What Is CMMC? CMMC 2.0 Explained for Defense Contractors
What is CMMC? CMMC (Cybersecurity Maturity Model Certification) is the U.S. Department of Defense program that requires defense contractors and subcontractors on applicable DoD solicitations, contracts, or flow-downs to prove — not just promise — that they protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) on their systems before they can win, perform, or stay eligible for that work. There are three levels: Level 1 (FCI; 15 requirements; annual self-assessment), Level 2 (CUI; 110 requirements; self-assessed or C3PAO-certified depending on the contract), and Level 3 (most sensitive CUI; 110 + 24 requirements; government-assessed by DCMA DIBCAC).
Here’s the part most pages bury, and the reason this guide exists: 2028 is the finish line, not your deadline. For most companies that touch CUI, the date that actually bites arrives much sooner — and the pool of assessors that has to certify them is far smaller than the demand. We read the rules, cross-checked the clause text against Acquisition.gov and the eCFR, and pulled the latest ecosystem numbers from The Cyber AB so you can find yourself in this program in about five minutes.
CMMC in One Screen
| Path a solicitation can require | Protects | Requirements | Who assesses you | Where it’s recorded | POA&M allowed? |
|---|---|---|---|---|---|
| Level 1 (Self) | FCI | 15 (from FAR 52.204-21) | You (annual self-assessment) | SPRS | No |
| Level 2 (Self) | CUI (lower-risk contracts) | 110 (NIST SP 800-171 Rev. 2), 14 families | You (every 3 years + annual affirmation) | SPRS | Limited |
| Level 2 (C3PAO) | CUI (prioritized contracts) | 110 (NIST SP 800-171 Rev. 2) | An independent C3PAO (every 3 years) | eMASS → SPRS | Limited |
| Level 3 (DIBCAC) | Most sensitive CUI / advanced-threat programs | 110 + 24 (NIST SP 800-172) | The government (DCMA DIBCAC); requires Final Level 2 (C3PAO) first | eMASS → SPRS | Limited |
One more wrinkle worth knowing up front: those four paths produce seven possible CMMC statuses, because Level 2 and Level 3 each come in a Conditional version (you passed above the 80% line with a few documented gaps to fix) and a Finalversion (everything met). The DFARS clause spells all seven out. You don’t need to memorize them — just know that “Conditional” is a clock you have to beat.
Not sure which row is you?
Use our free CMMC Level & Phase Finder — answer a few non-sensitive questions about your contract, your data, and your timeline, and it returns your likely path, your likely assessment type, and the phase date that applies to you. About 60 seconds. No login, no email wall.
Check my likely CMMC path →What Is CMMC in Plain English?
The DoD has required contractors to protect sensitive information for a long time — DFARS clause 252.204-7012 has obligated companies handling CUI to implement NIST SP 800-171 since the end of 2017. The problem was trust without proof. A contractor could check a box, report a score in a government database, and never be checked. CMMC closes that gap by tying a verified cybersecurity status to your eligibility for the contract.
The program you’ll hear about today is CMMC 2.0, the streamlined version DoD announced in November 2021. It collapsed an earlier five-level model down to three and aligned the framework with existing NIST standards. CMMC 2.0 is not a separate thing from “CMMC” — when people say either, they mean the current three-level program.
Two federal rules make it real, and it helps to keep them straight:
- 32 CFR Part 170 — the Program Rule. This is the rulebook. It defines the levels, assessment types, ecosystem roles, scoring, and the phased rollout. Published in the Federal Register on October 15, 2024 and effective December 16, 2024.
- DFARS 252.204-7021 (and the surrounding 48 CFR rule) — the acquisition rule. This is the contractual hook. It lets contracting officers put CMMC requirements into solicitations and contracts, making your CMMC status a condition of award. Published September 10, 2025 and effective November 10, 2025. That date started the clock.
Without the second rule, CMMC was a framework on paper. With it, CMMC has teeth.
Precision note on “Department of War”
In September 2025, Executive Order 14347 authorized “Department of War” as a secondary title for the department. But the statutory name remains the Department of Defense, only Congress can change it, and every CMMC rule — 32 CFR Part 170, the DFARS clauses — is written in the Department of Defense’s name. We use “DoD” throughout for accuracy.
What CMMC is not
- Not a generic cybersecurity “badge.” It’s a DoD contracting requirement tied to specific information types.
- Not applicable to every company in every situation. No CMMC clause in your contract, and no FCI or CUI in scope, generally means no CMMC obligation.
- Not the same as “we use Microsoft GCC High” or “we’re on GovCloud.” A compliant cloud can help, but a platform alone does not make you CMMC-ready.
- Not always a third-party audit. Many situations are self-assessed.
- Not legal or contractual advice — and neither is this page. Treat it as a fast, sourced orientation, then confirm your specifics with your contracting officer or qualified counsel.
