Cybersecurity Maturity Model Certification (CMMC)
A practical introduction to CMMC, including who it applies to, what the three levels require, how assessments work, and where the phased rollout stands.
defense · federal
Edited by Jeff Stiles, CISSP, Colin Doubek, CISSP, and Garrett Stiles, CISSP
Quick decision helper
Answer one question to find the CMMC level that likely applies.
What kind of information do your DoD contracts involve?
What is CMMC
The Cybersecurity Maturity Model Certification (CMMC) is the U.S. Department of Defense’s program for verifying that contractors actually implement the safeguarding requirements their contracts already impose. It covers two kinds of information: Federal Contract Information (FCI), which is non-public information provided or generated under a government contract, and Controlled Unclassified Information (CUI), which is more sensitive and carries its own government-wide marking rules.
CMMC did not invent new security requirements. Level 1 maps to the 15 basic safeguarding requirements that have been in the Federal Acquisition Regulation (FAR 52.204-21) for years, and Level 2 is the 110 requirements of NIST SP 800-171, which CUI-handling contractors have been contractually obligated to implement since 2017. What CMMC adds is verification: instead of trusting self-attestation alone, DoD now requires scored assessments, affirmations by a senior official, and, for most CUI work, certification by an outside assessor.
The current model is CMMC 2.0, codified in a program rule at 32 CFR Part 170 that took effect on December 16, 2024. The companion DFARS contract rule took effect on November 10, 2025, which started a phased rollout of CMMC requirements in solicitations.
One important status note: on July 13, 2026, DoD suspended Phase 2 of that rollout, which would have pushed third-party Level 2 assessments into more contracts starting November 10, 2026. Phase 1 self-assessment requirements remain fully in force. See our coverage of the suspension and watch the official CMMC site for the review outcome.
Who CMMC applies to
CMMC applies to contractors and subcontractors that process, store, or transmit FCI or CUI on their own systems in performance of a DoD contract. That includes:
- prime contractors of any size, from major integrators to small machine shops;
- subcontractors at any tier, because requirements flow down with the data; and
- non-U.S. companies performing on DoD contracts that involve FCI or CUI.
Contracts solely for commercially available off-the-shelf (COTS) items are excluded. Company size is otherwise irrelevant: a five-person engineering firm holding CUI needs the same Level 2 as a large prime, which is why scoping the data tightly matters so much for small businesses.
The level is set contract by contract, based on the information involved: FCI only points to Level 1, CUI points to Level 2, and a small set of high-sensitivity programs will require Level 3. Your contracts, not your industry, are the source of truth. If you are unsure whether you hold CUI at all, that question is worth settling before you spend anything on assessment; the level sections below describe what each one involves.
Who manages and enforces CMMC
The DoD Chief Information Officer’s office runs the CMMC program and maintains the rule at 32 CFR Part 170. The assessment ecosystem underneath it includes:
- the Cyber AB, the accreditation body that authorizes CMMC Third-Party Assessment Organizations (C3PAOs) to perform Level 2 certification assessments; and
- the Defense Contract Management Agency’s DIBCAC (Defense Industrial Base Cybersecurity Assessment Center), which performs Level 3 assessments and government reviews.
Enforcement is contractual eligibility. Once the CMMC clause appears in a solicitation, you must hold the required CMMC status in the Supplier Performance Risk System (SPRS) to receive the award. There is no fine schedule; the consequence is losing the ability to win or keep DoD work.
There is also a sharper edge: assessments and affirmations are representations to the government. Inaccurate scores or affirmations can trigger liability under the False Claims Act, and the Department of Justice has actively pursued cybersecurity misrepresentation cases. Treat every score you post and every affirmation you sign as a statement you can evidence.
Separate from CMMC, DFARS clause 252.204-7012 already requires covered contractors to safeguard CUI and report cyber incidents to DoD within 72 hours. Those duties apply regardless of where the CMMC rollout stands.
What is in scope
CMMC scope is defined by where FCI and CUI live. The assessment covers the systems, people, facilities, and external services that process, store, or transmit the covered information, plus the assets that protect them.
The program rule sorts assets into categories that determine assessment treatment, including CUI assets, security protection assets (things like your SIEM or identity provider that secure the environment), contractor risk-managed assets, and specialized assets such as operational technology. The practical consequence: your security tooling and the administrators who run it are in scope even if they never touch CUI directly.
