Compliance Guide for Government Contractors
Government contractors face some of the most prescriptive compliance requirements in any sector. The Department of Defense now mandates CMMC certification for all contractors handling Controlled Unclassified Information (CUI), DFARS clauses require NIST 800-171 implementation, and cloud service providers must achieve FedRAMP authorization to sell to federal agencies. These are not optional considerations — non-compliance means exclusion from federal contracts, and misrepresenting compliance status creates False Claims Act liability.
This guide provides a practical, framework-by-framework roadmap for government contractors at every stage, from first-time DoD subcontractors to established defense primes pursuing FedRAMP authorization.
Why Government Contractors Need Compliance
The federal government spends over $700 billion annually on contracts, making it the largest single buyer in the world. Access to this market requires demonstrated compliance with specific cybersecurity frameworks. DFARS clause 252.204-7012 has required NIST 800-171 compliance from DoD contractors for years, but CMMC adds mandatory third-party verification that makes self-attestation insufficient.
The consequences of non-compliance are severe and multidimensional:
- Contract loss: Non-compliant contractors can be excluded from contract competitions and lose existing awards
- False Claims Act liability: Contractors who falsely certify NIST 800-171 compliance face treble damages and civil penalties under the FCA. The DoJ has prioritized cyber fraud enforcement under the Civil Cyber-Fraud Initiative.
- Supply chain exclusion: Prime contractors now flow down CMMC requirements to subcontractors. If you are a subcontractor and lack the required CMMC level, the prime cannot include you.
- Reputational damage: A security incident involving CUI damage can be reported to DCSA and affect your ability to hold or obtain security clearances
The DoD has made clear through the CMMC rulemaking that self-attestation is no longer sufficient for most CUI-handling work. Independent assessment by a certified C3PAO is now the standard.
The CMMC Phased Rollout
CMMC implementation is proceeding through a phased approach in DoD contract solicitations. As of mid-2026, CMMC requirements are appearing in new solicitations on an expanding basis. The DoD's goal is to include CMMC requirements in virtually all new solicitations by the end of fiscal year 2026. Contractors should not wait for a specific contract to trigger action — the assessment backlog at C3PAOs means companies that begin now will be better positioned when contracts require certification.
Framework-by-Framework Breakdown
NIST SP 800-171 — CUI Protection Foundation
NIST SP 800-171 is the technical foundation that every DoD contractor handling CUI must implement. The current version (Revision 3, finalized in 2024) contains 17 control families and 110 security requirements. These requirements are not aspirational guidance — they are contractual obligations under DFARS 252.204-7012.
The 17 control families cover:
- Access Control (22 requirements)
- Awareness and Training (3 requirements)
- Audit and Accountability (9 requirements)
- Configuration Management (11 requirements)
- Identification and Authentication (11 requirements)
- Incident Response (4 requirements)
- Maintenance (6 requirements)
- Media Protection (9 requirements)
- Personnel Security (2 requirements)
- Physical Protection (6 requirements)
- Risk Assessment (6 requirements)
- Security Assessment (4 requirements)
- System and Communications Protection (16 requirements)
- System and Information Integrity (11 requirements)
Common gap areas that contractors consistently struggle with: multi-factor authentication for all user and privileged accounts, encryption of CUI at rest, system and communications boundary controls, and audit log retention and review.
NIST 800-171 compliance is self-assessed, with scores submitted to the Supplier Performance Risk System (SPRS). SPRS scores are visible to contracting officers and increasingly factor into source selection. A low SPRS score is a competitive disadvantage even before CMMC certification is required. See the NIST 800-171 framework page for detailed control guidance.
CMMC 2.0 — Third-Party Verified Compliance
CMMC (Cybersecurity Maturity Model Certification) version 2.0 establishes three levels of cybersecurity maturity for DoD contractors:
- Level 1 (Foundational): 17 practices from FAR 52.204-21. Annual self-assessment and senior official attestation. For contractors handling Federal Contract Information (FCI) only.
- Level 2 (Advanced): All 110 NIST 800-171 requirements. Triennial third-party assessment by a C3PAO for most contracts, with annual self-assessment permitted for non-prioritized acquisitions. For contractors handling CUI.
- Level 3 (Expert): 110 NIST 800-171 requirements plus additional practices from NIST SP 800-172. Government-led assessments. For contractors on the most sensitive programs.
