Skip to content

Complete guide

CMMC compliance, explained without the acronym soup

If you hold Department of Defense contracts, CMMC is no longer a future problem. This page covers what the levels actually require, which one applies to you, how the rollout is phased, and what it takes to get compliant without spending money you do not have.

What CMMC is, and why it exists

For years, defense contractors were required to protect Controlled Unclassified Information under DFARS 252.204-7012, and were trusted to self-report how well they were doing it. A great many self-reported perfect scores. Investigations and breaches suggested otherwise.

CMMC is the verification layer built on top of that existing obligation. The requirements themselves are not new. They are still NIST SP 800-171. What changed is that somebody now checks, your status is tied to contract eligibility, and a senior official at your company has to affirm compliance personally each year.

The three levels

Your level is determined by the information you handle and the clauses in your contracts. You do not get to pick it, and picking a lower one than your contract requires is not a strategy.

LevelInformationRequirementsHow it is assessed
Level 1Federal Contract Information (FCI)15 requirements from FAR 52.204-21Annual self-assessment
Level 2Controlled Unclassified Information (CUI)110 requirements from NIST SP 800-171 (320 assessment objectives)Self-assessment for some contracts; C3PAO certification assessment every three years for most
Level 3CUI on programmes at heightened risk from advanced threatsLevel 2 plus 24 selected requirements from NIST SP 800-172Government-led assessment by DCMA DIBCAC

Level 1

Basic safeguarding. Achievable for most small companies without a major programme, but it still has to be real and affirmed by a senior official.

Level 2

This is where the overwhelming majority of the defense industrial base sits, and where essentially all of the cost and effort lives.

Level 3

A small subset of contractors. You must already hold Level 2 certification before Level 3 is on the table.

How the rollout is phased

The CMMC Program rule (32 CFR Part 170) took effect in December 2024, establishing the programme itself. The acquisition rule that actually puts CMMC requirements into contracts followed, and the requirement is being introduced into new DoD solicitations across a multi-year phase-in rather than all at once.

  • Phase 1: Level 1 and Level 2 self-assessmentrequirements begin appearing as a condition of award in applicable solicitations.
  • Phase 2: Level 2 certification assessments by a C3PAO begin being required on applicable contracts.
  • Phase 3: Level 3 requirements are introduced for the programmes that call for them.
  • Phase 4: Full implementation across all applicable DoD contracts and options.

The practical implication is that waiting is expensive. Assessment capacity across the accredited C3PAO pool is finite, and demand is stacked toward the deadline. A contractor who starts when the clause appears in their solicitation is already late, because remediation takes months regardless of how motivated everyone is.

FCI, CUI, and why the distinction decides everything

Federal Contract Information is information provided by or generated for the government under a contract that is not intended for public release: statements of work, delivery schedules, that kind of thing. Protecting it is Level 1 territory.

Controlled Unclassified Information is the category that triggers the expensive obligations: technical data, drawings, specifications, engineering analyses, export-controlled information, and more. If CUI arrives in your business, you are in Level 2 territory, and the way that information flows through your company determines the size and cost of your entire programme.

A surprising number of contractors are not certain which they receive. If that is you, start there, before you buy a single licence. Our CUI enclave and scoping service exists precisely for this.

What compliance actually involves

Level 2 is not a document exercise. An assessor will look at your environment and test 320 discrete objectives. Broadly, you need to be able to demonstrate all of the following, with evidence:

  • Controlled access to CUI, enforced technically rather than by policy alone
  • Multifactor authentication that is genuinely deployed everywhere it is required
  • FIPS-validated cryptography protecting CUI at rest and in transit
  • Audit logging that is collected, protected, retained, and actually reviewed
  • Configuration baselines and change control that are followed in practice
  • Vulnerability management with evidence of remediation over time
  • Security awareness training with records of completion
  • An incident response capability that has been exercised, not just written
  • Media protection, physical security, and sanitisation procedures
  • A System Security Plan describing the environment you actually run

The POA&M rules

A Plan of Action and Milestones lets you certify with a small number of items still open, but the constraints are tight, and misunderstanding them is a common and expensive mistake.

  • You must already score at least 88 of 110 to be eligible at all.
  • Only lower-weighted requirements qualify. The highest-weighted requirements, plus a short list that includes multifactor authentication and FIPS-validated cryptography, can never sit on a POA&M.
  • Everything on it must be closed within 180 days, verified by a follow-up assessment.

This is why remediation sequencing matters. Fixing the items that can never be deferred has to come first, whatever else is on the list.

What it costs, and why the quotes vary so wildly

Contractors of similar size routinely receive quotes an order of magnitude apart. The difference is almost never quality. It is scope.

A programme that hardens an entire hundred-person company to Level 2 standards is a fundamentally different undertaking from one that isolates twelve engineers in a purpose-built enclave. The second costs a fraction of the first, satisfies the same obligation, and produces a shorter assessment. Our pricing page breaks down each cost driver and how we reduce it.

Where to go next

If you know you are facing Level 2, the Level 2 requirements breakdown covers all fourteen families and how scoring works. If you need to post or correct a score, the self-assessment walkthrough takes you through it step by step. If a certification assessment is on your horizon, read what a C3PAO assessment actually involves.

Do not do this alone

Reading the rules is the easy part

Understanding CMMC takes an afternoon. Implementing 320 assessment objectives across a live business without breaking it takes considerably longer, which is what we are for.

Straight answers

CMMC questions, answered

Ask us something else

What does CMMC stand for?

Cybersecurity Maturity Model Certification. It is the Department of Defense programme for verifying that companies in the defense supply chain are genuinely protecting Federal Contract Information and Controlled Unclassified Information, rather than merely claiming to.

Which CMMC level do I need?

It is written into your contracts, not chosen by you. Contracts containing only FAR 52.204-21 and Federal Contract Information point to Level 1. Contracts containing DFARS 252.204-7012 where you receive CUI point to Level 2. Level 3 applies to a small number of programmes handling CUI at heightened risk and is assessed by the government itself.

Does CMMC apply to subcontractors?

Yes. Requirements flow down through the supply chain. If a prime passes you CUI, you carry the same safeguarding obligations they do, and they are increasingly asking for evidence before they will place the order.

What happens if we are not compliant?

As the phase-in progresses, a CMMC status becomes a condition of award for applicable contracts: no valid status, no eligibility. Separately, misrepresenting your compliance posture has already produced False Claims Act settlements in this sector, so an inaccurate SPRS score carries its own risk independent of any contract award.

Can we self-assess for Level 2?

Some Level 2 contracts allow it; most CUI-bearing ones require a certification assessment by an accredited C3PAO. The determination is made in the solicitation. Read the clauses, or have someone read them for you, before you assume either way.

How much does CMMC compliance cost?

It varies enormously with scope. The programmes that cost six figures a year are usually the ones where an entire company was pulled into the assessment boundary. With a well-designed CUI enclave, small contractors can achieve and maintain Level 2 for a fraction of that. Our pricing page explains what actually drives the number.

Next step

Find out what your CMMC gap really looks like

A short, no-obligation conversation and a written summary of where you stand, what it will take, and roughly what it will cost. No sales theatre.