Compliance

What Is CMMC Compliance: Levels, Requirements, and Timeline

Learn what CMMC compliance is, how the three levels of the Cybersecurity Maturity Model Certification work, and what defense contractors must do by 2026.

Editorial Team ·
7 min read intermediate

Introduction

An aerospace manufacturer with 200 employees wins a contract to supply components to the Air Force. Inside their engineering system: CAD drawings, material specifications, and export-controlled technical data that, in adversary hands, could undermine the very weapons systems their components support. In 2019, a series of audits revealed that tens of thousands of defense contractors were self-certifying their cybersecurity compliance — and many were vastly overstating their actual security posture.

The response was CMMC compliance — the Cybersecurity Maturity Model Certification. Rather than trusting contractors to grade their own homework, the DoD built a framework that scales verification rigor to the sensitivity of the data handled. For small businesses handling only Federal Contract Information, a self-assessment is sufficient. For contractors touching the most sensitive Controlled Unclassified Information on high-priority programs, a U.S. government team conducts the assessment on-site.

The CMMC final rule became effective on November 10, 2025, initiating a phased rollout. If you work with the Defense Industrial Base — whether as a prime contractor, a subcontractor, or a software vendor to a defense prime — understanding CMMC is no longer optional. It is a contract requirement.

What Is CMMC Compliance?

CMMC (Cybersecurity Maturity Model Certification) is the DoD’s unified cybersecurity certification program for the Defense Industrial Base (DIB). It verifies that defense contractors and subcontractors have implemented the cybersecurity controls necessary to protect two categories of sensitive government information:

  • Federal Contract Information (FCI): Information not intended for public release that the government provides or generates under a contract. Even basic procurement information qualifies.
  • Controlled Unclassified Information (CUI): A broader, more sensitive category covering export-controlled technical data, engineering specifications, personally identifiable information on government personnel, and other data that requires protection by law or policy.

CMMC 2.0 was introduced in 2021 and streamlined the original CMMC 1.0 from five levels to three. The final rule (32 CFR Part 170), published in 2024, codified the program as law. Compliance is verified through a combination of self-assessments, third-party audits, and government-led assessments — scaled to the level required.

How CMMC Works

The program operates through a contractual mechanism. When a defense prime contractor issues a Request for Proposal (RFP) for a subcontract, or when the DoD awards a prime contract, the contract will specify the required CMMC Level. A contractor that does not meet the specified level cannot be awarded the contract.

Required levels are built into DoD contracts via DFARS clauses:

  • DFARS 252.204-7025 — specifies the CMMC Level required for the contract.
  • DFARS 252.204-7021 — requires flow-down of CMMC requirements from prime contractors to subcontractors handling FCI or CUI.

The flow-down requirement is critical: every subcontractor in the supply chain that touches FCI or CUI must meet the applicable CMMC level, not just the prime.

Withum's walkthrough explains CMMC's three levels, the role of C3PAOs, and the practical implications for both prime contractors and small-business subcontractors.

CMMC Level Comparison

FeatureLevel 1 — FoundationalLevel 2 — AdvancedLevel 3 — Expert
Who needs itContractors handling FCI only.Contractors handling CUI on most programs.Contractors on highest-priority CUI programs.
Practice count15 practices.110 practices.110 + subset of NIST SP 800-172 practices.
Standard basisFAR Clause 52.204-21.NIST SP 800-171 Rev 2.NIST SP 800-171 + SP 800-172.
Assessment typeAnnual company self-assessment + affirmation in SPRS.Third-party assessment by a C3PAO (or self-assess for some contracts).Government-led assessment by DIBCAC.
Renewal frequencyAnnual.Every three years.Every three years.

Real-World Use Cases

Tier-3 Machining Subcontractor: A 15-person precision machining shop supplies housings for military vehicle components. The contract drawings are CUI (export-controlled technical data). Even as a small subcontractor, this shop must achieve CMMC Level 2, implement all 110 NIST SP 800-171 controls, and — depending on the prime’s requirements — either self-assess or contract with a C3PAO for a formal third-party audit. Many small shops are unaware of this obligation until a prime contractor’s questionnaire arrives.

Cloud Service Provider to a Defense Prime: An enterprise cloud storage vendor provides the file-sharing platform used by a defense contractor’s engineering team. If CUI ever transits or resides in that cloud environment, the cloud service provider is part of the CUI enclave and must either hold FedRAMP authorization or meet equivalent CMMC-compliant security requirements. This “third-party support” scenario is one of the most frequently misunderstood compliance scenarios.

Software-as-a-Service Vendor to DoD: A SaaS company sells a project management tool to an Air Force acquisition program office. If DoD personnel use the tool to discuss, upload, or manage CUI — even indirectly — the SaaS platform must meet FedRAMP authorization and align with the CUI protection requirements. CMMC compliance for SaaS vendors processing CUI is not a future consideration; it is a present contractual reality.

