The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

What Is CMMC? CMMC 2.0 Explained for Defense Contractors

By The Defense Compliance Report Editorial TeamIndependent trade publication on CMMC 2.0 and DIB complianceLast verified:

What is CMMC? CMMC (Cybersecurity Maturity Model Certification) is the U.S. Department of Defense program that requires defense contractors and subcontractors on applicable DoD solicitations, contracts, or flow-downs to prove — not just promise — that they protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) on their systems before they can win, perform, or stay eligible for that work. There are three levels: Level 1 (FCI; 15 requirements; annual self-assessment), Level 2 (CUI; 110 requirements; self-assessed or C3PAO-certified depending on the contract), and Level 3 (most sensitive CUI; 110 + 24 requirements; government-assessed by DCMA DIBCAC).

Here’s the part most pages bury, and the reason this guide exists: 2028 is the finish line, not your deadline. For most companies that touch CUI, the date that actually bites arrives much sooner — and the pool of assessors that has to certify them is far smaller than the demand. We read the rules, cross-checked the clause text against Acquisition.gov and the eCFR, and pulled the latest ecosystem numbers from The Cyber AB so you can find yourself in this program in about five minutes.

CMMC in One Screen

CMMC has three levels. In a solicitation, a contracting officer specifies one of four required level-and-assessment paths. This is the single distinction that resolves most early confusion — because “Level 2” is two different paths, not one.

Path a solicitation can requireProtectsRequirementsWho assesses youWhere it’s recordedPOA&M allowed?
Level 1 (Self)FCI15 (from FAR 52.204-21)You (annual self-assessment)SPRSNo
Level 2 (Self)CUI (lower-risk contracts)110 (NIST SP 800-171 Rev. 2), 14 familiesYou (every 3 years + annual affirmation)SPRSLimited
Level 2 (C3PAO)CUI (prioritized contracts)110 (NIST SP 800-171 Rev. 2)An independent C3PAO (every 3 years)eMASS → SPRSLimited
Level 3 (DIBCAC)Most sensitive CUI / advanced-threat programs110 + 24 (NIST SP 800-172)The government (DCMA DIBCAC); requires Final Level 2 (C3PAO) firsteMASS → SPRSLimited

One more wrinkle worth knowing up front: those four paths produce seven possible CMMC statuses, because Level 2 and Level 3 each come in a Conditional version (you passed above the 80% line with a few documented gaps to fix) and a Finalversion (everything met). The DFARS clause spells all seven out. You don’t need to memorize them — just know that “Conditional” is a clock you have to beat.

Sources: four required paths and seven statuses — DFARS 252.204-7021 and 252.204-7025 (Acquisition.gov); requirement counts — 32 CFR Part 170, §§170.14–170.18 (eCFR). FCI = non-public information generated for or provided to the government under a contract; CUI = unclassified information the government requires to be safeguarded. C3PAO = Certified Third-Party Assessment Organization. DIBCAC = Defense Industrial Base Cybersecurity Assessment Center, run by the Defense Contract Management Agency.

Not sure which row is you?

Use our free CMMC Level & Phase Finder — answer a few non-sensitive questions about your contract, your data, and your timeline, and it returns your likely path, your likely assessment type, and the phase date that applies to you. About 60 seconds. No login, no email wall.

Please don’t enter CUI, drawings, system diagrams, or sensitive contract details into this or any web form. The questions are general by design.

Check my likely CMMC path →

What Is CMMC in Plain English?

CMMC stands for Cybersecurity Maturity Model Certification. The Department of Defense created it because contractors were allowed to self-attest that they met federal cybersecurity requirements — and too many didn’t, while sensitive defense information leaked out of the supply chain. CMMC adds independent verification and an enforceable contract status on top of requirements that already existed.

The DoD has required contractors to protect sensitive information for a long time — DFARS clause 252.204-7012 has obligated companies handling CUI to implement NIST SP 800-171 since the end of 2017. The problem was trust without proof. A contractor could check a box, report a score in a government database, and never be checked. CMMC closes that gap by tying a verified cybersecurity status to your eligibility for the contract.

The program you’ll hear about today is CMMC 2.0, the streamlined version DoD announced in November 2021. It collapsed an earlier five-level model down to three and aligned the framework with existing NIST standards. CMMC 2.0 is not a separate thing from “CMMC” — when people say either, they mean the current three-level program.

Two federal rules make it real, and it helps to keep them straight:

Without the second rule, CMMC was a framework on paper. With it, CMMC has teeth.

