Regulatory Guide

CMMC FAQ:
Official DoD Answers, Explained

The DoD's Office of the CIO published Revision 2.1 of the CMMC FAQ in November 2025. It covers 25 questions across assessments, cloud, MSPs, VDI, subcontractors, and POA&Ms. This article walks through the most consequential answers and explains what they mean in practice.

Updated March 27, 2026  ·  Source: DoD CIO CMMC FAQ Rev 2.1, November 2025

About CMMC The Model Assessments Implementation MSPs & ESPs VDI & Cloud Key Takeaways

Section A: About CMMC

The FAQ opens with the questions that dominate every early conversation about CMMC: when does this apply, what does it cost, and where do I go for help?

When do CMMC assessments become required?

CMMC requirements began appearing in applicable DoD procurements on November 10, 2025, when revised DFARS clause 252.204-7021 became effective. The first 12 months focus primarily on self-assessments at Level 1 and Level 2. Third-party C3PAO assessments roll in over a four-phase implementation period defined in 32 CFR 170.3(e). Phase 2 begins November 2026, at which point C3PAO assessments become standard for new CUI-handling solicitations.

What This Means for Contractors Starting Today
If your contract already includes DFARS 252.204-7012, you are required to be NIST SP 800-171 compliant right now, regardless of CMMC phase. CMMC adds a verification layer on top of an obligation that has existed since December 2017. The phased timeline governs when DoD will contractually verify compliance, not when compliance was required.

How much does CMMC compliance cost?

The DoD's answer is intentionally non-specific: costs depend on your CMMC level, network complexity, existing security posture, and market conditions. What the FAQ does clarify is that costs incurred implementing existing DFARS 252.204-7012 safeguarding requirements are not considered part of CMMC compliance cost. That distinction matters for cost accounting and contract reimbursement purposes.

The DoD also points to several no-cost resources: the DIBNet Cybersecurity-as-a-Service portal, the Cyber AB marketplace of certified practitioners, and free online training through the Defense Acquisition University.

Section B: The CMMC Model

NIST SP 800-171 Rev 2 vs. Rev 3: where things stand

This is one of the most actively misunderstood areas in CMMC right now. The FAQ is clear: CMMC assessments are conducted against Revision 2 until the class deviation memo is withdrawn or superseded through rulemaking. Rev 3 will be incorporated into the program through future rulemaking, but there is no timeline for that transition.

Contractors can implement Rev 3 voluntarily, but must use the DoD's Organization-Defined Parameters (ODPs) from the April 2025 memorandum to do so. Critically, any gaps between Rev 2 and Rev 3 must still be addressed, because the assessment will be conducted against Rev 2. Implementing Rev 3 does not give you a pass on Rev 2 requirements that are not covered or that differ in Rev 3.

NIST SP 800-172 and Level 3

CMMC Level 3 builds on the 110 requirements in NIST SP 800-171 by adding 24 requirements from NIST SP 800-172. These are designed to address advanced persistent threats. Level 3 is reserved for contractors working on the DoD's highest-priority programs and is specified in the contract when required.

Flow-down to subcontractors

CMMC requirements flow down to subcontractors handling FCI or CUI under the same contract, per 32 CFR 170.23. The required level is determined by the data type involved. One notable rule: when a prime contract requires Level 3, the minimum flow-down requirement for subcontractors is Level 2 with C3PAO assessment, unless the government provides specific contractual guidance otherwise.

Is encrypted CUI still CUI?

Yes. CUI remains controlled until formally decontrolled, regardless of encryption state. Encrypting CUI does not change its designation or remove safeguarding requirements. The FAQ acknowledges that certain transmission risks may be accepted for ciphertext that would not be accepted for plaintext, but that nuance does not decontrol the information or reduce the underlying obligation.

This has a direct practical consequence for the cloud question: a non-FedRAMP-authorized CSP cannot store encrypted CUI and claim the encryption eliminates the platform authorization requirement. The DoD addresses this explicitly in Section E.