Who Needs CMMC?
The instinct is to ask “what tools do we need?” The right first question is “what information do we actually handle?” Your answer decides almost everything.
Do subcontractors need CMMC?
Yes — and this catches small suppliers off guard. CMMC requirements flow down. Under DFARS 252.204-7021 and the scoping rules at 32 CFR §170.23, a prime must ensure that subcontractors at any tier who will handle FCI or CUI hold the required CMMC status before work is awarded. Under §170.23: a subcontractor handling only FCI needs Level 1 (Self); one handling CUI needs at least Level 2 (Self); if the prime’s contract requires Level 2 (C3PAO), the CUI-handling subcontractor needs at least Level 2 (C3PAO) too. Even when a prime holds Level 3 (DIBCAC), a CUI-handling subcontractor generally needs Level 2 (C3PAO) — not Level 3.
See our full guide on CMMC flow-down requirements for subcontractors for the detailed rules and prime-to-sub communication checklist.
Does CMMC apply to commercial or COTS purchases?
Mostly, the CMMC clause reaches commercial-item buys too — with one clear carve-out. The rule prescribes the clause for solicitations and contracts (including commercial products and services) except those solely for commercially available off-the-shelf (COTS) items, when the program office determines a CMMC level is required (DFARS 204.7504). If you only sell true COTS products to the DoD, you’re likely outside the requirement. If you’re not sure whether what you sell qualifies as COTS, confirm with your contracting officer — the COTS definition has meaningful edges.
What if you only bid on DoD work and don’t have a contract yet?
Read the solicitation first. The level you’ll need is announced beforeaward, in a solicitation provision (DFARS 252.204-7025). And one hard rule while you’re orienting: do not put CUI, drawings, system diagrams, or sensitive contract details into public tools, unsecured email, or web forms — including any intake form on any website, ours included. Figuring out CMMC is not a reason to mishandle the very information CMMC exists to protect.
What Is the Difference Between FCI and CUI?
This single distinction is the fork in the road:
| FCI (Federal Contract Information) | CUI (Controlled Unclassified Information) | |
|---|---|---|
| What it is | Non-public info provided by or generated for the government under a contract | Unclassified info that law, regulation, or government-wide policy requires you to protect |
| Defined by | FAR 52.204-21 | 32 CFR Part 2002 + the NARA CUI Registry |
| Common examples | Non-public emails, deliverables, or process info tied to a contract | Controlled technical data, export-controlled info, specs, drawings, or program details |
| Usually points to | Level 1 | Level 2 (or Level 3 for the most sensitive programs) |
| Not FCI/CUI | Information cleared for public release; simple transactional/payment info | Anything that isn't designated or markable as CUI |
How do I know if my document is actually CUI?
Three checks, in order:
- Look for markings — CUI is supposed to be marked by the government or the prime that shares it.
- Check the category against the NARA CUI Registry, which lists every recognized CUI category and its handling rules.
- Ask the contracting officer or your prime in writing what information you’ll receive and whether it’s FCI or CUI. Program offices have been marking more data as CUI over time, so “we’ve never been told we handle CUI” is not the same as “we don’t.” When the answer is genuinely unclear, treat it as the more protective category until you get written confirmation.
Want the clean starting move?
Download our free CMMC Starting-Point Worksheet — an FCI/CUI determination checklist, the scoping questions that decide your scope, the 14 control families in plain English, and the exact questions to send back to your prime.
Get the CMMC Starting-Point Worksheet →Which CMMC Level Do You Need — Level 1, Level 2, or Level 3?
Here’s the operational version — mapped to likely path, first safe action, and what you should not buy yet. (General guidance based on the rule, not a determination of your specific obligation.)
| If this is you | Likely path | Requirements | First safe action | What NOT to buy yet |
|---|---|---|---|---|
| We do DoD work but only handle FCI. | Level 1 (Self) | 15 (FAR 52.204-21) | Inventory where FCI lives; run the Level 1 self-assessment | A C3PAO assessment — Level 1 isn't third-party assessed |
| We handle CUI; the contract says Level 2 self-assessment. | Level 2 (Self) | 110 (NIST 800-171 Rev. 2) | Define scope, write the SSP, score honestly, build evidence | An assessor — confirm whether your contract actually requires C3PAO |
| The solicitation or our prime requires Level 2 C3PAO. | Level 2 (C3PAO) | 110 (NIST 800-171 Rev. 2) | Get readiness work done first, then schedule the C3PAO when evidence is defensible | A combined 'we'll prep you and assess you' deal — independence rules prohibit it |
| Our contract requires Level 3. | Level 3 (DIBCAC) | 110 + 24 (NIST 800-172) | Confirm you can reach Final Level 2 first, then plan Level 3 | A normal C3PAO-only plan — Level 3 is government-assessed |
| We run on cloud / an MSP / external IT. | A scoping question, not a separate level | Depends on level + contract | Map exactly where FCI/CUI flows before buying anything | The assumption that GCC High, GovCloud, or an MSP 'solves CMMC' by itself |
CMMC Level 1: FCI only
Fifteen basic safeguarding requirements, drawn straight from FAR 52.204-21. You assess yourself once a year, post the result (Met / Not Met) in SPRS, and a senior official affirms it. All 15 must be met — there is no POA&M at Level 1, meaning you can’t pass with open items. (You may still see outdated pages claim Level 1 is “17 practices” — that’s a leftover from the old CMMC 1.0 model; the current rule confirms 15.)