Precision note on “Department of War”

In September 2025, Executive Order 14347 authorized “Department of War” as a secondary title for the department. But the statutory name remains the Department of Defense, only Congress can change it, and every CMMC rule — 32 CFR Part 170, the DFARS clauses — is written in the Department of Defense’s name. We use “DoD” throughout for accuracy.

What CMMC is not

Who Needs CMMC?

You need CMMC if you process, store, or transmit FCI or CUI on the systems you’ll use to perform a DoD contract that carries the CMMC clause — and that includes subcontractors, because prime contractors must flow the requirement down. The trigger is always the contract: the solicitation, the clause, and the information type.

The instinct is to ask “what tools do we need?” The right first question is “what information do we actually handle?” Your answer decides almost everything.

Do subcontractors need CMMC?

Yes — and this catches small suppliers off guard. CMMC requirements flow down. Under DFARS 252.204-7021 and the scoping rules at 32 CFR §170.23, a prime must ensure that subcontractors at any tier who will handle FCI or CUI hold the required CMMC status before work is awarded. Under §170.23: a subcontractor handling only FCI needs Level 1 (Self); one handling CUI needs at least Level 2 (Self); if the prime’s contract requires Level 2 (C3PAO), the CUI-handling subcontractor needs at least Level 2 (C3PAO) too. Even when a prime holds Level 3 (DIBCAC), a CUI-handling subcontractor generally needs Level 2 (C3PAO) — not Level 3.

See our full guide on CMMC flow-down requirements for subcontractors for the detailed rules and prime-to-sub communication checklist.

Does CMMC apply to commercial or COTS purchases?

Mostly, the CMMC clause reaches commercial-item buys too — with one clear carve-out. The rule prescribes the clause for solicitations and contracts (including commercial products and services) except those solely for commercially available off-the-shelf (COTS) items, when the program office determines a CMMC level is required (DFARS 204.7504). If you only sell true COTS products to the DoD, you’re likely outside the requirement. If you’re not sure whether what you sell qualifies as COTS, confirm with your contracting officer — the COTS definition has meaningful edges.

What if you only bid on DoD work and don’t have a contract yet?

Read the solicitation first. The level you’ll need is announced beforeaward, in a solicitation provision (DFARS 252.204-7025). And one hard rule while you’re orienting: do not put CUI, drawings, system diagrams, or sensitive contract details into public tools, unsecured email, or web forms — including any intake form on any website, ours included. Figuring out CMMC is not a reason to mishandle the very information CMMC exists to protect.

What Is the Difference Between FCI and CUI?

FCI is non-public information provided by or generated for the government under a contract — protected under FAR 52.204-21. CUI is unclassified information that a law, regulation, or government-wide policy requires you to safeguard — defined under 32 CFR Part 2002 and catalogued in the National Archives’ CUI Registry. FCI usually points to Level 1; CUI usually points to Level 2 or Level 3.

This single distinction is the fork in the road:

FCI (Federal Contract Information)CUI (Controlled Unclassified Information)
What it isNon-public info provided by or generated for the government under a contractUnclassified info that law, regulation, or government-wide policy requires you to protect
Defined byFAR 52.204-2132 CFR Part 2002 + the NARA CUI Registry
Common examplesNon-public emails, deliverables, or process info tied to a contractControlled technical data, export-controlled info, specs, drawings, or program details
Usually points toLevel 1Level 2 (or Level 3 for the most sensitive programs)
Not FCI/CUIInformation cleared for public release; simple transactional/payment infoAnything that isn't designated or markable as CUI

Common examples, not legal determinations. Always confirm an item’s status against the contract, the CUI marking, and your contracting officer.

How do I know if my document is actually CUI?

Three checks, in order:

  1. Look for markings — CUI is supposed to be marked by the government or the prime that shares it.
  2. Check the category against the NARA CUI Registry, which lists every recognized CUI category and its handling rules.
  3. Ask the contracting officer or your prime in writing what information you’ll receive and whether it’s FCI or CUI. Program offices have been marking more data as CUI over time, so “we’ve never been told we handle CUI” is not the same as “we don’t.” When the answer is genuinely unclear, treat it as the more protective category until you get written confirmation.

Want the clean starting move?

Download our free CMMC Starting-Point Worksheet — an FCI/CUI determination checklist, the scoping questions that decide your scope, the 14 control families in plain English, and the exact questions to send back to your prime.

No CUI required — the worksheet is built to be filled out without exposing sensitive information.

Get the CMMC Starting-Point Worksheet →

Which CMMC Level Do You Need — Level 1, Level 2, or Level 3?

