By Uniqcli Team
CMMC (Cybersecurity Maturity Model Certification) is a U.S. Department of Defense program that verifies defense contractors have implemented required safeguards for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) on their information systems. It exists because the Defense Department for years relied on contractors to attest to their own cybersecurity under DFARS clause 252.204-7012, with little independent verification that the promised protections were actually in place. CMMC adds a graded, checkable assurance layer on top of that self-attestation model: instead of trusting a signature alone, the program ties eligibility for certain contracts to a demonstrated level of security maturity. The current framework, known as CMMC 2.0, was announced in November 2021 and streamlined an earlier five-level model down to three.
Most buyers and engineers meet CMMC not as an abstract standard but as a line in a Department of Defense solicitation: a specified level becomes a pass/fail eligibility gate that determines whether a company can even be considered for award. Because the requirement flows down contractually, it reaches far beyond large prime contractors — subcontractors, suppliers, and the IT or managed-service providers that touch a defense customer's FCI or CUI can all be pulled into scope. Understanding which level applies, how it maps to the NIST SP 800-171 control set, and how compliance is verified is therefore a procurement question as much as a technical one, especially while the rollout timeline continues to shift through 2026.
Why did the DoD create CMMC?
For most of the past decade, defense contractors handling sensitive but unclassified information were governed chiefly by DFARS 252.204-7012, which required them to safeguard covered defense information and report cyber incidents. That clause pointed to the NIST SP 800-171 control set but relied on contractors self-attesting to compliance, with limited government verification. A series of supply-chain breaches exposed the gap between what firms claimed on paper and what they had actually implemented. CMMC was created to close that gap by making a demonstrated security posture a condition of doing business with the Department of Defense, rather than a promise checked only after something goes wrong.
The program's scope is defined by two information categories. Federal Contract Information (FCI) is non-public information provided by or generated for the government under a contract, while Controlled Unclassified Information (CUI) is a broader, more sensitive category subject to specific handling rules. CMMC sets escalating requirements based on which category a contractor touches and how sensitive the associated program is. The framework itself was formally established by a rule at 32 CFR Part 170, which took effect on December 16, 2024, giving the model its own regulatory footing separate from the acquisition clauses that place it into individual contracts.
What are the three levels of CMMC 2.0?
CMMC 2.0 defines three levels, a deliberate simplification of the original 2020 model's five tiers — the intermediate old Levels 2 and 4 were eliminated, so a company reading legacy guidance about a five-level ladder is looking at a superseded structure. Level 1 (Foundational) covers basic protection of FCI and maps to the 15 basic safeguarding requirements in FAR clause 52.204-21. Level 2 (Advanced) is built for CUI and requires implementing all 110 security requirements of NIST SP 800-171, currently Revision 2. Each level adds obligations rather than replacing the one beneath it.
Level 3 (Expert) is reserved for the highest-priority, most sensitive programs. It builds on Level 2's 110 requirements and adds a subset of roughly 24 enhanced requirements drawn from NIST SP 800-172, which targets advanced persistent threats. The levels also differ in how they are checked: Level 1 and some Level 2 contracts allow self-assessment, other Level 2 contracts require a third-party assessment, and Level 3 is assessed by the government itself. Which level a contract carries depends on the sensitivity of the information involved, so a single supplier may face different requirements across different awards.
Who in the defense industrial base does CMMC apply to?
A common misconception is that CMMC only concerns large prime contractors. In practice the requirement travels down the entire Defense Industrial Base supply chain. Any organization whose information systems process, store, or transmit FCI or CUI can be in scope — including subcontractors, component suppliers, and small businesses several tiers removed from the government. Prime contractors are responsible for flowing the applicable CMMC requirement down to their subcontractors contractually, so a firm that never contracts directly with the Department of Defense can still inherit an obligation through the companies it sells to.
The reach extends to service providers as well. An IT reseller, integrator, or managed-service provider that provisions systems or handles data touching a defense customer's FCI or CUI can itself be treated as an external service provider within that customer's assessment scope. The practical consequence is that scoping — determining exactly which systems, people, and data fall inside the boundary — is often the hardest early step. A company that only handles FCI and never touches CUI may need only Level 1, while a single CUI enclave can pull an otherwise ordinary environment up to Level 2 and its full 110-requirement burden.