Two scoping decisions dominate cost:
- Enclaves. Many contractors confine CUI to a dedicated enclave, a segmented environment with its own systems and access controls, rather than certifying the whole corporate network. Done well, this shrinks the assessment boundary dramatically. Done loosely, with CUI leaking into email and file shares, it fails at assessment time.
- External service providers and cloud. Managed service providers and cloud offerings that handle CUI bring their own requirements; cloud services storing or processing CUI are expected to meet FedRAMP Moderate or equivalent. Ask vendors for their CMMC and FedRAMP posture in writing before you build on them.
A useful first exercise: trace each contract’s data. What do you receive, what do you generate, where does it land (including email, backups, and collaboration tools), and who can reach it? That trace is the draft assessment boundary.
What CMMC requires
CMMC 2.0 has three levels, and each contract specifies one. In brief:
- Level 1 covers FCI and requires the 15 basic safeguarding requirements of FAR 52.204-21, verified by an annual self-assessment.
- Level 2 covers CUI and requires all 110 requirements of NIST SP 800-171 Rev. 2, verified by either a self-assessment or a C3PAO certification assessment, depending on the contract.
- Level 3 adds 24 selected requirements from NIST SP 800-172 for a small set of critical programs, assessed by the government.
The details of each level, including who assesses, what it costs, and what the work looks like, are broken out in the level sections below.
Across levels, the recurring obligations are the same shape: maintain a System Security Plan (SSP) describing how each requirement is met, post assessment results in SPRS, and have a senior official affirm continuing compliance annually. Levels 2 and 3 allow a conditional status with a Plan of Action and Milestones (POA&M) for a limited subset of lower-weight requirements, which must be closed out within 180 days. Level 1 allows no POA&Ms.
How compliance is validated
Validation depends on the level and, during the rollout, on timing.
- Self-assessments (Level 1, and Level 2 where the contract permits) are performed by the organization, scored using the official assessment methodology, entered in SPRS, and affirmed annually by a senior official.
- C3PAO certification assessments (most Level 2 CUI work) are performed by an authorized C3PAO against NIST SP 800-171, result in a certification valid for three years, and still require annual affirmations in between.
- Government assessments (Level 3) are performed by DIBCAC on top of an existing Level 2 certification, also on a three-year cycle.
The rollout was designed in four phases beginning November 10, 2025. Phase 1, which is in force now, puts Level 1 and Level 2 self-assessment requirements into applicable new solicitations. Phase 2 would have made C3PAO certification a condition of award for applicable CUI contracts starting November 10, 2026, but DoD suspended that phase in July 2026 while a task force reviews the program. Contracting officers retain discretion to include certification requirements in specific solicitations, so read each solicitation rather than assuming the pause covers you.
Find authorized C3PAOs through the Cyber AB marketplace. As with any assessor ecosystem, verify current authorization before you sign, and be wary of anyone selling a “CMMC certificate” outside the SPRS process; there is no such product.
The CMMC compliance process
A realistic first cycle for a contractor facing Level 2 looks like this:
- Confirm the requirement. Read current contracts and target solicitations for the CMMC clause and level, and ask your contracting officer or prime when unclear.
- Trace and contain the data. Map where FCI and CUI actually live, then decide whether an enclave can contain the CUI footprint.
- Gap-assess against NIST SP 800-171. Score honestly using the DoD assessment methodology; the gap list becomes your remediation plan. The Risk Assessment family (3.11) also expects a periodic risk assessment of your own; the free risk assessment tool on this site produces one you can attach to the SSP.
- Remediate and document. Close gaps, write the SSP, and collect evidence as you go. This is usually the longest and most expensive stage.
- Self-assess or engage a C3PAO. Schedule early; assessor capacity fluctuates, and preparation deadlines are driven by contract dates, not assessment dates.
- Record and affirm. Post results in SPRS, close any permitted POA&M items within 180 days, and calendar the annual affirmation.
- Maintain. Keep the SSP current, monitor scope changes, and prepare for reassessment every three years.
Who decides, and what to ask them
The level, and whether you self-assess or need a certification, come from each solicitation and contract, not from a general rule about your industry. For a prime contractor the contracting officer sets it. For a subcontractor it arrives as a flow-down from the prime, and the prime’s contracts or supply chain contact is who answers questions about it. Contracting officers will tell you what the contract requires; they generally will not scope your environment or tell you whether a particular system is in scope.
Ask, and keep the answers in writing:
- Which CMMC level this contract or solicitation requires, and the clause it appears under.
- Whether the award requires a self-assessment or a C3PAO certification, and by what date the status must be posted in SPRS.