Your level depends on the sensitivity of the information your systems will handle and the status your contract requires. Level 1 is for FCI and is self-assessed. Level 2 is for CUI and maps to the 110 requirements of NIST SP 800-171 Revision 2 — self-assessed on some contracts, third-party-assessed (C3PAO) on others. Level 3 is for the most sensitive CUI, adds 24 NIST SP 800-172 requirements, and is assessed by the government’s DIBCAC after you’ve earned Final Level 2.

Here’s the operational version — mapped to likely path, first safe action, and what you should not buy yet. (General guidance based on the rule, not a determination of your specific obligation.)

If this is youLikely pathRequirementsFirst safe actionWhat NOT to buy yet
We do DoD work but only handle FCI.Level 1 (Self)15 (FAR 52.204-21)Inventory where FCI lives; run the Level 1 self-assessmentA C3PAO assessment — Level 1 isn't third-party assessed
We handle CUI; the contract says Level 2 self-assessment.Level 2 (Self)110 (NIST 800-171 Rev. 2)Define scope, write the SSP, score honestly, build evidenceAn assessor — confirm whether your contract actually requires C3PAO
The solicitation or our prime requires Level 2 C3PAO.Level 2 (C3PAO)110 (NIST 800-171 Rev. 2)Get readiness work done first, then schedule the C3PAO when evidence is defensibleA combined 'we'll prep you and assess you' deal — independence rules prohibit it
Our contract requires Level 3.Level 3 (DIBCAC)110 + 24 (NIST 800-172)Confirm you can reach Final Level 2 first, then plan Level 3A normal C3PAO-only plan — Level 3 is government-assessed
We run on cloud / an MSP / external IT.A scoping question, not a separate levelDepends on level + contractMap exactly where FCI/CUI flows before buying anythingThe assumption that GCC High, GovCloud, or an MSP 'solves CMMC' by itself

Sources: requirement counts and statuses — 32 CFR Part 170, §§170.14–170.18; cloud/external-provider scoping — 32 CFR Part 170 and DFARS 252.204-7012.

CMMC Level 1: FCI only

Fifteen basic safeguarding requirements, drawn straight from FAR 52.204-21. You assess yourself once a year, post the result (Met / Not Met) in SPRS, and a senior official affirms it. All 15 must be met — there is no POA&M at Level 1, meaning you can’t pass with open items. (You may still see outdated pages claim Level 1 is “17 practices” — that’s a leftover from the old CMMC 1.0 model; the current rule confirms 15.)

CMMC Level 2 (Self): CUI on the self-assessment path

The full 110 requirements of NIST SP 800-171 Revision 2, organized into 14 control families. Some lower-risk Level 2 contracts let you self-assess every three years, post your score in SPRS, and affirm annually. This path is real but narrower than it sounds — in DoD’s own Year 4 modeling, only about 2% of impacted entities fall on the Level 2 self-assessment path, versus about 35% on the Level 2 C3PAO path.

CMMC Level 2 (C3PAO): CUI on the third-party path

Same 110 requirements — but here an independent C3PAO (a Certified Third-Party Assessment Organization authorized by The Cyber AB) conducts the assessment. Results go into eMASS and feed SPRS; the certification is good for up to three years; a senior official still affirms continuous compliance every year. This is the path most CUI-handling contractors are heading toward.

CMMC Level 3: DIBCAC-assessed protection against advanced threats

Reserved for the most sensitive CUI on higher-risk programs. Level 3 layers 24 selected requirements from NIST SP 800-172 on top of a complete Level 2 implementation. You must first achieve Final Level 2 (C3PAO)for the same scope; then the government itself — DCMA DIBCAC — performs the Level 3 assessment. This is not a bigger C3PAO engagement; it’s a different assessor entirely.

Why “Level 2” does not automatically mean “C3PAO”

This is one of the most common — and most expensive — misreadings. Level 2 is a requirement set; the assessment type is set separately by your contract. Some Level 2 work is self-assessed; some requires a C3PAO. Booking a third-party assessment you didn’t need, or skipping one you did, both cost real money and time. Read the clause, confirm the required status, then plan.

Genuinely unsure which path your contract points to? Find my likely CMMC path in 60 seconds — then verify the answer against your clause before you spend a dollar.

Is CMMC Required Now? The Four-Phase Timeline and the Date That Actually Matters

Yes — CMMC is in force. The Program Rule has been effective since December 16, 2024, and the acquisition rule took effect November 10, 2025, starting a four-phase rollout that runs through November 10, 2028. The phase that matters most for CUI-handling companies is Phase 2 — November 10, 2026 — when third-party (C3PAO) certification begins appearing as a condition of award on applicable contracts.

