Compliance · US
CMMC 2.0DoD contractors & subcontractors

CMMC

Plain-English definition

The Cybersecurity Maturity Model Certification is a US Department of Defense requirement for contractors and subcontractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). CMMC 2.0 streamlined the model to three levels: Level 1 (self-assessed, basic safeguarding of FCI), Level 2 (mirrors NIST SP 800-171's 110 controls for CUI, self-assessed or third-party assessed by a C3PAO depending on criticality), and Level 3 (adds NIST SP 800-172 enhanced requirements, government-led assessment).

Requirements are being rolled into contracts via a phased DFARS clause rollout, so applicability depends on your specific contract's requirements.

Who needs it

Defense contractors and subcontractors in the Defense Industrial Base that handle Federal Contract Information or Controlled Unclassified Information as part of a DoD contract.

Key requirements

Implementation of the 110 security controls from NIST SP 800-171 for Level 2, a System Security Plan and Plan of Action & Milestones documenting current status, and assessment (self, C3PAO-led, or government-led) matched to your required level.

Cyber/privacy implications

Controlled Unclassified Information flowing through your environment needs to be identified and scoped precisely, since the control burden and assessment type both depend on exactly where CUI lives and moves.

Assessment methodology

CUI data-flow scoping, gap assessment against the applicable NIST SP 800-171 or 800-172 control set, System Security Plan development, and readiness support for self-assessment or C3PAO engagement.

Implementation phases

01
Scope

Identify FCI/CUI data flows and determine your required CMMC level.

02
Remediate

Close control gaps against NIST SP 800-171 (Level 2) or 800-172 (Level 3).

03
Assess

Complete self-assessment or support a C3PAO/government-led assessment.

Evidence & documentation requirements

System Security Plan, Plan of Action & Milestones, CUI data-flow diagrams, and control implementation evidence mapped to each applicable NIST SP 800-171 requirement.

Common mistakes

Under-scoping the CUI boundary to minimize apparent assessment burden, which creates contract compliance risk; waiting until a contract requires a specific level before starting remediation, when the underlying control implementation takes months.

Related standards

Expert review

Nitzan Levi
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA

FAQ

What level do we need?
Determined by your specific contract requirements and whether you handle FCI only (Level 1) or CUI (Level 2 or above); we confirm this during scoping against your actual contract language.
Can we self-assess?
Level 1 and most Level 2 requirements allow self-assessment; certain critical Level 2 programs and all Level 3 require third-party or government-led assessment.
How long does Level 2 readiness typically take?
Highly dependent on starting maturity; organizations with no prior NIST SP 800-171 alignment often need 6 to 12 months of remediation work.

Request a Gap Assessment

Scope your CUI boundary and see where your controls stand against NIST SP 800-171.

Request a Gap Assessment →