What is CMMC? The Defense Department's Cybersecurity Certification Program Explained

19 minute read
Intermediate

CMMC is the DoD program that verifies defense contractors have implemented NIST SP 800-171. The three levels, the phased rollout starting November 2025, how assessments work, and why it matters in defense M&A.

The Three Levels

Level 1: Foundational

Fifteen practices drawn from FAR clause 52.204-21, the basic safeguarding requirements for Federal Contract Information. FCI is information provided by or generated for the government under contract that is not intended for public release. The practices are elementary: limit access to authorized users, sanitize media, escort visitors, patch systems, use anti-malware. Level 1 is an annual self-assessment with results entered in the Supplier Performance Risk System and an annual affirmation by a senior company official. There is no POA&M at Level 1; all fifteen must be met.

Level 2: Advanced

The 110 security requirements of NIST SP 800-171 Revision 2, across fourteen families, for contractors that process, store, or transmit CUI. This is where most of the program's weight sits. Level 2 comes in two forms, and DoD decides which applies per contract. Level 2 Self-Assessment is an annual self-assessment against all 110 requirements, posted to SPRS, with an annual senior-official affirmation. Level 2 Certification Assessment is a triennial assessment by a CMMC Third-Party Assessment Organization, a C3PAO, with annual affirmations between assessments. DoD has indicated that most contracts involving CUI will require certification rather than self-assessment.

Level 2 permits a conditional certification with a limited POA&M. The contractor must score at least 88 of 110 under the assessment methodology, no requirement weighted at 5 points may be open (with a small number of specified exceptions), and every open item must be closed and verified within 180 days. If the deadline passes, the conditional status lapses and the contractor is not certified. This is a fundamental change from the open-ended POA&Ms that were tolerated under DFARS 7012 alone, where a requirement could remain unimplemented for years with a plan attached.

Level 3: Expert

The 110 requirements of 800-171 plus 24 selected from NIST SP 800-172, Enhanced Security Requirements for Protecting Controlled Unclassified Information, aimed at defending against advanced persistent threats. Level 3 requires a prior Level 2 certification and is assessed by the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center, DIBCAC, not by a C3PAO. It applies to a small number of programs handling the most sensitive CUI.

The Rollout Timeline

Two rules created the program. The CMMC Program Rule, 32 CFR Part 170, defines the levels, the assessment requirements, and the ecosystem; it took effect December 16, 2024. The acquisition rule, an amendment to 48 CFR (the DFARS), authorizes contracting officers to put CMMC requirements into solicitations and contracts; it took effect November 10, 2025. The acquisition rule phases CMMC in over three years.

Phase 1, from November 10, 2025. Level 1 and Level 2 self-assessment requirements appear in applicable solicitations. DoD may, at its discretion, require Level 2 certification in some contracts.

Phase 2, from November 10, 2026. Level 2 certification assessment requirements appear in applicable solicitations for contracts involving CUI. DoD may delay the requirement to an option period at its discretion. This is the phase that changes the market, because it is the first time most CUI contracts require a C3PAO result rather than a self-attestation.

Phase 3, from November 10, 2027. Level 3 requirements appear in applicable solicitations, and Level 2 certification becomes a requirement for option periods on existing contracts.

Phase 4, from November 10, 2028. Full implementation. CMMC requirements in all applicable solicitations and contracts.

The phases describe when DoD may require certification. They do not describe when a contractor should be ready. A contractor bidding on a contract that will be awarded in late 2026 with a CUI requirement should assume certification will be required and should be scheduling a C3PAO now, because assessment capacity is finite and every other contractor is reading the same calendar.

CMMC and NIST SP 800-171

The two are frequently conflated. 800-171 is the standard: the security requirements for CUI in nonfederal systems, published by NIST, derived from the 800-53 moderate baseline. CMMC is the assessment and certification program: DoD's mechanism for verifying that the standard was implemented. Before CMMC, DFARS 7012 required 800-171, DFARS 7019 and 7020 required contractors to self-assess and post a score to SPRS, and nobody checked. CMMC does not change what contractors must implement at Level 2. It changes who verifies it.

Which Revision

NIST published 800-171 Revision 3 in May 2024. It reduced the requirement count from 110 to 97, added three families, and replaced vague terms with organization-defined parameters. CMMC does not use it yet. DoD issued a class deviation the same month keeping Revision 2 as the standard for DFARS 7012 compliance and CMMC assessment, because the program rule, the assessment guides, the C3PAO training, and SPRS are all built on Rev 2. DoD has placed a rule on its regulatory agenda to transition CMMC to Rev 3 and has published proposed organization-defined parameter values. Until that rule is final and the assessment infrastructure is reissued, every Level 2 assessment is against Rev 2. The prudent posture is to certify against Rev 2 and map to Rev 3 in parallel, particularly the new Planning, System and Services Acquisition, and Supply Chain Risk Management families, so the eventual transition is documentation rather than remediation.

