Compliance · US
CMMC 2.0DoD contractors & subcontractors
CMMC
Plain-English definition
The Cybersecurity Maturity Model Certification is a US Department of Defense requirement for contractors and subcontractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). CMMC 2.0 streamlined the model to three levels: Level 1 (self-assessed, basic safeguarding of FCI), Level 2 (mirrors NIST SP 800-171's 110 controls for CUI, self-assessed or third-party assessed by a C3PAO depending on criticality), and Level 3 (adds NIST SP 800-172 enhanced requirements, government-led assessment).
Requirements are being rolled into contracts via a phased DFARS clause rollout, so applicability depends on your specific contract's requirements.
Who needs it
Defense contractors and subcontractors in the Defense Industrial Base that handle Federal Contract Information or Controlled Unclassified Information as part of a DoD contract.
Key requirements
Implementation of the 110 security controls from NIST SP 800-171 for Level 2, a System Security Plan and Plan of Action & Milestones documenting current status, and assessment (self, C3PAO-led, or government-led) matched to your required level.
Cyber/privacy implications
Controlled Unclassified Information flowing through your environment needs to be identified and scoped precisely, since the control burden and assessment type both depend on exactly where CUI lives and moves.
Assessment methodology
CUI data-flow scoping, gap assessment against the applicable NIST SP 800-171 or 800-172 control set, System Security Plan development, and readiness support for self-assessment or C3PAO engagement.
Implementation phases
01
Scope
Identify FCI/CUI data flows and determine your required CMMC level.
02
Remediate
Close control gaps against NIST SP 800-171 (Level 2) or 800-172 (Level 3).
03
Assess
Complete self-assessment or support a C3PAO/government-led assessment.
Evidence & documentation requirements
System Security Plan, Plan of Action & Milestones, CUI data-flow diagrams, and control implementation evidence mapped to each applicable NIST SP 800-171 requirement.
Common mistakes
Under-scoping the CUI boundary to minimize apparent assessment burden, which creates contract compliance risk; waiting until a contract requires a specific level before starting remediation, when the underlying control implementation takes months.
Expert review
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA
FAQ
What level do we need?
Determined by your specific contract requirements and whether you handle FCI only (Level 1) or CUI (Level 2 or above); we confirm this during scoping against your actual contract language.
Can we self-assess?
Level 1 and most Level 2 requirements allow self-assessment; certain critical Level 2 programs and all Level 3 require third-party or government-led assessment.
How long does Level 2 readiness typically take?
Highly dependent on starting maturity; organizations with no prior NIST SP 800-171 alignment often need 6 to 12 months of remediation work.
Request a Gap Assessment
Scope your CUI boundary and see where your controls stand against NIST SP 800-171.
Request a Gap Assessment →