CMMC Level 2 (Self): CUI on the self-assessment path
The full 110 requirements of NIST SP 800-171 Revision 2, organized into 14 control families. Some lower-risk Level 2 contracts let you self-assess every three years, post your score in SPRS, and affirm annually. This path is real but narrower than it sounds — in DoD’s own Year 4 modeling, only about 2% of impacted entities fall on the Level 2 self-assessment path, versus about 35% on the Level 2 C3PAO path.
CMMC Level 2 (C3PAO): CUI on the third-party path
Same 110 requirements — but here an independent C3PAO (a Certified Third-Party Assessment Organization authorized by The Cyber AB) conducts the assessment. Results go into eMASS and feed SPRS; the certification is good for up to three years; a senior official still affirms continuous compliance every year. This is the path most CUI-handling contractors are heading toward.
CMMC Level 3: DIBCAC-assessed protection against advanced threats
Reserved for the most sensitive CUI on higher-risk programs. Level 3 layers 24 selected requirements from NIST SP 800-172 on top of a complete Level 2 implementation. You must first achieve Final Level 2 (C3PAO)for the same scope; then the government itself — DCMA DIBCAC — performs the Level 3 assessment. This is not a bigger C3PAO engagement; it’s a different assessor entirely.
Why “Level 2” does not automatically mean “C3PAO”
This is one of the most common — and most expensive — misreadings. Level 2 is a requirement set; the assessment type is set separately by your contract. Some Level 2 work is self-assessed; some requires a C3PAO. Booking a third-party assessment you didn’t need, or skipping one you did, both cost real money and time. Read the clause, confirm the required status, then plan.
Genuinely unsure which path your contract points to? Find my likely CMMC path in 60 seconds — then verify the answer against your clause before you spend a dollar.
Is CMMC Required Now? The Four-Phase Timeline and the Date That Actually Matters
The DoD is introducing CMMC in four annual phases, defined in 32 CFR §170.3(e):
| Phase | Window | What changes |
|---|---|---|
| Phase 1 | Nov 10, 2025 – Nov 9, 2026 | DoD intends to require Level 1 (Self) or Level 2 (Self) as a condition of award on applicable contracts, and may require Level 2 (C3PAO) at its discretion. |
| Phase 2 | Nov 10, 2026 – Nov 9, 2027 | In addition to Phase 1, DoD intends to include Level 2 (C3PAO) for applicable solicitations and contracts as a condition of award. DoD may delay the requirement to an option period, and may include Level 3 (DIBCAC) at its discretion. |
| Phase 3 | Nov 10, 2027 – Nov 9, 2028 | DoD intends to include Level 2 (C3PAO) for all applicable solicitations and contracts as a condition of award and as a condition to exercise an option period. DoD also intends to include Level 3 (DIBCAC) for all applicable solicitations and contracts, with discretion to delay Level 3 to an option period. |
| Phase 4 | Begins Nov 10, 2028 | Full implementation across all applicable DoD solicitations and contracts. |
The trap, stated plainly
The rule says full implementation by November 10, 2028.
What it means for you: 2028 is the outer boundary, not a grace period. If a contract you want carries a CMMC clause today, you must meet it today. The only date that matters is the first solicitation, award, or option you care about — and for a great many contractors handling CUI, that’s Phase 2, starting November 10, 2026.
Why does Phase 2 sting more than Phase 1? Because Phase 1 leans on self-assessment, which you control. Phase 2 brings in independent assessors to verify what you’ve built — and authorized assessors are the scarcest resource in this entire program. We put real numbers on that gap further down.
For the full phase-by-phase timeline and what each means for your contracting calendar, see our CMMC phases guide.
How Does CMMC Relate to the DFARS Clauses (7012, 7019, 7020, 7021, 7025)?
