Want to learn more about our services? Book a free introductory call - "Here"

What is CMMC? What Is CMMC? A Practical Overview for Defense Contractors

CMMC stands for Cybersecurity Maturity Model Certification.

CMMC does not introduce an entirely separate set of security controls. It creates a structured assessment process around requirements that come primarily from:

  • FAR 52.204-21

  • NIST SP 800-171

  • Selected requirements from NIST SP 800-172

  • Applicable DFARS cybersecurity clauses

It is the Department of Defense framework used to assess whether contractors and subcontractors have implemented the cybersecurity requirements needed to protect sensitive, unclassified government information.

The goal is straightforward:

Organizations that handle sensitive defense information must be able to demonstrate that the required safeguards are actually in place.

Why was CMMC created?

The Defense Industrial Base includes hundreds of thousands of organizations that design, manufacture, transport, maintain, support, and protect products and services used by the Department of Defense.

Many of these organizations operate outside government networks but still receive sensitive contract information.

Cyberattacks against a contractor can expose:

  • Technical drawings

  • Engineering specifications

  • Contract information

  • Manufacturing data

  • System configurations

  • Operational information

  • Supply-chain information

CMMC gives the Department of Defense a consistent method for verifying that contractors and subcontractors are protecting this information.

What Information Does CMMC Protect?

The required CMMC level depends largely on the type of information an organization processes, stores, or transmits.

Federal Contract Information, commonly called FCI, is nonpublic information provided by or generated for the government under a contract.

Examples may include:

  • Contract schedules

  • Delivery information

  • Internal project communications

  • Nonpublic contract documents

  • Information related to contract performance

FCI does not include information intended for public release.

Organizations that handle FCI but not CUI are generally associated with CMMC Level 1 requirements when CMMC applies to the contract.

Controlled Unclassified Information, commonly called CUI, is information that requires safeguarding or dissemination controls under federal law, regulation, or government-wide policy.

Examples may include:

  • Controlled technical information

  • Engineering drawings

  • Military system specifications

  • Export-controlled information

  • Certain research and development data

  • Sensitive logistics or maintenance information

Organizations that process, store, or transmit CUI in support of a DoD contract are generally associated with CMMC Level 2 or, in limited cases, Level 3.

Not every sensitive-looking document is automatically CUI!

CUI status must come from an authorized government source and should be supported by proper contract language, markings, or program guidance.

The three CMMC Levels

CMMC uses three levels based on the type and sensitivity of the information being protected.

Purpose: Basic safeguarding of FCI

Level 1 is based on the 15 safeguarding requirements found in FAR 52.204-21.

Key points:

  • Intended for systems that process, store, or transmit FCI

  • Requires an annual self-assessment

  • Requires annual affirmation by an authorized company official

  • Results are submitted through SPRS

  • All requirements must be met

  • Plans of Action and Milestones are not permitted

Level 1 is not simply a checklist. The organization must be able to show that each applicable safeguarding requirement is implemented.

Purpose: Broad protection of CUI

Level 2 is based on the 110 security requirements in NIST SP 800-171 Revision 2.

Key points:

  • Intended for systems that process, store, or transmit CUI

  • May require a self-assessment or a C3PAO assessment

  • The required assessment type is determined by the contract

  • Final Level 2 status is generally valid for three years

  • Annual affirmation is required

  • Limited use of Plans of Action and Milestones may be permitted

  • Assessment results and status are recorded in government systems

A C3PAO is a Certified Third-Party Assessment Organization authorized to conduct CMMC Level 2 certification assessments.

Handling CUI does not automatically tell you whether your Level 2 assessment will be self-conducted or performed by a C3PAO. The solicitation or contract determines the required assessment type.

Level 3 is intended for selected programs involving especially sensitive CUI or greater cybersecurity risk.

Key points:

  • Builds upon the Level 2 requirements

  • Includes selected enhanced requirements from NIST SP 800-172

  • Requires Final Level 2 C3PAO status before the Level 3 assessment

  • Assessments are performed by DCMA DIBCAC

  • Final status is generally valid for three years

  • Annual affirmation is required

Level 3 will apply to a much smaller group of defense contractors than Levels 1 and 2.

Purpose: Enhanced protection of CUI against advanced threats

Who Determines the Required Level?

A company does not simply choose its preferred CMMC level.

The required level and assessment type are established through the DoD contracting process and identified in the applicable solicitation or contract.