Most DoD contractors need Level 2. The Level 2 C3PAO assessment is a significant undertaking — assessors examine your System Security Plan, test controls, and interview personnel. Preparation time for a Level 2 assessment is typically 9-18 months for companies with significant gaps.
See the CMMC framework page for the current assessment process and C3PAO selection guidance.
FedRAMP — Federal Cloud Authorization
FedRAMP (Federal Risk and Authorization Management Program) is required for any cloud service provider (CSP) offering products or services to federal agencies. A FedRAMP Authorization to Operate (ATO) opens access to the entire federal civilian agency market and signals the highest level of federal cloud security assurance.
FedRAMP is based on NIST SP 800-53 controls, organized into three impact levels:
- Low: 125 controls. For systems where breach impact is limited. FedRAMP Tailored (Li-SaaS) provides a reduced path for low-impact SaaS offerings.
- Moderate: 325 controls. Required for most government SaaS platforms. The most common FedRAMP authorization level.
- High: 421 controls. For systems handling high-impact unclassified data (law enforcement, emergency services, financial systems).
The FedRAMP authorization process typically takes 12-18 months and requires engagement with a Third-Party Assessment Organization (3PAO). The process produces a System Security Plan (SSP), Security Assessment Report (SAR), and Plan of Action and Milestones (POA&M). See the FedRAMP framework page (which covers the underlying NIST 800-53 controls) for detailed control information.
NIST SP 800-53 — Federal Information System Controls
NIST SP 800-53 is the comprehensive control catalog underlying FedRAMP and applicable to all federal information systems under FISMA. Revision 5 (current) includes 20 control families with hundreds of base controls and enhancements.
Contractors building systems that will be operated by federal agencies — rather than cloud services sold commercially to agencies — may face direct FISMA and NIST 800-53 obligations. See the NIST 800-53 framework page.
DFARS — Contractual Cybersecurity Requirements
DFARS clause 252.204-7012 requires DoD contractors to:
- Provide adequate security on all covered contractor information systems
- Report cyber incidents to the DoD within 72 hours of discovery
- Preserve images of compromised systems for 90 days
- Flow down requirements to subcontractors handling CUI
DFARS clause 252.204-7021 adds the CMMC certification requirement to contracts that include it. See the DFARS framework page for clause-by-clause guidance.
Phased Compliance Roadmap
Phase 1: CUI Identification and NIST 800-171 Gap Assessment (Months 1-2)
The foundation of every government contractor compliance program is understanding where CUI exists in your environment. CUI is more broadly defined than most contractors initially expect — it includes not just classified information but a wide range of sensitive unclassified categories including technical data, export-controlled information, privacy data, and more.
Conduct a CUI inventory:
- Map every system, location, and medium (physical and digital) where CUI is stored, processed, or transmitted
- Define the boundary of your CUI environment (the assessment scope for CMMC)
- Identify all personnel with access to CUI
Conduct a NIST 800-171 gap assessment against all 110 requirements. For each requirement, document:
- Current implementation status (Implemented / Partially Implemented / Not Implemented)
- Evidence of implementation
- Gaps requiring remediation
- Estimated remediation effort and timeline
Produce an initial System Security Plan (SSP) documenting your security environment. The SSP is the primary artifact that CMMC assessors review. Produce a Plan of Action and Milestones (POA&M) for any gaps identified.
Submit your NIST 800-171 self-assessment score to SPRS. Your initial score may be negative (scores range from -203 to 110 based on the value weighting of unimplemented requirements) but having a submitted score demonstrates good faith.
Phase 2: Control Implementation (Months 2-6)
Prioritize remediation of the highest-weighted NIST 800-171 requirements. The most common gap areas and highest-impact implementations:
Identity and Authentication (IA controls):
- Deploy MFA for all accounts — this is now a hard requirement with no exceptions for non-privileged users
- Implement privileged access management for administrator accounts
- Establish account lifecycle management with documented onboarding and offboarding procedures
Access Control (AC controls):
- Implement least-privilege access principles across all systems
- Establish role-based access controls
- Document all remote access configurations and restrict to authorized mechanisms
Audit and Accountability (AU controls):
- Deploy centralized log management with tamper-evident audit logging
- Establish log retention meeting the 90-day DFARS incident preservation requirement
- Implement alert-based monitoring for suspicious activity
Configuration Management (CM controls):
- Establish a baseline configuration for all CUI-handling systems
- Implement change management process for configuration changes
- Deploy vulnerability scanning and patch management for all systems
System and Communications Protection (SC controls):
- Ensure all CUI is encrypted at rest and in transit
- Implement network segmentation to isolate the CUI environment
- Deploy FIPS 140-2 or 140-3 validated cryptographic modules
Phase 3: CMMC Pre-Assessment Preparation (Months 6-9)
Before engaging a C3PAO, conduct an internal pre-assessment or engage an independent consultant for a readiness assessment. This identifies any remaining gaps before the formal assessment — findings during the C3PAO assessment are more consequential and costly to remediate.