These five clauses are how CMMC actually reaches you. We pulled each from Acquisition.gov so the descriptions match the live text:
| Clause / provision | What it is | Why you care |
|---|---|---|
| DFARS 252.204-7012 | Safeguarding Covered Defense Information & Cyber Incident Reporting | The long-standing CUI clause. Requires NIST SP 800-171, plus cloud and rapid (72-hour) incident-reporting obligations. CMMC does not replace it. |
| DFARS 252.204-7019 | Notice of NIST SP 800-171 DoD Assessment Requirements | Solicitation notice that you must have a current NIST 800-171 assessment on file. |
| DFARS 252.204-7020 | NIST SP 800-171 DoD Assessment Requirements | Governs DoD's own Basic/Medium/High assessments and SPRS posting mechanics. |
| DFARS 252.204-7021 | Contractor Compliance With the CMMC Level Requirements | The CMMC contract clause. Requires you to hold the specified current CMMC status during performance, affirm annually, and flow the requirement down to subcontractors. Effective Nov 10, 2025. |
| DFARS 252.204-7025 | Notice of CMMC Level Requirements | The gatekeeper. A solicitation provision that states the CMMC level required for award and requires you to provide SPRS-issued CMMC Unique Identifiers (UIDs) for each system that will handle FCI or CUI. |
Which clause tells you the level you need?
The solicitation provision -7025is where the contracting officer writes the required level — Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), or Level 3 (DIBCAC). Rule of thumb, confirmed by the Federal Register’s own clause prescription: when you see -7025 in a solicitation, expect -7021 in the resulting contract. One announces the requirement; the other enforces it.
Which clause still matters for NIST 800-171?
All of them, together. CMMC doesn’t erase -7012, -7019, or -7020 — those still govern safeguarding, assessment scoring, and SPRS mechanics. CMMC adds the verified status and the annual affirmation on top.
Is CMMC the Same as NIST SP 800-171?
Think of it this way: NIST SP 800-171 is the test, and CMMC is the proctor plus the consequences. The 110 requirements are NIST’s. What CMMC adds is verification (self or third-party), an annual affirmation by a senior official, and limits on how many gaps you can carry on a POA&M.
Why CMMC Level 2 still uses Rev. 2, even though Rev. 3 exists
NIST published Revision 3 of SP 800-171 in May 2024, but CMMC Level 2 is still assessed against Revision 2. Aligning your program onlyto Rev. 3 today can make you show “unmet” requirements in a Rev. 2 assessment — an avoidable way to fail. Until DoD amends the CMMC rule to incorporate Rev. 3, Rev. 2 is the controlling baseline.If a consultant or a page tells you to build to Rev. 3 right now for CMMC, ask them to point to the rule that says so. There isn’t one yet. (Rev. 2 has 110 requirements across 14 families; Rev. 3 is structured differently, which is exactly why mixing them up causes trouble.)
What about NIST SP 800-172?
Level 3’s 24 enhanced requirements come from NIST SP 800-172, February 2021 version— the edition incorporated by reference into the current CMMC rule. NIST released SP 800-172 Revision 3 in May 2026 and withdrew the February 2021 version on May 13, 2026. Same principle as above: for CMMC purposes, cite the version the active rule actually incorporates (Feb 2021), not the newest one on NIST’s site, until DoD updates the rule.
What Actually Happens in a CMMC Assessment?
Whatever your level, the spine of the work is the same: define your scope, implement the controls, document them in a System Security Plan (SSP), prove them with evidence, score yourself honestly, and keep it current.
- Level 1 self-assessment: You evaluate the 15 requirements, post the result in SPRS, and a senior official affirms. No partial credit.
- Level 2 self-assessment: You assess all 110 requirements against the DoD methodology, post your score in SPRS, and affirm. The SPRS score for NIST 800-171 runs from −203 to a maximum of 110 — yes, it can go deeply negative, because some unmet requirements carry heavy deductions.
- Level 2 C3PAO assessment: An authorized C3PAO conducts the assessment, submits results into eMASS(which feeds SPRS), and issues your certification. You’ll go through readiness first, then the formal assessment, then artifact retention and annual affirmation. The certification is valid up to three years.
- Level 3 DIBCAC assessment: After Final Level 2, DCMA DIBCAC assesses the additional NIST 800-172 requirements directly. Government-led, every three years.
For a detailed walkthrough of the Level 2 C3PAO process, see our CMMC certification process guide.
What evidence do assessors expect?
Not a folder of policies you wrote the night before. Expect to show: a defined assessment scope and asset inventory; network and CUI data-flow diagrams; your SSP; written policies andthe procedures that operationalize them; configuration evidence; access-control and logging evidence; training records; incident-response records; and your POA&M status. The theme is demonstrated, not described — assessors want to see the control working, not read that it should.
The annual affirmation is a personal signature, not a checkbox
Every level requires a yearly affirmation of continuous compliance, entered in SPRS by an affirming official — a senior company representative responsible for and able to attest to your compliance (32 CFR §170.22). A missing or stale affirmation makes your CMMC status no longer current, which can make you ineligible for award. That signature also carries weight under the federal False Claims Act — the Department of Justice pursues its Civil Cyber-Fraud Initiative against contractors that knowingly misrepresent their cybersecurity practices. Affirmation is now an executive accountability, not an IT formality.
