Section A: About CMMC
The FAQ opens with the questions that dominate every early conversation about CMMC: when does this apply, what does it cost, and where do I go for help?
When do CMMC assessments become required?
CMMC requirements began appearing in applicable DoD procurements on November 10, 2025, when revised DFARS clause 252.204-7021 became effective. The first 12 months focus primarily on self-assessments at Level 1 and Level 2. Third-party C3PAO assessments roll in over a four-phase implementation period defined in 32 CFR 170.3(e). Phase 2 begins November 2026, at which point C3PAO assessments become standard for new CUI-handling solicitations.
How much does CMMC compliance cost?
The DoD's answer is intentionally non-specific: costs depend on your CMMC level, network complexity, existing security posture, and market conditions. What the FAQ does clarify is that costs incurred implementing existing DFARS 252.204-7012 safeguarding requirements are not considered part of CMMC compliance cost. That distinction matters for cost accounting and contract reimbursement purposes.
The DoD also points to several no-cost resources: the DIBNet Cybersecurity-as-a-Service portal, the Cyber AB marketplace of certified practitioners, and free online training through the Defense Acquisition University.
Section B: The CMMC Model
NIST SP 800-171 Rev 2 vs. Rev 3: where things stand
This is one of the most actively misunderstood areas in CMMC right now. The FAQ is clear: CMMC assessments are conducted against Revision 2 until the class deviation memo is withdrawn or superseded through rulemaking. Rev 3 will be incorporated into the program through future rulemaking, but there is no timeline for that transition.
Contractors can implement Rev 3 voluntarily, but must use the DoD's Organization-Defined Parameters (ODPs) from the April 2025 memorandum to do so. Critically, any gaps between Rev 2 and Rev 3 must still be addressed, because the assessment will be conducted against Rev 2. Implementing Rev 3 does not give you a pass on Rev 2 requirements that are not covered or that differ in Rev 3.
NIST SP 800-172 and Level 3
CMMC Level 3 builds on the 110 requirements in NIST SP 800-171 by adding 24 requirements from NIST SP 800-172. These are designed to address advanced persistent threats. Level 3 is reserved for contractors working on the DoD's highest-priority programs and is specified in the contract when required.
Flow-down to subcontractors
CMMC requirements flow down to subcontractors handling FCI or CUI under the same contract, per 32 CFR 170.23. The required level is determined by the data type involved. One notable rule: when a prime contract requires Level 3, the minimum flow-down requirement for subcontractors is Level 2 with C3PAO assessment, unless the government provides specific contractual guidance otherwise.
Is encrypted CUI still CUI?
Yes. CUI remains controlled until formally decontrolled, regardless of encryption state. Encrypting CUI does not change its designation or remove safeguarding requirements. The FAQ acknowledges that certain transmission risks may be accepted for ciphertext that would not be accepted for plaintext, but that nuance does not decontrol the information or reduce the underlying obligation.
This has a direct practical consequence for the cloud question: a non-FedRAMP-authorized CSP cannot store encrypted CUI and claim the encryption eliminates the platform authorization requirement. The DoD addresses this explicitly in Section E.
Section C: Assessments
Assessment frequency
| CMMC Level | Assessment Type | Frequency | Annual Affirmation Required? |
|---|---|---|---|
| Level 1 | Self-assessment | Annual | Yes |
| Level 2 | Self-assessment or C3PAO | Every 3 years | Yes, annually |
| Level 3 | DCSA-led government assessment | Every 3 years | Yes, annually |
Do FCI-only contractors need an independent assessment?
No. If a contractor handles only FCI and no CUI, a Level 1 self-assessment is required. Independent C3PAO assessment is only required at Level 2 and above, and only when specified in the contract.
POA&Ms: what is and is not permitted
The FAQ addresses two POA&M-related questions that catch contractors off guard.
First, six security requirements are prohibited from appearing on a POA&M. These are defined in 32 CFR 170.21 and must be fully implemented before a conditional CMMC status can be granted. Missing any of the six results in no CMMC status, not a conditional one. The FAQ does not list them by name. Contractors need to review 32 CFR 170.21(a)(2)(iii) directly.
Second, a POA&M Closeout Assessment can only be finalized in CMMC eMASS once during the 180-day conditional window. If requirements are still not met at closeout, conditional status is terminated and the organization must start over with a new assessment. There is no second chance within the same window.
The SSP requirement and SPRS scoring
The FAQ includes a question about a specific SPRS error that many contractors encounter: marking CA.L2-3.12.4 (System Security Plan) as "Not Met" results in a "No Score" rather than a numeric score. The DoD's reasoning is that without a current SSP, an assessment cannot be completed. An absent SSP is not a gap that produces a point deduction. It is a condition that makes the assessment impossible.
Section D: Implementation
Does CMMC apply to non-US companies?
Yes. When CMMC requirements appear in a DoD solicitation, they apply to all performing contractors regardless of nationality or country of origin. International companies operating under DoD contracts are subject to the same assessment requirements as domestic contractors.
Non-US citizens and organizations can also participate in the CMMC ecosystem as C3PAOs, Registered Practitioners, or assessors, provided they meet all requirements in the 32 CFR CMMC rule.
