Who Needs CMMC Certification? A 2026 Decision Guide for DoD Contractors, Subcontractors, and Suppliers
Who needs CMMC (Cybersecurity Maturity Model Certification)? You need a CMMC statuswhen a U.S. Department of Defense (DoD) solicitation, contract, subcontract, or prime flow-down requires it for the systems you use to process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Here’s the part most of page one gets wrong, though: needing CMMC is not the same as needing a certificate. Handle only FCI? You need Level 1— a 15-requirement self-assessment you run yourself, with no auditor and no certificate. Handle CUI? You need at least Level 2 (110 requirements). Only two paths produce an actual Certificate of CMMC Status: a third-party (C3PAO) assessment at Level 2, and a government assessment at Level 3. The DoD’s own Federal Register estimate puts the Level 2 (C3PAO) population at about 8,350medium and large entities — everyone else who’s covered is on a self-assessment path. And solicitations solely for commercially available off-the-shelf (COTS) products are carved out from the CMMC requirement.
The expensive trap — the one we’ll show you how to sidestep — is paying for a third-party assessment before you’ve confirmed your contract even requires one. Let’s get you to the right answer first, then the right next move.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. We are not affiliated with the Department of Defense, the Cyber AB, DCMA DIBCAC, NIST, or any U.S. government agency, and no provider can guarantee a certification outcome.
Not sure which CMMC path applies to you?
Tell us your role, your contract clause, and whether FCI or CUI enters your systems. We route you to the correct status path and the right next action — in about two minutes, without uploading any sensitive data.
Run the 2-minute CMMC Applicability Checker →The CMMC scope matrix: find your row
Your CMMC path follows your data and your contract clause— not your size, your industry, or how many people work for you. Here is the whole decision in one table. Find the row that matches your situation, then read the section below it for the detail.
| If, on DoD work, you handle… | Your CMMC path | Requirements (standard) | Assessment | Certificate of CMMC Status issued? | Recorded in | Reassessed |
|---|---|---|---|---|---|---|
| No FCI or CUI on the systems used for the work — or the solicitation is solely for COTS items | No current CMMC status for that acquisition (document why) | — | None | No | — | — |
| FCI only (no CUI) | Level 1 (Self) | 15 (FAR 52.204-21) | Annual self-assessment | No | SPRS | Every year |
| CUI, non-prioritized work | Level 2 (Self) | 110 (NIST SP 800-171 Rev. 2) | Self-assessment | No | SPRS | Every 3 years + annual affirmation |
| CUI, prioritized/critical work | Level 2 (C3PAO) | 110 (NIST SP 800-171 Rev. 2) | Third-party (C3PAO) | Yes | CMMC eMASS (affirmations in SPRS) | Every 3 years + annual affirmation |
| CUI on the highest-risk programs | Level 3 (DIBCAC) | 134 (NIST SP 800-171 Rev. 2 + 24 from NIST SP 800-172) | Government-led (DIBCAC) | Yes | CMMC eMASS (affirmations in SPRS) | Every 3 years + annual affirmation |
We assembled this matrix from the program rule itself (32 CFR Part 170), the DoD’s contract clauses (DFARS 252.204-7021 and -7025), and the DoD Chief Information Officer’s published CMMC model.
What “who needs CMMC certification” really means
CMMC applies when a DoD solicitation, contract, subcontract, or prime flow-down requires a CMMC status for the systems you use to process, store, or transmit FCI or CUI. It is not “everyone in defense,” and it is not “only big primes.” It comes down to four triggers working together: a covered contract, covered data, the systems that touch that data, and the specific CMMC status written into the deal.
Here’s the word that trips everyone up. Searchers type “certification.” The rule and the clauses use CMMC status(DFARS 252.204-7021). The difference is not pedantic — it’s the difference between an afternoon of internal paperwork and a multi-month, third-party audit. Under 32 CFR Part 170, a Certificate of CMMC Status is issued only when a C3PAO or DCMA DIBCAC conducts the assessment. Level 1 and the self-assessment route at Level 2 produce a status you post in SPRS yourself. No auditor sets foot in your environment. No certificate prints.
So when a 12-person machine shop reads “you need CMMC certification” and pictures a five-figure audit, that fear is usually misplaced. Many companies that handle only FCI land at Level 1 self-assessment.
Two terms you’ll see on every covered contract:
- FCI (Federal Contract Information):non-public information provided by, or generated for, the government under a contract — and notintended for public release. Per DFARS 252.204-7021, it excludes information on public websites and simple transactional payment data. Think solicitation details, schedules, drawings, and order specifics that aren’t public.
- CUI (Controlled Unclassified Information): government information that isn’t classified but still requires safeguarding under a law, regulation, or government-wide policy. Covered defense information, controlled technical data, and many engineering and program records qualify.