Can You Pass CMMC with a POA&M?
The rule (32 CFR §170.21) is specific:
- No POA&M at Level 1. All 15 must be Met.
- The 80% gate. To reach a Conditional Level 2 status, your assessment score divided by total requirements must be at least 0.8 (80%).
- Only the small stuff. Generally, only requirements worth one point in the scoring methodology can go on a POA&M. Several high-value, security-critical requirements cannot be deferred at all. (There’s a narrow exception allowing the CUI-encryption requirement on a POA&M if encryption is in place but not yet FIPS-validated.)
- The 180-day clock. A POA&M closeout assessment must confirm the gaps are fixed within 180 days of your Conditional status date. Miss it, and the conditional status expires — which can take your eligibility with it.
Why a POA&M is not a strategy
It’s tempting to treat the POA&M as a way to “pass now, fix later.” Don’t build your plan on it. The items that most often block contractors are exactly the high-value requirements you can’tdefer. Plan to actually meet the requirements; treat the POA&M as a narrow safety valve for genuinely minor items, not a runway.
What Does CMMC Cost, and How Long Does It Take?
Our one hard truth
CMMC Level 2 is genuinely expensive and slow, and no consultant or C3PAO can guarantee you’ll pass. Anyone promising a guaranteed certification outcome is selling something the rules don’t allow them to deliver — The Cyber AB’s own conduct rules prohibit assessors from guaranteeing results. This page is education, not legal or contractual advice, and the program is still refining some interpretations as it rolls out.
The cheapest part of CMMC is clarity, and the most expensive mistake is waiting. The DoD figures below are assessment-and-affirmation costs; the rule assumes you’ve alreadyimplemented NIST SP 800-171, because that’s been required since 2017. In the real world, the implementation — closing gaps, standing up a CUI enclave, documenting everything, training people — is where the money goes.
What the DoD’s CMMC Program Rule estimates (assessment + affirmation, over the cycle):
- Level 1 (Self): about $4,042 per year for other-than-small entities; about $5,977 for small entities.
- Level 2 (Self): about $37,196 (small) to $48,827 (other-than-small) over three years.
- Level 2 (C3PAO): about $104,670 (small) to $117,768 (other-than-small) over three years.
- Level 3 (DIBCAC): Level 2 costs plus roughly $41,000 for implementing the additional NIST 800-172 requirements (DIBCAC conducts the Level 3 assessment, so there’s no separate C3PAO fee for that part).
DCR editorial estimate: once you add real implementation and remediation, all-in spend to reach Level 2 commonly runs $100,000–$200,000+for a contractor starting from a material gap. That is not a DoD figure — it’s a market-derived planning range; verify it with scoped quotes for your own environment.
DCR planning range on timeline: many Level 2 readiness programs take 6–18 months depending on scope, starting maturity, evidence quality, and assessor scheduling.
For a full breakdown of what drives your number, see our CMMC Level 2 cost guide.
How Big Is the CMMC Readiness Gap Right Now?
What the rule models — DoD regulatory analysis (DFARS final rule, Sept 10, 2025)
| Metric | Figure |
|---|---|
| Total impacted entities (Year 4) | ~337,968 |
| Small entities among them | ~229,818 |
| Level 1 (Self) | ~62% |
| Level 2 (Self) | ~2% (≈ 6,759 entities) |
| Level 2 (C3PAO) | ~35% (≈ 118,289 entities) |
| Level 3 | ~1% (≈ 3,380 entities) |
| Small-entity ramp | ~1,104 (Yr 1) → ~5,565 (Yr 2) → ~18,554 (Yr 3) → ~229,818 (Yr 4) |
What’s on the ground — The Cyber AB, March 2026 Town Hall
| Metric | Figure |
|---|---|
| Authorized C3PAOs (the only firms that can certify Level 2) | ~103 |
| Certified Assessors (CCAs) | ~759 |
| New Level 2 certificates issued in the month | ~178 |
| Organizations certified to Level 2 to date | ~1,000 |
The DCR calculation: roughly 1,000 organizations certified, against a DoD-modeled eventual Level 2 (C3PAO) population near 118,000, is under 1% of that population certified so far. At about 178 certificates a month, clearing that population would take many years at the current pace. The queue, not the rule, is the near-term risk.
What’s the Safest First Move If You Just Heard About CMMC?
The cheapest path runs in this order:
- Find the clause or flow-down. Look for DFARS 252.204-7012, -7019, -7020, -7021, and -7025 in your solicitation, contract, or your prime’s email. -7025 tells you the required level.
