AuditXYZ

Compliance Framework

Cybersecurity Maturity Model Certification (CMMC) 2.0 (CMMC)

CMMC 2.0 is the DoD's framework for verifying cybersecurity practices among defense contractors. Learn about the three certification levels and how to prepare for assessment.

$20,000–$300,0003–18 monthsAudit Required2.0 (2024)
Issuing BodyUnited States Department of Defense (DoD)
First Published2020-01-31
Latest Version2.0 (2024)
Typical Cost$20,000–$300,000
Typical Timeline3–18 months
Audit RequiredYes
Audit FrequencyLevel 1: annual self-assessment. Level 2: triennial third-party assessment (C3PAO) or annual self-assessment depending on contract. Level 3: triennial government-led assessment.
Geographyunited-states

CMMC: Cybersecurity Maturity Model Certification Guide

The Cybersecurity Maturity Model Certification (CMMC) is the U.S. Department of Defense's program for verifying that defense contractors adequately protect sensitive information. CMMC 2.0, finalized in 2024, streamlined the model from five levels to three and aligned directly with existing NIST standards.

What CMMC Covers

CMMC 2.0 defines three certification levels:

Level 1 (Foundational) — 17 basic cyber hygiene practices derived from FAR 52.204-21, protecting Federal Contract Information (FCI). Covers basic access control, identification, media protection, physical protection, system protection, and system integrity.

Level 2 (Advanced) — 110 practices directly mapped to NIST SP 800-171 Rev 2, protecting Controlled Unclassified Information (CUI). This is the most common level required for defense contracts involving CUI.

Level 3 (Expert) — All Level 2 requirements plus additional practices from NIST SP 800-172, protecting CUI against advanced persistent threats. Required for the most sensitive programs.

Who Needs CMMC

Any organization in the Defense Industrial Base (DIB) that handles FCI or CUI will need CMMC certification. This includes prime contractors, subcontractors, and suppliers at every tier of the defense supply chain. An estimated 200,000+ companies will need some level of CMMC certification.

CMMC requirements will be phased into DoD contracts starting in 2025. Organizations without the required CMMC level will be ineligible to bid on or continue performing affected contracts.

Assessment Process

Level 1 — Annual self-assessment with senior official affirmation. Results reported to the Supplier Performance Risk System (SPRS).

Level 2 (Third-Party) — Assessment by a CMMC Third-Party Assessor Organization (C3PAO). The assessor evaluates all 110 practices, and the organization must demonstrate implementation with evidence. Certification is valid for three years.

Level 2 (Self-Assessment) — Permitted for certain contracts with lower CUI sensitivity. Annual self-assessment with SPRS reporting.

Level 3 — Government-led assessment conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).

Preparation Steps

  1. Determine required level — Review current and anticipated contracts for CMMC requirements
  2. Scope your environment — Identify all systems that process, store, or transmit FCI/CUI
  3. Conduct gap assessment — Compare current practices against required controls
  4. Create SSP and POA&M — Document your system security plan and remediation milestones
  5. Implement controls — Deploy required technical, administrative, and physical safeguards
  6. Self-assess — Score your implementation using the DoD assessment methodology
  7. Engage C3PAO — For Level 2 third-party assessment, schedule your certification audit

Common Challenges

The most challenging aspects for small and mid-size defense contractors include defining the CUI boundary, implementing multi-factor authentication across all CUI-handling systems, establishing a security operations capability for monitoring, and managing the cost of compliance relative to contract value.

CMMC Phased Rollout: Current Status

The CMMC program's phased rollout began in December 2024 following finalization of the CMMC rule (32 CFR Part 170). The rollout follows a phased implementation schedule:

Phase 1 (from December 2024) — CMMC Level 1 self-assessment and Level 2 self-assessment requirements may be included in new DoD contracts. Contracting officers can include CMMC requirements in contracts at their discretion.

Phase 2 (from late 2025) — Level 2 C3PAO assessment requirements become widely mandated in new contracts involving CUI. Existing contracts that are modified or renewed will begin incorporating CMMC requirements.

Phase 3 (from 2026) — Level 3 government-led assessment requirements begin appearing in contracts involving critical programs. Level 2 self-assessment option is phased out for contracts requiring third-party assessment.

Phase 4 (from 2027) — Full implementation. All applicable DoD contracts include CMMC requirements at the appropriate level.

Organizations that have not yet started their CMMC journey should treat Phase 2 as an urgent timeline. Missing CMMC requirements when contracts require them means inability to compete.

The Three Certification Levels in Detail

Level 1 — Foundational (17 practices) protects Federal Contract Information (FCI) — information provided by or generated for the government under contract, not intended for public release. The 17 practices derive from FAR clause 52.204-21 and cover basic access control (limiting system access to authorized users), identification of users, media protection (disposal of media containing FCI), physical protection, system and communications protection, and system integrity (malware defenses). Annual self-assessment by a senior company official is required.

Level 2 — Advanced (110 practices) protects Controlled Unclassified Information (CUI) against serious cyber threats. All 110 practices map directly to NIST SP 800-171 Rev 2 requirements. This level is required for the vast majority of defense contracts involving CUI. For most contracts, a third-party assessment by a C3PAO is required every three years. For certain contracts with lower CUI sensitivity, annual self-assessment is permitted. The distinction between self-assessment and C3PAO-assessed contracts is determined by the program manager based on information sensitivity.