The cleanest one-sentence answer for your leadership: “CMMC applies when our covered DoD work causes FCI or CUI to enter systems that must carry the CMMC status named in the solicitation, contract, or flow-down.”
Does CMMC actually apply to my company? Start with the clause, not the sales pitch
To know whether CMMC applies to you, read your contract documents before you talk to a single vendor. Look for the CMMC clauses in the solicitation or contract, confirm whether FCI or CUI will actually enter your systems, define which systems are in scope, and — if you’re a subcontractor — get the requirement in writing from your prime. The answer is in the paperwork, not the marketing.
This is the most useful 30 minutes you can spend, and almost nobody on page one walks you through it. Here’s the sequence we use.
Step 1 — Check the clauses
The clause set tells you what’s required and when. We pulled them together so you know exactly what you’re looking at:
| Clause | What it does | Why it matters to you |
|---|---|---|
| FAR 52.204-21 | Basic safeguarding for covered contractor information systems | These 15 safeguards are the basis for CMMC Level 1 |
| DFARS 252.204-7012 | Safeguarding covered defense information and cyber incident reporting | Long-standing duty to protect CUI and report incidents; flows down to subs |
| DFARS 252.204-7019 | Notice of NIST SP 800-171 DoD Assessment requirements (legacy/codified path) | Requires a current NIST SP 800-171 assessment score in SPRS where applicable; present in legacy/codified solicitations |
| DFARS 252.204-7020 | NIST SP 800-171 DoD Assessment requirements (legacy/codified path) | Covers the Basic/Medium/High DoD assessments and government access to assess; DFARS 252.240-7997 carries this function under the 2026 RFO/Class Deviation |
| DFARS 252.240-7997 | NIST SP 800-171 DoD Assessment requirements (2026 RFO/Class Deviation path) | Carries the assessment-and-SPRS-posting function in solicitations issued under the 2026 RFO/Class Deviation; replaces standalone DFARS 252.204-7019 in those solicitations |
| DFARS 252.204-7021 | Contractor compliance with the required CMMC level | Requires a current CMMC status, correct flow-down, and an annual affirmation |
| DFARS 252.204-7025 | Notice of the required CMMC level in the solicitation | Tells offerors the required level before award— and you’re not eligible without a current status and affirmation in SPRS |
If you see 7021 or 7025, CMMC is in play right now. If you see only 7012/7019/7020 (or 7012 plus DFARS 252.240-7997 under the 2026 RFO/Class Deviation), you’re in the NIST SP 800-171 world that CMMC is built to verify. CMMC requirements arrive through a new solicitation, a contract modification, an option exercise, or a prime flow-down — and by full implementation in November 2028, they apply to all applicable contracts involving FCI or CUI. Confirm with your contracting officer or prime before you spend.
Step 2 — Identify the data
Walk your actual workflows. Will the government provide, or will you generate, FCI or CUI in performance? Look at the statement of work, the data deliverables, drawings, specs, and any system access you’re granted. Be honest here — “we don’t think we have CUI” is one of the most common and most expensive misreads in the entire program. Covered defense information and controlled technical data sneak in through submittals, email, and shared drives constantly.
Step 3 — Draw the system boundary
CMMC is not “your whole company” by default. It applies to the assessment scope: the systems, people, facilities, and services that process, store, or transmit FCI or CUI — plus anything that provides security protection for those systems, or that isn’t separated from them. Get this boundary right and you can dramatically cut what you have to assess. Get it wrong and you either over-build or fail.
Step 4 — Ask your prime or contracting officer, in writing
If you’re a subcontractor, don’t guess what’s flowing down. Send this:
“Please confirm the required CMMC level and assessment type for our scope of work, the data category being flowed down (FCI or CUI), whether FCI or CUI will be provided to us or generated by us in performance, and whether a CMMC unique identifier or SPRS affirmation is required before subcontract award.”
That one paragraph turns a vague worry into a documented requirement you can plan and budget against.
Still not sure which side of the line you’re on? Answer four short questions about your role, your contract clause, and whether FCI or CUI enters your systems to get your likely status path and what to verify next. No CUI, contract files, or sensitive details required.
Confirm your CMMC path in 2 minutes
Tell us your role (prime or sub), your contract clause (FCI or CUI), and your system boundary. We return your likely status path, what to verify next, and which provider category makes sense — without asking for any sensitive data.
Run the 2-minute CMMC Applicability Checker →Which CMMC level do I need?
Your level depends on the type and sensitivity of the information you handle and the assessment type written into the solicitation or flow-down. Level 1 covers FCI with 15 safeguards. Level 2 covers CUI with the 110 requirements of NIST SP 800-171 Revision 2. Level 3 adds 24 selected requirements from NIST SP 800-172 for the highest-risk programs and is assessed by the government.