- Identify your information. FCI or CUI? This single answer points to your path. Don’t ask “what do we need to buy” — ask “what do we handle.”
- Map the environment. Where does FCI/CUI actually live — email, SharePoint, file shares, ERP/CRM, CAD/CAM, endpoints, backups, your MSP’s tools? Scope is the biggest cost lever in the entire program; shrinking it legitimately is the highest-leverage move you can make.
- Determine your likely path and assessment type. Use the Finder, then verify against the clause.
- Build the minimum evidence baseline. SSP, asset inventory, CUI data-flow map, core policies, your SPRS score, your POA&M, and a named affirming official.
- Choose a provider category only after scope is known — readiness/RPO/MSP, enclave/GCC High, GRC software, or C3PAO, depending on your stage.
Still not sure where you land, or which kind of help fits?
Tell us your level, scope, and timeline, and we’ll match you with source-checked CMMC provider options — no obligation.
Get matched with source-checked provider options →What Kind of CMMC Provider Do You Actually Need?
| Provider category | Use when | Don’t use when | Can it certify you? | Conflict-of-interest risk | What to verify before paying |
|---|---|---|---|---|---|
| Readiness / RPO / RP | You're scoping, remediating, or need help preparing | You only need a final certification stamp | No | The same firm generally can't also be your C3PAO | Track record, references, whether they'll create a conflict with your future assessor |
| MSP / MSSP / vCISO | You need implementation, monitoring, or managed security | You think managed IT alone equals compliance | No | Same separation applies if they also offer assessment | Government/CMMC experience, how they document evidence |
| GRC / evidence / SSP & POA&M software | You need to organize control mapping, evidence, and continuous compliance | You expect software to 'do' compliance | No | Low — but it doesn't reduce the separation rule for assessment | That it maps to NIST 800-171 Rev. 2, not just generic frameworks |
| CUI enclave / GCC High / GovCloud | You want to shrink scope by isolating CUI | You assume the cloud finishes the job | No | Low | FedRAMP posture, shared-responsibility matrix, what's still on you |
| C3PAO | Your contract requires Level 2 (C3PAO) and you're assessment-ready | You're still remediating | Yes (Level 2 certification) | High if they also prepared you — prohibited | Authorized status in The Cyber AB Marketplace, on the day you engage |
Why readiness and assessment must stay separate
This is a genuine independence rule, not a nicety. Under the CMMC conflict-of-interest rules — 32 CFR §170.8 and The Cyber AB’s Code of Professional Conduct — a CMMC ecosystem member that served as a consultant to prepare you for any CMMC assessment within the prior three years is prohibited from participating in your Level 2 certification assessment. That prohibition applies to the C3PAO organization and to the individual assessors on the team. Budget for two relationships, keep them at arm’s length, and be wary of anyone offering to both prepare you and grade you.
How do I verify a C3PAO?
Go to The Cyber AB Marketplace (the official registry at cyberab.org), search for the firm, and confirm it shows an Authorized C3PAO status. Two cautions. First, check it on the day you engage — authorization status can lapse or change. Second, don’t accept “almost certified,” “candidate,” or “pre-authorized” as a substitute; only a currently authorized C3PAO can conduct an official Level 2 certification assessment.
When you’re ready to compare specific firms, our provider-category breakdown and who to hire first resources put providers in source-checked tables with their role, status, and what to verify before you hire.
What Are the Most Common CMMC Mistakes?
- Mistake 1 — Buying technology before mapping FCI/CUI. Tools bought before scope is understood almost always over-cover, over-cost, or miss the actual gap. Scope is defined under 32 CFR §170.19.
- Mistake 2 — Assuming GCC High or GovCloud “solves” CMMC. A compliant environment is foundational, not sufficient; you still implement, document, and prove the 110 requirements of NIST 800-171 Rev. 2.
- Mistake 3 — Treating Level 2 as always C3PAO-assessed. The assessment type is set by the contract (DFARS 252.204-7025), not by the level alone. Confirm it; don’t assume it.
- Mistake 4 — Building to NIST 800-171 Rev. 3 for CMMC right now. 32 CFR §170.14 incorporates Rev. 2; Level 2 is assessed against Rev. 2 until DoD changes the rule.
- Mistake 5 — Ignoring SPRS and the annual affirmation. Under 32 CFR §170.22, a missing or stale affirmation can make your CMMC status no longer current — and quietly cost you eligibility.
- Mistake 6 — Entering CUI into unsafe intake forms or tools — including online forms. Protect the information CMMC exists to protect, even while you’re learning about CMMC.
Frequently Asked Questions
What does CMMC stand for?
CMMC stands for Cybersecurity Maturity Model Certification, a U.S. Department of Defense program that verifies defense contractors protect FCI and CUI on their systems before they can win or keep applicable DoD contracts.
