a provider-category recommendation — the type of CMMC provider you need, not a named firm. It implements the DCR CMMC Path Framework, which is documented in full on the methodology page.

The tool is independent and vendor-neutral. It does not pass your answers to any provider, and it does not produce a ranked or scored list of named firms. The output is a provider-category recommendation with a checklist of questions to ask any provider in that category.

Inputs

The router collects five inputs:

  1. CMMC level required.Derived from your contract clause — specifically whether DFARS 252.204-7021 is present and what level and assessment type it specifies. If you have not confirmed the clause, you can select “Not sure / need to check.”
  2. FCI/CUI data scope. Whether you handle Federal Contract Information (FCI) only, FCI and Controlled Unclassified Information (CUI), or are unsure. This drives the enclave question.
  3. Current environment. Where your relevant IT systems live — on-premises infrastructure, commercial Microsoft 365 or Google Workspace, GCC, GCC High, a FedRAMP-authorized cloud service, or a mix.
  4. Current maturity stage.Where you are in the CMMC readiness lifecycle: no SSP started, SSP in progress, SSP complete and self-assessed, SPRS score posted, or active POA&M remediation underway.
  5. Timeline. How much time you have before your contract compliance deadline — under 6 months, 6 to 12 months, 12 to 24 months, or more than 24 months.

Decision rules

The router applies these rules in order. The first matching rule produces the output:

Level 1 — FCI only, no CUI

Level 2 — self-assessment pathway

Level 2 — C3PAO assessment pathway

Level 3 — DIBCAC

Outputs

For each combination of inputs, the router produces:

What the tool does not do

Use the interactive tool

The interactive version of the router — which applies these rules through a two-minute question sequence — is at /find-my-path/. No contact information is required. The routing logic documented on this page is the same logic the interactive tool applies.

For the full decision framework and evaluation methodology behind the tool, see our methodology page.