There are three levels, but five real paths, because Level 2 splits in two. Here’s each one in plain terms.
Level 1 (Self) — FCI only
Fifteen basic safeguards from FAR 52.204-21(b)(1)(i) through (xv). You self-assess annually, post the result in SPRS, and a senior official signs an annual affirmation. No third party. No Plan of Action and Milestones (POA&M) is allowed at Level 1 — every requirement has to be met, full stop.
A note on a number you’ll see fought over:some sources call Level 1 “17 practices.” The governing count for what you must implement is 15— the basic safeguarding requirements at FAR 52.204-21(b)(1)(i)–(xv), which 32 CFR § 170.14 adopts as the Level 1 set. You’ll see “17” because those 15 requirements map to 17 of the NIST SP 800-171 Rev. 2 requirements in some scoring contexts, and because older CMMC 1.0 materials used that count. For deciding what to implement at Level 1 today, it’s 15.
Level 2 (Self) — CUI, self-assessment route
The full 110 requirements of NIST SP 800-171 Revision 2, organized into 14 control families. You self-assess every three years, post the score in SPRS, and affirm annually. A limited POA&M is allowed: your score has to be at least 0.8 of the total, certain requirements can’t be deferred, and you must close the plan within 180 days or your conditional status expires.
This route is used when the solicitation or flow-down specifies Level 2 (Self). During the current phase-in (through late 2026), the DoD’s stated focus is Level 1 and Level 2 self-assessments — so if you’re being asked to self-assess CUI right now, that’s expected, not a loophole. See the full Level 2 self-assessment vs. C3PAO breakdown for where the line falls.
Level 2 (C3PAO) — CUI, third-party assessment route
Same 110 requirements. The difference is who checks: an authorized C3PAO assesses you, the results flow through CMMC eMASS, and you receive a Certificate of CMMC Status. You still affirm annually in SPRS, reassess every three years, and the same 0.8 / 180-day POA&M rules apply.
Over the full rollout, this becomes the dominant CUI path — the DoD estimates about 8,350medium and large entities will need it — and beginning November 10, 2026, it’s a condition of award for applicable CUI contracts. Some Phase 1 procurements can already require it at the DoD’s discretion.
Level 3 (DIBCAC) — the highest-risk CUI programs
The 110 Level 2 requirements plus24 selected enhanced requirements from NIST SP 800-172 — 134 in total. You must already hold a final Level 2 (C3PAO) status for the same scope, and then the government itself (DCMA DIBCAC) performs the Level 3 assessment. You reassess every three years and must keep both your Level 2 and Level 3 affirmations current in SPRS each year. This applies to a small slice of the base.
Level comparison at a glance
| Level / path | Usually applies when | Assessment | Requirements | The mistake we see |
|---|---|---|---|---|
| Level 1 (Self) | You handle FCI only | Annual self-assessment | 15 (FAR 52.204-21) | Treating it as optional because it’s self-assessed |
| Level 2 (Self) | CUI work the contract lets you self-assess | Self-assessment, every 3 years | 110 (NIST SP 800-171 R2) | Assuming all CUI requires a C3PAO immediately |
| Level 2 (C3PAO) | CUI work the contract flags for third-party assessment | Authorized C3PAO | 110 (NIST SP 800-171 R2) | Hiring an assessor before your scope and evidence are clean |
| Level 3 (DIBCAC) | Highest-risk / critical programs | Government (DCMA DIBCAC) | 134 (adds 24 from NIST SP 800-172) | Assuming subcontractors automatically need Level 3 |
Want a self-serve next step instead of a sales call?
Our CMMC Readiness Checklist maps the 110 Level 2 requirements to the 14 control families, so you can see exactly where you stand before you spend a dollar on outside help.
Download the CMMC Readiness Checklist (mapped to the 14 control families) →CMMC certification vs. CMMC status vs. your SPRS score — what’s the difference?
“Certification” is the search term, but the contract language is about your CMMC statusand your annual affirmation in SPRS — and neither of those is the same as your NIST SP 800-171 self-assessment score. A high SPRS score is good and often required, but it is not a Level 2 (C3PAO) certificate or a Level 3 (DIBCAC) status. People conflate the three constantly, and it leads to real award risk.
Untangle them like this:
- CMMC status is the result of meeting the minimum score for your required assessment (DFARS 252.204-7021). It can be Final Level 1 (Self), Conditional or Final Level 2 (Self), Conditional or Final Level 2 (C3PAO), or Conditional or Final Level 3 (DIBCAC). Note there is no conditional status at Level 1 — it’s final or nothing.