What is CMMC in simple terms?
It’s the DoD’s way of checking — not just trusting — that a contractor meets required cybersecurity standards for the sensitive information it handles, at the level and assessment type the contract specifies. (Source: 32 CFR Part 170.)
Who needs CMMC?
DoD contractors and subcontractors that process, store, or transmit FCI or CUI on the systems used to perform a contract carrying the CMMC clause. Requirements flow down to subcontractors at any tier. (Source: 32 CFR §170.23; DFARS 252.204-7021.)
Is CMMC the same as CMMC 2.0?
Yes. “CMMC 2.0” is the current three-level program, codified at 32 CFR Part 170. When people say either, they mean the same thing.
Is CMMC required now?
Yes. The Program Rule (32 CFR Part 170) has been effective since December 16, 2024, and the DFARS acquisition rule took effect November 10, 2025, beginning the phased rollout. Whether a specific contract requires it depends on its clauses. (Source: Federal Register.)
What are the three CMMC levels?
Level 1 protects FCI with 15 requirements and annual self-assessment. Level 2 protects CUI with 110 NIST SP 800-171 Rev. 2 requirements. Level 3 adds 24 selected NIST SP 800-172 requirements and is assessed by DCMA DIBCAC after Final Level 2. (Source: 32 CFR §§170.14–170.18.)
What is the difference between FCI and CUI?
FCI is non-public information provided by or generated for the government under a contract (FAR 52.204-21). CUI is unclassified information that law, regulation, or government-wide policy requires you to safeguard (32 CFR Part 2002 and the NARA CUI Registry). FCI usually points to Level 1; CUI usually points to Level 2 or higher.
Is CMMC the same as NIST 800-171?
No. NIST SP 800-171 is the security requirement set for protecting CUI; CMMC is the program that verifies you’ve implemented it and ties that verification to your contract.
Does CMMC Level 2 use NIST SP 800-171 Rev. 2 or Rev. 3?
Revision 2. NIST published Rev. 3 in May 2024, but CMMC Level 2 is still assessed against Rev. 2, and DoD would need to amend the rule before Rev. 3 becomes the CMMC baseline. (Source: NIST CSRC; 32 CFR Part 170.)
Do I always need a C3PAO?
No. Level 1 is self-assessed, and some Level 2 contracts allow self-assessment. A C3PAO is required when your solicitation or contract specifies Level 2 (C3PAO). (Source: 32 CFR Part 170.)
How do I verify that a C3PAO is authorized?
Check The Cyber AB Marketplace (cyberab.org) on the day you engage and confirm the firm shows an Authorized status. Don’t accept “candidate,” “pre-authorized,” or “almost certified” — only a currently authorized C3PAO can conduct an official Level 2 certification assessment.
Can a readiness consultant or RPO certify me?
No. RPOs and consultants help you prepare; only an authorized C3PAO conducts the Level 2 (C3PAO) certification assessment — and generally not for a client it prepared within the prior three years. (Source: 32 CFR §170.8; Cyber AB Code of Professional Conduct.)
Can I pass CMMC with open items on a POA&M?
Only in limited cases. No POA&M is allowed at Level 1. At Level 2/3 you need at least 80% of requirements met, only low-value items qualify, and you must close them within 180 days. (Source: 32 CFR §170.21.)
What is SPRS?
The Supplier Performance Risk System — the government database where Level 1 and Level 2 self-assessment scores and all annual affirmations are recorded. C3PAO and DIBCAC results are recorded in eMASS, which feeds SPRS.
How much does CMMC cost?
It varies widely. DoD estimates roughly $4,000–$6,000 for Level 1 self-assessment, about $37,000–$49,000 over three years for Level 2 self-assessment, and about $104,670 (small) to $117,768 (other-than-small) for a Level 2 C3PAO cycle — figures that exclude the cost of implementing controls.
How long does CMMC take?
There’s no universal answer. Many Level 2 readiness programs run 6–18 months depending on scope, starting maturity, evidence quality, and assessor scheduling. A narrow CUI enclave with mature documentation moves faster than an enterprise brought into scope from scratch.
Is this page legal or compliance advice?
No. It’s educational. Confirm your contract’s applicability, your CUI scope, and your assessment type with your contracting officer or qualified counsel.
How We Verified This Guide
This guide separates three kinds of claims: primary-source regulatory facts, current-state figures, and our editorial judgments.