How is CMMC compliance verified?
Verification depends on the level and the specific contract. Level 1 and self-assessment Level 2 contractors evaluate their own environment against the applicable requirements using the NIST SP 800-171 DoD Assessment Methodology and submit the resulting score to the Supplier Performance Risk System (SPRS), backed by a senior-official affirmation of accuracy. Other Level 2 contracts require a third-party assessment by a Certified Third-Party Assessment Organization (C3PAO), while Level 3 assessments are performed by the government's own Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) rather than a commercial assessor.
Self-assessment is not the same as no accountability. Scores are filed under a signed senior-official affirmation, and inaccurate affirmations can expose a company to civil fraud liability under the government's cyber-enforcement posture. The scoring rules are strict: a 'conditional' status can be granted when certain unmet requirements are placed on a plan of action and milestones (POA&M), but requirements that cannot legally be deferred — and any gap at Level 1, where POA&Ms are not permitted — result in 'No CMMC Status.' Certifications carry defined lifespans, commonly cited as three years for Levels 2 and 3 and one year for Level 1, with an annual affirmation of continued compliance in between.
Where does the CMMC rollout stand as of mid-2026?
CMMC obligations enter contracts through a separate acquisition rule, DFARS 252.204-7021, which took effect on November 10, 2025 and started a phased rollout clock. The rollout was designed in four phases: Phase 1 (from November 2025) introduces self-assessment requirements for Levels 1 and 2 in new solicitations; Phase 2 was slated to make third-party C3PAO certification mandatory for Level 2; Phase 3 (targeted for November 2027) would extend requirements to contract option periods and begin Level 3 DIBCAC assessments; and Phase 4 (November 2028) would make CMMC clauses standard across essentially all applicable DoD contracts, excluding commercial off-the-shelf-only buys.
That timeline is in flux. As of July 2026, the Department suspended the Phase 2 mandatory third-party certification step on July 13, 2026 and stood up a 'CMMC Reform Task Force' for a roughly 60-day review of the program's cost and administrative burden, with an industry request-for-information response deadline of August 14, 2026. Crucially, the suspension is not a cancellation: Phase 1 self-assessments, SPRS score submissions, senior-official affirmations, and the underlying DFARS 252.204-7012 safeguarding and incident-reporting duties all remain fully in force. Because the review was only days old at this writing, the Phase 2 status should be treated as provisional and likely to change again.
How does CMMC relate to NIST 800-171, FedRAMP, and 889 — and how do contractors prepare?
CMMC is best understood as a verification wrapper around control catalogs it does not itself invent. Its Level 2 content is NIST SP 800-171, and Level 3 adds part of NIST SP 800-172, so a strong NIST SP 800-171 program is the foundation of CMMC readiness. (NIST published Revision 3 of SP 800-171 in May 2024, but CMMC assessments still benchmark against Revision 2 as of mid-2026, with no published migration date.) Two adjacent programs are frequently confused with it. FedRAMP authorizes cloud service offerings against NIST SP 800-53 for government-wide use, and a cloud provider handling CUI for a defense contractor must separately meet a FedRAMP Moderate or DoD-defined equivalent baseline — a related but legally distinct obligation. NDAA Section 889, by contrast, restricts certain covered telecommunications and video-surveillance equipment in federal supply chains, which is a procurement prohibition rather than a security-maturity assessment.
Preparation typically starts with scoping: mapping exactly where FCI and CUI live, then drawing the smallest defensible boundary around the systems that touch them, since a narrower scope is cheaper to secure and to assess. From there, contractors implement the applicable NIST SP 800-171 requirements, document them in a system security plan, and record any remaining gaps in a POA&M where permitted. Concepts covered elsewhere — network segmentation and DMZ design, zero-trust access controls, and hardware roots of trust — are common building blocks of that work. Firms then generate an SPRS score and, where third-party certification applies, engage an authorized assessor. Industry reporting has flagged limited assessor capacity heading into the certification phases, so contractors on that path generally plan well ahead rather than treating certification as a last-minute step.