- A certificateis issued only for the C3PAO and DIBCAC routes. Self-assessment routes don’t get one.
- Your SPRS scoreis your NIST SP 800-171 DoD Assessment result, tracked under DFARS 252.204-7019/-7020 (legacy/codified path) or DFARS 252.240-7997 (2026 RFO/Class Deviation path). It feeds the picture, but having one does not mean you’re “CMMC certified.”
- The annual affirmationis a senior official’s yearly attestation, in SPRS, that you still meet the requirements. Miss it and your status can go inactive — which can cost you eligibility even if your controls are fine.
If you remember one thing: a number in SPRS is not a certificate, and a certificate is not the same as staying current. All three have to be right.
Do subcontractors and suppliers need CMMC certification?
Yes — when they process, store, or transmit FCI or CUI on the systems they use to perform a covered DoD subcontract. Under 32 CFR § 170.23, CMMC applies to prime contractors and subcontractors at every tier of the supply chain. The required level depends entirely on the data the sub handles and what the prime’s contract requires — not on company size or distance from the DoD.
Here’s the flow-down, straight from the rule:
| Your situation as a subcontractor | Minimum CMMC status |
|---|---|
| You receive/handle FCI only | Level 1 (Self) |
| You receive/handle CUI | Level 2 (Self) minimum |
| You handle CUIand the prime’s contract requires Level 2 (C3PAO) | Level 2 (C3PAO) minimum |
| You handle CUIand the prime’s contract requires Level 3 (DIBCAC) | Level 2 (C3PAO) minimum — not Level 3, unless the DoD gives specific guidance |
That last row catches a lot of people off guard, so read it twice: even when your prime is on a Level 3 (DIBCAC) program, a CUI-handling subcontractor’s floor is Level 2 (C3PAO). The rule does not automatically push Level 3 down to you.
If you’re a prime managing subs, get these on file from each one before award: a written data-flow confirmation, their CMMC status or plan, a CMMC unique identifier where applicable, their SPRS affirmation status, a scope statement, and confirmation that no CUI is flowing through unsecured intake channels like personal email.
See the full prime-to-subcontractor CMMC flow-down matrix — every tier, with the exact minimums.
Do small businesses, foreign companies, MSPs, software vendors, and cloud providers need CMMC?
Size, location, and vendor category don’t get you out of CMMC. What matters is whether covered data and a covered contract pull your systems, staff, tools, or services into scope. A small shop, a foreign supplier, a managed service provider, or a SaaS vendor can each be in scope — at different levels, or not at all — based on the same clause-data-scope analysis everyone else runs.
Small businesses
Not exempt. But “not exempt” doesn’t mean “Level 2 C3PAO.” A small business handling only FCI is a Level 1 self-assessment. A small business with no covered data and no covered contract may need no current status at all. Run the same analysis the primes run — and if you’re a small DIB supplier weighing help, our guide to the best CMMC providers for small business breaks down the options by category.
Foreign and non-U.S. companies
Location alone doesn’t exempt you. The DoD’s CMMC FAQ is direct: when CMMC requirements are identified in a Department solicitation, they apply to every company performing under the resulting contract, domestic or international. Separate issues — export controls (ITAR/EAR), foreign ownership, control, or influence (FOCI), data residency, and sanctions — still need their own review, but they don’t remove the CMMC requirement.
MSPs, MSSPs, SaaS, and cloud providers — the scoping question
This is where companies get it wrong in both directions: assuming “all MSPs need certification,” or assuming “my MSP handles it, so I’m covered.” Neither is right. The real question is whether the provider touches your CUI or protects your in-scope systems. Here’s how the common cases break down:
| Vendor type | Handles your CUI? | Provides security protection for your CUI systems? | Needs its own CMMC assessment? | In your assessment scope? | What to nail down |
|---|---|---|---|---|---|
| MSP storing/processing your CUI | Yes | Often | Not separately — assessed within your scope | Yes (as an External Service Provider) | Document it in your SSP; its service must meet your level’s requirements |
| MSSP with security data but no CUI | No | Yes (handles Security Protection Data) | Not separately | Yes, to the extent it protects in-scope assets | A customer responsibility matrix; what exactly it protects |
| SaaS storing/processing your CUI | Yes | Sometimes | Not separately | Yes | Where the CUI actually lives; cloud requirements; the responsibility matrix |
| Cloud (CSP) storing your CUI — even encrypted | Yes | — | — | Yes | FedRAMP Moderate (or equivalent) under DFARS 252.204-7012 |
| Vendor that never touches CUI or SPD | No | No | No | No | Confirm and document the separation |
| Hard-copy CUI only (never on a system) | Paper only | — | No assessment required | N/A | Safeguard per DoD Instruction 5200.48; the moment it’s digitized, that system is in scope |
The headline for service buyers: an External Service Provider (ESP) — your MSP, MSSP, or SaaS — doesn’t necessarily need its own certificate, but if it touches your CUI or protects your in-scope systems, its services are assessed as part of your scope, and they have to meet your level’s requirements. “We outsourced it” does not outsource the obligation. And no piece of software, by itself, makes you compliant — it can help you implement and prove controls, but the responsibility stays with you.