The DoD is introducing CMMC in four annual phases, defined in 32 CFR §170.3(e):

PhaseWindowWhat changes
Phase 1Nov 10, 2025 – Nov 9, 2026DoD intends to require Level 1 (Self) or Level 2 (Self) as a condition of award on applicable contracts, and may require Level 2 (C3PAO) at its discretion.
Phase 2Nov 10, 2026 – Nov 9, 2027In addition to Phase 1, DoD intends to include Level 2 (C3PAO) for applicable solicitations and contracts as a condition of award. DoD may delay the requirement to an option period, and may include Level 3 (DIBCAC) at its discretion.
Phase 3Nov 10, 2027 – Nov 9, 2028DoD intends to include Level 2 (C3PAO) for all applicable solicitations and contracts as a condition of award and as a condition to exercise an option period. DoD also intends to include Level 3 (DIBCAC) for all applicable solicitations and contracts, with discretion to delay Level 3 to an option period.
Phase 4Begins Nov 10, 2028Full implementation across all applicable DoD solicitations and contracts.

The trap, stated plainly

The rule says full implementation by November 10, 2028.

What it means for you: 2028 is the outer boundary, not a grace period. If a contract you want carries a CMMC clause today, you must meet it today. The only date that matters is the first solicitation, award, or option you care about — and for a great many contractors handling CUI, that’s Phase 2, starting November 10, 2026.

Why does Phase 2 sting more than Phase 1? Because Phase 1 leans on self-assessment, which you control. Phase 2 brings in independent assessors to verify what you’ve built — and authorized assessors are the scarcest resource in this entire program. We put real numbers on that gap further down.

For the full phase-by-phase timeline and what each means for your contracting calendar, see our CMMC phases guide.

How Does CMMC Relate to the DFARS Clauses (7012, 7019, 7020, 7021, 7025)?

CMMC sits on top of cybersecurity clauses that already exist in your DoD contracts. DFARS 252.204-7012 is still the core safeguarding and incident reporting clause for covered defense information. DFARS 252.204-7021 is the CMMC contract clause, and DFARS 252.204-7025 is the CMMC solicitation provision. NIST SP 800-171 assessment mechanics depend on the clause path in the actual solicitation or contract: legacy/codified solicitations may still cite DFARS 252.204-7019/-7020, while 2026 RFO/Class Deviation solicitations may use DFARS 252.240-7997 instead.

These five clauses are how CMMC actually reaches you. We pulled each from Acquisition.gov so the descriptions match the live text:

Clause / provisionWhat it isWhy you care
DFARS 252.204-7012Safeguarding Covered Defense Information & Cyber Incident ReportingThe long-standing CUI clause. Requires NIST SP 800-171, plus cloud and rapid (72-hour) incident-reporting obligations. CMMC does not replace it.
DFARS 252.204-7019Notice of NIST SP 800-171 DoD Assessment RequirementsSolicitation notice that you must have a current NIST 800-171 assessment on file.
DFARS 252.204-7020NIST SP 800-171 DoD Assessment RequirementsGoverns DoD's own Basic/Medium/High assessments and SPRS posting mechanics.
DFARS 252.204-7021Contractor Compliance With the CMMC Level RequirementsThe CMMC contract clause. Requires you to hold the specified current CMMC status during performance, affirm annually, and flow the requirement down to subcontractors. Effective Nov 10, 2025.
DFARS 252.204-7025Notice of CMMC Level RequirementsThe gatekeeper. A solicitation provision that states the CMMC level required for award and requires you to provide SPRS-issued CMMC Unique Identifiers (UIDs) for each system that will handle FCI or CUI.

Which clause tells you the level you need?

The solicitation provision -7025is where the contracting officer writes the required level — Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), or Level 3 (DIBCAC). Rule of thumb, confirmed by the Federal Register’s own clause prescription: when you see -7025 in a solicitation, expect -7021 in the resulting contract. One announces the requirement; the other enforces it.

Which clause still matters for NIST 800-171?

All of them, together. CMMC doesn’t erase -7012, -7019, or -7020 — those still govern safeguarding, assessment scoring, and SPRS mechanics. CMMC adds the verified status and the annual affirmation on top.

Is CMMC the Same as NIST SP 800-171?

No. NIST SP 800-171 is the security requirement set — the actual list of controls for protecting CUI on non-government systems. CMMC is the DoD program that verifies you’ve implemented it and ties that verification to your contract. At Level 2, CMMC currently maps to NIST SP 800-171 Revision 2 — not Revision 3 — under 32 CFR Part 170.

