Overview

What is CMMC 2.0? A Plain-English Guide for Defense Contractors (2026)

Last updated: 2026-02-01

The Short Version Why CMMC Was Created The Three Certification Levels CMMC vs. NIST SP 800-171: What Is the Difference? How CMMC Enters Your Contracts

The Short Version

CMMC 2.0 (Cybersecurity Maturity Model Certification) is the Department of Defense's framework requiring defense contractors to implement and independently verify specific cybersecurity practices before they can hold contracts involving Controlled Unclassified Information (CUI).

If your company holds or processes CUI and you want to keep doing business with the DoD, CMMC compliance is mandatory. The final rule took effect November 10, 2025, and requirements are now appearing in new solicitations across the defense acquisition system.

Key Definition
Controlled Unclassified Information (CUI) is government-created or government-owned information that requires safeguarding under law, regulation, or government-wide policy but is not classified. If your DoD contracts involve sensitive technical data, ITAR-controlled information, military specifications, or proprietary program details, you almost certainly handle CUI and need CMMC Level 2.

Why CMMC Was Created

The Defense Industrial Base has been under systematic cyber attack for decades. Nation-state adversaries have repeatedly stolen sensitive program data not by penetrating classified networks, but by compromising the unclassified systems of smaller contractors who lacked robust security practices. The problem was not that requirements did not exist. DFARS 252.204-7012 and NIST SP 800-171 had been contractually required since 2017. The problem was that self-attestation was not working.

Contractors were submitting SPRS scores that bore little relationship to their actual security posture. A 2023 DoD OIG audit documented systemic deficiencies across the contractor population, with consistent failures in six foundational domains: Access Control, Audit and Accountability, Configuration Management, Identification and Authentication, System and Communications Protection, and System and Information Integrity. Contractors were certifying these as implemented while leaving them largely unaddressed.

The DOJ's Civil Cyber-Fraud Initiative, launched in October 2021, has since settled more than $26 million in False Claims Act cases against contractors who falsified their compliance certifications. CMMC closes the self-certification gap by requiring a Certified Third-Party Assessment Organization to independently verify your implementation before you can hold Level 2 contracts.

The Three Certification Levels

1
Foundational — 17 Practices
2
Advanced — 110 Practices
3
Expert — 110+ Practices

Level 1 — Foundational

17 practices aligned with FAR 52.204-21. Applies to contractors handling Federal Contract Information (FCI) but not CUI. Annual self-assessment and attestation filed in SPRS. No C3PAO assessment required. If your contracts involve basic administrative or logistical work without access to sensitive technical data, this is your level.

Level 2 — Advanced (Most Contractors)

110 practices aligned exactly with NIST SP 800-171 Rev 2. Applies to any contractor handling CUI. For the vast majority of Level 2 contracts, a formal C3PAO assessment is required every three years with annual affirmations. Roughly 35% of DoD contractors fall here, including most manufacturing, engineering, IT services, and research organizations in the defense supply chain.

A limited subset of lower-priority Level 2 contracts may permit self-assessment, but prime contractors are increasingly requiring C3PAO certification from their subcontractors regardless of the specific contract language. If you handle CUI, plan for a C3PAO assessment.

Level 3 — Expert

110 or more practices building on Level 2 with additional controls from NIST SP 800-172. Reserved for the highest-priority DoD programs with the most sensitive CUI. Government-led assessments by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). Affects roughly 1% of contractors.

CMMC vs. NIST SP 800-171: What Is the Difference?

NIST SP 800-171 is the security standard — 110 requirements across 14 domains for protecting CUI in nonfederal systems. It has been contractually required since 2017 with contractors self-reporting compliance via SPRS scores.

CMMC 2.0 Level 2 is the verification framework. It uses the identical 110 NIST 800-171 requirements without adding new technical controls, but replaces self-attestation with mandatory independent assessment. A C3PAO must verify that the controls you claim to have implemented are actually functioning as described in your System Security Plan.

If your organization has genuinely implemented all 110 requirements, CMMC does not require additional technical work. What it requires is thorough documentation, organized evidence, and the ability to demonstrate your implementation to an external assessor through the Assessment Guide's examine, interview, and test methodology.