Section C: Assessments

Assessment frequency

CMMC Level Assessment Type Frequency Annual Affirmation Required?
Level 1 Self-assessment Annual Yes
Level 2 Self-assessment or C3PAO Every 3 years Yes, annually
Level 3 DCSA-led government assessment Every 3 years Yes, annually

Do FCI-only contractors need an independent assessment?

No. If a contractor handles only FCI and no CUI, a Level 1 self-assessment is required. Independent C3PAO assessment is only required at Level 2 and above, and only when specified in the contract.

POA&Ms: what is and is not permitted

The FAQ addresses two POA&M-related questions that catch contractors off guard.

First, six security requirements are prohibited from appearing on a POA&M. These are defined in 32 CFR 170.21 and must be fully implemented before a conditional CMMC status can be granted. Missing any of the six results in no CMMC status, not a conditional one. The FAQ does not list them by name. Contractors need to review 32 CFR 170.21(a)(2)(iii) directly.

Second, a POA&M Closeout Assessment can only be finalized in CMMC eMASS once during the 180-day conditional window. If requirements are still not met at closeout, conditional status is terminated and the organization must start over with a new assessment. There is no second chance within the same window.

The SSP requirement and SPRS scoring

The FAQ includes a question about a specific SPRS error that many contractors encounter: marking CA.L2-3.12.4 (System Security Plan) as "Not Met" results in a "No Score" rather than a numeric score. The DoD's reasoning is that without a current SSP, an assessment cannot be completed. An absent SSP is not a gap that produces a point deduction. It is a condition that makes the assessment impossible.

The SSP Is Not Optional
Before any other remediation work begins, you need a System Security Plan that documents your environment and your implementation of all 110 requirements. It is the foundation every other artifact depends on. An assessor cannot evaluate controls they cannot read about, and SPRS will not accept a score from an organization that has not produced one.

Section D: Implementation

Does CMMC apply to non-US companies?

Yes. When CMMC requirements appear in a DoD solicitation, they apply to all performing contractors regardless of nationality or country of origin. International companies operating under DoD contracts are subject to the same assessment requirements as domestic contractors.

Non-US citizens and organizations can also participate in the CMMC ecosystem as C3PAOs, Registered Practitioners, or assessors, provided they meet all requirements in the 32 CFR CMMC rule.

Phase 1 and C3PAO discretion

During Phase 1 (the first 12 months after November 10, 2025), Program Managers are not required to include C3PAO assessment requirements in solicitations, even for contracts involving CUI from the Defense Organizational Index Group. The default during Phase 1 is Level 2 self-assessment for CUI contracts. Program Managers retain discretion to require C3PAO assessment during Phase 1, but only when market research indicates sufficient qualified offerors exist to support adequate competition.

Section E: External Service Providers and MSPs

Section E is where the FAQ delivers some of the most practically useful guidance in the document. MSP and cloud questions dominate real-world compliance conversations, and the official answers resolve several persistent points of confusion.

Does an MSP need its own CMMC assessment?

The answer depends on the MSP's role and what it handles.

MSP Scenario Own CMMC Assessment Required? How They Are Handled
MSP provides a non-cloud system where the OSA stores CUI No (but may elect to pursue one) Assessed as part of the OSA's assessment. If MSP obtains its own certification, it must be at the same or higher level as the OSA's contract requirement.
MSP provides IT support; no CUI is sent to the MSP No Still assessed as part of the OSA's assessment as an External Service Provider. The MSP qualifies as an ESP and applicable security requirements are evaluated in the OSA's assessment.
MSSP manages security tools; no CUI is sent to the MSSP No Also assessed as part of the OSA's assessment as an ESP. Security protection data is in scope regardless of whether CUI is directly shared.
The Critical Clarification for MSPs
Not sending CUI to your MSP or MSSP does not remove them from your assessment scope. If they provide IT support or manage security tools for your CUI environment, they are External Service Providers and will be evaluated during your C3PAO assessment. The question is not whether CUI touches the MSP directly. The question is whether the MSP has administrative access to systems that process CUI.

When does an MSP become a CSP?