If your real problem is shrinking what’s in scope, that’s a solvable architecture question — see our guides to a CMMC secure enclave, Microsoft Azure Government, and AWS GovCloud for the trade-offs.
When do you actually need to be CMMC certified?
CMMC contractual implementation began November 10, 2025, when the revised DFARS clause took effect, and the DoD is phasing it in over three years. During the current phase, solicitations mainly require Level 1 and Level 2 self-assessments, though the DoD can require a Level 2 (C3PAO) assessment in select procurements. By the final phase, CMMC applies across all applicable DoD contracts. But your real deadline isn’t a calendar date — it’s the first contract you want that names a CMMC requirement, which can be today.
The program rests on two rules we read in full: the CMMC Program rule (32 CFR Part 170), published October 15, 2024 and effective December 16, 2024; and the DFARS rule (48 CFR), published September 10, 2025 and effective November 10, 2025. Here’s the rollout:
| Phase | Begins | What becomes a condition of award |
|---|---|---|
| Phase 1 | Nov. 10, 2025 | Level 1 (Self) and Level 2 (Self) where applicable; Level 2 (C3PAO) at the DoD’s discretion |
| Phase 2 | Nov. 10, 2026 | Level 2 (C3PAO) for applicable contracts |
| Phase 3 | Nov. 10, 2027 | Level 3 (DIBCAC) for applicable contracts |
| Phase 4 | Nov. 10, 2028 | Full implementation across applicable contracts |
Under DFARS 252.204-7025, the required CMMC level must be met before award, and a contracting officer will not award to an offeror without a current CMMC status and affirmation in SPRS.
The operational reality: in the Federal Register (89 FR 83092), the DoD estimated about 8,350 medium and large entitieswill need the Level 2 (C3PAO) path. Industry data (Cyber AB Town Hall, March 2026 — re-check the live numbers on the Cyber AB Marketplace) put only around 100 C3PAOs authorized to perform those assessments, roughly 1,000 organizationsholding a Level 2 certification (≈1% of the affected base), and C3PAO engagements booking 8 to 12 weeks out. Stack that against a Phase 2 award in November 2026 and a 6-to-18-month readiness effort, and the runway is far shorter than it looks.
The honest part:the most expensive CMMC mistake isn’t moving too slowly. It’s a CUI contractor spending months and tens of thousands of dollars chasing a Level 2 (C3PAO) assessment before confirming the solicitation requires it. Verify the clause, the data, and the scope first, so every dollar goes toward the path you’re actually on.
What should you do first if you think you need CMMC?
Do not start by buying an assessment. Start by confirming the clause, the data, the scope, and the required status — then run a self-assessment or gap assessment and close your biggest gaps before you schedule anything. The DoD’s own guidance says contractors should carefully self-assess and take corrective action before initiating a CMMC assessment. Sequence is everything, and getting it wrong is where the money leaks.
Our seven-step order:
- Gather the paperwork— solicitation, contract, subcontract, statement of work, and any prime flow-down language.
- Identify FCI and CUI in your actual workflows.
- Map the data flows— where covered data enters, lives, and leaves.
- Define the assessment scope— and look hard at whether you can reduce it.
- Run a self-assessment or gap assessment against Level 1 or Level 2.
- Build or update your evidence— System Security Plan (SSP), POA&M, policies, and proof.
- Choose the right provider category— readiness, managed services, enclave/cloud, evidence software, or a C3PAO.
That last step is where most of the wasted money happens, so here’s who to call first based on where you actually are:
| Where you are | Talk to this category first | Not this |
|---|---|---|
| “I don’t even know if CMMC applies” | Neutral scope/readiness triage (or our matching form) | A named C3PAO |
| “We have CUI but our environment is a mess” | Readiness / RPO / MSP / MSSP / GCC High or enclave implementation | A formal C3PAO assessment |
| “We need to shrink our scope” | CUI enclave / secure collaboration / cloud architecture | A generic GRC-only tool |
| “We have controls but weak evidence” | GRC / evidence-management software plus a readiness advisor | A C3PAO first |
| “Our solicitation requires Level 2 (C3PAO) and we’re ready” | An authorized C3PAO | A remediation vendor implying it can also certify you |
| “Level 3 language appeared” | Level 3 / DIBCAC readiness + contract review | A Level 2-only consultant |
One rule that protects you: keep readiness implementation and the formal assessment separate unlessthe C3PAO can document that the conflict is avoided or sufficiently mitigated under the Cyber AB’s CMMC Assessment Process and Code of Professional Conduct. Default to one provider to build your program and a different one to assess it, unless your assessor can show there’s no unmitigated conflict.
