The Short Version
CMMC 2.0 (Cybersecurity Maturity Model Certification) is the Department of Defense's framework requiring defense contractors to implement and independently verify specific cybersecurity practices before they can hold contracts involving Controlled Unclassified Information (CUI).
If your company holds or processes CUI and you want to keep doing business with the DoD, CMMC compliance is mandatory. The final rule took effect November 10, 2025, and requirements are now appearing in new solicitations across the defense acquisition system.
Why CMMC Was Created
The Defense Industrial Base has been under systematic cyber attack for decades. Nation-state adversaries have repeatedly stolen sensitive program data not by penetrating classified networks, but by compromising the unclassified systems of smaller contractors who lacked robust security practices. The problem was not that requirements did not exist. DFARS 252.204-7012 and NIST SP 800-171 had been contractually required since 2017. The problem was that self-attestation was not working.
Contractors were submitting SPRS scores that bore little relationship to their actual security posture. A 2023 DoD OIG audit documented systemic deficiencies across the contractor population, with consistent failures in six foundational domains: Access Control, Audit and Accountability, Configuration Management, Identification and Authentication, System and Communications Protection, and System and Information Integrity. Contractors were certifying these as implemented while leaving them largely unaddressed.
The DOJ's Civil Cyber-Fraud Initiative, launched in October 2021, has since settled more than $26 million in False Claims Act cases against contractors who falsified their compliance certifications. CMMC closes the self-certification gap by requiring a Certified Third-Party Assessment Organization to independently verify your implementation before you can hold Level 2 contracts.
The Three Certification Levels
Level 1 — Foundational
17 practices aligned with FAR 52.204-21. Applies to contractors handling Federal Contract Information (FCI) but not CUI. Annual self-assessment and attestation filed in SPRS. No C3PAO assessment required. If your contracts involve basic administrative or logistical work without access to sensitive technical data, this is your level.
Level 2 — Advanced (Most Contractors)
110 practices aligned exactly with NIST SP 800-171 Rev 2. Applies to any contractor handling CUI. For the vast majority of Level 2 contracts, a formal C3PAO assessment is required every three years with annual affirmations. Roughly 35% of DoD contractors fall here, including most manufacturing, engineering, IT services, and research organizations in the defense supply chain.
A limited subset of lower-priority Level 2 contracts may permit self-assessment, but prime contractors are increasingly requiring C3PAO certification from their subcontractors regardless of the specific contract language. If you handle CUI, plan for a C3PAO assessment.
Level 3 — Expert
110 or more practices building on Level 2 with additional controls from NIST SP 800-172. Reserved for the highest-priority DoD programs with the most sensitive CUI. Government-led assessments by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). Affects roughly 1% of contractors.
CMMC vs. NIST SP 800-171: What Is the Difference?
NIST SP 800-171 is the security standard — 110 requirements across 14 domains for protecting CUI in nonfederal systems. It has been contractually required since 2017 with contractors self-reporting compliance via SPRS scores.
CMMC 2.0 Level 2 is the verification framework. It uses the identical 110 NIST 800-171 requirements without adding new technical controls, but replaces self-attestation with mandatory independent assessment. A C3PAO must verify that the controls you claim to have implemented are actually functioning as described in your System Security Plan.
If your organization has genuinely implemented all 110 requirements, CMMC does not require additional technical work. What it requires is thorough documentation, organized evidence, and the ability to demonstrate your implementation to an external assessor through the Assessment Guide's examine, interview, and test methodology.
How CMMC Enters Your Contracts
CMMC requirements enter contracts through specific DFARS clauses. Knowing which clauses are present tells you your obligations.
| DFARS 252.204-7012 | The original CUI safeguarding clause requiring NIST SP 800-171 implementation and SPRS reporting. Present in most DoD contracts involving CUI since 2017. If this clause is in your contract, you are already required to be NIST 800-171 compliant — CMMC adds third-party verification on top. |
| DFARS 252.204-7021 | The CMMC clause introduced under the 2025 final rule. Specifies the required CMMC level and requires a valid certification at contract award. Being phased into new solicitations starting November 2025. |
| DFARS 252.204-7019 & 7020 | Govern SPRS score submission and the DoD's right to verify those scores. Submitting an inaccurate score is the legal basis for False Claims Act exposure. |
If DFARS 252.204-7012 is in your current contracts, CMMC is coming. If 252.204-7021 is present, it is already required. Review your existing contracts now if you are uncertain about your timeline.
The Enforcement Timeline
CMMC enforcement phases in over four years beginning November 2025.