Think of it this way: NIST SP 800-171 is the test, and CMMC is the proctor plus the consequences. The 110 requirements are NIST’s. What CMMC adds is verification (self or third-party), an annual affirmation by a senior official, and limits on how many gaps you can carry on a POA&M.

Why CMMC Level 2 still uses Rev. 2, even though Rev. 3 exists

NIST published Revision 3 of SP 800-171 in May 2024, but CMMC Level 2 is still assessed against Revision 2. Aligning your program onlyto Rev. 3 today can make you show “unmet” requirements in a Rev. 2 assessment — an avoidable way to fail. Until DoD amends the CMMC rule to incorporate Rev. 3, Rev. 2 is the controlling baseline.If a consultant or a page tells you to build to Rev. 3 right now for CMMC, ask them to point to the rule that says so. There isn’t one yet. (Rev. 2 has 110 requirements across 14 families; Rev. 3 is structured differently, which is exactly why mixing them up causes trouble.)

What about NIST SP 800-172?

Level 3’s 24 enhanced requirements come from NIST SP 800-172, February 2021 version— the edition incorporated by reference into the current CMMC rule. NIST released SP 800-172 Revision 3 in May 2026 and withdrew the February 2021 version on May 13, 2026. Same principle as above: for CMMC purposes, cite the version the active rule actually incorporates (Feb 2021), not the newest one on NIST’s site, until DoD updates the rule.

What Actually Happens in a CMMC Assessment?

The assessment depends on your required status. Level 1 is a yearly self-assessment you post in SPRS. Level 2 is either a self-assessment (every three years) or a C3PAO certification assessment (every three years), with results in SPRS or eMASS. Level 3 is a government assessment by DCMA DIBCAC, conducted only after you hold Final Level 2 (C3PAO). All paths require an annual affirmation by a senior official.

Whatever your level, the spine of the work is the same: define your scope, implement the controls, document them in a System Security Plan (SSP), prove them with evidence, score yourself honestly, and keep it current.

For a detailed walkthrough of the Level 2 C3PAO process, see our CMMC certification process guide.

What evidence do assessors expect?

Not a folder of policies you wrote the night before. Expect to show: a defined assessment scope and asset inventory; network and CUI data-flow diagrams; your SSP; written policies andthe procedures that operationalize them; configuration evidence; access-control and logging evidence; training records; incident-response records; and your POA&M status. The theme is demonstrated, not described — assessors want to see the control working, not read that it should.

The annual affirmation is a personal signature, not a checkbox

Every level requires a yearly affirmation of continuous compliance, entered in SPRS by an affirming official — a senior company representative responsible for and able to attest to your compliance (32 CFR §170.22). A missing or stale affirmation makes your CMMC status no longer current, which can make you ineligible for award. That signature also carries weight under the federal False Claims Act — the Department of Justice pursues its Civil Cyber-Fraud Initiative against contractors that knowingly misrepresent their cybersecurity practices. Affirmation is now an executive accountability, not an IT formality.

Can You Pass CMMC with a POA&M?

Sometimes — but only within tight limits. A POA&M (Plan of Action and Milestones) is a documented plan to close specific gaps. It is never allowed at Level 1. At Level 2 and Level 3, you can earn a “Conditional” status with a limited POA&M only if you’ve met at least 80% of requirements, only certain low-value items qualify, and you must close them within 180 days — or the conditional status expires.

The rule (32 CFR §170.21) is specific:

Why a POA&M is not a strategy

It’s tempting to treat the POA&M as a way to “pass now, fix later.” Don’t build your plan on it. The items that most often block contractors are exactly the high-value requirements you can’tdefer. Plan to actually meet the requirements; treat the POA&M as a narrow safety valve for genuinely minor items, not a runway.

What Does CMMC Cost, and How Long Does It Take?

Cost depends heavily on your level, scope, and starting maturity. DoD’s official estimates cover assessment and affirmation activity — roughly $4,000–$6,000 for Level 1, about $37,000–$49,000 over three years for Level 2 self-assessment, and roughly $104,670–$117,768 over three years for Level 2 C3PAO certification. Those figures exclude the cost of implementing the controls. Many Level 2 contractors need 6–18 months of preparation before they’re assessment-ready.

Our one hard truth

CMMC Level 2 is genuinely expensive and slow, and no consultant or C3PAO can guarantee you’ll pass. Anyone promising a guaranteed certification outcome is selling something the rules don’t allow them to deliver — The Cyber AB’s own conduct rules prohibit assessors from guaranteeing results. This page is education, not legal or contractual advice, and the program is still refining some interpretations as it rolls out.

