What Is CMMC Compliance: Levels, Requirements, and Timeline
Learn what CMMC compliance is, how the three levels of the Cybersecurity Maturity Model Certification work, and what defense contractors must do by 2026.
Introduction
An aerospace manufacturer with 200 employees wins a contract to supply components to the Air Force. Inside their engineering system: CAD drawings, material specifications, and export-controlled technical data that, in adversary hands, could undermine the very weapons systems their components support. In 2019, a series of audits revealed that tens of thousands of defense contractors were self-certifying their cybersecurity compliance — and many were vastly overstating their actual security posture.
The response was CMMC compliance — the Cybersecurity Maturity Model Certification. Rather than trusting contractors to grade their own homework, the DoD built a framework that scales verification rigor to the sensitivity of the data handled. For small businesses handling only Federal Contract Information, a self-assessment is sufficient. For contractors touching the most sensitive Controlled Unclassified Information on high-priority programs, a U.S. government team conducts the assessment on-site.
The CMMC final rule became effective on November 10, 2025, initiating a phased rollout. If you work with the Defense Industrial Base — whether as a prime contractor, a subcontractor, or a software vendor to a defense prime — understanding CMMC is no longer optional. It is a contract requirement.
What Is CMMC Compliance?
CMMC (Cybersecurity Maturity Model Certification) is the DoD’s unified cybersecurity certification program for the Defense Industrial Base (DIB). It verifies that defense contractors and subcontractors have implemented the cybersecurity controls necessary to protect two categories of sensitive government information:
- Federal Contract Information (FCI): Information not intended for public release that the government provides or generates under a contract. Even basic procurement information qualifies.
- Controlled Unclassified Information (CUI): A broader, more sensitive category covering export-controlled technical data, engineering specifications, personally identifiable information on government personnel, and other data that requires protection by law or policy.
CMMC 2.0 was introduced in 2021 and streamlined the original CMMC 1.0 from five levels to three. The final rule (32 CFR Part 170), published in 2024, codified the program as law. Compliance is verified through a combination of self-assessments, third-party audits, and government-led assessments — scaled to the level required.
How CMMC Works
The program operates through a contractual mechanism. When a defense prime contractor issues a Request for Proposal (RFP) for a subcontract, or when the DoD awards a prime contract, the contract will specify the required CMMC Level. A contractor that does not meet the specified level cannot be awarded the contract.
Required levels are built into DoD contracts via DFARS clauses:
- DFARS 252.204-7025 — specifies the CMMC Level required for the contract.
- DFARS 252.204-7021 — requires flow-down of CMMC requirements from prime contractors to subcontractors handling FCI or CUI.
The flow-down requirement is critical: every subcontractor in the supply chain that touches FCI or CUI must meet the applicable CMMC level, not just the prime.
CMMC Level Comparison
| Feature | Level 1 — Foundational | Level 2 — Advanced | Level 3 — Expert |
|---|---|---|---|
| Who needs it | Contractors handling FCI only. | Contractors handling CUI on most programs. | Contractors on highest-priority CUI programs. |
| Practice count | 15 practices. | 110 practices. | 110 + subset of NIST SP 800-172 practices. |
| Standard basis | FAR Clause 52.204-21. | NIST SP 800-171 Rev 2. | NIST SP 800-171 + SP 800-172. |
| Assessment type | Annual company self-assessment + affirmation in SPRS. | Third-party assessment by a C3PAO (or self-assess for some contracts). | Government-led assessment by DIBCAC. |
| Renewal frequency | Annual. | Every three years. | Every three years. |
Real-World Use Cases
Tier-3 Machining Subcontractor: A 15-person precision machining shop supplies housings for military vehicle components. The contract drawings are CUI (export-controlled technical data). Even as a small subcontractor, this shop must achieve CMMC Level 2, implement all 110 NIST SP 800-171 controls, and — depending on the prime’s requirements — either self-assess or contract with a C3PAO for a formal third-party audit. Many small shops are unaware of this obligation until a prime contractor’s questionnaire arrives.