Requirements begin appearing in new solicitations. Level 1 self-assessments and select Level 2 self-assessments become conditions for contract award. Several prime contractor supply chains are already requiring C3PAO certification ahead of the formal mandate.
C3PAO assessments become mandatory for most Level 2 CUI contracts. This is the critical deadline for the majority of the defense contractor population. Assessment slots are filling with 3 to 6 month lead times. Organizations that have not begun preparation now risk missing this deadline entirely.
Level 3 requirements begin appearing in solicitations for highest-priority programs. Level 2 C3PAO assessments expand to additional contract categories.
Full enforcement across all applicable DoD contracts. Contracting officers verify certification validity before exercising option periods. No waivers, no grace periods.
The 14 CMMC Security Domains
The 110 Level 2 requirements span 14 security domains. Understanding where your current gaps are across these domains is the foundation of any effective compliance effort.
| Access Control 22 req. | Who can access systems, under what conditions, and with what privilege level. Includes multi-factor authentication, least-privilege enforcement, and remote access controls. The largest domain by requirement count. |
| System & Comms Protection 16 req. | Network boundary controls, encryption of CUI in transit, and architectural separation of CUI from general-purpose networks. |
| Identification & Authentication 11 req. | Managing user identities, enforcing strong authenticators, and ensuring only authorized individuals access CUI systems. |
| Audit & Accountability 9 req. | Logging user and system activity, protecting audit records, and reviewing logs for anomalous behavior. |
| Configuration Management 9 req. | Maintaining secure baseline configurations, controlling system changes, and restricting unauthorized software. |
| Media Protection 9 req. | Controlling access to physical and digital media containing CUI, and sanitizing media before disposal or reuse. |
| System & Info Integrity 7 req. | Malware protection, security alert monitoring, and timely patching of identified vulnerabilities. |
| Maintenance 6 req. | Controlling maintenance activities, sanitizing equipment removed for off-site work, and vetting maintenance personnel. |
| Physical Protection 6 req. | Controlling physical access to CUI systems and facilities, and monitoring physical access events. |
| Risk Assessment 5 req. | Periodic risk assessments, vulnerability scanning, and remediation of identified weaknesses. |
| Security Assessment 4 req. | Periodically assessing security controls and maintaining a Plan of Action and Milestones for deficiencies. |
| Incident Response 3 req. | Documented incident response capability, testing, and reporting confirmed incidents to the DoD within 72 hours. |
| Awareness & Training 3 req. | Ensuring personnel understand their security responsibilities and recognize current threats. |
| Personnel Security 2 req. | Screening individuals before granting access, and revoking access promptly upon termination. |
The SPRS Score: Accuracy Is Not Optional
The SPRS (Supplier Performance Risk System) score is your DoD-visible self-assessment score for NIST 800-171 compliance. Starting at 110, it decrements by the weighted value of each unimplemented requirement. The minimum is -203.
Your SPRS score must be accurate and updated when your posture changes. The MORSECORP settlement illustrates the consequence of delay: a third-party gap assessment in July 2022 revealed their true score was -142, yet the company continued reporting a higher score for nearly a year. That gap cost them $4.6 million in a False Claims Act settlement.
An honest SPRS score with a credible POA&M is more defensible than an inflated score that will not survive C3PAO scrutiny. The DoD understands that gaps exist. What they cannot tolerate is misrepresentation of those gaps.
CMMC and the Supply Chain
CMMC requirements flow down through prime contractors to any subcontractor that handles CUI under the same contract. If a prime's contract requires CMMC Level 2, that requirement must be passed to every sub that touches CUI in performance of that work.
In practice, primes are not waiting for formal flow-down. Many are already requiring subcontractors to provide current SPRS scores, complete compliance questionnaires, or hold C3PAO certification as a condition of subcontract award. Several high-priority DoD programs have already made this standard practice for their full supply chains.
If you are a subcontractor that handles any CUI from a DoD prime contract, assume CMMC Level 2 applies to you and begin your compliance program now. The earlier you start, the more control you have over your timeline and costs, and the stronger your competitive position when primes start screening their supply chains in earnest.
How to Determine If You Handle CUI
One of the most common questions from contractors approaching CMMC for the first time is whether they actually handle CUI. The answer is not always obvious, and guessing wrong in either direction carries real risk. Under-scoping leaves you exposed to FCA liability; over-scoping wastes resources on compliance work you do not need.
The authoritative source is the DoD CUI Registry at archives.gov, which catalogs every category of information the government has designated as CUI. For most defense contractors, the practical question can be answered by examining your contracts and the data you receive under them.