The Verification Reality
A C3PAO assessor will not accept your word that a control is implemented. They will examine your policies, interview your personnel, and directly test your technical configurations. Your SSP must accurately describe your actual environment, not your aspirational one. The gap between documented and actual compliance is exactly what CMMC was designed to surface and eliminate.

How CMMC Enters Your Contracts

CMMC requirements enter contracts through specific DFARS clauses. Knowing which clauses are present tells you your obligations.

DFARS 252.204-7012The original CUI safeguarding clause requiring NIST SP 800-171 implementation and SPRS reporting. Present in most DoD contracts involving CUI since 2017. If this clause is in your contract, you are already required to be NIST 800-171 compliant — CMMC adds third-party verification on top.
DFARS 252.204-7021The CMMC clause introduced under the 2025 final rule. Specifies the required CMMC level and requires a valid certification at contract award. Being phased into new solicitations starting November 2025.
DFARS 252.204-7019 & 7020Govern SPRS score submission and the DoD's right to verify those scores. Submitting an inaccurate score is the legal basis for False Claims Act exposure.

If DFARS 252.204-7012 is in your current contracts, CMMC is coming. If 252.204-7021 is present, it is already required. Review your existing contracts now if you are uncertain about your timeline.

The Enforcement Timeline

CMMC enforcement phases in over four years beginning November 2025.

Phase 1 — November 10, 2025 (Active Now)

Requirements begin appearing in new solicitations. Level 1 self-assessments and select Level 2 self-assessments become conditions for contract award. Several prime contractor supply chains are already requiring C3PAO certification ahead of the formal mandate.

Phase 2 — November 10, 2026

C3PAO assessments become mandatory for most Level 2 CUI contracts. This is the critical deadline for the majority of the defense contractor population. Assessment slots are filling with 3 to 6 month lead times. Organizations that have not begun preparation now risk missing this deadline entirely.

Phase 3 — November 10, 2027

Level 3 requirements begin appearing in solicitations for highest-priority programs. Level 2 C3PAO assessments expand to additional contract categories.

Phase 4 — November 10, 2028

Full enforcement across all applicable DoD contracts. Contracting officers verify certification validity before exercising option periods. No waivers, no grace periods.

The 14 CMMC Security Domains

The 110 Level 2 requirements span 14 security domains. Understanding where your current gaps are across these domains is the foundation of any effective compliance effort.

Access Control 22 req.Who can access systems, under what conditions, and with what privilege level. Includes multi-factor authentication, least-privilege enforcement, and remote access controls. The largest domain by requirement count.
System & Comms Protection 16 req.Network boundary controls, encryption of CUI in transit, and architectural separation of CUI from general-purpose networks.
Identification & Authentication 11 req.Managing user identities, enforcing strong authenticators, and ensuring only authorized individuals access CUI systems.
Audit & Accountability 9 req.Logging user and system activity, protecting audit records, and reviewing logs for anomalous behavior.
Configuration Management 9 req.Maintaining secure baseline configurations, controlling system changes, and restricting unauthorized software.
Media Protection 9 req.Controlling access to physical and digital media containing CUI, and sanitizing media before disposal or reuse.
System & Info Integrity 7 req.Malware protection, security alert monitoring, and timely patching of identified vulnerabilities.
Maintenance 6 req.Controlling maintenance activities, sanitizing equipment removed for off-site work, and vetting maintenance personnel.
Physical Protection 6 req.Controlling physical access to CUI systems and facilities, and monitoring physical access events.
Risk Assessment 5 req.Periodic risk assessments, vulnerability scanning, and remediation of identified weaknesses.
Security Assessment 4 req.Periodically assessing security controls and maintaining a Plan of Action and Milestones for deficiencies.
Incident Response 3 req.Documented incident response capability, testing, and reporting confirmed incidents to the DoD within 72 hours.
Awareness & Training 3 req.Ensuring personnel understand their security responsibilities and recognize current threats.
Personnel Security 2 req.Screening individuals before granting access, and revoking access promptly upon termination.

The SPRS Score: Accuracy Is Not Optional

The SPRS (Supplier Performance Risk System) score is your DoD-visible self-assessment score for NIST 800-171 compliance. Starting at 110, it decrements by the weighted value of each unimplemented requirement. The minimum is -203.

Your SPRS score must be accurate and updated when your posture changes. The MORSECORP settlement illustrates the consequence of delay: a third-party gap assessment in July 2022 revealed their true score was -142, yet the company continued reporting a higher score for nearly a year. That gap cost them $4.6 million in a False Claims Act settlement.