Common Mistakes to Avoid

The most dangerous mistake is underestimating the scope of CUI. Organizations frequently assume CMMC only applies to their engineering team handling classified drawings. In practice, CUI extends to human resources records of cleared personnel, procurement pricing sensitive to national security, and even certain categories of personally identifiable information on government contracts. A thorough CUI discovery exercise — identifying every location where CUI is created, stored, transmitted, or processed — must precede any gap assessment.

A second critical error is failing to enforce the flow-down requirement. A prime contractor may achieve CMMC Level 2 themselves but then transmit CUI to a subcontractor who has not achieved Level 2. This creates a compliance gap that can jeopardize the prime’s own certification and expose both parties to False Claims Act liability if they have affirmed compliance while knowingly sharing CUI with a non-compliant sub.

Organizations also routinely overlook the SPRS score submission requirement. Even before formal CMMC assessment, contractors must submit a self-scored cybersecurity assessment score in the Supplier Performance Risk System (SPRS). A missing or drastically incorrect SPRS score is an immediate red flag during contract award and can result in contract denial or termination for cause.

Getting Started

Moving toward CMMC compliance is a phased journey. Work through this checklist to establish the right foundation.

  1. Determine your applicable CMMC Level under 32 CFR § 170.14 based on whether you handle FCI (Level 1) or CUI (Level 2 or 3). Review existing contracts for DFARS 252.204-7012 clauses that indicate CUI is in scope.

  2. Conduct a CUI discovery and scoping exercise to identify every network segment, cloud tenant, laptop, and shared drive where CUI is created, stored, transmitted, or processed. The boundary of your CUI enclave defines assessment scope under 32 CFR § 170.19.

  3. Perform a gap assessment against the 110 security requirements in NIST SP 800-171 Rev 2 and, for Level 3 programs, the additional enhanced requirements in NIST SP 800-172.

  4. Document unimplemented controls in a Plan of Action and Milestones (POA&M) as permitted by 32 CFR § 170.21 — noting that certain controls cannot be POA&M’d and must be fully implemented before certification.

  5. Calculate and submit your NIST SP 800-171 self-assessment score in the Supplier Performance Risk System (SPRS) as required by DFARS 252.204-7020, along with the annual affirmation required by 32 CFR § 170.22.

  6. For Level 2 certification, engage an accredited C3PAO from the Cyber AB marketplace to conduct the third-party assessment mandated by 32 CFR § 170.17. Allow 6–12 months for scheduling, evidence collection, and findings remediation.

  7. Flow down CMMC requirements to all subcontractors handling FCI or CUI, as required by DFARS 252.204-7021, and verify their status before sharing controlled information.

CMMC compliance sits squarely within the broader NIST Cybersecurity Framework, as NIST SP 800-171 maps directly to NIST CSF subcategories. Understanding the full framework context helps compliance teams prioritize their control implementation roadmap.

FAQ

Common questions — answered in plain English.

What is CMMC compliance?
CMMC (Cybersecurity Maturity Model Certification) is the U.S. Department of Defense's framework for verifying that defense contractors adequately protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Contractors must achieve the required CMMC level to win or renew DoD contracts.
What are the three CMMC levels?
Level 1 (Foundational) requires 15 basic cybersecurity practices for contractors handling FCI and is verified by annual self-assessment. Level 2 (Advanced) requires 110 controls from NIST SP 800-171 for contractors handling CUI, verified by a C3PAO third-party assessment. Level 3 (Expert) adds NIST SP 800-172 controls for highest-risk programs, verified by government assessors.
When does CMMC become mandatory?
The CMMC final rule became effective November 10, 2025. DoD began phasing CMMC requirements into contracts from that date, with a three-year phased rollout. By late 2028, CMMC requirements are expected to appear in virtually all relevant DoD contracts.
What is CUI in CMMC?
Controlled Unclassified Information (CUI) is government-created or possessed information that requires safeguarding under law, regulation, or government-wide policy, but is not classified. Examples include engineering drawings, technical specifications, export-controlled data, and personally identifiable information on federal contracts.
What is a C3PAO?
A C3PAO (CMMC Third-Party Assessment Organization) is an organization authorized by the CMMC Accreditation Body (Cyber AB) to conduct official Level 2 assessments of defense contractors. Only assessments conducted by an accredited C3PAO produce a certified CMMC score.
Does CMMC replace DFARS 252.204-7012?
No, CMMC complements DFARS 252.204-7012, which remains in place. DFARS 7012 required contractors to self-attest NIST SP 800-171 compliance. CMMC adds independent third-party verification for Level 2 contractors and government assessment for Level 3, replacing the honor-system self-attestation for CUI handlers.

References

  1. [1]
    CMMC Program Final Rule (32 CFR Part 170)U.S. Department of Defense, 2024
  2. [2]
  3. [3]
  4. [4]
  5. [5]
    CMMC Program Overview — DoD CIOU.S. Department of Defense