The cheapest part of CMMC is clarity, and the most expensive mistake is waiting. The DoD figures below are assessment-and-affirmation costs; the rule assumes you’ve alreadyimplemented NIST SP 800-171, because that’s been required since 2017. In the real world, the implementation — closing gaps, standing up a CUI enclave, documenting everything, training people — is where the money goes.

What the DoD’s CMMC Program Rule estimates (assessment + affirmation, over the cycle):

DCR editorial estimate: once you add real implementation and remediation, all-in spend to reach Level 2 commonly runs $100,000–$200,000+for a contractor starting from a material gap. That is not a DoD figure — it’s a market-derived planning range; verify it with scoped quotes for your own environment.

DCR planning range on timeline: many Level 2 readiness programs take 6–18 months depending on scope, starting maturity, evidence quality, and assessor scheduling.

For a full breakdown of what drives your number, see our CMMC Level 2 cost guide.

How Big Is the CMMC Readiness Gap Right Now?

As of the March 2026 Cyber AB Town Hall, roughly 103 authorized C3PAOs and about 759 certified assessors exist to serve a defense industrial base that DoD models at hundreds of thousands of impacted entities — about 35% of them eventually needing a Level 2 third-party certification. Only about 1,000 organizations have been certified to Level 2 so far. With Phase 2’s third-party requirement landing November 10, 2026, the binding near-term constraint isn’t whether CMMC is real — it’s whether an authorized assessor is available when your deadline arrives.

What the rule models — DoD regulatory analysis (DFARS final rule, Sept 10, 2025)

MetricFigure
Total impacted entities (Year 4)~337,968
Small entities among them~229,818
Level 1 (Self)~62%
Level 2 (Self)~2% (≈ 6,759 entities)
Level 2 (C3PAO)~35% (≈ 118,289 entities)
Level 3~1% (≈ 3,380 entities)
Small-entity ramp~1,104 (Yr 1) → ~5,565 (Yr 2) → ~18,554 (Yr 3) → ~229,818 (Yr 4)

What’s on the ground — The Cyber AB, March 2026 Town Hall

MetricFigure
Authorized C3PAOs (the only firms that can certify Level 2)~103
Certified Assessors (CCAs)~759
New Level 2 certificates issued in the month~178
Organizations certified to Level 2 to date~1,000

The DCR calculation: roughly 1,000 organizations certified, against a DoD-modeled eventual Level 2 (C3PAO) population near 118,000, is under 1% of that population certified so far. At about 178 certificates a month, clearing that population would take many years at the current pace. The queue, not the rule, is the near-term risk.

Last verified .

What’s the Safest First Move If You Just Heard About CMMC?

Don’t start by buying a tool or booking a C3PAO. Start by reading the contract for the clause, identifying whether you handle FCI or CUI, mapping where that information lives, and determining your required path. Only after you know your path and scope should you choose a provider.

The cheapest path runs in this order:

  1. Find the clause or flow-down. Look for DFARS 252.204-7012, -7019, -7020, -7021, and -7025 in your solicitation, contract, or your prime’s email. -7025 tells you the required level.
  2. Identify your information. FCI or CUI? This single answer points to your path. Don’t ask “what do we need to buy” — ask “what do we handle.”
  3. Map the environment. Where does FCI/CUI actually live — email, SharePoint, file shares, ERP/CRM, CAD/CAM, endpoints, backups, your MSP’s tools? Scope is the biggest cost lever in the entire program; shrinking it legitimately is the highest-leverage move you can make.
  4. Determine your likely path and assessment type. Use the Finder, then verify against the clause.
  5. Build the minimum evidence baseline. SSP, asset inventory, CUI data-flow map, core policies, your SPRS score, your POA&M, and a named affirming official.
  6. Choose a provider category only after scope is known — readiness/RPO/MSP, enclave/GCC High, GRC software, or C3PAO, depending on your stage.

Still not sure where you land, or which kind of help fits?

Tell us your level, scope, and timeline, and we’ll match you with source-checked CMMC provider options — no obligation.

We may receive compensation for qualified introductions when disclosed. We do not route based on compensation, and we are not affiliated with the DoD or The Cyber AB. Please don’t include CUI or sensitive contract details — your level, scope, and timeline are all we need.

Get matched with source-checked provider options →

What Kind of CMMC Provider Do You Actually Need?

The right provider depends on your stage, not on who markets hardest. If you’re scoping or remediating, you likely need readiness help — an RPO, a CMMC-focused MSP/MSSP, a vCISO, or a GCC High/enclave implementer. If your contract requires Level 2 (C3PAO) and you’re assessment-ready, you need an authorized C3PAO. A critical rule: the firm that prepares you generally cannot also be the firm that certifies you.