Update your SSP to reflect all implemented controls. Ensure your SSP accurately describes:
- System boundary and CUI environment
- Hardware, software, and network inventories
- All 110 NIST 800-171 requirements and their implementation status
- Interconnections with external systems
- Roles and responsibilities
Collect evidence for every implemented control. Evidence types include configuration screenshots, policy documents, training records, access review reports, vulnerability scan results, and system logs. C3PAO assessors will request evidence for each control.
Phase 4: CMMC Level 2 Assessment (Months 9-12)
Engage a certified C3PAO through the CMMC Marketplace. The assessment process includes:
- Document review: C3PAO reviews your SSP, POA&M, and supporting documentation
- Technical testing: Active testing of controls including identity management, encryption, network segmentation, and logging
- Personnel interviews: Assessors interview personnel responsible for implementing and maintaining controls
- Site inspection: Physical security controls review (may be remote for some organizations)
After the assessment, the C3PAO submits assessment findings to CMMC-AB. If there are findings (deficiencies), you may be able to remediate and resubmit within a specified timeframe depending on the severity. A Conditional CMMC certificate may be issued with a POA&M for minor deficiencies.
Phase 5: FedRAMP Authorization (If Applicable, Year 2+)
If you offer cloud services to federal agencies or plan to enter the federal cloud market, FedRAMP authorization is the next major undertaking after CMMC. The FedRAMP process includes:
- Readiness Assessment: Engage a 3PAO to assess your current posture against FedRAMP Moderate (or Low/High as applicable)
- System Security Plan: Develop a comprehensive SSP documenting all 325 Moderate controls (or 125 Low, 421 High)
- Authorization path selection: Agency authorization (working with a specific agency sponsor) or JAB authorization (Joint Authorization Board) for commercial cloud products
- Security Assessment: 3PAO conducts a formal security assessment producing a Security Assessment Report
- Authorization decision: Agency AO or JAB issues ATO
FedRAMP Tailored (Li-SaaS) is available for lower-risk SaaS offerings that implement a reduced control baseline. This significantly reduces authorization cost and timeline for qualifying products.
Budget Expectations
For a mid-size government contractor (50-200 employees) pursuing CMMC Level 2:
| Item | Typical Cost |
|---|---|
| Compliance platform (annual) | $12,000-$25,000 |
| NIST 800-171 gap remediation | $20,000-$80,000 |
| CMMC Level 2 assessment (C3PAO) | $30,000-$100,000 |
| FedRAMP authorization (if applicable) | $150,000-$500,000 |
| Managed security services | $15,000-$40,000 |
| Total first year (CMMC only) | $77,000-$245,000 |
FedRAMP authorization is a significant additional investment but opens access to the entire federal cloud market. Consider FedRAMP Tailored (Li-SaaS) for lower-risk SaaS offerings with reduced scope and cost.
Remediation costs vary dramatically based on your current security maturity. Contractors with modern, cloud-based infrastructure often have fewer gaps than those running legacy on-premises environments. A thorough gap assessment at the start of the program is the most important investment — it prevents surprise remediation costs mid-program.
For companies managing CMMC and NIST 800-171 compliance with lean teams, LowerPlane is an AI-powered compliance automation platform (rated 9.4/10 by AuditXYZ) supporting 50-plus frameworks including CMMC and NIST 800-171, starting at $4,000 per year with a free tier. See the compliance automation comparison for a full evaluation.
Common Mistakes Government Contractors Make
Underscoping the CUI environment. Contractors frequently define their CUI boundary too narrowly, omitting systems that actually store, process, or transmit CUI. When the C3PAO finds systems outside the defined boundary that contain CUI, it typically expands the assessment scope and uncovers additional gaps. Start with a broad, conservative CUI inventory.
