Cybersecurity now plays a critical role in Department of War (DoW) contracting, particularly for contractors and subcontractors that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). The department was known as the Department of Defense (DoD) before its 2025 rename, so you will still see DoD references throughout CMMC policies, standards, and source documents. CMMC was established to strengthen verification of how defense contractors protect FCI and CUI based on the requirements that apply to their contracts.
If your organization holds a DoW contract or supports one as a subcontractor, CMMC requirements may affect you directly. Since November 10, 2025, applicable new solicitations and contracts have begun incorporating Level 1 or Level 2 self-assessment requirements based on the type of information involved and the contract terms. These requirements can flow down to subcontractors that handle FCI or CUI, so your position in the supply chain matters as much as your role as a prime or subcontractor.
Also Read: CMMC Level 1 vs Level 2, Which Applies to You?
Identifying Your CMMC Compliance Obligations
You do not need a cybersecurity background to understand what CMMC requires or how to prepare for it. This guide walks through the framework's origins, its three certification levels, the assessment process, typical cost ranges, and the practical decisions you need to make, including whether to work with a Registered Provider Organization (RPO) or a Certified Third-Party Assessment Organization (C3PAO).
To determine whether CMMC requirements apply to your organization, start with one question: does your organization handle Federal Contract Information or Controlled Unclassified Information for the DoW? Answering that requires you to identify the data you actually handle, review the specific clauses in your contracts, assess your position in the supply chain, and determine which CMMC requirements apply. The sections below walk through each of those steps, so you can move from uncertainty about your obligations to a concrete plan for addressing them.
CMMC Compliance Status and Current Requirements
As of September 2026, parts of the CMMC rollout are paused, but the pause does not affect every requirement. Understanding what remains active, what is currently on hold, and what could change next is essential for planning your compliance strategy.
CMMC Phase 2 and Future Rollout Paused
On July 13, 2026, the DoW suspended the transition to CMMC Phase 2, which had been scheduled to introduce third-party Level 2 certification as a contract requirement beginning November 10, 2026. The department also paused subsequent phases, including the planned rollout of Level 3 assessments, pending further review. Source: DoW announcement, July 13, 2026.
The suspension of CMMC Phase 2 does not mean that all existing cybersecurity requirements have stopped. Phase 1 self-assessments, DFARS 252.204-7012, NIST SP 800-171 Rev. 2, SPRS scores, and annual affirmations continue to apply where applicable. Organizations should continue their compliance and security work while the DoW reviews the future implementation of CMMC.
Organizations should verify the latest requirements against official DoW guidance before making certification or contracting decisions.
CMMC Reform Review Could Change Future Requirements
A CMMC Reform Task Force is conducting a 60-day review of the program that began on July 13, 2026. The Task Force is expected to deliver its report to the DoW CIO by approximately September 11, 2026, with the public version expected in late September or early October. Because the review could change the scope or timing of future CMMC requirements, treat projected certification dates as provisional until the DoW issues updated guidance. Your immediate planning should focus on requirements that are already active rather than waiting for future milestones to become certain.
Existing CMMC and NIST Requirements Remain in Effect
The requirements that are already in effect remain important. Applicable Level 1 and Level 2 self-assessment obligations remain part of the current CMMC landscape, while DFARS 252.204-7012 continues to establish NIST SP 800-171 requirements for contractors handling CUI. Existing C3PAO certifications remain relevant, and organizations may continue to pursue assessments where appropriate. Because the program is under active review, verify current submission, assessment, and affirmation requirements before relying on any future-state timeline.
For planning purposes, organizations should continue the self-assessment, gap analysis, remediation, and documentation work that supports their current obligations. The third-party certification requirement and the associated cost and timeline planning may be on hold, but the underlying security practices remain relevant. Continuing this work also positions your organization to respond quickly if third-party assessment requirements return in a revised form.
The Evolution of CMMC
CMMC emerged from years of cyber incidents targeting defense contractors and growing concerns that existing compliance mechanisms did not provide sufficient verification of security practices.
Cybersecurity Risks Across the Defense Supply Chain
Foreign nation-state actors have targeted defense contractors across the supply chain, including smaller subcontractors that may have access to sensitive information but fewer security resources than larger prime contractors. Attackers can use weaknesses at one supplier to gain access to information connected to a larger defense program. Years of incidents involving the theft of controlled technical data and intellectual property highlighted the need for stronger security practices and more consistent verification across the Defense Industrial Base.