An honest SPRS score with a credible POA&M is more defensible than an inflated score that will not survive C3PAO scrutiny. The DoD understands that gaps exist. What they cannot tolerate is misrepresentation of those gaps.

SPRS and C3PAO Together
Under CMMC, your self-reported SPRS score and your C3PAO assessment findings will exist side by side in DoD systems. A substantial gap between what you claimed and what your assessor found is not just an audit embarrassment. For the period between when you knew about the gap and when you disclosed it, that gap is potential False Claims Act exposure.

CMMC and the Supply Chain

CMMC requirements flow down through prime contractors to any subcontractor that handles CUI under the same contract. If a prime's contract requires CMMC Level 2, that requirement must be passed to every sub that touches CUI in performance of that work.

In practice, primes are not waiting for formal flow-down. Many are already requiring subcontractors to provide current SPRS scores, complete compliance questionnaires, or hold C3PAO certification as a condition of subcontract award. Several high-priority DoD programs have already made this standard practice for their full supply chains.

If you are a subcontractor that handles any CUI from a DoD prime contract, assume CMMC Level 2 applies to you and begin your compliance program now. The earlier you start, the more control you have over your timeline and costs, and the stronger your competitive position when primes start screening their supply chains in earnest.

How to Determine If You Handle CUI

One of the most common questions from contractors approaching CMMC for the first time is whether they actually handle CUI. The answer is not always obvious, and guessing wrong in either direction carries real risk. Under-scoping leaves you exposed to FCA liability; over-scoping wastes resources on compliance work you do not need.

The authoritative source is the DoD CUI Registry at archives.gov, which catalogs every category of information the government has designated as CUI. For most defense contractors, the practical question can be answered by examining your contracts and the data you receive under them.

The Practical CUI Test
Review your contracts for DFARS 252.204-7012. If that clause is present, the DoD has already determined that CUI is involved. Look at the technical data, drawings, and specifications your customer provides. If it carries distribution statement markings (Distribution Statement B through F) or is labeled "CUI" or "FOUO," it qualifies. When in doubt, ask your contracting officer directly — they are required to identify CUI in the contract.

Common categories of CUI encountered by defense contractors include technical specifications and engineering drawings for controlled items, export-controlled technical data under ITAR or EAR, contract performance information marked sensitive, proprietary information the government receives under a non-disclosure agreement, and controlled technical information related to military systems. If any of these descriptions fit what moves through your systems, CMMC Level 2 applies to you.

One important nuance: if you are a subcontractor and your prime sends you a technical data package to execute your scope, that data is CUI if the prime's contract with the DoD treats it as such. You inherit the obligation even if your direct contract with the prime does not spell it out explicitly.

CMMC and Cloud Services: What You Need to Know

Cloud computing introduces one of the most commonly misunderstood scoping questions in CMMC compliance. If your organization stores, processes, or transmits CUI in a cloud environment, that cloud service is in scope for your assessment — and the cloud provider's compliance posture directly affects yours.

The DoD's position on cloud services for CUI is clear: cloud services that handle CUI must meet FedRAMP Moderate baseline requirements at minimum. The MORSECORP enforcement case established the cost of getting this wrong — MORSE used a commercial SaaS email provider that did not meet FedRAMP Moderate requirements to transmit CUI, and that failure was a central element of a $4.6 million DOJ settlement.

For Microsoft 365 users, the relevant offering is Microsoft 365 GCC (Government Community Cloud), which meets FedRAMP Moderate requirements. Standard commercial Microsoft 365 subscriptions do not meet this bar for CUI handling. Google Workspace has a comparable GCC offering. Moving to a compliant cloud environment is often one of the more significant infrastructure investments in a CMMC program, but it is a bright-line requirement.

Your SSP must identify every cloud service that touches CUI and document that each meets the required authorization baseline. Assessors will specifically examine this. Undocumented or non-compliant cloud services in scope are among the most common significant findings in Level 2 assessments.

Common Myths About CMMC 2.0

Several persistent misconceptions cause contractors to delay compliance work or pursue it in the wrong direction. These are the five most consequential ones.