Key takeaways
- CMMC verifies that defense contractors protect FCI and CUI, replacing pure self-attestation with graded, independently checkable assurance.
- CMMC 2.0 has three levels: Level 1 (FCI, FAR 52.204-21), Level 2 (all 110 NIST SP 800-171 controls for CUI), and Level 3 (adds NIST SP 800-172).
- Requirements flow down the entire Defense Industrial Base — subcontractors, suppliers, and service providers touching FCI or CUI are in scope, not just primes.
- Verification ranges from SPRS self-assessment (Level 1 and some Level 2) to C3PAO third-party certification (Level 2) and government DIBCAC assessment (Level 3).
- The DFARS acquisition rule took effect November 10, 2025; as of July 2026 the Phase 2 mandatory third-party step is suspended for a reform review while Phase 1 duties continue.
- CMMC wraps NIST SP 800-171/172 and is distinct from FedRAMP (cloud authorization) and NDAA Section 889 (covered-equipment restriction), which are commonly confused with it.
Shop it at Uniqcli
Frequently asked
- How much does CMMC certification cost and how long does it take?
- There is no official DoD price tag, and public estimates come almost entirely from compliance vendors, so treat them as rough industry-reported ranges rather than fixed figures. Those sources put total cost anywhere from a few thousand dollars for a small Level 1 self-assessment to well over a million for a large Level 2 or 3 environment, with timelines commonly cited between roughly six and thirty-plus months depending on level, company size, and how much remediation is needed. The biggest variables are scope and current maturity: a firm already running a mature NIST SP 800-171 program faces far less work than one starting from a blank slate. Because it drives both cost and schedule, tightly scoping which systems touch FCI or CUI is usually the highest-leverage early decision.
- Does CMMC apply to a company that only handles FCI and never touches CUI?
- Yes, but typically only at Level 1. Federal Contract Information triggers the foundational tier: a company that receives or generates FCI under a DoD contract but never stores, processes, or transmits CUI generally needs to meet the 15 basic safeguarding requirements of FAR 52.204-21, verified by an annual self-assessment and a senior-official affirmation. It does not, on that basis alone, need the full 110-requirement Level 2 program. The catch is scoping accuracy: CUI can enter an environment in non-obvious ways — through drawings, specifications, or shared systems — and even a single CUI workflow can pull the relevant enclave up to Level 2. Confirming that no CUI is actually present is therefore part of the assessment, not an assumption.
- What happens if a contractor doesn't achieve the required CMMC level?
- It generally cannot be awarded the contract. CMMC functions as a pass/fail eligibility gate: once a solicitation specifies a level, an offeror's current SPRS status determines whether it can be considered at all, so a missing or insufficient result can remove a bidder from contention. Under the scoring rules, certain unmet requirements can be placed on a plan of action and milestones (POA&M) to earn a time-limited conditional status, but requirements that cannot be deferred — or any gap at Level 1, where POA&Ms are not allowed — produce 'No CMMC Status.' Because the requirement also flows down, a subcontractor that cannot meet its level can jeopardize a prime's ability to staff the work, which is why readiness is treated as a business-continuity issue rather than a paperwork formality.
- What is a C3PAO, and who is allowed to perform a CMMC assessment?
- A C3PAO — Certified Third-Party Assessment Organization — is a company authorized to conduct the third-party CMMC assessments that some Level 2 contracts require. C3PAOs are trained, credentialed, and authorized by the Cyber AB (formerly the CMMC Accreditation Body), the DoD-authorized nonprofit that oversees the assessor ecosystem. Not every level uses a C3PAO: Level 1 and self-assessment Level 2 contractors evaluate themselves and file the result in SPRS, while Level 3 assessments are conducted by the government's own Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), not a commercial firm. Industry reporting has flagged a limited pool of authorized assessors relative to the number of contractors in scope, which is one reason organizations on the certification path are advised to schedule well in advance.