Level 3 — Expert (110+ practices) protects CUI in programs where advanced persistent threats (APTs) are a realistic concern. In addition to all Level 2 requirements, Level 3 includes additional practices from NIST SP 800-172, which addresses enhanced security requirements against sophisticated adversaries. Level 3 assessments are conducted by the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). The number of contracts requiring Level 3 is relatively small — primarily advanced weapons systems and highly sensitive research programs.

The C3PAO Assessment Experience

For organizations pursuing Level 2 third-party certification, understanding the C3PAO process is essential.

C3PAO selection — Only organizations on the Cyber AB Marketplace can conduct CMMC Level 2 assessments. Request quotes from multiple C3PAOs. Prices vary significantly; so does assessor experience with your industry vertical.

Assessment preparation — The C3PAO reviews your System Security Plan, POA&M, and evidence artifacts before scheduling the on-site visit. Organizations with well-organized evidence in a compliance automation platform typically see shorter, lower-cost assessments.

On-site or remote assessment — Assessors evaluate all 110 practices through document review, interviews, and limited testing. They verify evidence for each practice and assign a finding of MET, NOT MET, or NOT APPLICABLE.

CMMC Level 2 recommendation — If all practices are MET (or NOT APPLICABLE), the C3PAO recommends Level 2 certification to the Cyber AB. If any practices are NOT MET, the organization receives a conditional recommendation contingent on closing findings within a defined period.

Cyber AB certification decision — The Cyber Accreditation Body makes the final certification decision based on the C3PAO's report. Certificates are valid for three years.

Costs and Timeline

ComponentLow EstimateHigh Estimate
CUI scoping and SSP development$10,000$40,000
Gap assessment$10,000$30,000
Control implementation and remediation$20,000$200,000
C3PAO assessment (Level 2)$30,000$150,000
SPRS reporting setup$2,000$5,000
Compliance tooling$5,000$20,000
Total Level 2 (C3PAO path)$77,000$445,000

Timeline: 3 to 18 months. Small defense contractors with limited IT environments and existing NIST 800-171 programs trend toward 3 to 6 months. Large manufacturers with complex, multi-site environments may take 12 to 18 months.

CMMC vs. NIST 800-171 — About 95% overlap. CMMC Level 2 directly implements all 110 NIST 800-171 requirements. The key difference is verification: CMMC provides third-party certification that NIST 800-171 self-assessment lacks. Organizations with a mature NIST 800-171 self-assessment program are well-positioned for CMMC Level 2 but still need to prepare for the third-party assessment rigor. See /frameworks/security-governance/nist-800-171.

CMMC vs. NIST 800-53 — About 70% overlap. CMMC Level 2 maps to NIST 800-53 Moderate baseline controls that underlie NIST 800-171. Organizations already implementing NIST 800-53 (for example, FedRAMP organizations) have addressed most CMMC Level 2 requirements.

CMMC vs. ISO 27001 — About 60% overlap. ISO 27001 provides a governance and management system framework that aligns well with CMMC's organizational and process controls. CUI-specific requirements and the SPRS reporting obligation are unique to CMMC. Organizations with ISO 27001 have strong documentation and risk management foundations that accelerate CMMC preparation.

How Automation Helps

CMMC evidence management is substantial — 110 practices, each requiring documented evidence for C3PAO review, with continuous monitoring evidence spanning a three-year certification period. Manual evidence management at this scale creates inconsistency and gaps that assessors flag.

LowerPlane supports CMMC Level 2 alongside NIST 800-171 and its 50-plus framework library. Continuous evidence collection from cloud and on-premises environments, mapped to all 110 practices, significantly reduces assessment preparation time. At $4,000/year entry pricing with a free tier, it is accessible for defense contractors across the size spectrum. AuditXYZ rates it 9.4/10. Compare at Best Compliance Automation Platforms.

Frequently Asked Questions

What is CUI and how do I know if I have it? Controlled Unclassified Information is government-created or government-owned information that must be safeguarded under law, regulation, or policy. If your contracts include DFARS clause 252.204-7012 or reference handling CUI, you handle it. The National Archives CUI Registry lists all CUI categories. Common examples include technical drawings for defense systems, pre-decisional budget information, law enforcement sensitive data, and export-controlled technical data.

What is the difference between a C3PAO assessment and a DIBCAC assessment? C3PAO assessments are conducted by commercial organizations accredited by the Cyber Accreditation Body to certify Level 2 compliance. DIBCAC assessments are government-led assessments conducted by the Defense Contract Management Agency for Level 3 certification. Only a very small number of contracts require Level 3.

Can we start a contract before achieving CMMC certification? Once CMMC requirements appear in a contract, you must hold the required CMMC level to be awarded the contract. For renewal contracts, you must achieve certification before the contract modification that introduces CMMC requirements takes effect. Organizations currently performing on contracts without CMMC requirements have a window to achieve certification before their contract modifications.

What happens if we fail our C3PAO assessment? The C3PAO provides a conditional recommendation with specific NOT MET findings. You then have a defined period (typically 90 to 180 days) to remediate those findings and request a follow-up review. Multiple NOT MET findings in critical areas may require a full reassessment. Certification is not achieved until all 110 practices are MET or documented as NOT APPLICABLE with sufficient justification.

Request a CMMC consultation

Step 1 of 520%

Which framework do you need?

Framework Mappings

Overlap with other frameworks

NIST SP 800 171High95%
NIST SP 800 53Medium70%
ISO 27001Medium60%

Get matched with a CMMC auditor in 24 hours

Free, no-obligation — just tell us your email and we'll do the rest.

By submitting, you agree to our privacy policy.

Recommended Tools