"We already have IT security, so we're probably fine." General commercial IT security and NIST SP 800-171 compliance are not the same thing. A contractor can have a professionally managed IT environment with modern tools and still fail a C3PAO assessment because the specific 110 requirements — particularly around CUI handling, audit logging, incident response procedures, and access control granularity — were never formally implemented or documented against the standard. "We're a pretty secure shop" is not a compliance posture.

"Our MSP handles cybersecurity, so they handle CMMC." Your Managed Service Provider may implement technical controls, but CMMC requires documented policies, personnel training, a signed System Security Plan, an accurate SPRS score, and formal incident response procedures. These organizational obligations belong to you. You cannot fully outsource compliance accountability to a vendor, even a capable one.

"We'll get compliant right before the assessment." C3PAO assessors evaluate whether controls are implemented and operating effectively over time. Evidence requirements include audit logs, training records, and documented procedures demonstrating sustained operation. A rushed implementation the week before an assessment produces evidence that either does not exist yet or raises immediate questions about how long controls have actually been in place.

"If we have a POA&M, we're covered." A Plan of Action and Milestones documents your gaps and your plan to close them. It does not make you compliant with the requirements listed in it. During an assessment, significant unimplemented requirements without credible active remediation paths result in findings that can prevent certification. A POA&M is a management tool, not a compliance shield.

"CMMC is just a paperwork exercise." The documentation requirement is extensive, but C3PAO assessors also directly test implemented controls. They will attempt unauthorized access to verify controls work, observe MFA prompts in real time, review live firewall rules, and examine actual audit log outputs. Controls that exist only in your SSP and not in your systems will be identified during the assessment.

The Cost of Getting CMMC Wrong

Non-compliance carries three distinct risk categories, each with a different timeline and consequence.

Contract loss is the most immediate risk. Once DFARS 252.204-7021 appears in a solicitation, organizations without the required CMMC certification cannot bid. Phase 2 begins November 2026 — at that point, most CUI contracts will require C3PAO certification at award. Contractors who have not started the process will find themselves unable to compete for renewals and new work at the same time.

False Claims Act exposure is less visible but potentially more severe. If your organization currently submits SPRS scores, you are making a representation to the government about your compliance posture. The critical FCA trigger is knowledge: if you conduct a gap assessment, learn your true SPRS score is materially lower than what you submitted, and continue without updating it, you have the knowledge element required for FCA liability. Whistleblower suits filed by employees who share that knowledge are how most of these cases originate.

Incident liability is the emerging third category. If a CUI breach occurs and investigation reveals required NIST 800-171 controls were not implemented, FCA exposure and breach notification obligations intersect in ways that are still being developed through litigation. The Georgia Tech settlement flagged the absence of anti-malware software on CUI systems as a core violation — a basic technical control that was simply absent.

The Enforcement Record
Five False Claims Act settlements since 2022 totaling more than $26 million: Aerojet Rocketdyne ($9M), Raytheon/RTX/Nightwing ($8.4M), MORSECORP ($4.6M), Pennsylvania State University ($1.25M), and Georgia Tech ($875K). In four of five cases, the action originated from a senior technical employee acting as a whistleblower. Read the full enforcement case analysis.

Frequently Asked Questions

Who needs CMMC certification?

Any defense contractor or subcontractor handling Controlled Unclassified Information (CUI) under a DoD contract. This includes primes and their full supply chains. If your contracts involve sensitive technical data, ITAR-controlled information, or proprietary defense program details, CMMC Level 2 applies.

What is the difference between CMMC and NIST 800-171?

NIST SP 800-171 is the security standard with 110 requirements for protecting CUI. CMMC Level 2 uses those same 110 requirements but replaces self-attestation with mandatory C3PAO verification. CMMC does not add new technical requirements over NIST 800-171 — it changes how compliance is verified.

When does C3PAO assessment become mandatory?

Phase 2 begins November 10, 2026, when C3PAO assessments become required for most Level 2 CUI contracts. As of February 2026, assessment slots were filling with 3 to 6 month lead times, and that window has been lengthening as the deadline approaches. Organizations that have not begun preparation risk missing this deadline.

How long does CMMC certification take?

6 to 12 months to prepare, plus 3 to 6 months to book an assessment slot as of February 2026 (longer if booking windows continue to lengthen as Phase 2 approaches), plus 6 to 8 weeks for the formal assessment. Plan for at least 12 months from the start of your compliance program to receiving your certificate.