DFARS Established the Initial Security Requirements
The DoW's first major response came through DFARS clause 252.204-7012, which required contractors handling CUI to implement the 110 security requirements in NIST SP 800-171 Rev. 2. This rule gave contractors a clear technical standard to meet.
Self-Assessment Created a Verification Gap
DFARS 252.204-7012 relied heavily on contractor self-assessment and attestation. That approach created a verification gap because organizations could report compliance without the independent validation required under a third-party assessment model. Subsequent audits and investigations highlighted the need for stronger mechanisms to verify whether reported security practices matched actual implementation.
CMMC Introduced Independent Verification
The Department of War (DoW) created CMMC to close that gap by requiring independent verification for higher-risk contracts, formalizing a tiered structure that ties assessment rigor to the sensitivity of the information involved.
CMMC 2.0 Simplified the Framework
The original CMMC framework drew criticism for its complexity and cost, particularly among small and mid-size contractors. It introduced five maturity levels, expanded third-party assessment requirements, and included process maturity expectations beyond the core technical requirements in NIST SP 800-171. Industry feedback raised concerns that the additional cost and administrative burden could make federal contracting more difficult for smaller organizations.
CMMC 2.0 responded to that feedback by reducing the framework from five levels to three, aligning its requirements more closely with established NIST standards, and expanding the circumstances in which self-assessment is permitted. The revised framework retains formal security requirements while using different assessment methods based on the sensitivity of the information involved.
Also Read: How to Complete Your CMMC Level 1 Self Assessment
Understanding the Three CMMC 2.0 Levels
CMMC 2.0 organizes requirements into three tiers based on the sensitivity of the information your organization handles.
Level 1: Foundational
Level 1 applies to contractors who handle Federal Contract Information only. It requires 15 basic safeguarding requirements drawn directly from FAR 52.204-21, covering fundamentals like access control, authentication, and media protection. Organizations complete an annual self-assessment and submit an executive affirmation confirming their compliance status. Level 1 does not require an outside assessor, though many organizations choose to bring in outside support to validate their work before submitting it.
Level 2: Advanced
Level 2 applies to contractors who handle Controlled Unclassified Information. It requires all 110 requirements specified in NIST SP 800-171, spanning 14 security domains from access control to system integrity. Under the original CMMC 2.0 design, some contracts involving less critical information permit self-assessment while the majority of CUI-handling contracts require a third-party assessment conducted by a C3PAO. With Phase 2 currently suspended, contracting officers cannot require the C3PAO path for new solicitations right now, and self-assessment is the operative requirement across Level 2 until the CMMC Reform Task Force reports and DoW decides how to proceed. This is still where most contractors will eventually encounter the real weight of CMMC, both in technical scope and in cost, once third-party assessment resumes in some form.
Level 3: Expert
Level 3 applies to the smallest group of contractors, those handling CUI on the DoW's most critical programs and technologies. It builds on Level 2 with a subset of enhanced requirements from NIST SP 800-172, addressing advanced persistent threats that standard controls do not fully address. Government assessors from the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), not private C3PAOs, conduct Level 3 assessments on a triennial basis. Level 3 falls under the same Phase 2 and later suspension as the C3PAO path for Level 2, so no organization is currently undergoing a new DIBCAC assessment tied to a fixed 2026 milestone.
Understanding the Key CMMC Terms
Three key terms are central to understanding your CMMC obligations: FCI, CUI, and the DIB.
Federal Contract Information (FCI)
It is information provided by or generated for the government under a contract that is not intended for public release. Examples can include procurement information, contract-related information, and operational information your organization receives or generates while performing a DoW contract, depending on the applicable contract requirements.
Controlled Unclassified Information (CUI)
It requires safeguarding or dissemination controls under applicable law, regulation, or government-wide policy and generally carries greater protection requirements than FCI. Depending on the applicable CUI category and contract requirements, examples can include controlled technical information, certain export-controlled information, contract-related personally identifiable information, and unclassified defense-related technical information.