Not sure which row in that table is yours?
Tell us your level, scope, and timeline, and we’ll match you with source-checked CMMC provider categories — readiness, MSP/MSSP, enclave/cloud, evidence software, or C3PAO — based on where you actually are, not on whoever markets hardest.
Get matched with source-checked provider options →Who does NOT need CMMC certification (yet)?
You may not need a current CMMC status today if you have no covered DoD contract path, no FCI or CUI entering your systems, a solely-COTS line of work, or systems that are genuinely separated from any FCI/CUI environment. But the safe answer never rests on your industry label — it rests on your contract language, your data flows, and a documented scope. Get the analysis on paper either way.
You’re likely in a “not yet” position if:
- You sell onlyCOTS items under a solicitation that’s solely for COTS items, and you don’t process, store, or transmit FCI or CUI beyond ordinary transactions (DFARS 204.7504 keeps the CMMC clause out of solely-COTS solicitations).
- You’re a commercial vendor with no DoD contract, subcontract, or covered-data flow.
- Your corporate systems are physically or logically separated and can’t process, store, or transmit CUI or provide security protection to CUI assets.
- You receive only public information or payment-processing data.
If that’s you, you don’t need to spend anything right now. Bookmark this page, document your reasoning, and revisit the moment a CMMC clause or a prime request changes the picture. What you should keep on file: your clause-review notes, an FCI/CUI data-flow map, any written clarification from your prime or contracting officer, your out-of-scope rationale, and an architecture diagram that shows the separation.
What evidence will a prime, contracting officer, or assessor expect?
Expect to proveyour status, scope, and affirmation — not just assert “we’re compliant.” Depending on your level, that means a current SPRS status, a CMMC unique identifier, your CAGE code(s), an SSP, scope diagrams, any conditional/POA&M details, current annual affirmations, and Level 2 (C3PAO) certificate information where it applies.
| Status | Evidence to have ready |
|---|---|
| Level 1 (Self) | SPRS result, CMMC unique identifier(s), scope, CAGE code(s), annual affirmation |
| Level 2 (Self) | SPRS score, CMMC unique identifier(s), scope, SSP, CAGE code(s), POA&M status if conditional, annual affirmation |
| Level 2 (C3PAO) | CMMC unique identifier(s), C3PAO assessment status/certificate info, SSP and scope, annual affirmation |
| Level 3 (DIBCAC) | Final Level 2 (C3PAO) prerequisite evidence, DIBCAC status, Level 3 scope, current Level 2 and Level 3 affirmations |
One safety warning: do not submit CUI, export-controlled technical data, drawings, contract attachments, or sensitive system diagrams through anywebsite form — including ours. A legitimate matching or intake process asks only for your role, level, scope category, timeline, and contact information. If a form asks you to upload your SSP or covered data, that’s a red flag.
The most common mistakes when deciding who needs CMMC
The big ones: overgeneralizing, under-scoping CUI, confusing a self-assessment with a certification assessment, treating an SPRS score as a certificate, building to NIST SP 800-171 Revision 3 instead of the Revision 2 set CMMC actually uses, and letting one firm both remediate and assess you. Each of these creates award risk, assessment conflict, or wasted work — and each is avoidable.
Mistake 1 — “All DoD suppliers need Level 2 (C3PAO).” No. FCI-only subs are Level 1 (Self); CUI subs need at least Level 2 (Self); Level 2 (C3PAO) is the floor only when you handle CUI and the prime’s requirement is Level 2 (C3PAO) (32 CFR § 170.23).
Mistake 2 — “A C3PAO can get us ready and then assess us.” Treat that as a conflict of interest. The Cyber AB’s Assessment Process requires C3PAOs to manage conflicts and stop if they can’t be sufficiently mitigated. Default to one provider to prepare you and a different one to assess you.
Mistake 3 — “We have an SPRS score, so we’re certified.” An SPRS score, status, and affirmation are not the same as a Level 2 (C3PAO) certificate or a Level 3 (DIBCAC) status.
Mistake 4 — “CMMC Level 2 uses NIST SP 800-171 Rev. 3 now.” It doesn’t. 32 CFR Part 170 maps Level 2 to NIST SP 800-171 Revision 2. NIST published a newer revision, but adopting it for CMMC would take future DoD rulemaking. Until that happens, you assess against Rev. 2.
