What CMMC is, and why it exists
For years, defense contractors were required to protect Controlled Unclassified Information under DFARS 252.204-7012, and were trusted to self-report how well they were doing it. A great many self-reported perfect scores. Investigations and breaches suggested otherwise.
CMMC is the verification layer built on top of that existing obligation. The requirements themselves are not new. They are still NIST SP 800-171. What changed is that somebody now checks, your status is tied to contract eligibility, and a senior official at your company has to affirm compliance personally each year.
The three levels
Your level is determined by the information you handle and the clauses in your contracts. You do not get to pick it, and picking a lower one than your contract requires is not a strategy.
| Level | Information | Requirements | How it is assessed |
|---|---|---|---|
| Level 1 | Federal Contract Information (FCI) | 15 requirements from FAR 52.204-21 | Annual self-assessment |
| Level 2 | Controlled Unclassified Information (CUI) | 110 requirements from NIST SP 800-171 (320 assessment objectives) | Self-assessment for some contracts; C3PAO certification assessment every three years for most |
| Level 3 | CUI on programmes at heightened risk from advanced threats | Level 2 plus 24 selected requirements from NIST SP 800-172 | Government-led assessment by DCMA DIBCAC |
Level 1
Basic safeguarding. Achievable for most small companies without a major programme, but it still has to be real and affirmed by a senior official.
Level 2
This is where the overwhelming majority of the defense industrial base sits, and where essentially all of the cost and effort lives.
Level 3
A small subset of contractors. You must already hold Level 2 certification before Level 3 is on the table.
How the rollout is phased
The CMMC Program rule (32 CFR Part 170) took effect in December 2024, establishing the programme itself. The acquisition rule that actually puts CMMC requirements into contracts followed, and the requirement is being introduced into new DoD solicitations across a multi-year phase-in rather than all at once.
- Phase 1: Level 1 and Level 2 self-assessmentrequirements begin appearing as a condition of award in applicable solicitations.
- Phase 2: Level 2 certification assessments by a C3PAO begin being required on applicable contracts.
- Phase 3: Level 3 requirements are introduced for the programmes that call for them.
- Phase 4: Full implementation across all applicable DoD contracts and options.
The practical implication is that waiting is expensive. Assessment capacity across the accredited C3PAO pool is finite, and demand is stacked toward the deadline. A contractor who starts when the clause appears in their solicitation is already late, because remediation takes months regardless of how motivated everyone is.
FCI, CUI, and why the distinction decides everything
Federal Contract Information is information provided by or generated for the government under a contract that is not intended for public release: statements of work, delivery schedules, that kind of thing. Protecting it is Level 1 territory.
Controlled Unclassified Information is the category that triggers the expensive obligations: technical data, drawings, specifications, engineering analyses, export-controlled information, and more. If CUI arrives in your business, you are in Level 2 territory, and the way that information flows through your company determines the size and cost of your entire programme.
A surprising number of contractors are not certain which they receive. If that is you, start there, before you buy a single licence. Our CUI enclave and scoping service exists precisely for this.
What compliance actually involves
Level 2 is not a document exercise. An assessor will look at your environment and test 320 discrete objectives. Broadly, you need to be able to demonstrate all of the following, with evidence:
- Controlled access to CUI, enforced technically rather than by policy alone
- Multifactor authentication that is genuinely deployed everywhere it is required
- FIPS-validated cryptography protecting CUI at rest and in transit
- Audit logging that is collected, protected, retained, and actually reviewed
- Configuration baselines and change control that are followed in practice
- Vulnerability management with evidence of remediation over time
- Security awareness training with records of completion
- An incident response capability that has been exercised, not just written
- Media protection, physical security, and sanitisation procedures
- A System Security Plan describing the environment you actually run
The POA&M rules
A Plan of Action and Milestones lets you certify with a small number of items still open, but the constraints are tight, and misunderstanding them is a common and expensive mistake.
- You must already score at least 88 of 110 to be eligible at all.
- Only lower-weighted requirements qualify. The highest-weighted requirements, plus a short list that includes multifactor authentication and FIPS-validated cryptography, can never sit on a POA&M.
- Everything on it must be closed within 180 days, verified by a follow-up assessment.
This is why remediation sequencing matters. Fixing the items that can never be deferred has to come first, whatever else is on the list.
What it costs, and why the quotes vary so wildly
Contractors of similar size routinely receive quotes an order of magnitude apart. The difference is almost never quality. It is scope.
A programme that hardens an entire hundred-person company to Level 2 standards is a fundamentally different undertaking from one that isolates twelve engineers in a purpose-built enclave. The second costs a fraction of the first, satisfies the same obligation, and produces a shorter assessment. Our pricing page breaks down each cost driver and how we reduce it.
Where to go next
If you know you are facing Level 2, the Level 2 requirements breakdown covers all fourteen families and how scoring works. If you need to post or correct a score, the self-assessment walkthrough takes you through it step by step. If a certification assessment is on your horizon, read what a C3PAO assessment actually involves.