The decision is based on factors such as:

  • Whether the contractor will handle FCI

  • Whether the contractor will handle CUI

  • The sensitivity of the information

  • The systems used to perform the contract

  • Program-specific cybersecurity risk

  • Applicable FAR and DFARS clauses

Prime contractors must also communicate and flow down applicable CMMC requirements to subcontractors.

CMMC Applies Beyond Prime Contractors

CMMC is not limited to large companies contracting directly with the Department of Defense.

Requirements can extend throughout the supply chain to organizations such as:

  • Subcontractors

  • Machine shops

  • Manufacturers

  • Engineering companies

  • Software developers

  • Managed service providers

  • Cloud service providers

  • Logistics providers

  • Testing laboratories

  • Professional service providers

The important question is not simply whether the company considers itself a defense contractor.

The important question is whether its people, systems, or service providers process, store, transmit, or protect FCI or CUI for a DoD contract or subcontract.

Understanding CMMC Scope

CMMC does not automatically require every device, location, and business system in the company to be assessed.

The assessment scope is based on the systems, assets, people, facilities, and service providers connected to the contract information.

Depending on the required level, scope may include:

  • Workstations

  • Servers

  • Networks

  • Cloud environments

  • Business applications

  • Security tools

  • Employees

  • Physical locations

  • External service providers

  • Systems that provide security protection

Poor scoping can make a CMMC project unnecessarily expensive.

It can also create serious assessment problems if systems or service providers that should have been included are left out.

Scope should be defined before major technology or compliance decisions are made.

The Basic CMMC Process

A typical CMMC readiness effort follows several stages.

1. Review the Contract

Identify the applicable FAR and DFARS clauses, required CMMC level, assessment type, and information-handling requirements.

2. Identify FCI and CUI

Determine what protected information the organization receives, creates, stores, processes, and transmits.

3. Define the Assessment Scope

Identify the systems, users, locations, service providers, and security assets connected to the protected information.

4. Assess the Current Environment

Compare the organization’s existing practices against the requirements for the applicable CMMC level.

5. Remediate Gaps

Implement missing technical, physical, and administrative safeguards.

6. Document the Environment

Develop the policies, procedures, system security plan, diagrams, inventories, and supporting documentation needed to explain how the requirements are met.

7. Collect Evidence

Confirm that the safeguards are operating and that objective evidence is available.

8. Complete the Required Assessment

Conduct the applicable self-assessment, C3PAO assessment, or government-led assessment.

9. Affirm and Maintain Compliance

Submit the required affirmation and continue operating, monitoring, and maintaining the safeguards after the assessment.

CMMC Is More Than Documentation

Policies and procedures are important, but documents alone do not establish compliance.

An assessor may examine:

  • System configurations

  • User accounts

  • Access permissions

  • Security logs

  • Technical settings

  • Network diagrams

  • Training records

  • Incident-response activities

  • Interviews with employees

  • Evidence that procedures are followed

A written policy that does not match the real environment can create more problems than having no policy at all.

The documented process, technical implementation, employee explanation, and assessment evidence must support the same conclusion.

CMMC Is Not a One-Time Project

Achieving the required CMMC status does not end the organization’s responsibility.

Cybersecurity requirements must continue to operate throughout the life of the contract.

Organizations must maintain:

  • Required security controls

  • Accurate system documentation

  • Current assessment scope

  • Supporting evidence

  • Annual affirmations

  • Employee awareness

  • Incident-reporting capabilities

  • Oversight of external service providers

Changes to systems, locations, cloud services, personnel, or contract scope can affect continued compliance.

Current Implementation Status

As of August 2026, CMMC Phase I self-assessment requirements remain in effect. The Department of Defense suspended the planned implementation of Phase II while it reviews the program.

Organizations should not interpret that suspension as the end of CMMC or the removal of existing cybersecurity obligations.

NIST SP 800-171, FAR, DFARS, SPRS, incident-reporting, and contract-specific requirements may still apply independently of a future third-party CMMC assessment.

Because implementation policy can change, organizations should verify current requirements against official guidance and the language in each solicitation or contract.

The Main Takeaway

CMMC is a contract-driven cybersecurity assessment program for organizations supporting the Department of Defense.

The required level depends on the information handled and the requirements included in the contract.

The most important early steps are to:

  • Review the contract

  • Determine whether FCI or CUI is involved

  • Identify the required CMMC level and assessment type

  • Define the correct scope

  • Understand the current gaps

  • Build evidence before the assessment

If your organization supports defense work and is unsure where it stands, start with the contract and the information flow.

Those two areas usually determine whether CMMC applies and what the organization must do next.

Copyright © 2026 ICTS USA LLC - All Rights Reserved.