Mistake 5 — “Encryption makes our systems out of scope.” It doesn’t, on its own. Under DoD scoping guidance, a system that processes, stores, or transmits CUI is in scope even when that CUI is encrypted; encryption is a control, not a scope boundary.
Mistake 6 — “The provider’s website proves they’re authorized.” Verify it yourself. And here’s why that matters more than it sounds.
A primary-source case study: why you verify a C3PAO yourself
In January 2025, the DoD Office of Inspector General published an audit — Report No. DODIG-2025-056— of how C3PAOs get authorized in the first place. C3PAOs must clear 12 requirements before they can perform Level 2 assessments, a process the DoD assigned to the Cyber AB under a no-cost contract. Reviewing 11 of the 48 C3PAOs authorized as of September 21, 2023, the OIG found the DoD and Cyber AB met 10 of the 12requirements — but authorized two C3PAOs without a signed C3PAO Agreement and Code of Professional Conduct, four without verifying their quality-control leads’ certifications, and all of them without adequately confirming a certified assessor and a certified quality-control lead were on the team. The root cause: the DoD Chief Information Officer had no quality-assurance process to verify the Cyber AB’s work. The OIG made 10 recommendations to fix it, and DoD CMMC officials partially agreed.
The takeaway: an “authorized” badge on a vendor’s site is not the end of your diligence. Before you sign with any C3PAO, confirm its current status directly on the Cyber AB Marketplace, and ask how it manages assessor independence and conflicts.
What does CMMC cost, and how long does it take?
Cost and timeline ride on your level, your starting maturity, how much CUI you handle, your number of users and systems, your cloud or enclave decisions, the state of your evidence, and whether you need readiness work or only an assessment. The DoD’s own FAQ says assessment cost depends on the level, the complexity of your environment, your existing posture, and market forces.
What actually moves the number — and how to keep your quote from ballooning:
| Cost driver | Cheaper when… | More expensive when… | What lowers your quote |
|---|---|---|---|
| Scope | CUI is enclaved to a small, defined boundary | CUI sprawls across your whole network | A clean CUI data-flow map and scope diagram |
| Starting maturity | You already meet most of NIST SP 800-171 Rev. 2 | You’re starting near zero | A recent gap or self-assessment with your SPRS score |
| Environment | Few users, simple systems | Many users, complex or legacy systems | An accurate asset inventory |
| Cloud decisions | You use a compliant enclave or GovCloud | You retrofit on-prem for every control | A decided cloud/enclave strategy before you ask for quotes |
| Evidence | Policies, SSP, and proof are organized | Evidence is scattered or missing | A maintained SSP and evidence library |
| The assessment | You’re truly assessment-ready | The assessor finds gaps mid-engagement | An independent readiness review first |
The single biggest lever you control is scope— reduce it, and you reduce nearly every line above. For a deeper breakdown, see our Level 2 cost guide rather than padding this page with numbers that depend on your environment.
What we actually verified for this guide
We don’t ask you to take our word for it. Here’s what we checked, where, and when — separating primary regulatory sources from industry data that moves.
Primary regulatory sources (read directly):
| What we verified | Source we read | Verified |
|---|---|---|
| CMMC program scope, definitions, and the “Certificate of CMMC Status” rule | 32 CFR Part 170 (eCFR) | |
| Level 1/2/3 requirement counts and assessment types | 32 CFR §§ 170.14–170.18; DoD CIO CMMC model | |
| POA&M, conditional status, and scoring rules (0.8 threshold, 180-day closeout) | 32 CFR §§ 170.21, 170.24 | |
| Subcontractor flow-down | 32 CFR § 170.23 | |
| CMMC contract and solicitation clauses | DFARS 252.204-7021 and -7025 (Acquisition.gov) | |
| COTS treatment | DFARS 204.7504 (Acquisition.gov) | |
| Dual-rule effective dates and the four-phase schedule | Federal Register (89 FR 83092; DFARS final rule, 2025); DoD CIO | |
| Level 2 (C3PAO) population estimate (≈8,350 entities) | Federal Register, 89 FR 83092 | |
| C3PAO authorization weaknesses (12 requirements; no-cost contract; 10 recommendations) | DoD OIG audit, Report No. DODIG-2025-056 |
Operational snapshot (industry data — re-verified quarterly, verify the live numbers yourself):
| Figure | Source | As of | How to check |
|---|---|---|---|
| ≈100 authorized C3PAOs | Cyber AB Town Hall | March 2026 | Cyber AB Marketplace |
| ≈1,000 Level 2 certifications / ∼1% DIB readiness | Cyber AB Town Hall analysis | March 2026 | Cyber AB Town Hall |
| 8–12 week C3PAO booking window; 6–18 month readiness | Industry rule of thumb | 2026 | Provider quotes |
Frequently asked questions
Is CMMC required for all DoD contractors?