What we verified: We read the CMMC Program Rule at 32 CFR Part 170 (Federal Register, published October 15, 2024; effective December 16, 2024) and the DFARS acquisition rule (published September 10, 2025; effective November 10, 2025) directly. We confirmed the level requirement counts — 15 / 110 / 24 — against the eCFR text of 32 CFR §170.14, and confirmed the four required paths and seven possible CMMC statuses against the live text of DFARS 252.204-7021 and 252.204-7025 on Acquisition.gov. We confirmed that CMMC Level 2 currently maps to NIST SP 800-171 Revision 2 (not Rev. 3) and that CMMC Level 3 uses the February 2021SP 800-172 against NIST CSRC. We pulled the impacted-entity model from the DFARS final rule’s regulatory analysis, and the ecosystem figures from the March 2026 Cyber AB Town Hall. Last verified: Next scheduled review: September 2026, or sooner if DoD, NIST, DFARS, Cyber AB, or SPRS guidance changes.
What we could not independently verify:Real-world, all-in cost ranges and readiness timelines (these come from market reporting and vary by environment — labeled as DCR editorial estimates, not DoD figures) and any individual provider’s authorization status (always confirm directly in The Cyber AB Marketplace on the day you engage).
Need help deciding what type of CMMC provider you need?
Tell us your level, scope, and timeline, and we’ll match you with source-checked CMMC provider options.
Get matched with source-checked options →Related Guides
- CMMC Level 1 vs Level 2 vs Level 3
- CMMC Level 2 cost guide
- CMMC self-assessment vs. C3PAO assessment
- CMMC flow-down requirements for subcontractors
- CMMC Readiness Checklist (14 control families)
- CMMC provider categories: who to hire first
Primary sources & references
All guides in this topic: CMMC fundamentals & rules
- CMMC Reform Review 2026: Task Force, RFI & Updates
- Is CMMC Still Required After the Suspension? 2026 Status
- CMMC 2.0 Requirements 2026: Levels, Cost & What Changed
- CMMC Final Rule Explained (2026): Dates, Clauses & Steps
- CMMC Phase II Suspended: What Changed July 13, 2026
- 32 CFR Part 170 CMMC: What the Final Rule Requires (2026)
- 48 CFR CMMC Final Rule: DFARS 7021, 7025 & 2026 Changes
- Basic Safeguarding Requirements FCI: 15 Safeguards (2026)
- CMMC Program Rule vs Acquisition Rule: 32 CFR vs 48 CFR
- CUI Compliance for Civilian Contractors: 2026 Rule Map
- CUI Requirements for Federal Contractors: 2026 Rules by Agency
- FAR 52.204-21 Explained (2026): 15 Safeguards, Not 17
- FAR CUI Rule 2026: Proposed Changes & What Applies Now
- Governmentwide CUI Rule (2026): What Applies Now
- CMMC Annual Affirmation: SPRS Deadlines, Who Signs & Risk
- CMMC Deadlines 2026: Timeline, Phase 2 & Your Real Date
- CMMC Flowdown Letter Template (2026): Levels + Evidence
- CMMC Level 3 Requirements: 24 Controls + DIBCAC Path (2026)
- CMMC Waiver: Can You Get One, and What It Won't Do (2026)
- How Long Is CMMC Certification Good For? 3 Years (2026)
- Is CMMC Worth It? ROI for Small Contractors (2026)
- NIST 800-171 Rev 2 vs Rev 3: Which Applies to CMMC 2026
- NIST 800-171 vs 800-172: Which One Applies to You in 2026
- Who Needs CMMC Certification? 2026 Level & Scope Guide
- CMMC Level 2 Requirements: 110 Controls, Cost & Path (2026)
- CDI vs CUI: The Two-Part DFARS 252.204-7012 Test (2026)
- CMMC Deadline Missed? What Now — Scenario Triage (2026, Sourced)
- CMMC Flowdown Requirements (2026): Prime-to-Sub Matrix
- CMMC Implementation Phases: Phase 1 and Phase 2 Explained
- CMMC Level 1 vs 2 vs 3
- CMMC Level 1 vs Level 2 (2026): FCI, CUI, 15 vs 110 Requirements
- CMMC vs ISO 27001: What Counts, What Doesn't (2026)
- CMMC vs NIST 800-171: Same Controls, Different Job (2026)
- CMMC vs SOC 2: Does SOC 2 Satisfy CMMC? (Sourced, 2026)
- FCI vs CUI Explained
- Can't Bid Without CMMC Certification? What's Actually True (2026)
- DFARS 252.204-7012 Explained: Requirements & 72-Hour Rule
- DFARS 252.204-7021 Explained: CMMC Status, SPRS & Flow-Down
- CMMC Level 2 Required in Solicitation: What To Do Now (2026)
- CMMC Required to Bid on Contract? Bid vs Award Rules (2026)
- DFARS 252.204-7021 in My Contract? What It Requires (2026)
- DFARS 252.204-7025 Explained: CMMC Notice Provision (2026)
- Do I Need CMMC to Win My Contract? (2026 Award Rules)
- Prime Contractor Requiring CMMC Certification? Do This First
- CMMC Flowdown Letter Pack (2026) — Editable Templates