Provider categoryUse whenDon’t use whenCan it certify you?Conflict-of-interest riskWhat to verify before paying
Readiness / RPO / RPYou're scoping, remediating, or need help preparingYou only need a final certification stampNoThe same firm generally can't also be your C3PAOTrack record, references, whether they'll create a conflict with your future assessor
MSP / MSSP / vCISOYou need implementation, monitoring, or managed securityYou think managed IT alone equals complianceNoSame separation applies if they also offer assessmentGovernment/CMMC experience, how they document evidence
GRC / evidence / SSP & POA&M softwareYou need to organize control mapping, evidence, and continuous complianceYou expect software to 'do' complianceNoLow — but it doesn't reduce the separation rule for assessmentThat it maps to NIST 800-171 Rev. 2, not just generic frameworks
CUI enclave / GCC High / GovCloudYou want to shrink scope by isolating CUIYou assume the cloud finishes the jobNoLowFedRAMP posture, shared-responsibility matrix, what's still on you
C3PAOYour contract requires Level 2 (C3PAO) and you're assessment-readyYou're still remediatingYes (Level 2 certification)High if they also prepared you — prohibitedAuthorized status in The Cyber AB Marketplace, on the day you engage

Why readiness and assessment must stay separate

This is a genuine independence rule, not a nicety. Under the CMMC conflict-of-interest rules — 32 CFR §170.8 and The Cyber AB’s Code of Professional Conduct — a CMMC ecosystem member that served as a consultant to prepare you for any CMMC assessment within the prior three years is prohibited from participating in your Level 2 certification assessment. That prohibition applies to the C3PAO organization and to the individual assessors on the team. Budget for two relationships, keep them at arm’s length, and be wary of anyone offering to both prepare you and grade you.

How do I verify a C3PAO?

Go to The Cyber AB Marketplace (the official registry at cyberab.org), search for the firm, and confirm it shows an Authorized C3PAO status. Two cautions. First, check it on the day you engage — authorization status can lapse or change. Second, don’t accept “almost certified,” “candidate,” or “pre-authorized” as a substitute; only a currently authorized C3PAO can conduct an official Level 2 certification assessment.

When you’re ready to compare specific firms, our provider-category breakdown and who to hire first resources put providers in source-checked tables with their role, status, and what to verify before you hire.

What Are the Most Common CMMC Mistakes?

The expensive mistakes are rarely about misunderstanding the acronym. They’re operational: over-scoping the environment, assuming every Level 2 contract needs a C3PAO, building to NIST Rev. 3 for CMMC today, buying technology before mapping CUI, treating the POA&M as a strategy, and ignoring SPRS scores and annual affirmations.

Frequently Asked Questions

What does CMMC stand for?

CMMC stands for Cybersecurity Maturity Model Certification, a U.S. Department of Defense program that verifies defense contractors protect FCI and CUI on their systems before they can win or keep applicable DoD contracts.

What is CMMC in simple terms?

It’s the DoD’s way of checking — not just trusting — that a contractor meets required cybersecurity standards for the sensitive information it handles, at the level and assessment type the contract specifies. (Source: 32 CFR Part 170.)

Who needs CMMC?

DoD contractors and subcontractors that process, store, or transmit FCI or CUI on the systems used to perform a contract carrying the CMMC clause. Requirements flow down to subcontractors at any tier. (Source: 32 CFR §170.23; DFARS 252.204-7021.)

Is CMMC the same as CMMC 2.0?

Yes. “CMMC 2.0” is the current three-level program, codified at 32 CFR Part 170. When people say either, they mean the same thing.

Is CMMC required now?

Yes. The Program Rule (32 CFR Part 170) has been effective since December 16, 2024, and the DFARS acquisition rule took effect November 10, 2025, beginning the phased rollout. Whether a specific contract requires it depends on its clauses. (Source: Federal Register.)

What are the three CMMC levels?

Level 1 protects FCI with 15 requirements and annual self-assessment. Level 2 protects CUI with 110 NIST SP 800-171 Rev. 2 requirements. Level 3 adds 24 selected NIST SP 800-172 requirements and is assessed by DCMA DIBCAC after Final Level 2. (Source: 32 CFR §§170.14–170.18.)

What is the difference between FCI and CUI?

FCI is non-public information provided by or generated for the government under a contract (FAR 52.204-21). CUI is unclassified information that law, regulation, or government-wide policy requires you to safeguard (32 CFR Part 2002 and the NARA CUI Registry). FCI usually points to Level 1; CUI usually points to Level 2 or higher.

Is CMMC the same as NIST 800-171?