What happens if I fail a C3PAO assessment?

For non-critical findings you may receive Conditional CMMC Level 2 status with 180 days to remediate. For failures on high-value requirements, you receive a determination letter and must fully remediate before reassessment. Thorough preparation significantly reduces this risk.

Does CMMC apply to my subcontractors?

Yes. Requirements flow down to any subcontractor handling CUI under the same contract. Primes are also independently requiring CMMC compliance from their supply chains. If you handle CUI from a DoD prime contract, assume Level 2 applies.

What is the SPRS score and why does it matter?

Your SPRS score is your DoD-visible self-assessment score for NIST 800-171 compliance, ranging from -203 to 110. It must be accurate. Multiple contractors have paid DOJ settlements between $875,000 and $9 million for submitting inflated SPRS scores under the False Claims Act.

Can I self-assess for CMMC Level 2?

A limited subset of lower-priority Level 2 contracts may allow self-assessment. However, most CUI contracts require C3PAO assessment, and primes are increasingly requiring it regardless of the specific contract requirement. If you handle CUI, plan for a C3PAO assessment.

How much does CMMC Level 2 certification cost?

Total cost typically ranges from $50,000 to $250,000 depending on your organization's size, current security posture, and the gap between where you are and full compliance. The C3PAO assessment fee itself generally runs $30,000 to $80,000. Remediation costs vary enormously — an organization that has genuinely implemented NIST 800-171 controls will spend far less than one starting from scratch. Factor in internal staff time, required tool purchases, and potentially upgrading to a FedRAMP Moderate cloud environment for a realistic total number.

What is the difference between CMMC Level 1 and Level 2?

Level 1 covers 17 basic cybersecurity practices aligned with FAR 52.204-21 and applies to contractors handling only Federal Contract Information (FCI) — basic contract data without sensitive technical content. It requires annual self-assessment and SPRS attestation with no third-party assessment. Level 2 covers all 110 NIST SP 800-171 requirements, applies to any contractor handling CUI, and requires a formal C3PAO assessment every three years. If your work involves sensitive technical data, military drawings, or ITAR-controlled information, you are almost certainly a Level 2 contractor.

Can my MSP help me get CMMC certified?

An MSP can implement many of the technical controls required by NIST SP 800-171, but they cannot make your organization CMMC-compliant on their own. The obligations that rest with your organization specifically include maintaining and signing a System Security Plan, submitting and maintaining your SPRS score, conducting personnel security screening, providing security awareness training to your staff, and establishing incident response procedures. Some MSPs offer CMMC-specific compliance services that go beyond basic IT management — verify that they understand documentation and evidence requirements, not just technical controls.

Does moving to Microsoft GCC solve my cloud compliance issue?

Moving to Microsoft 365 GCC addresses the FedRAMP Moderate authorization requirement for your email and productivity environment, which is one of the most common cloud compliance gaps. It does not automatically make you CMMC-compliant — you still need to configure GCC correctly for CUI handling, apply appropriate access controls, enable audit logging, and document the environment in your SSP. GCC is a necessary foundation for cloud-based CUI handling, not a complete solution. Every other cloud service that touches CUI must also be evaluated against the FedRAMP Moderate requirement.

What is a Conditional CMMC Level 2 certification?

If a C3PAO assessment identifies deficiencies in non-critical requirements, you may receive Conditional CMMC Level 2 status rather than full certification. This gives you 180 days to remediate identified findings. During that period, you can attest to the conditional certification for contract purposes while actively closing the gaps. If remediation is not completed within 180 days, the conditional certification lapses. Conditional certification is not available for findings related to the highest-priority requirements or HVA (High Value Asset) programs.

How do I find a C3PAO?

All authorized C3PAOs are listed in the Cyber AB Marketplace at cyberab.org — verify any organization you are considering is actually authorized before engaging. Beyond authorization, the practical differentiators are experience with organizations similar to yours in size and sector, the number of certified assessors on their team, their approach to pre-assessment readiness, and their assessment timeline track record. Get references from contractors they have assessed, specifically asking about how they handled findings and communicated throughout the process.

Your SPRS score, live.

1TEN maps your documented controls to all 110 NIST SP 800-171 requirements and scores your posture in real time.

Request a Demo