CMMC Compliance — Program Guide

The CMMC Program Guide

Levels, timelines, and the route to certification, mapped to how DoD contractors actually get assessed.

Book a readiness call
124

Days to Phase 2

Until CMMC becomes a mandatory contract requirement (Nov 10, 2026).

3

Certification levels

Level 1, 2, and 3, scoped to the sensitivity of the data you handle.

110

NIST SP 800-171 controls

The control set assessed for a Level 2 certification.

3-yr

Certification cycle

How often a C3PAO assessment must be renewed.

Program timeline

You have 124 days until CMMC becomes a standard contract clause. Contractors who wait for a solicitation to require it typically run out of runway.

01

Self-assessment (today)

Level 1 and select Level 2 contractors self-attest annually in SPRS.

02

Phase 2: Nov 10, 2026

C3PAO-certified Level 2 assessments start appearing in new contracts.

03

Phase 3: contract flow-down

CMMC requirements cascade to subcontractors handling CUI further down the supply chain.

04

Full enforcement

CMMC becomes a standard condition of contract award and renewal across the DIB.

Three levels, one determining factor

Your level is set by what you handle: Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), not by company size.

L1

Level 1 — Foundational

FCI only. 17 basic safeguarding practices. Annual self-assessment.

L2

Level 2 — Advanced

CUI in scope. All 110 NIST SP 800-171 controls. Third-party (C3PAO) assessment for most contracts.

L3

Level 3 — Expert

Highest-sensitivity CUI. Level 2 plus a further control set. Government-led assessment.

Self-assessment route

For Level 1 (FCI-only) and select Level 2 contractors, who can self-attest in SPRS without a third-party assessor.

Annual self-attestation in SPRS

Senior official affirmation required

Lower cost, faster to complete

No third-party assessor involved

C3PAO-assessed route

Required for most Level 2 contracts and all of Level 3. An accredited third-party assessment organization conducts the assessment.

Assessed against all 110 controls

Certification valid for three years

POA&Ms allowed for a limited control set

Required to hold CUI on most DoD contracts

Why contractors run this with Essendis

A program guide is only as good as the artifacts behind it. This is what we bring to the engagement.

Advisory and engineering under one roof, not handed off between vendors

SSPs written to match the environment as built, not as originally scoped

Assessor-grade dry runs before the real assessment starts

Secure Enclave and Microsoft Gov Cloud partner on staff for the CUI boundary itself

Frequently asked questions

Do we need CMMC if we only have FCI, not CUI?

Yes, at Level 1. Any contractor processing Federal Contract Information under a covered contract needs an annual Level 1 self-assessment, even without CUI in scope.

Can we self-assess at Level 2?

Only a subset of Level 2 contracts allow self-assessment. Most Level 2 contracts, and all of Level 3, require a C3PAO-led third-party assessment.

What happens if we're not certified by November 10, 2026?

Phase 2 makes CMMC certification a condition of contract award for in-scope solicitations issued on or after that date. Contractors without the required level are ineligible for those awards.

How long does a Level 2 engagement take?

Most programs run 4 to 9 months from initial scoping through a passed C3PAO assessment, depending on how much remediation the environment needs.

Ready to map your route to certification?

Book a readiness call

Secure Enclave

Where CUI actually lives while the rest of the business runs outside the boundary.

Explore the enclave

RPS Defense: 110/110

A perfect CMMC Level 2 assessment, and how the engagement ran.

Read the case study

Microsoft Government Cloud

GCC vs. GCC High, and how licensing actually works.

Explore licensing