Defense Industrial Base (DIB)
The Defense Industrial Base (DIB) is the network of companies, from prime contractors to subcontractors, that support the development, production, and maintenance of military systems and capabilities for the DoW. If your organization operates within that supply chain and handles FCI or CUI, review your contracts and applicable CMMC requirements to determine whether and how CMMC applies to you.
How These Terms Affect Your CMMC Obligations
FCI and CUI are key factors in determining which CMMC requirements may apply, while your position within the Defense Industrial Base (DIB) helps determine how those requirements may flow down through the supply chain. The distinction between FCI and CUI can indicate whether Level 1 or Level 2 requirements apply, but the solicitation and resulting contract ultimately determine the specific CMMC requirements you need to meet.
Organizations may also discover during a gap assessment that they handle more CUI than initially expected, particularly when working as subcontractors or receiving technical data, drawings, or other controlled information from a prime contractor. Reviewing your actual contract deliverables, data flows, and role within the DIB, rather than relying on assumptions about what "sensitive" means, gives you a stronger basis for determining your CMMC scope and compliance obligations.
Determine Which CMMC Level Applies to You
Before you can plan your compliance strategy, determine which CMMC requirements apply to your organization. Use the questions below as a starting point, then confirm your conclusions against the specific solicitation, contract, and applicable regulations.
| Question | What to Check | Why It Matters |
|---|---|---|
| What type of information do you handle? | Determine whether you possess, process, or transmit FCI or CUI. | Handling FCI generally points to Level 1, while handling CUI generally points to Level 2. The solicitation and contract ultimately determine the applicable requirements. |
| What cybersecurity clauses are in your contracts? | Look for DFARS clauses such as 252.204-7012, 252.204-7019, 252.204-7020, or 252.204-7021. | These clauses can establish requirements related to NIST SP 800-171 and cybersecurity assessments. A DFARS clause alone does not necessarily determine your CMMC level. |
| What CMMC level does the contract require? | Review the solicitation and resulting contract for the specified CMMC level and assessment requirements. | Contractual language provides the starting point for determining your compliance obligations. |
| Are you a prime contractor or subcontractor? | Review your role in the supply chain and whether CMMC requirements flow down from the prime contract. | Subcontractors may have CMMC obligations based on the FCI or CUI they handle and the terms of the prime contract. |
| Do you qualify for an exemption? | Check whether your organization, product, or service falls within an applicable exemption, including certain COTS situations. | An exemption should be based on applicable contract language and regulatory criteria, not simply on your product category. |
| Where is your FCI or CUI located? | Map where controlled information is stored, processed, and transmitted, including the systems, networks, locations, and personnel involved. | Defining your assessment scope can reduce unnecessary compliance complexity and may lower implementation and assessment costs. |
| Have you reported your assessment information in SPRS? | Determine whether your applicable CMMC assessment score must be reported in the Supplier Performance Risk System (SPRS). | Where required, SPRS reporting forms part of the assessment and affirmation process. |
| Do you have a System Security Plan (SSP)? | Confirm that your SSP documents how applicable security requirements are implemented within your environment. | An accurate SSP helps demonstrate how your organization meets applicable requirements and supports assessment readiness. |
Also Read: CMMC Level 1 Compliance, Handled End to End
The CMMC Assessment Process
The path to demonstrating CMMC compliance follows a defined sequence, although the assessment method varies by level and contract requirement.
Define Your CMMC Scope
You identify which networks, systems, personnel, and physical locations store, process, or transmit FCI or CUI. A clearly defined scope can reduce unnecessary compliance complexity and may lower implementation and assessment costs. Some organizations use appropriately designed secure enclaves to isolate CUI-handling systems from the broader corporate environment.
Conduct a Gap Assessment
You evaluate your current security posture against the practices required for your applicable level, whether that involves the 15 Level 1 requirements or the 110 Level 2 requirements. This step identifies which requirements you have addressed and where additional work or evidence may be needed.
Remediate Identified Gaps
You address the gaps identified during the assessment. This can involve upgrading technical infrastructure, implementing missing controls, and developing or updating the security policies and procedures required for your applicable level. The scope and cost of remediation depend heavily on your starting security posture and the size and complexity of your environment.
Develop Required Documentation
You develop or update your SSP and, where permitted, document remaining gaps through a Plan of Action and Milestones (POA&M). CMMC 2.0 places limits on the use of POA&Ms and does not permit them for certain requirements, so confirm which gaps can be carried forward under the rules applicable to your assessment.