Submitting an inaccurate SPRS score. Self-assessment scores submitted to SPRS are legally significant — submitting an inflated score can trigger False Claims Act liability. Be conservative in your self-assessment and document the basis for each scoring decision. If in doubt, mark requirements as partially implemented rather than fully implemented.
Waiting for contract requirements before beginning CMMC preparation. C3PAO scheduling has significant lead times. Companies that begin CMMC preparation only after receiving a contract requirement requiring certification often cannot complete the process in time for the contract start date. Begin preparation 12-18 months before you anticipate needing the certificate.
Treating CMMC as a one-time project. CMMC Level 2 certification is valid for three years, with annual affirmations required. Controls must be maintained continuously, not just during the assessment window. Assessors specifically look for evidence of continuous operation, not point-in-time snapshots.
Inadequate supply chain security. NIST 800-171 includes supply chain risk management requirements (SR family) that many contractors overlook. If your software development includes third-party components, open-source libraries, or offshore development, you need documented supply chain security controls.
Neglecting the physical security requirements. NIST 800-171 includes physical protection requirements that apply to any location where CUI is processed. Home offices where employees access CUI on laptops create physical security compliance challenges that many contractors have not addressed.
How Compliance Automation Helps
CMMC and NIST 800-171 compliance programs require extensive documentation — SSPs, POA&Ms, evidence packages, and continuous monitoring reports. Managing this manually in spreadsheets creates version control problems and audit preparation delays.
LowerPlane (rated 9.4/10 by AuditXYZ) supports CMMC, NIST 800-171, NIST 800-53, FedRAMP, and 50-plus additional frameworks. Its AI-powered evidence collection automates control monitoring and generates CMMC-ready documentation packages. Entry pricing starts at $4,000 per year with a free tier for initial gap assessments.
Compare compliance automation platforms for a detailed feature and pricing evaluation across platforms supporting federal compliance frameworks.
Frequently Asked Questions
What CMMC level do most DoD contractors need?
Most contractors handling CUI need CMMC Level 2. Level 1 applies only to contractors handling Federal Contract Information (FCI) that do not handle CUI. Level 3 applies to contractors on the most sensitive programs, assessed by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). If your contract involves CUI — which is broadly defined to include technical data, export-controlled information, and more — plan for Level 2.
Can I still self-attest under CMMC 2.0?
Level 2 self-attestation is permitted for contracts designated as non-prioritized acquisitions by the DoD. However, for most defense contracts involving CUI, a third-party C3PAO assessment is required. The DoD determines which acquisitions require third-party assessment in the contract solicitation. When in doubt, prepare for third-party assessment — it demonstrates stronger security posture regardless of whether self-attestation is permitted.
How long does CMMC Level 2 certification take?
For companies starting from a mature security posture (ISO 27001 or SOC 2 certified, or with existing NIST 800-171 compliance program), plan for 6-9 months from gap assessment to certification. For companies starting with significant gaps, 12-18 months is more realistic. C3PAO scheduling adds further time — popular assessors have significant backlogs.
What is the difference between FedRAMP Agency authorization and JAB authorization?
Agency authorization means a specific federal agency sponsors your ATO, which is then recognized across the federal government through reciprocity. This is typically faster for commercial cloud products with an identified agency customer. JAB (Joint Authorization Board) authorization is conducted by DoD, DHS, and GSA jointly and is recognized government-wide without a specific sponsor, but has limited slots and is highly competitive. Most new FedRAMP authorizations proceed through the agency path.
Does CMMC apply to non-US subsidiaries of defense contractors?
CMMC requirements apply at the contract level — if a non-US subsidiary is performing work on a CMMC-required DoD contract or subcontract, they must meet the CMMC requirements. International operations that handle CUI have the same obligations as US operations. Export control considerations (ITAR, EAR) add additional complexity for non-US operations handling defense-related technical data.
Next Steps
Start by understanding which CMMC level your existing and target contracts require. For most contractors, this means reviewing current contract DFARS clauses and anticipated future solicitation requirements. Complete a NIST 800-171 self-assessment to establish your baseline SPRS score and identify gaps.
Review the CMMC framework guide for the full assessment process. Explore the NIST 800-171 framework page and the NIST 800-53 framework page for detailed control guidance. Compare compliance automation platforms to find tooling that supports CMMC-specific evidence collection and SSP management.