Phase 1 and C3PAO discretion
During Phase 1 (the first 12 months after November 10, 2025), Program Managers are not required to include C3PAO assessment requirements in solicitations, even for contracts involving CUI from the Defense Organizational Index Group. The default during Phase 1 is Level 2 self-assessment for CUI contracts. Program Managers retain discretion to require C3PAO assessment during Phase 1, but only when market research indicates sufficient qualified offerors exist to support adequate competition.
Section E: External Service Providers and MSPs
Section E is where the FAQ delivers some of the most practically useful guidance in the document. MSP and cloud questions dominate real-world compliance conversations, and the official answers resolve several persistent points of confusion.
Does an MSP need its own CMMC assessment?
The answer depends on the MSP's role and what it handles.
| MSP Scenario | Own CMMC Assessment Required? | How They Are Handled |
|---|---|---|
| MSP provides a non-cloud system where the OSA stores CUI | No (but may elect to pursue one) | Assessed as part of the OSA's assessment. If MSP obtains its own certification, it must be at the same or higher level as the OSA's contract requirement. |
| MSP provides IT support; no CUI is sent to the MSP | No | Still assessed as part of the OSA's assessment as an External Service Provider. The MSP qualifies as an ESP and applicable security requirements are evaluated in the OSA's assessment. |
| MSSP manages security tools; no CUI is sent to the MSSP | No | Also assessed as part of the OSA's assessment as an ESP. Security protection data is in scope regardless of whether CUI is directly shared. |
When does an MSP become a CSP?
The FAQ addresses this directly. If the cloud tenant is subscribed or licensed to the OSA (even if the MSP resells the service), the MSP is not a CSP. The cloud licensing relationship determines the designation, not who manages it day-to-day. However, if the MSP contracts with the CSP directly and modifies the base cloud service, the MSP may itself be considered a CSP and must meet FedRAMP or equivalency requirements.
Cloud service requirements for CUI
Two questions in Section E confirm what many contractors are still resisting: FedRAMP Moderate authorization is required for any CSP storing, processing, or transmitting CUI. This cannot be satisfied by applying encryption or additional controls on top of a non-authorized platform. The DoD closes that door explicitly by answering both "must CSPs meet FedRAMP Moderate?" (yes) and "can a non-FedRAMP CSP store encrypted CUI?" (no).
VDI Endpoints: In Scope or Out?
Questions E-Q6 and E-Q7 address Virtual Desktop Infrastructure, which has become a popular approach for limiting assessment scope. The DoD's answers are nuanced but workable.
An endpoint accessing a VDI can be considered out of scope if the VDI is configured to prevent any CUI from reaching the local device. The configuration requirements are specific and must be enforced server-side, not just policy-stated:
- Copy-paste between the virtual session and the local device must be blocked.
- File transfers, drive mounting, and printing from the virtual session to the local device must be disabled.
- Only keyboard, video, and mouse data should transit the VDI session.
- Multifactor authentication to the VDI server must be implemented separately from the unmanaged client, using a hardware token or PKI credential with PIN.
- Access must be restricted to authorized users and allowable locations.
If all of these configurations are in place and verified, the local endpoint hosting the VDI client can be out of scope for NIST SP 800-171 and CMMC. If any of these configurations are missing or only policy-controlled rather than technically enforced, the endpoint is in scope as a CUI asset.
Key Takeaways from the Official FAQ
The FAQ resolves ambiguity in several areas that have generated conflicting guidance from practitioners and consultants. Here are the most important conclusions for small defense contractors:
| Topic | Official Position |
|---|---|
| CMMC timeline | Phase 1 began November 10, 2025. Self-assessments are the primary focus through the first 12 months. C3PAO assessments become standard in Phase 2 (November 2026). |
| Rev 2 vs. Rev 3 | All CMMC assessments are conducted against Rev 2 until a class deviation is withdrawn. Contractors can implement Rev 3 voluntarily using DoD ODPs but must still satisfy Rev 2 requirements. |
| Encrypted CUI | Encryption does not decontrol CUI or eliminate safeguarding requirements. A non-FedRAMP CSP cannot store encrypted CUI. |
| MSP/MSSP scope | MSPs and MSSPs with access to CUI environments are ESPs and are assessed as part of the OSA's assessment, even if no CUI is sent directly to them. They do not require their own CMMC certification. |
| POA&M limits | Six critical requirements cannot appear on a POA&M. POA&M closeout has one attempt within a 180-day window. Failure resets the entire assessment. |
| SSP requirement | Marking the SSP requirement as "Not Met" produces no SPRS score, not a deduction. A current SSP is a prerequisite for any assessment result. |
| VDI endpoints | VDI endpoints can be out of scope if CUI never reaches the local device and the VDI is server-side configured to enforce that boundary. Configuration must be verified, not just documented. |
| Non-US companies | CMMC applies to all contractors performing under applicable DoD contracts, regardless of country of origin. |
| Subcontractor flow-down | CUI subcontractors require the same CMMC level as the prime. If the prime requires Level 3, subs must meet Level 2 C3PAO minimum unless otherwise directed. |
The full FAQ document is available directly from the DoD CIO at dodcio.defense.gov. Revision 2.1 was published November 2025 and supersedes all prior versions.