Complete the Required Assessment
Level 1 uses a self-assessment process. For Level 2 contracts that require third-party validation, a C3PAO conducts the formal assessment by reviewing documentation, examining evidence, observing practices, and interviewing relevant personnel. Because the Level 2 third-party requirement is currently subject to the program's implementation status, verify the assessment method required by your specific contract before scheduling an assessment.
Report Your Results in SPRS
Where required, you submit your assessment score and associated information to the Supplier Performance Risk System. Treat the reporting requirement as part of your compliance obligations rather than as an optional administrative step.
Complete Executive Affirmation and Certification
An authorized executive affirms the organization's assessment results and ongoing responsibility for maintaining its security posture. The reporting and certification steps depend on the CMMC level and assessment method required by the contract, so confirm the current submission and issuance process before completing this step.
Maintain Compliance
CMMC compliance is not a one-time event. Level 1 requires an annual self-assessment and affirmation, while applicable Level 2 requirements include ongoing annual affirmations and periodic reassessment. The exact assessment cycle depends on the applicable CMMC requirement and contract, so verify the current rules before planning your renewal schedule.
Throughout this sequence, one of the biggest cost and schedule risks is treating remediation as an afterthought rather than a core part of the project. Budget realistic time and resources for closing identified gaps instead of assuming that documentation alone will resolve compliance issues. Understanding remediation needs early gives you a stronger basis for planning your timeline and overall investment.
CMMC Implementation Timeline and Contract Flow-Down
CMMC requirements enter into force through the federal rulemaking process and are incorporated into applicable contracts and solicitations through the relevant contractual clauses. The program is being implemented in phases rather than through a single requirement applied to every contractor at once.
Understanding the CMMC Implementation Phases
- Phase 1, which added Level 1 and Level 2 self-assessment requirements to applicable new solicitations, took effect November 10, 2025, and remains active.
- Phase 2, which would have added the C3PAO third-party assessment requirement for Level 2 starting November 10, 2026, is currently suspended pending the CMMC Reform Task Force review.
- Phases 3 and 4 are not yet in effect and remain frozen until further notice.
There is no single date on which every contractor's CMMC obligations become active. Your requirements depend on the specific solicitation, contract, applicable clauses, and the type of information your organization handles. If you have a current or pending contract involving FCI or CUI, review the applicable CMMC requirements now rather than relying on a future program milestone.
When CMMC Requirements Apply to Your Contract
Prime contractors play an important role in ensuring that applicable CMMC requirements flow down to subcontractors that handle protected information. The specific obligations depend on the prime contract, subcontract terms, information involved, and applicable CMMC requirements. Organizations should continue reviewing those flow-down requirements even while broader implementation timelines remain under review.
Once the Reform Task Force completes its review, the DoW may revise the scope and timing of future CMMC requirements. Organizations should therefore prepare for the possibility that verified assessment requirements will expand again, while avoiding assumptions about the final structure until the department issues updated guidance. Maintaining a strong security posture now gives you more flexibility regardless of how the program evolves.
Also Read: CMMC Level 1 Compliance for DoD Contractors
Choosing Between an RPO and a C3PAO
Once you know which CMMC requirements apply, one of your most important decisions is whether you need support from a Registered Provider Organization (RPO), a Certified Third-Party Assessment Organization (C3PAO), or both at different stages. Understanding the difference is essential before you engage either type of provider.
| Criteria | RPO | C3PAO |
|---|---|---|
| Primary role | Helps organizations prepare for CMMC | Independently assesses CMMC compliance |
| What it can help with | Gap assessments, SSP development, security control implementation, remediation, documentation, and assessment preparation | Reviewing documentation and evidence, examining security practices, interviewing personnel, and conducting the formal assessment |
| When to engage | During preparation and remediation, before an applicable assessment | When your contract requires a third-party assessment and your organization is assessment-ready |
| Can provide consulting? | Yes | Its role is independent assessment rather than implementation support |
| Can conduct the formal CMMC assessment? | No | Yes, when third-party validation is required |
| Can issue CMMC certification? | No | Yes, for an applicable successful assessment |
| Independence | Works with you to prepare your organization | Must independently evaluate whether your organization meets the applicable requirements |
| Simple way to think about it | Coach - helps you get ready | Referee - independently evaluates your readiness |
| Typical cost considerations | Consulting and implementation costs vary based on the scope of work and complexity of your environment | Assessment fees vary based on assessment scope and organizational complexity |
With the Phase 2 implementation currently under review, organizations should verify whether their specific contracts require a C3PAO assessment before scheduling one. The distinction between preparation and independent assessment remains important regardless of the final implementation timeline. Organizations that use the current period to close security gaps, maintain documentation, and prepare evidence can respond more quickly if third-party assessment requirements return in a revised form.