The FAQ addresses this directly. If the cloud tenant is subscribed or licensed to the OSA (even if the MSP resells the service), the MSP is not a CSP. The cloud licensing relationship determines the designation, not who manages it day-to-day. However, if the MSP contracts with the CSP directly and modifies the base cloud service, the MSP may itself be considered a CSP and must meet FedRAMP or equivalency requirements.

Cloud service requirements for CUI

Two questions in Section E confirm what many contractors are still resisting: FedRAMP Moderate authorization is required for any CSP storing, processing, or transmitting CUI. This cannot be satisfied by applying encryption or additional controls on top of a non-authorized platform. The DoD closes that door explicitly by answering both "must CSPs meet FedRAMP Moderate?" (yes) and "can a non-FedRAMP CSP store encrypted CUI?" (no).

VDI Endpoints: In Scope or Out?

Questions E-Q6 and E-Q7 address Virtual Desktop Infrastructure, which has become a popular approach for limiting assessment scope. The DoD's answers are nuanced but workable.

An endpoint accessing a VDI can be considered out of scope if the VDI is configured to prevent any CUI from reaching the local device. The configuration requirements are specific and must be enforced server-side, not just policy-stated:

  • Copy-paste between the virtual session and the local device must be blocked.
  • File transfers, drive mounting, and printing from the virtual session to the local device must be disabled.
  • Only keyboard, video, and mouse data should transit the VDI session.
  • Multifactor authentication to the VDI server must be implemented separately from the unmanaged client, using a hardware token or PKI credential with PIN.
  • Access must be restricted to authorized users and allowable locations.

If all of these configurations are in place and verified, the local endpoint hosting the VDI client can be out of scope for NIST SP 800-171 and CMMC. If any of these configurations are missing or only policy-controlled rather than technically enforced, the endpoint is in scope as a CUI asset.

Verified, Not Just Configured
The FAQ uses the word "verified" when describing proper VDI configuration. A C3PAO assessor will not take your word for it. They will look at the VDI server configuration directly to confirm these restrictions are enforced at the platform level. Document the configuration, test it, and be prepared to demonstrate it during the assessment.

Key Takeaways from the Official FAQ

The FAQ resolves ambiguity in several areas that have generated conflicting guidance from practitioners and consultants. Here are the most important conclusions for small defense contractors:

Topic Official Position
CMMC timeline Phase 1 began November 10, 2025. Self-assessments are the primary focus through the first 12 months. C3PAO assessments become standard in Phase 2 (November 2026).
Rev 2 vs. Rev 3 All CMMC assessments are conducted against Rev 2 until a class deviation is withdrawn. Contractors can implement Rev 3 voluntarily using DoD ODPs but must still satisfy Rev 2 requirements.
Encrypted CUI Encryption does not decontrol CUI or eliminate safeguarding requirements. A non-FedRAMP CSP cannot store encrypted CUI.
MSP/MSSP scope MSPs and MSSPs with access to CUI environments are ESPs and are assessed as part of the OSA's assessment, even if no CUI is sent directly to them. They do not require their own CMMC certification.
POA&M limits Six critical requirements cannot appear on a POA&M. POA&M closeout has one attempt within a 180-day window. Failure resets the entire assessment.
SSP requirement Marking the SSP requirement as "Not Met" produces no SPRS score, not a deduction. A current SSP is a prerequisite for any assessment result.
VDI endpoints VDI endpoints can be out of scope if CUI never reaches the local device and the VDI is server-side configured to enforce that boundary. Configuration must be verified, not just documented.
Non-US companies CMMC applies to all contractors performing under applicable DoD contracts, regardless of country of origin.
Subcontractor flow-down CUI subcontractors require the same CMMC level as the prime. If the prime requires Level 3, subs must meet Level 2 C3PAO minimum unless otherwise directed.

The full FAQ document is available directly from the DoD CIO at dodcio.defense.gov. Revision 2.1 was published November 2025 and supersedes all prior versions.

Built for the DIB.

1TEN tracks your control posture across all 110 NIST SP 800-171 requirements and generates C3PAO-ready documentation automatically.

Request a Demo