CMMC Ready Now
Knowledge Center

Everything You Need to Know About CMMC

28 in-depth topics covering every aspect of CMMC 2.0 compliance — from foundational concepts to advanced assessment preparation, DFARS clauses, documentation requirements, and post-certification obligations.

28 topics · 6 categories · Updated June 2026

Getting Started6 min read

What Is CMMC?

The Cybersecurity Maturity Model Certification is the DoD's unified cybersecurity standard for defense contractors — replacing the self-attestation honor system with mandatory third-party verification.

Read more
Getting Started5 min read

Who Needs CMMC?

Any organization in the DoD supply chain that handles Federal Contract Information or Controlled Unclassified Information needs CMMC — including subcontractors at every tier.

Read more
Getting Started5 min read

The CMMC Rollout Timeline

CMMC is rolling out in four phases from 2024 through 2028. Phase 2 began in June 2025 — meaning Level 2 C3PAO assessments are now appearing in new DoD contracts involving CUI.

Read more
Getting Started7 min read

What Is Controlled Unclassified Information (CUI)?

CUI is information the government creates or possesses that requires safeguarding but is not classified. Understanding exactly what qualifies as CUI — and what doesn't — is the foundation of scoping your CMMC environment.

Read more
Getting Started5 min read

CMMC 2.0: What Changed from Version 1.0

The 2021 overhaul collapsed five levels to three, eliminated 20 unique CMMC practices, reintroduced POA&Ms, and aligned the model directly with NIST standards. Here's what changed and why.

Read more
The Framework4 min read

CMMC Level 1: Foundational

17 basic safeguarding practices covering Federal Contract Information. Annual self-assessment with senior official affirmation, no third-party C3PAO required.

Read more
The Framework6 min read

CMMC Level 2: Advanced

110 practices aligned to all of NIST SP 800-171 Rev 2. Required for any contractor handling CUI. Most contracts require a C3PAO third-party assessment every three years.

Read more
The Framework4 min read

CMMC Level 3: Expert

The highest CMMC level, with 130+ practices adding NIST SP 800-172 requirements on top of Level 2. Reserved for the most sensitive DoD programs, assessed by the government (DCSA).

Read more
The Framework10 min read

The 14 NIST SP 800-171 Control Domains

CMMC Level 2's 110 controls are organized into 14 domains. Each domain covers a distinct area of cybersecurity — from access control to system integrity.

Read more
The Framework5 min read

NIST SP 800-171 Rev 2 vs Rev 3: What Changed

NIST published Rev 3 in May 2024, but CMMC still uses Rev 2 as of 2026. Here's what Rev 3 changes, when DoD will transition, and what contractors should do now.

Read more
DFARS & Legal6 min read

DFARS 252.204-7012: Safeguarding CUI

The foundational DFARS clause requiring CUI protection, 72-hour cyber incident reporting, and cloud provider security standards. Has been in DoD contracts since 2016.

Read more
DFARS & Legal5 min read

DFARS 252.204-7019 & 7020: SPRS Assessment Requirements

These two clauses require contractors to assess themselves against NIST SP 800-171, post the score to SPRS, and allow DoD to conduct higher-level assessments. Both have been in effect since November 2020.

Read more
DFARS & Legal4 min read

DFARS 252.204-7021: The CMMC Contract Clause

The CMMC clause itself — making certification a condition of contract award. Went into effect in June 2025. If this clause is in your solicitation, you must be CMMC-certified to win the work.

Read more
DFARS & Legal5 min read

Flow-Down Requirements: Prime to Subcontractor Obligations

Under 32 CFR 170.23, primes must flow CMMC requirements to every subcontractor who touches FCI or CUI — and verify compliance before sharing sensitive data.

Read more
DFARS & Legal4 min read

The FAR CUI Rule: Coming for Civilian Contractors Too

A proposed FAR clause would extend CUI protection requirements — and NIST SP 800-171 — to contractors working with civilian agencies like NASA, HHS, and the Department of State.

Read more
Assessment5 min read

Self-Assessment vs. C3PAO Assessment: Which Do You Need?

Level 1 is always self-assessed. Most Level 2 contracts now require a C3PAO. Level 3 is government-led. Here's how to determine which applies to your contracts.

Read more
Assessment7 min read

How a C3PAO Assessment Works: Step by Step

A Level 2 C3PAO assessment is a structured multi-week engagement with examine, interview, and test phases. Here's exactly what to expect from initial scoping through the certification decision.

Read more
Assessment5 min read

How to Find and Vet a C3PAO

There are 100+ authorized C3PAOs as of 2026. Not all have equal experience. Here's how to find one, what to look for, and what questions to ask before signing a contract.

Read more
Assessment4 min read

Conditional vs. Full CMMC Certification: The Difference

A conditional certificate lets you win contracts while completing remaining remediation within 180 days. But not all controls are POA&M-eligible — some must be fully met before you can be certified.

Read more
Assessment6 min read

What CMMC Assessors Actually Look For

Assessors use examine, interview, and test methods across all 110 controls. They're not just looking at documents — they want evidence, consistency, and proof that staff actually know the procedures.

Read more
Documentation7 min read

System Security Plan (SSP): What It Must Contain

The SSP is the master document of your CMMC program — describing your CUI boundary, every system in scope, and how each of the 110 controls is implemented. Assessors read it first.

Read more
Documentation5 min read

Plan of Action & Milestones (POA&M): Structure and Rules

The POA&M documents gaps that remain open after assessment and tracks their remediation. CMMC 2.0 allows POA&Ms for conditional certification, but limits which controls qualify.

Read more
Documentation6 min read

SPRS Scores: How to Calculate and Submit Your Score

The Supplier Performance Risk System score is your self-assessed compliance number — ranging from -203 to 110. Here's how it's calculated, where to post it, and what a realistic score looks like.

Read more
Documentation6 min read

Evidence Collection Best Practices for CMMC

Assessors need evidence for every control they evaluate. Here's what types of evidence satisfy the examine, interview, and test methods — and how to organize it before your assessment.

Read more
Planning6 min read

CMMC Compliance Costs: What to Budget

DoD estimates CMMC Level 2 compliance costs $75K–$150K+, but real-world costs vary widely. Here's a breakdown of the major cost categories and what drives them up or down.

Read more
Planning5 min read

CMMC Preparation Timeline: How Long It Really Takes

DoD estimates 12–18 months for typical contractors. In practice, most small businesses need 18–24 months from gap assessment to certified. Here's what happens in each phase.

Read more
Planning6 min read

10 Common CMMC Mistakes That Delay Certification

From underscoping your CUI boundary to inflating SPRS scores, these are the mistakes that most commonly derail CMMC programs — and how to avoid them.

Read more
Planning5 min read

After Certification: Maintaining CMMC Compliance

Getting certified is not the finish line. Annual affirmations, triennial reassessments, continuous monitoring, and incident response readiness are all ongoing obligations.

Read more

Need help applying this to your organization?

CMMC Ready Now helps defense contractors navigate the path from gap assessment to certified. Start with a no-cost 30-minute conversation with Rick.