CMMC 2.0 — the Cybersecurity Maturity Model Certification — is how the Department of Defense verifies that contractors actually protect Federal Contract Information and Controlled Unclassified Information, rather than taking their word for it. The stakes are simple: no certification, no contract. This guide walks through what the framework requires, who it applies to, what it costs, and the deadlines that should be driving your planning.
CMMC 2.0 is the DoD's assessment framework for verifying contractor cybersecurity. It doesn't invent new security controls — Level 2 maps directly to the 110 requirements of NIST SP 800-171 — it adds verification: self-assessments, affirmations, and third-party audits with real contractual consequences. Two federal rules give it teeth: the 32 CFR program rule (effective December 16, 2024) defines the program itself, and the 48 CFR acquisition rule (effective November 10, 2025) writes it into DoD contracts. If your company holds — or wants — defense work, CMMC 2.0 is now part of the price of admission.
CMMC 2.0 is also a simplification. The original 2020 framework had five levels and process-maturity requirements unique to CMMC; version 2.0 cut that to three levels, dropped the bespoke maturity practices, and aligned the requirements directly with existing NIST standards. That matters practically: security work you've already done against NIST SP 800-171 counts toward certification, and the transitional levels are gone. What remains is a straightforward question — what federal information do you handle, and can you prove you protect it?
CMMC 2.0 collapsed the original five levels into three, each tied to the sensitivity of the information you handle. Your contracts — and the data flowing through your systems — determine which one applies. The levels aren't aspirational tiers; they're floor requirements written into your award.
Each level pairs a set of security requirements with a verification method. Level 1 relies on an annual self-assessment. Level 2 requires a triennial C3PAO assessment for most contracts, with a small subset permitted to self-assess. Level 3 adds a government-led assessment. In every case the result lands in SPRS, where contracting officers can see it — which is why an inflated self-score is a liability, not a shortcut.
17 practices drawn from basic safeguarding requirements, verified by an annual self-assessment and an executive affirmation submitted in SPRS. Level 1 applies when you handle Federal Contract Information — the routine data of government work — but no CUI.
See our CMMC Level 1 compliance servicesAll 110 requirements of NIST SP 800-171 Rev 2. Most contractors need a triennial assessment by a certified third-party assessor organization (C3PAO); a small subset of contracts allow self-assessment. If you touch technical drawings, specifications, or export-controlled data, this is almost certainly your level.
See our CMMC Level 2 compliance servicesBuilds on Level 2 with additional requirements drawn from NIST SP 800-172 and a government-led assessment. Level 3 applies to a small population of contractors supporting the DoD's most sensitive programs — if it applies to you, you almost certainly already know.
CMMC is no longer pending — the rules are final and enforcement is underway. Two federal rules did the heavy lifting, and the calendar now drives contractor decisions more than any technical requirement does.
Update (July 2026): the Department of War has suspended CMMC Phase 2 and opened a 60-day program review — existing DFARS obligations and certifications still stand. Read our analysis of what the suspension means for contractors.
The 32 CFR CMMC Program rule formally established the assessment framework: the three levels, the role of C3PAOs, the limits on POA&Ms, and the affirmation requirements. This is the rule that defines what certification actually is.
The 48 CFR acquisition rule lets contracting officers write CMMC requirements into new DoD solicitations. Since this date, certification status has been a gate to award for covered contracts — Phase 1 of the phased rollout.
Phase 2 broadens the range of solicitations requiring Level 2 certification by a C3PAO rather than self-assessment. Contractors bidding into 2027 pipelines need certification work well underway before this date arrives.
There are far more contractors needing Level 2 certification than there are C3PAO assessment slots. Contractors who start readiness work early choose their assessment window; late movers take what's left. Treat the dates above as a latest-possible timeline, not a start date.
If your revenue touches the DoD supply chain — as a prime or as a subcontractor at any tier — CMMC applies to you. The requirement follows the data, not the size of your company or your distance from the prime contract.
Primes flow CMMC requirements down to every subcontractor that handles FCI or CUI on the effort. A five-person machine shop three tiers below the prime carries the same Level 2 obligation as the prime itself if CUI reaches its systems.
Many subcontractors first hear about CMMC from a prime's supplier questionnaire, not from a contracting officer. Primes are de-risking their supply chains now, and suppliers without a credible compliance story are quietly losing their places on bid teams.
Handle only Federal Contract Information? Level 1. Store, process, or transmit CUI — drawings, specifications, technical data? Level 2. The fastest way to know for certain is a scoping review of where government data actually lives in your environment.
Most contractors misjudge their own scope — usually by overestimating it. A readiness assessment settles the question with evidence: what data you hold, which systems are in boundary, and what certification will realistically take.
The honest answer: it depends on scope more than anything else. Published industry estimates vary widely, and any fixed number quoted before a scoping conversation is a guess. What we can tell you is which variables move the number — and which levers pull it down.
A large assessment boundary, flat networks where CUI can travel anywhere, legacy systems that can't meet encryption or logging requirements, and missing documentation. Every system in scope is a system you must control, monitor, and produce evidence for.
Ruthless scoping. Isolating CUI in a purpose-built secure enclave means the 110 controls apply to a small, well-instrumented environment instead of your entire company — typically the single largest cost reduction available to a defense contractor.