- Whether the information you will receive or generate is FCI only or includes CUI, and how CUI will be marked when it arrives.
- For subcontractors: which parts of the work carry CUI, so you can confine the flow-down to the systems that will actually touch it.
- Whether a conditional status with an open POA&M is acceptable for the award, or only a final status.
- Who at the prime or program office answers CMMC questions during performance, including incident reporting contacts.
If a prime cannot tell you whether the data is CUI, treat that as a warning sign and get the answer from the contract documents or the government customer before you build to Level 2.
The step that surprises people is the second one. Most first-time Level 2 efforts discover CUI in more places than expected, and the containment decision made there drives every cost that follows.
Cost, time, and internal effort
The cost range on this page covers assessor fees only, for the most common audited path: a Level 2 C3PAO certification. That definition keeps standards comparable across this site. Level 1 and Level 2 self-assessments involve no assessor at all, so their external cost is near zero. DoD’s own cost model for the rule puts the Level 2 C3PAO fee at roughly $31,000 to $52,000, while noting that actual market pricing is set by supply and demand; quotes above that model are common.
The assessor fee is rarely the real cost of CMMC. The program cost is really three costs. First, remediation: closing gaps against NIST SP 800-171, which for an organization starting cold routinely exceeds every other line item, and which DoD deliberately excluded from its estimates because implementation was already contractually required. Second, the assessment fee above. Third, operations: running the controls, keeping evidence, and affirming annually. At Level 3, DoD prices the enhanced-security engineering separately, at $2.7 million and up in nonrecurring costs.
The page’s ranges are directional; the level sections below carry per-level detail, and a full breakdown, including where these figures come from, is in How much does CMMC cost? The strongest predictors:
- the level your contracts require;
- how contained CUI is, or can be made, before assessment;
- your real starting score against SP 800-171, not the optimistic one;
- reliance on service providers whose own posture you must verify; and
- whether you build an enclave or certify a broad environment.
Time follows remediation. An organization already operating SP 800-171 seriously can reach a Level 2 assessment in months; one starting from scratch should think in terms of a year or more, and plan against contract award dates rather than assessment availability.
Maintaining compliance
CMMC status is not fire-and-forget:
- Affirm annually. A senior official reaffirms continuing compliance in SPRS for every active level. Missed or inaccurate affirmations carry the same False Claims Act exposure as the original assessment.
- Reassess every three years for Level 2 certification and Level 3.
- Close conditional items on time. POA&M closeout has a hard 180-day limit; missing it invalidates the conditional status.
- Keep the SSP and scope current. New contracts, new tools, new vendors, and new teams move CUI. Put a CMMC check into contract intake and change management.
- Keep meeting DFARS 252.204-7012, including 72-hour incident reporting, independent of assessment cycles.
Also track the program itself. With the Phase 2 review underway, timelines may move again; follow CMMC on this site or watch the DoD CMMC page for rule changes and new dates.
How to get started
If CMMC just appeared in a solicitation or a prime’s flow-down letter, start with these five actions:
- Confirm the level and timing in writing from the contracting officer or prime, including whether a self-assessment or certification is required for the award you care about.
- Inventory your contracts for FCI and CUI. If nothing involves CUI, your problem is Level 1, and it is much smaller.
- Trace the data. One diagram: where covered information enters, moves, rests, and who touches it, including email, file sharing, and backups.
- Score yourself against NIST SP 800-171 using the official methodology, and let the honest number set your remediation budget and calendar.
- Decide the containment strategy. Enclave versus enterprise-wide scope is the biggest cost lever you control; make it deliberately before engaging assessors.
The DoD CMMC documentation page has the program rule, scoping guides, and assessment guides. The Cyber AB lists authorized C3PAOs.
The first goal is not a certificate. It is knowing which level your contracts require and where covered information actually lives. Those two facts turn CMMC from an intimidating acronym into a scoped, plannable project.
Levels
Level 1
- Who does it apply to?
- Contracts involving Federal Contract Information (FCI) only, with no Controlled Unclassified Information (CUI).
- Who audits / assesses?
- Annual self-assessment. No third-party assessor is involved.
- What report is required?
- Self-assessment result and annual affirmation by a senior official, recorded in SPRS.
- Org effort
- 20 – 120 hours
Level 1 covers the foundational safeguarding of FCI: the 15 basic requirements from FAR 52.204-21 that have applied to federal contractors for years. They are fundamentals such as limiting system access to authorized users, using malware protection, patching, and controlling visitor access to facilities.