The SPRS Score

The DoD Assessment Methodology assigns each of the 110 requirements a weight of 1, 3, or 5 points. A contractor starts at 110 and subtracts for each requirement not fully implemented. Scores can go negative. The result is posted to SPRS, where contracting officers see it. CMMC Level 2 self-assessments use the same methodology, and certification assessments are recorded in the same system. The score is a representation to the government. The Department of Justice's Civil Cyber-Fraud Initiative has settled False Claims Act cases against contractors whose posted scores and attestations did not match their environments. An honest 70 with a credible POA&M is a defensible position. A 110 that an assessor contradicts is a legal one.

The Assessment Ecosystem

The Cyber AB. The Cybersecurity Maturity Model Certification Accreditation Body, a nonprofit that accredits C3PAOs and, through its training arm, certifies the individual assessors and instructors who work for them.

C3PAOs. CMMC Third-Party Assessment Organizations conduct Level 2 certification assessments. Each has itself passed a Level 2 assessment by DIBCAC. There are a limited number, and Phase 2 demand is expected to exceed their capacity for some time.

Certified assessors. Individuals credentialed as CMMC Certified Assessors or Certified Professionals who staff C3PAO assessment teams.

Registered Practitioner Organizations. Consulting firms registered with the Cyber AB to help contractors prepare. An RPO cannot assess a client it helped prepare; independence rules apply.

DIBCAC. The DCMA center that assesses C3PAOs and conducts Level 3 assessments.

What a Level 2 Assessment Involves

The assessor evaluates each of the 110 requirements against the 320 assessment objectives in NIST SP 800-171A, using the examine, interview, and test methods. The System Security Plan is the primary artifact: it must describe the CUI boundary, where CUI lives, and how each requirement is implemented. The assessor then verifies the SSP against the environment. An SSP that describes controls the environment does not enforce is the single most common cause of a failed assessment and the single most common fact pattern in False Claims Act cases. Scoping matters enormously: an enclave that isolates CUI to a defined set of systems and users is assessed on that enclave, while a flat network that lets CUI reach every workstation is assessed on the whole company.

Where Contractors Fail

The failures cluster in the same families in every assessment cycle.

Scoping. The contractor does not know where CUI is. It arrives by email, is saved to a shared drive, is forwarded to a subcontractor, and lives in a dozen places the SSP does not describe. Without a defined boundary, every system is in scope and the assessment fails on breadth.

Identification and Authentication. MFA is enabled for email but not for the ERP, the engineering file share, or the remote access path. The requirement is MFA for local and network access to privileged accounts and network access to non-privileged accounts. Partial coverage is a 5-point requirement scored as zero.

Audit and Accountability. Logs are collected but not retained for a defined period, not protected from modification, and not reviewed. Four requirements, all weighted, all commonly open.

Configuration Management. No baseline, no change control, no inventory. Requirements that describe the foundation every other control sits on.

Incident Response. A plan exists and has never been exercised. DFARS 7012 also requires cyber incident reporting to DoD within 72 hours, which an untested plan will miss.

Risk and Security Assessment. The risk assessment is a template. Vulnerability scanning is periodic in policy and absent in practice.

Every one of these can be closed. Most are configuration, policy, and administrative work rather than capital projects. The contractors who fail are rarely the ones who could not afford the controls; they are the ones who described controls in an SSP that nobody then implemented.

Level 1 vs Level 2 at a Glance

  • Information type. Level 1 protects Federal Contract Information. Level 2 protects Controlled Unclassified Information. If a contract, drawing, or specification is marked CUI, or would be if the government followed its own marking rules, Level 2 applies.
  • Requirement count. 15 practices versus 110 requirements assessed against 320 objectives.
  • Assessor. Level 1 is always self-assessed. Level 2 is self-assessed or C3PAO-certified depending on the contract; expect certification for most CUI work.
  • Frequency. Level 1 annually. Level 2 certification every three years with annual affirmations in between.
  • POA&M. None permitted at Level 1. Limited at Level 2: minimum score 88, no open 5-point items with narrow exceptions, 180 days to close.
  • Typical environment. Level 1 can be met in a well-configured commercial tenant. Level 2 usually means a defined CUI enclave, often Microsoft 365 GCC High, with the boundary documented in the SSP.

The Preparation Sequence That Works

Scope first. Find every place CUI enters, lives, and leaves. Decide whether to isolate it in an enclave or bring the whole company into scope. This decision sets the cost of everything after it.

Assess honestly. An independent gap assessment against the 320 objectives, on the actual environment, before anyone writes an SSP. The point is to know the real score, not to produce a good one.

Fix what configuration can fix. Identity, logging, access, and cloud posture findings are the bulk of most gap lists and can be closed in days, not quarters. Do these before scoping structural projects.

Write the SSP to the environment. Not to the requirement. Every implementation statement should be one an assessor can verify by looking.

Post the honest score and book the C3PAO. Assessment capacity is the constraint in Phase 2. A contractor with a real 95 and a scheduled assessment is ahead of one with a paper 110 and no date.

Rehearse. A mock assessment by someone who was not involved in preparation. The assessor will examine, interview, and test; the organization should have done the same.