Questions to Ask Before Engaging an RPO or C3PAO
Before engaging an RPO or C3PAO, verify the provider's credentials, experience, scope of services, pricing, and approach to ongoing support. Ask the following questions:
- Are you registered with Cyber AB? Verify the provider's credentials before signing an agreement.
- Do you have experience with organizations about my size and in my industry? Ask for relevant references or examples of similar engagements.
- What exactly is included in your scope of work? Clarify whether the engagement covers gap assessment, SSP development, remediation support, SPRS reporting, assessment preparation, or other services.
- If you are an RPO, can you help me transition to a C3PAO? Ask whether the RPO has relationships or experience working alongside C3PAOs.
- What ongoing support do you provide after the initial engagement? Understand what annual assessments, affirmations, documentation updates, and continuing compliance support may involve.
- How do you charge for your services? Ask for fixed fees, hourly rates, recurring costs, and potential additional charges.
- Can you provide references from similar organizations? Speak with previous or current clients when possible.
- What happens if significant gaps are identified or an assessment is unsuccessful? Understand how the provider handles remediation, reassessment, and additional work.
Not every company advertising CMMC services is actually registered with the Cyber AB. Verify credentials before you engage anyone. Working with an unqualified provider can lead to failed assessments, lost contracts, and, in some cases, legal exposure under the False Claims Act if you submit an inaccurate compliance attestation based on their guidance.
Sequence RPO Support Before a C3PAO Assessment
For organizations pursuing Level 2 through the third-party path, the typical sequence is to engage an RPO first for preparation and then a C3PAO for formal assessment. The RPO helps the organization identify and address gaps before the C3PAO independently evaluates its environment. Bringing in a C3PAO before remediation and documentation are substantially complete can increase the risk of an unsuccessful assessment because the C3PAO's role is to evaluate compliance, not to fix the gaps it identifies.
An unsuccessful assessment can also add significant cost and delay, making the timing and sequencing of outside support an important part of your CMMC planning.
Common CMMC Compliance Pitfalls
A handful of mistakes account for most of the pain organizations experience on the path to certification.
Scope Creep - Leaving your entire corporate network in scope, rather than isolating CUI-handling systems into a secure enclave, drives cost and complexity far higher than necessary.
Documentation Gaps - Missing or thin System Security Plans, Incident Response Plans, and supporting policies are among the most common assessment findings.
MSP Misconceptions - Believing that a Managed Service Provider automatically makes your organization compliant is a serious and common misconception. Responsibility for compliance stays with you as the DoW contractor, regardless of what your MSP manages on your behalf.
Last-Minute Preparation - Ignoring compliance planning until the day you need to bid results in rushed remediation and a meaningfully higher risk of a failed audit.
Weak Authentication - Failing to enforce FIPS-validated multi-factor authentication across all endpoints remains one of the most frequently cited gaps in Level 2 assessments.
Outdated SSPs - Many organizations write a System Security Plan to pass the initial assessment, then let it drift out of date as systems, vendors, and personnel change. Assessors expect your SSP to reflect your actual environment at the time of review, not the environment you had when you first wrote it. An outdated SSP is one of the fastest ways to turn a routine reassessment into a failed one.
Also Read: Why Pen Test Evidence Fails C3PAO Assessments (and How to Fix It)
Managing CMMC With an MSP
If a Managed Service Provider or Managed Security Service Provider handles your IT environment, they are in scope for your CMMC assessment if they have access to your systems or manage infrastructure connected to your FCI or CUI. You need specific commitments from them: documented evidence of the controls they manage on your behalf, cooperation during your gap assessment and eventual audit, and a clear division of responsibility for which controls they own versus which controls remain yours.