Cloud Service Provider to a Defense Prime: An enterprise cloud storage vendor provides the file-sharing platform used by a defense contractor’s engineering team. If CUI ever transits or resides in that cloud environment, the cloud service provider is part of the CUI enclave and must either hold FedRAMP authorization or meet equivalent CMMC-compliant security requirements. This “third-party support” scenario is one of the most frequently misunderstood compliance scenarios.
Software-as-a-Service Vendor to DoD: A SaaS company sells a project management tool to an Air Force acquisition program office. If DoD personnel use the tool to discuss, upload, or manage CUI — even indirectly — the SaaS platform must meet FedRAMP authorization and align with the CUI protection requirements. CMMC compliance for SaaS vendors processing CUI is not a future consideration; it is a present contractual reality.
Common Mistakes to Avoid
The most dangerous mistake is underestimating the scope of CUI. Organizations frequently assume CMMC only applies to their engineering team handling classified drawings. In practice, CUI extends to human resources records of cleared personnel, procurement pricing sensitive to national security, and even certain categories of personally identifiable information on government contracts. A thorough CUI discovery exercise — identifying every location where CUI is created, stored, transmitted, or processed — must precede any gap assessment.
A second critical error is failing to enforce the flow-down requirement. A prime contractor may achieve CMMC Level 2 themselves but then transmit CUI to a subcontractor who has not achieved Level 2. This creates a compliance gap that can jeopardize the prime’s own certification and expose both parties to False Claims Act liability if they have affirmed compliance while knowingly sharing CUI with a non-compliant sub.
Organizations also routinely overlook the SPRS score submission requirement. Even before formal CMMC assessment, contractors must submit a self-scored cybersecurity assessment score in the Supplier Performance Risk System (SPRS). A missing or drastically incorrect SPRS score is an immediate red flag during contract award and can result in contract denial or termination for cause.
Getting Started
Moving toward CMMC compliance is a phased journey. Work through this checklist to establish the right foundation.
-
Determine your applicable CMMC Level under 32 CFR § 170.14 based on whether you handle FCI (Level 1) or CUI (Level 2 or 3). Review existing contracts for DFARS 252.204-7012 clauses that indicate CUI is in scope.
-
Conduct a CUI discovery and scoping exercise to identify every network segment, cloud tenant, laptop, and shared drive where CUI is created, stored, transmitted, or processed. The boundary of your CUI enclave defines assessment scope under 32 CFR § 170.19.
-
Perform a gap assessment against the 110 security requirements in NIST SP 800-171 Rev 2 and, for Level 3 programs, the additional enhanced requirements in NIST SP 800-172.
-
Document unimplemented controls in a Plan of Action and Milestones (POA&M) as permitted by 32 CFR § 170.21 — noting that certain controls cannot be POA&M’d and must be fully implemented before certification.
-
Calculate and submit your NIST SP 800-171 self-assessment score in the Supplier Performance Risk System (SPRS) as required by DFARS 252.204-7020, along with the annual affirmation required by 32 CFR § 170.22.
-
For Level 2 certification, engage an accredited C3PAO from the Cyber AB marketplace to conduct the third-party assessment mandated by 32 CFR § 170.17. Allow 6–12 months for scheduling, evidence collection, and findings remediation.
-
Flow down CMMC requirements to all subcontractors handling FCI or CUI, as required by DFARS 252.204-7021, and verify their status before sharing controlled information.
CMMC compliance sits squarely within the broader NIST Cybersecurity Framework, as NIST SP 800-171 maps directly to NIST CSF subcategories. Understanding the full framework context helps compliance teams prioritize their control implementation roadmap.
FAQ
Common questions — answered in plain English.
What is CMMC compliance?
What are the three CMMC levels?
When does CMMC become mandatory?
What is CUI in CMMC?
What is a C3PAO?
Does CMMC replace DFARS 252.204-7012?
References
- [1]CMMC Program Final Rule (32 CFR Part 170)U.S. Department of Defense, 2024
- [2]
- [3]
- [4]Defense Federal Acquisition Regulation Supplement (DFARS)U.S. Department of Defense
- [5]CMMC Program Overview — DoD CIOU.S. Department of Defense