Executive Implications

For a CEO or CFO of a defense contractor, CMMC converts cybersecurity from a cost center into a revenue-continuity control. The question is not whether the program is worth its cost; it is which contracts require which level at which date, and whether the company will hold the certification when the option period arrives. The senior-official affirmation that accompanies every self-assessment and every certification is a personal statement to the government, and the False Claims Act attaches to it.

For a General Counsel, CMMC is a compliance program with a litigation history already attached. The Civil Cyber-Fraud Initiative has pursued contractors for cybersecurity misrepresentations, and the affirmation requirement was designed to make responsibility personal. The SSP is a legal document as much as a technical one; it should describe the environment that exists.

For a board, CMMC is a schedule. Which contracts, which level, which date, who is the C3PAO, when is the assessment, what is the score today. A board that can answer those has exercised oversight. One that has heard the program is in progress has not.

PE Implications

Defense and aerospace consolidation is one of the most active mid-market theses, and every target in it carries CMMC exposure that the buyer inherits at close. Three diligence questions follow.

What did the target post to SPRS, when, and can the SSP support it? An inflated score is a False Claims Act liability that transfers with the entity. A buyer who closes and leaves the score in place converts the seller's misrepresentation into the buyer's.

Which contracts will require Level 2 certification at their next award or option period, and does the target have a C3PAO scheduled? A target that cannot achieve certification before a contract requires it is at risk of losing revenue the model assumes. Assessment capacity is the constraint, and a target that has not booked one is behind every competitor that has.

Has the environment ever been assessed for active compromise, or only for control implementation? CUI that has already been exfiltrated is a reportable incident under DFARS 7012 regardless of what the SSP says. A compromise assessment in diligence finds it before it becomes the buyer's disclosure.

Post-close, the 100-day plan for a defense portco typically includes an independent 800-171 gap assessment against the actual environment, SSP reconciliation, SPRS correction if warranted, enclave scoping if CUI is sprawling, and a C3PAO booking. For a platform with multiple portcos, a shared enclave and a shared SSP methodology are the efficiency the sponsor can capture. The remediation of identity, logging, and configuration gaps at each portco is the cost the sponsor should have priced.

CMMC and Adjacent Frameworks

NIST 800-53. The parent catalog from which 800-171 is derived. A register built on 800-53 produces the 800-171 crosswalk mechanically and serves the contractor if it later pursues FedRAMP or a prime flows down 800-53 controls directly.

CIS Benchmarks. The configuration guidance for the Microsoft 365 GCC High or commercial tenant where most contractors' CUI actually lives. CIS tells the engineer which setting satisfies the 800-171 requirement.

FedRAMP. Cloud services that store CUI for a contractor must meet FedRAMP Moderate or equivalent under DFARS 7012. Choosing a cloud provider that is not authorized is a scoping failure before the assessment begins.

ITAR and export control. Not a CMMC requirement, but frequently the reason a contractor chooses GCC High, and a diligence item in its own right.

Related Reading

Real-World Example: The Attestation That Became a False Claim

The Department of Justice launched its Civil Cyber-Fraud Initiative in October 2021 to pursue government contractors that knowingly misrepresent their cybersecurity practices. The cases that followed share a pattern. A contractor certifies compliance with DFARS 7012 and 800-171, or posts an SPRS score reflecting full implementation. An insider, an assessor, or an incident reveals that the environment does not match the attestation: MFA not enforced, systems outside the described boundary, controls documented in the SSP and never deployed. DOJ intervenes in a whistleblower suit or brings its own, and the contractor settles for a multiple of the contract value at issue.

The settlements have ranged from the low millions for smaller firms to eight figures for larger ones, and several involved contractors that were, by any commercial standard, reputable and well-run. The through-line is not malice. It is that the attestation was signed by someone who believed the SSP, and the SSP described a program rather than an environment. CMMC exists to close that gap by putting an assessor between the SSP and the signature. For a contractor, that is the reason to have an independent assessment find the gap first. For a buyer, it is the reason the SPRS score in the data room is a liability until someone has reconciled it to the tenant.

Nov 10, 2026

The start of CMMC Phase 2, when Level 2 third-party certification requirements begin appearing in most Department of Defense contracts that involve Controlled Unclassified Information. Contractors that are not certified, or not in the queue for a C3PAO assessment, will be unable to bid. The program reaches an estimated 200,000-plus companies, most of them small, most of them subcontractors.

How Cloudskope Can Help

Cloudskope's compliance advisory practice conducts NIST SP 800-171 gap assessments, develops System Security Plans, and prepares defense contractors for CMMC C3PAO assessments. For PE sponsors with defense sector portfolio companies, we assess CMMC readiness as part of M&A due diligence.

Where the gap is closure rather than documentation, Cloudskope SARTUS™ is the instrument: a six-day, fixed-fee engagement that spends three days finding what current controls missed across Microsoft 365, Azure, dark web exposure, and active compromise, and three days fixing it. Every finding lands in one risk register mapped to NIST SP 800-53 and the CIS Benchmarks, with an SP 800-171 crosswalk for the CMMC practices in scope. A gap assessment tells a contractor what is missing. SARTUS™ closes the identity, cloud, and compromise findings that most often hold up a Level 2 assessment. See how the register maps across frameworks.