Some MSPs raise their prices once CMMC-related work enters the picture, since supporting compliance requires additional documentation, monitoring, and coordination beyond typical managed services. If that happens, it is worth having a direct conversation about what specifically is driving the increase and whether those services genuinely map to CMMC requirements. If your current MSP cannot clearly explain how their services support your compliance obligations, that is worth examining closely before you renew.
Building Your CMMC Technology Stack
Most of what CMMC requires runs on standard SaaS infrastructure rather than exotic, purpose-built tools. A typical compliant environment includes secure email and collaboration platforms, an isolated enclave for CUI-handling systems, endpoint protection across every device in scope, a log management or SIEM solution to track and review system activity, and multi-factor authentication across key systems. Larger and more mature environments add governance, risk, and compliance platforms to manage documentation and evidence at scale, along with dedicated security operations capabilities.
Level 1 Tools
For Level 1, the tooling required is genuinely modest. A documented SSP, which a simple template can support for smaller organizations, a vulnerability scanner to check for known weaknesses, endpoint protection on every in-scope system, multi-factor authentication on key systems and email, and basic log management, often nothing more sophisticated than native Windows event logs at this stage, cover the core requirement.
Level 2 Tools
For Level 2, the toolset expands meaningfully to include a SIEM platform, advanced endpoint detection, an email security gateway, encrypted file storage, and a GRC platform to manage documentation and evidence across the full set of 110 practices.
Scope-Based Buying
Smaller organizations rarely need to buy everything at once. A proper gap assessment tells you exactly what you already have, what is missing, and what is actually worth the investment for your specific environment, which keeps you from overspending on tools that exceed what your actual scope requires.
Also Read: What Is CMMC and Do You Need It?
Who Governs CMMC?
Several organizations share responsibility for CMMC policy, oversight, accreditation, assessment, and enforcement.
DoW Oversight
The DoW Chief Information Officer oversees overall CMMC policy and implementation rules. The CMMC Program Management Office manages the framework's day-to-day operations.
Cyber AB and C3PAOs
The Cyber AB (Accreditation Body) is the official body designated by the DoW to manage the assessment marketplace and accredit third-party assessment organizations. C3PAOs are the private auditing companies certified to conduct assessments and issue formal certifications.
Assessors and DIBCAC
CMMC Certified Assessors (CCAs) are the individual professionals authorized to lead assessment teams and evaluate contractor environments. DIBCAC, the DoW's internal audit organization, handles high-level compliance checks and leads Level 3 assessments.
Understanding CMMC Costs
Cost is the question every contractor asks first, and the honest answer is that it depends heavily on your organization's size, current security maturity, and target level.
Level 1 Costs
Smaller organizations (under 50 employees): Initial readiness and implementation typically run $5,000 to $20,000, with annual ongoing support of $3,000 to $8,000.
Mid-size organizations (50 to 300 employees): Initial readiness and implementation typically run $15,000 to $50,000, with annual ongoing support of $8,000 to $20,000.
Level 2 Costs
Smaller organizations pursuing the self-assessed path: Initial readiness and implementation typically run $20,000 to $80,000, with annual ongoing support of $10,000 to $30,000.
Mid-size organizations preparing for eventual third-party certification: Initial readiness and implementation typically run $50,000 to $150,000. If and when a C3PAO assessment is required, that fee typically runs $76,000 to $118,000 as a periodic cost.
Annual ongoing support and affirmations typically run $20,000 to $60,000. With Phase 2 suspended, this fee is not currently a condition of any new award, but the underlying readiness work still applies whenever third-party assessment resumes.
Level 3 Costs
Costs climb substantially given the specialized software, hardware, and advanced monitoring required, often exceeding $500,000 in total investment.
Start With a Gap Assessment
Organizations often underestimate the resources required to prepare for CMMC. Starting with a gap assessment, typically $2,000 to $8,000, can help identify where investment is needed before you commit to a larger engagement. These figures also explain why scope discipline matters as much as budget discipline. Two organizations of identical size and identical target level can see dramatically different costs depending on how much of their network sits inside the assessment boundary.
An organization that isolates its CUI-handling systems into a dedicated enclave, separate from general corporate email, file storage, and workstations, often spends significantly less on both remediation and the eventual assessment than an organization that leaves its entire network in scope by default. Scoping decisions made early in the process, before you engage a C3PAO, have more influence over your total cost than almost any other single factor.
