Everything You Need to Know About CMMC
28 in-depth topics covering every aspect of CMMC 2.0 compliance — from foundational concepts to advanced assessment preparation, DFARS clauses, documentation requirements, and post-certification obligations.
28 topics · 6 categories · Updated June 2026
What Is CMMC?
The Cybersecurity Maturity Model Certification is the DoD's unified cybersecurity standard for defense contractors — replacing the self-attestation honor system with mandatory third-party verification.
Who Needs CMMC?
Any organization in the DoD supply chain that handles Federal Contract Information or Controlled Unclassified Information needs CMMC — including subcontractors at every tier.
The CMMC Rollout Timeline
CMMC is rolling out in four phases from 2024 through 2028. Phase 2 began in June 2025 — meaning Level 2 C3PAO assessments are now appearing in new DoD contracts involving CUI.
What Is Controlled Unclassified Information (CUI)?
CUI is information the government creates or possesses that requires safeguarding but is not classified. Understanding exactly what qualifies as CUI — and what doesn't — is the foundation of scoping your CMMC environment.
CMMC 2.0: What Changed from Version 1.0
The 2021 overhaul collapsed five levels to three, eliminated 20 unique CMMC practices, reintroduced POA&Ms, and aligned the model directly with NIST standards. Here's what changed and why.
CMMC Level 1: Foundational
17 basic safeguarding practices covering Federal Contract Information. Annual self-assessment with senior official affirmation, no third-party C3PAO required.
CMMC Level 2: Advanced
110 practices aligned to all of NIST SP 800-171 Rev 2. Required for any contractor handling CUI. Most contracts require a C3PAO third-party assessment every three years.
CMMC Level 3: Expert
The highest CMMC level, with 130+ practices adding NIST SP 800-172 requirements on top of Level 2. Reserved for the most sensitive DoD programs, assessed by the government (DCSA).
The 14 NIST SP 800-171 Control Domains
CMMC Level 2's 110 controls are organized into 14 domains. Each domain covers a distinct area of cybersecurity — from access control to system integrity.
NIST SP 800-171 Rev 2 vs Rev 3: What Changed
NIST published Rev 3 in May 2024, but CMMC still uses Rev 2 as of 2026. Here's what Rev 3 changes, when DoD will transition, and what contractors should do now.
DFARS 252.204-7012: Safeguarding CUI
The foundational DFARS clause requiring CUI protection, 72-hour cyber incident reporting, and cloud provider security standards. Has been in DoD contracts since 2016.
DFARS 252.204-7019 & 7020: SPRS Assessment Requirements
These two clauses require contractors to assess themselves against NIST SP 800-171, post the score to SPRS, and allow DoD to conduct higher-level assessments. Both have been in effect since November 2020.
DFARS 252.204-7021: The CMMC Contract Clause
The CMMC clause itself — making certification a condition of contract award. Went into effect in June 2025. If this clause is in your solicitation, you must be CMMC-certified to win the work.
Flow-Down Requirements: Prime to Subcontractor Obligations
Under 32 CFR 170.23, primes must flow CMMC requirements to every subcontractor who touches FCI or CUI — and verify compliance before sharing sensitive data.
The FAR CUI Rule: Coming for Civilian Contractors Too
A proposed FAR clause would extend CUI protection requirements — and NIST SP 800-171 — to contractors working with civilian agencies like NASA, HHS, and the Department of State.
Self-Assessment vs. C3PAO Assessment: Which Do You Need?
Level 1 is always self-assessed. Most Level 2 contracts now require a C3PAO. Level 3 is government-led. Here's how to determine which applies to your contracts.
How a C3PAO Assessment Works: Step by Step
A Level 2 C3PAO assessment is a structured multi-week engagement with examine, interview, and test phases. Here's exactly what to expect from initial scoping through the certification decision.
How to Find and Vet a C3PAO
There are 100+ authorized C3PAOs as of 2026. Not all have equal experience. Here's how to find one, what to look for, and what questions to ask before signing a contract.
Conditional vs. Full CMMC Certification: The Difference
A conditional certificate lets you win contracts while completing remaining remediation within 180 days. But not all controls are POA&M-eligible — some must be fully met before you can be certified.
What CMMC Assessors Actually Look For
Assessors use examine, interview, and test methods across all 110 controls. They're not just looking at documents — they want evidence, consistency, and proof that staff actually know the procedures.
System Security Plan (SSP): What It Must Contain
The SSP is the master document of your CMMC program — describing your CUI boundary, every system in scope, and how each of the 110 controls is implemented. Assessors read it first.
Plan of Action & Milestones (POA&M): Structure and Rules
The POA&M documents gaps that remain open after assessment and tracks their remediation. CMMC 2.0 allows POA&Ms for conditional certification, but limits which controls qualify.
SPRS Scores: How to Calculate and Submit Your Score
The Supplier Performance Risk System score is your self-assessed compliance number — ranging from -203 to 110. Here's how it's calculated, where to post it, and what a realistic score looks like.
Evidence Collection Best Practices for CMMC
Assessors need evidence for every control they evaluate. Here's what types of evidence satisfy the examine, interview, and test methods — and how to organize it before your assessment.
CMMC Compliance Costs: What to Budget
DoD estimates CMMC Level 2 compliance costs $75K–$150K+, but real-world costs vary widely. Here's a breakdown of the major cost categories and what drives them up or down.
CMMC Preparation Timeline: How Long It Really Takes
DoD estimates 12–18 months for typical contractors. In practice, most small businesses need 18–24 months from gap assessment to certified. Here's what happens in each phase.
10 Common CMMC Mistakes That Delay Certification
From underscoping your CUI boundary to inflating SPRS scores, these are the mistakes that most commonly derail CMMC programs — and how to avoid them.
After Certification: Maintaining CMMC Compliance
Getting certified is not the finish line. Annual affirmations, triennial reassessments, continuous monitoring, and incident response readiness are all ongoing obligations.
Need help applying this to your organization?
CMMC Ready Now helps defense contractors navigate the path from gap assessment to certified. Start with a no-cost 30-minute conversation with Rick.