No. It’s required when an applicable solicitation, contract, subcontract, or flow-down requires a CMMC status for systems that process, store, or transmit FCI or CUI. Solicitations solely for COTS items, and situations with no FCI or CUI, can be different — the contract language controls.
Do subcontractors need CMMC certification?
Yes, if they process, store, or transmit FCI or CUI under a covered subcontract. The minimum depends on whether they handle FCI only (Level 1 Self), CUI (Level 2 Self minimum), CUI under a Level 2 (C3PAO) prime requirement (Level 2 C3PAO), or CUI under a Level 3 prime (Level 2 C3PAO minimum) — per 32 CFR § 170.23.
Do small businesses need CMMC?
Small businesses are not exempt if the contract, data, and scope trigger CMMC. Their path can still be Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), or no current status, depending on the same analysis everyone runs.
Does Level 2 always mean a C3PAO assessment?
No. Level 2 can be a self-assessment or a C3PAO assessment, depending on the solicitation or flow-down. 32 CFR Part 170 defines both a Level 2 self-assessment route and a Level 2 certification assessment route.
Do I need CMMC if I only handle FCI?
If your covered DoD work requires CMMC and you handle only FCI, your likely path is Level 1 (Self) — a 15-requirement annual self-assessment in SPRS, not a Level 2 audit.
Do I need a CMMC assessment if I only handle hard-copy CUI?
Not necessarily. The DoD’s CMMC FAQ clarifies that organizations handling CUI onlyin hard-copy form are not required to complete a CMMC assessment — but they must still safeguard that CUI and train their people, with hard-copy handling governed by DoD Instruction 5200.48. The catch: the moment that CUI is scanned, photographed, emailed, uploaded, printed, or otherwise placed on an information system, that system is in scope and must meet the applicable CMMC requirements before the CUI touches it. Treat paper-only as fragile — routine business practices break it fast.
Is an SPRS score the same as CMMC certification?
No. SPRS is where certain scores, statuses, unique identifiers, and affirmations are recorded. A Level 2 (C3PAO) assessment is a separate certification assessment that produces a Certificate of CMMC Status.
Are CMMC results public?
No. There’s no public directory listing every company’s CMMC self-assessment score or certificate. You can view your own status in SPRS, DoD officials can see what they need for procurement, and you can voluntarily share your status, score, or certificate with a prime for teaming. Expect to provideproof to your primes and contracting officers — not to look others up.
Can a C3PAO prepare us and then assess us?
Default to separate providers for readiness and assessment unless the C3PAO can document that any conflict is avoided or sufficiently mitigated under the Cyber AB’s CMMC Assessment Process and Code of Professional Conduct.
Does CMMC Level 2 use NIST SP 800-171 Rev. 2 or Rev. 3?
Current CMMC Level 2 maps to NIST SP 800-171 Revision 2 under 32 CFR Part 170. Adopting a newer revision for CMMC would require future DoD action.
What if my contract has DFARS 252.204-7012 but not 252.204-7021?
DFARS 252.204-7012 puts you in the NIST SP 800-171 / covered-defense-information world — you must safeguard CUI and report incidents — but on its own it does not insert a CMMC status requirement. The CMMC obligation arrives through the CMMC clauses, DFARS 252.204-7021 and the solicitation notice at 252.204-7025, when they apply to your contract.
What happens if I’m not compliant at award?
You can’t be awarded a covered contract without the required current CMMC status and a current affirmation in SPRS (DFARS 252.204-7025). But there’s a useful wrinkle at Level 2 and Level 3: if your assessment score is at least 0.8 of the total and you have a qualifying POA&M, you can receive a conditionalstatus that supports award — and you then have 180 days to close the POA&M (32 CFR § 170.21). Level 1 has no conditional status; it must be final.
Who should I talk to first if I’m not ready?
Start with scope and readiness help, not a formal assessment. Engage a C3PAO only when your solicitation requires it and your environment is genuinely assessment-ready.
Get the right answer before you spend a dollar
Many companies performing covered DoD work involving FCI or CUI will need a CMMC status— but that status may be self-assessed or independently assessed, and only your data plus your contract clause pin down which. Confirm those, scope your environment, and move in the right order.
Related guides
- CMMC levels explained: Level 1, 2, and 3 compared (2026)
- CMMC Level 2 self-assessment vs. C3PAO: how to choose
- CMMC flow-down requirements: prime-to-sub matrix
- CMMC Level 2 cost in 2026: DoD vs. real market
- Best CMMC providers for small business
- How to choose the right C3PAO for Level 2
- CMMC secure enclave: scope reduction and options
- CMMC RPO consultants: readiness help before the assessment