Verification is an annual self-assessment. You check your environment against the 15 requirements, record the result in the Supplier Performance Risk System (SPRS), and a senior company official affirms compliance each year. There are no assessors to hire and no certificate; the affirmation is the deliverable, and it must be accurate, because it is a representation to the government.
Level 1 allows no Plans of Action and Milestones (POA&Ms). All 15 requirements must be fully met at the time of the assessment. For most small contractors the work is basic IT hygiene plus honest documentation, and the hardest part is confirming that no CUI is hiding in the contract data, which would move the requirement to Level 2.
Level 2
- Who does it apply to?
- Contracts involving Controlled Unclassified Information (CUI). This is the level most defense contractors handling technical data face.
- Who audits / assesses?
- A C3PAO certification assessment for most CUI contracts; some contracts permit self-assessment. The broader third-party ramp-up (Phase 2) is currently suspended.
- What report is required?
- Certification or self-assessment score in SPRS, valid for three years, with annual affirmations in between.
- Typical cost
- $30,000 – $60,000
- Org effort
- 200 – 1,500 hours
Level 2 protects CUI and requires implementing all 110 requirements of NIST SP 800-171 Rev. 2, covering access control, incident response, encryption, auditing, personnel security, and more. Contractors handling CUI have been contractually required to implement SP 800-171 since 2017; Level 2 verifies it.
Verification takes one of two forms, set by each contract. Most CUI contracts point to a certification assessment by a CMMC Third-Party Assessment Organization (C3PAO), valid for three years. A smaller set of contracts permits an annual self-assessment. Either way, results go into SPRS and a senior official affirms compliance annually. A conditional status is available with a Plan of Action and Milestones (POA&M) for a limited subset of lower-weight requirements, which must close within 180 days.
Note the timing: the phase that would have made C3PAO certification a condition of award across applicable contracts starting November 2026 was suspended in July 2026 pending a program review. Self-assessment obligations under Phase 1 continue, and individual solicitations may still require certification.
Requirements flow down: primes must ensure subcontractors handling CUI meet Level 2 as well. The dominant cost decision is containment. Confining CUI to a well-built enclave keeps the assessment boundary small; letting CUI spread through general email and file shares puts the whole environment in scope. If you are not sure this level applies to you, the deciding question is whether any contract data is CUI; FCI alone points to Level 1.
Level 3
- Who does it apply to?
- A small set of contracts with higher-sensitivity CUI on the Department's most critical programs.
- Who audits / assesses?
- Government-led assessment by DCMA DIBCAC, on top of an existing Level 2 C3PAO certification.
- What report is required?
- Level 3 certification in SPRS, valid for three years, with annual affirmations.
- Org effort
- 400 – 2,000 hours
Level 3 exists for the small population of contractors supporting the Department’s most sensitive programs, where CUI is a target for advanced persistent threats. It adds 24 selected requirements from NIST SP 800-172, the enhanced-security companion to SP 800-171, covering areas like threat hunting, advanced authentication, and resilience against sophisticated adversaries.
Level 3 is cumulative. A contractor must first hold a current Level 2 certification from a C3PAO for the same scope, then undergo a government-led assessment by the Defense Contract Management Agency’s DIBCAC. The certification is valid for three years, with annual affirmations, and limited POA&M use follows the same 180-day closeout rule as Level 2.
Most contractors will never need Level 3, and you do not opt into it; DoD designates the programs that require it. If you believe a target program may carry Level 3, engage the program office early, because the enhanced requirements reach into architecture and staffing decisions that are expensive to retrofit. Later rollout phases covering Level 3 are also affected by the current program review.
Guides
- How much does CMMC cost?
What DoD's own rule says CMMC assessments cost by level, what the C3PAO fee covers, and why remediation, not the assessment, is usually the real number.
Version history
| Version | Status | Released | Effective | Retired | Summary |
|---|---|---|---|---|---|
| 2.0 | current | Nov 4, 2021 | Dec 16, 2024 | — | Streamlined the model to three levels aligned with existing NIST standards. Codified at 32 CFR Part 170, effective December 16, 2024. The DFARS contract rule took effect November 10, 2025, starting the phased rollout; the Phase 2 third-party ramp-up was suspended in July 2026 pending a program review. |
| 1.0 | retired → 2.0 | Jan 31, 2020 | — | Nov 4, 2021 | The original five-level model with third-party assessments at every level. Replaced by the simpler CMMC 2.0 structure before it reached meaningful contract use. |
New versions are announced in news. Follow this standard to get notified.