No. NIST SP 800-171 is the security requirement set for protecting CUI; CMMC is the program that verifies you’ve implemented it and ties that verification to your contract.

Does CMMC Level 2 use NIST SP 800-171 Rev. 2 or Rev. 3?

Revision 2. NIST published Rev. 3 in May 2024, but CMMC Level 2 is still assessed against Rev. 2, and DoD would need to amend the rule before Rev. 3 becomes the CMMC baseline. (Source: NIST CSRC; 32 CFR Part 170.)

Do I always need a C3PAO?

No. Level 1 is self-assessed, and some Level 2 contracts allow self-assessment. A C3PAO is required when your solicitation or contract specifies Level 2 (C3PAO). (Source: 32 CFR Part 170.)

How do I verify that a C3PAO is authorized?

Check The Cyber AB Marketplace (cyberab.org) on the day you engage and confirm the firm shows an Authorized status. Don’t accept “candidate,” “pre-authorized,” or “almost certified” — only a currently authorized C3PAO can conduct an official Level 2 certification assessment.

Can a readiness consultant or RPO certify me?

No. RPOs and consultants help you prepare; only an authorized C3PAO conducts the Level 2 (C3PAO) certification assessment — and generally not for a client it prepared within the prior three years. (Source: 32 CFR §170.8; Cyber AB Code of Professional Conduct.)

Can I pass CMMC with open items on a POA&M?

Only in limited cases. No POA&M is allowed at Level 1. At Level 2/3 you need at least 80% of requirements met, only low-value items qualify, and you must close them within 180 days. (Source: 32 CFR §170.21.)

What is SPRS?

The Supplier Performance Risk System — the government database where Level 1 and Level 2 self-assessment scores and all annual affirmations are recorded. C3PAO and DIBCAC results are recorded in eMASS, which feeds SPRS.

How much does CMMC cost?

It varies widely. DoD estimates roughly $4,000–$6,000 for Level 1 self-assessment, about $37,000–$49,000 over three years for Level 2 self-assessment, and about $104,670 (small) to $117,768 (other-than-small) for a Level 2 C3PAO cycle — figures that exclude the cost of implementing controls.

How long does CMMC take?

There’s no universal answer. Many Level 2 readiness programs run 6–18 months depending on scope, starting maturity, evidence quality, and assessor scheduling. A narrow CUI enclave with mature documentation moves faster than an enterprise brought into scope from scratch.

Is this page legal or compliance advice?

No. It’s educational. Confirm your contract’s applicability, your CUI scope, and your assessment type with your contracting officer or qualified counsel.

How We Verified This Guide

This guide separates three kinds of claims: primary-source regulatory facts, current-state figures, and our editorial judgments.

What we verified: We read the CMMC Program Rule at 32 CFR Part 170 (Federal Register, published October 15, 2024; effective December 16, 2024) and the DFARS acquisition rule (published September 10, 2025; effective November 10, 2025) directly. We confirmed the level requirement counts — 15 / 110 / 24 — against the eCFR text of 32 CFR §170.14, and confirmed the four required paths and seven possible CMMC statuses against the live text of DFARS 252.204-7021 and 252.204-7025 on Acquisition.gov. We confirmed that CMMC Level 2 currently maps to NIST SP 800-171 Revision 2 (not Rev. 3) and that CMMC Level 3 uses the February 2021SP 800-172 against NIST CSRC. We pulled the impacted-entity model from the DFARS final rule’s regulatory analysis, and the ecosystem figures from the March 2026 Cyber AB Town Hall. Last verified: Next scheduled review: September 2026, or sooner if DoD, NIST, DFARS, Cyber AB, or SPRS guidance changes.

What we could not independently verify:Real-world, all-in cost ranges and readiness timelines (these come from market reporting and vary by environment — labeled as DCR editorial estimates, not DoD figures) and any individual provider’s authorization status (always confirm directly in The Cyber AB Marketplace on the day you engage).

The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We are not affiliated with the Department of Defense, The Cyber AB, DCMA, DIBCAC, NIST, or any U.S. government agency. This article is for general education and is not legal, contractual, or compliance advice. See our Editorial Standards, Methodology, and Corrections Policy.

Need help deciding what type of CMMC provider you need?

Tell us your level, scope, and timeline, and we’ll match you with source-checked CMMC provider options.

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. We are not affiliated with the DoD or The Cyber AB. Please don’t submit CUI or sensitive contract details through this form.

Get matched with source-checked options →

Related Guides

Primary sources & references

Verify any regulatory claim above directly. We link to primary and authoritative sources only.

All guides in this topic: CMMC fundamentals & rules