Common categories of CUI encountered by defense contractors include technical specifications and engineering drawings for controlled items, export-controlled technical data under ITAR or EAR, contract performance information marked sensitive, proprietary information the government receives under a non-disclosure agreement, and controlled technical information related to military systems. If any of these descriptions fit what moves through your systems, CMMC Level 2 applies to you.
One important nuance: if you are a subcontractor and your prime sends you a technical data package to execute your scope, that data is CUI if the prime's contract with the DoD treats it as such. You inherit the obligation even if your direct contract with the prime does not spell it out explicitly.
CMMC and Cloud Services: What You Need to Know
Cloud computing introduces one of the most commonly misunderstood scoping questions in CMMC compliance. If your organization stores, processes, or transmits CUI in a cloud environment, that cloud service is in scope for your assessment — and the cloud provider's compliance posture directly affects yours.
The DoD's position on cloud services for CUI is clear: cloud services that handle CUI must meet FedRAMP Moderate baseline requirements at minimum. The MORSECORP enforcement case established the cost of getting this wrong — MORSE used a commercial SaaS email provider that did not meet FedRAMP Moderate requirements to transmit CUI, and that failure was a central element of a $4.6 million DOJ settlement.
For Microsoft 365 users, the relevant offering is Microsoft 365 GCC (Government Community Cloud), which meets FedRAMP Moderate requirements. Standard commercial Microsoft 365 subscriptions do not meet this bar for CUI handling. Google Workspace has a comparable GCC offering. Moving to a compliant cloud environment is often one of the more significant infrastructure investments in a CMMC program, but it is a bright-line requirement.
Your SSP must identify every cloud service that touches CUI and document that each meets the required authorization baseline. Assessors will specifically examine this. Undocumented or non-compliant cloud services in scope are among the most common significant findings in Level 2 assessments.
Common Myths About CMMC 2.0
Several persistent misconceptions cause contractors to delay compliance work or pursue it in the wrong direction. These are the five most consequential ones.
"We already have IT security, so we're probably fine." General commercial IT security and NIST SP 800-171 compliance are not the same thing. A contractor can have a professionally managed IT environment with modern tools and still fail a C3PAO assessment because the specific 110 requirements — particularly around CUI handling, audit logging, incident response procedures, and access control granularity — were never formally implemented or documented against the standard. "We're a pretty secure shop" is not a compliance posture.
"Our MSP handles cybersecurity, so they handle CMMC." Your Managed Service Provider may implement technical controls, but CMMC requires documented policies, personnel training, a signed System Security Plan, an accurate SPRS score, and formal incident response procedures. These organizational obligations belong to you. You cannot fully outsource compliance accountability to a vendor, even a capable one.
"We'll get compliant right before the assessment." C3PAO assessors evaluate whether controls are implemented and operating effectively over time. Evidence requirements include audit logs, training records, and documented procedures demonstrating sustained operation. A rushed implementation the week before an assessment produces evidence that either does not exist yet or raises immediate questions about how long controls have actually been in place.
"If we have a POA&M, we're covered." A Plan of Action and Milestones documents your gaps and your plan to close them. It does not make you compliant with the requirements listed in it. During an assessment, significant unimplemented requirements without credible active remediation paths result in findings that can prevent certification. A POA&M is a management tool, not a compliance shield.
"CMMC is just a paperwork exercise." The documentation requirement is extensive, but C3PAO assessors also directly test implemented controls. They will attempt unauthorized access to verify controls work, observe MFA prompts in real time, review live firewall rules, and examine actual audit log outputs. Controls that exist only in your SSP and not in your systems will be identified during the assessment.
The Cost of Getting CMMC Wrong
Non-compliance carries three distinct risk categories, each with a different timeline and consequence.
Contract loss is the most immediate risk. Once DFARS 252.204-7021 appears in a solicitation, organizations without the required CMMC certification cannot bid. Phase 2 begins November 2026 — at that point, most CUI contracts will require C3PAO certification at award. Contractors who have not started the process will find themselves unable to compete for renewals and new work at the same time.
False Claims Act exposure is less visible but potentially more severe. If your organization currently submits SPRS scores, you are making a representation to the government about your compliance posture. The critical FCA trigger is knowledge: if you conduct a gap assessment, learn your true SPRS score is materially lower than what you submitted, and continue without updating it, you have the knowledge element required for FCA liability. Whistleblower suits filed by employees who share that knowledge are how most of these cases originate.
Incident liability is the emerging third category. If a CUI breach occurs and investigation reveals required NIST 800-171 controls were not implemented, FCA exposure and breach notification obligations intersect in ways that are still being developed through litigation. The Georgia Tech settlement flagged the absence of anti-malware software on CUI systems as a core violation — a basic technical control that was simply absent.