Expect costs in four buckets: the readiness assessment, remediation or enclave build, the C3PAO assessment itself, and ongoing operations to stay audit-ready between assessments. Sequencing them correctly — scope first, build second — keeps every bucket smaller.
Assessor scarcity pushes prices up as demand grows, and a lost recompete costs more than any compliance program. Contractors who treat CMMC as a market advantage — not a tax — are winning work from competitors who stalled.
Step one is always the same: find out where you actually stand. A CMMC readiness assessment scores you against all 110 NIST SP 800-171 controls, produces the SPRS number you're required to report, and turns "we think we're close" into a costed, sequenced plan.
Schedule a CMMC readiness assessmentStep two is the build-or-remediate decision. Some contractors close gaps in their existing environment; many are better served isolating CUI in a purpose-built secure enclave on Microsoft GCC High, which shrinks assessment scope, cost, and timeline in one move.
Compare your options with a CMMC secure enclaveStep three is assessment preparation: assembling the evidence package, rehearsing interviews, and support through the C3PAO engagement itself. That's where our consultants — former Big Four auditors — earn their keep. One client, RPS Defense, scored a perfect 110/110 on its Level 2 assessment with A-LIGN, with no POA&M required.
And step four — the one contractors forget to budget — is staying certified. Level 2 runs on a three-year assessment cycle with annual affirmations in between, and each affirmation is a formal statement that your controls still operate. Evidence collection, monitoring, and change control have to keep running after the assessors leave, or the next affirmation becomes a problem instead of a formality.
It's the Department of Defense's way of verifying — rather than trusting — that contractors protect federal information. If NIST SP 800-171 is the rulebook, CMMC is the referee: an assessment regime that checks the rules were actually implemented before contracts are awarded.
Yes, incrementally. Since November 10, 2025, new DoD solicitations can carry CMMC requirements, and coverage expands again when Phase 2 begins in November 2026. If your contracts include DFARS clauses today, assume your next recompete carries CMMC language.
NIST SP 800-171 defines the 110 security requirements for protecting CUI. CMMC Level 2 assesses your implementation of those same requirements. If you've genuinely implemented 800-171, you're most of the way to Level 2 — the remaining work is proving it with evidence.
Read our NIST SP 800-171 compliance guideLevel 2 currently assesses against NIST SP 800-171 Rev 2 — that's what the program rule specifies. NIST has published Rev 3, and DoD is expected to address the transition through future rulemaking. The practical guidance: build and certify against Rev 2 now, and design your program so a Rev 3 uplift is an update, not a rebuild.
No. FCI-only contractors self-assess annually at Level 1 against 17 practices. But be careful: technical drawings, specs, and export-controlled data are CUI, and one mismarked file server can quietly move you into Level 2 territory.
Only within strict limits. POA&Ms are permitted for a subset of lower-weight requirements, you must still meet a minimum assessment score, and every open item has to close within 180 days — or the conditional certification lapses. The highest-weight controls can't be deferred at all, so a POA&M is a short runway, not a parking lot.
ITAR technical data is generally CUI, so handling it typically points you to Level 2 — and it adds data-sovereignty requirements on top: US-persons-only access and US-based infrastructure, which is why many ITAR shops run Microsoft GCC High.
Learn when Microsoft GCC High is requiredHave a question we didn't cover here?
Browse the full CMMC 2.0 FAQExplore more guides and resources from the Essendis team:
CMMC 2.0 Compliance SolutionsCJIS Compliance: A Step-by-Step GuideCMMC 2.0 Level 2 vs. Level 3: Which Penetration Testing Requirements Apply to You?The CMMC Assessor Shortage: What Every DoD Contractor Needs to Know Before November 2026Beyond the Checkbox: Why CMMC Compliance Alone Won't Protect Your OrganizationCMMC Flow-Down: What Prime Contractors Owe Their Subcontractors (and Vice Versa)CMMC Level 1: The 15 Requirements in Plain EnglishCMMC Level 2 Requirements Checklist for Defense ContractorsWhat CMMC Phase 2 Actually Means for Your 2026 IT and Compliance BudgetDFARS 7012 Incident Reporting: How Vulnerability Management Supports ComplianceFedRAMP Penetration Testing Requirements GuideGCC vs GCC High: Which Does Your Contract Actually Require?How Much Does a Penetration Test Cost in 2026?How Much Does CMMC Compliance Cost? A Realistic BreakdownITAR Compliance and Penetration Testing: Protecting Controlled Technical DataNIST 800-171 Rev 3 Is Coming: What Defense Contractors Need to Know Before the TransitionNIST 800-53 Control Validation Through Penetration TestingNIST CSF 2.0: Implications for Your Vulnerability Management ProgramPCI DSS 4.0 Penetration Testing: What's New and How to PrepareHow Often Should You Pen Test? Testing Frequency by FrameworkPreparing for CMMC Certification: A Pre-Assessment Security Testing ChecklistSEC Cybersecurity Disclosure Rules: What They Mean for Your Security ProgramSOC 2 and Penetration Testing: Meeting Trust Services CriteriaState Privacy Laws and Vulnerability Management: A Multi-State Compliance GuideStateRAMP vs. FedRAMP: Security Testing Requirements ComparedWhat Defense Contractors Need to Think About Before November 10, 2025What Does a vCISO Do? Deliverables in the First 90 DaysWhat Is CUI? A Defense Contractor's Complete GuideWhy Cybersecurity Should Be Your Number One Priority