Understanding the NIST SP 800-171 Requirements
Level 2 compliance rests on 110 requirements spread across 14 security domains. Understanding these domains at a high level helps you see where your organization's effort will actually go and which areas tend to demand the most remediation work in practice. Access Control, System and Communications Protection, and Configuration Management typically account for the largest share of findings during a gap assessment because they touch nearly every system in scope rather than a single process or policy.
| Security Domain | What It Covers | Practical Focus |
|---|---|---|
| Access Control | Limits system access to authorized users and processes, controls how CUI flows internally and externally, and enforces least privilege. | User permissions, access restrictions, remote access, and CUI flow. |
| Awareness and Training | Ensures managers, administrators, and users understand security risks and can recognize social engineering and malicious email. | Security awareness and role-based training. |
| Audit and Accountability | Requires organizations to create, protect, retain, and regularly review system audit logs. | Logging, log protection, retention, and monitoring. |
| Configuration Management | Establishes and maintains baseline configurations and enforces security settings for systems, software, and hardware. | Secure configurations, baselines, and configuration changes. |
| Identification and Authentication | Requires user authentication before access and MFA for applicable local and network access. | Account management, passwords, authentication, and MFA. |
| Incident Response | Establishes an operational incident response capability and requires organizations to track, document, and report incidents. | Incident planning, detection, response, reporting, and recovery. |
| Maintenance | Covers routine and emergency system maintenance and controls the tools and methods used for remote maintenance. | Maintenance procedures, tools, and remote maintenance controls. |
| Media Protection | Protects and sanitizes system media containing CUI and restricts access to authorized individuals. | Media handling, sanitization, storage, and access. |
| Personnel Security | Requires appropriate screening before granting system access and action when personnel terminate or transfer. | Personnel screening, access changes, and termination procedures. |
| Physical Protection | Limits physical access to systems, equipment, and operating environments and requires appropriate facility security controls. | Facility access, visitors, physical safeguards, and monitoring. |
| Risk Assessment | Requires periodic vulnerability scanning and risk-based prioritization of identified weaknesses. | Vulnerability management, risk analysis, and remediation priorities. |
| Security Assessment | Requires periodic assessment of security controls and documented plans for addressing deficiencies. | Control assessments, evidence, findings, and remediation plans. |
| System and Communications Protection | Protects communications at external boundaries and requires appropriate cryptographic mechanisms for CUI. | Network security, boundary protection, encryption, and secure communications. |
| System and Information Integrity | Requires organizations to identify and correct system flaws, protect against malicious code, and verify software integrity. | Vulnerability remediation, malware protection, endpoint security, and integrity monitoring. |
Also Read: Why CHIPS Act Manufacturers Can't Rely on CMMC Pen Testing Alone
Where to Find Authoritative CMMC Information
The DoW CIO CMMC website is the authoritative source for foundational CMMC policies and framework documents. The NIST SP 800-171 documentation, published by NIST's Computer Security Resource Center, details the full baseline of 110 requirements that Level 2 compliance is built on. Bookmark both sources as your organization's compliance posture evolves alongside future rule changes.
CMMC compliance rewards organizations that start early and act deliberately rather than those that scramble as a deadline approaches. Begin by identifying your required level, mapping exactly where your FCI or CUI lives, and running a gap assessment against the practices that apply to you.
- Identify Your Requirements - Determine which CMMC level applies to your organization based on the information you handle, and the requirements stated in your solicitation or contract.
- Assess Your Environment - Map where FCI or CUI is stored, processed, and transmitted, then conduct a gap assessment to identify which requirements you have already addressed and where remediation is needed.
- Build and Maintain Compliance - Close identified gaps, maintain the required documentation, and establish processes for keeping your security practices aligned with your actual environment. Whether you are self-assessing at Level 1 or preparing for a potential third-party Level 2 assessment, early preparation gives you more time to address issues deliberately.
Moving Ahead
Level 1 self-assessment is already a live requirement, while Level 2's third-party requirement is currently paused rather than canceled. Organizations that continue preparing during the review period will be better positioned to respond if assessment requirements return in a revised form. Treat CMMC as an ongoing compliance program rather than a one-time certification project.