Want to learn more about our services? Book a free introductory call - "Here"
What is CMMC? What Is CMMC? A Practical Overview for Defense Contractors
CMMC stands for Cybersecurity Maturity Model Certification.
CMMC does not introduce an entirely separate set of security controls. It creates a structured assessment process around requirements that come primarily from:
FAR 52.204-21
NIST SP 800-171
Selected requirements from NIST SP 800-172
Applicable DFARS cybersecurity clauses
It is the Department of Defense framework used to assess whether contractors and subcontractors have implemented the cybersecurity requirements needed to protect sensitive, unclassified government information.
The goal is straightforward:
Organizations that handle sensitive defense information must be able to demonstrate that the required safeguards are actually in place.
Why was CMMC created?
The Defense Industrial Base includes hundreds of thousands of organizations that design, manufacture, transport, maintain, support, and protect products and services used by the Department of Defense.
Many of these organizations operate outside government networks but still receive sensitive contract information.
Cyberattacks against a contractor can expose:
Technical drawings
Engineering specifications
Contract information
Manufacturing data
System configurations
Operational information
Supply-chain information
CMMC gives the Department of Defense a consistent method for verifying that contractors and subcontractors are protecting this information.
What Information Does CMMC Protect?
The required CMMC level depends largely on the type of information an organization processes, stores, or transmits.
Federal Contract Information, commonly called FCI, is nonpublic information provided by or generated for the government under a contract.
Examples may include:
Contract schedules
Delivery information
Internal project communications
Nonpublic contract documents
Information related to contract performance
FCI does not include information intended for public release.
Organizations that handle FCI but not CUI are generally associated with CMMC Level 1 requirements when CMMC applies to the contract.
Controlled Unclassified Information, commonly called CUI, is information that requires safeguarding or dissemination controls under federal law, regulation, or government-wide policy.
Examples may include:
Controlled technical information
Engineering drawings
Military system specifications
Export-controlled information
Certain research and development data
Sensitive logistics or maintenance information
Organizations that process, store, or transmit CUI in support of a DoD contract are generally associated with CMMC Level 2 or, in limited cases, Level 3.
Not every sensitive-looking document is automatically CUI!
CUI status must come from an authorized government source and should be supported by proper contract language, markings, or program guidance.

The three CMMC Levels
CMMC uses three levels based on the type and sensitivity of the information being protected.
Purpose: Basic safeguarding of FCI


Level 1 is based on the 15 safeguarding requirements found in FAR 52.204-21.
Key points:
Intended for systems that process, store, or transmit FCI
Requires an annual self-assessment
Requires annual affirmation by an authorized company official
Results are submitted through SPRS
All requirements must be met
Plans of Action and Milestones are not permitted
Level 1 is not simply a checklist. The organization must be able to show that each applicable safeguarding requirement is implemented.




Purpose: Broad protection of CUI
Level 2 is based on the 110 security requirements in NIST SP 800-171 Revision 2.
Key points:
Intended for systems that process, store, or transmit CUI
May require a self-assessment or a C3PAO assessment
The required assessment type is determined by the contract
Final Level 2 status is generally valid for three years
Annual affirmation is required
Limited use of Plans of Action and Milestones may be permitted
Assessment results and status are recorded in government systems
A C3PAO is a Certified Third-Party Assessment Organization authorized to conduct CMMC Level 2 certification assessments.
Handling CUI does not automatically tell you whether your Level 2 assessment will be self-conducted or performed by a C3PAO. The solicitation or contract determines the required assessment type.
Level 3 is intended for selected programs involving especially sensitive CUI or greater cybersecurity risk.
Key points:
Builds upon the Level 2 requirements
Includes selected enhanced requirements from NIST SP 800-172
Requires Final Level 2 C3PAO status before the Level 3 assessment
Assessments are performed by DCMA DIBCAC
Final status is generally valid for three years
Annual affirmation is required
Level 3 will apply to a much smaller group of defense contractors than Levels 1 and 2.
Purpose: Enhanced protection of CUI against advanced threats
Who Determines the Required Level?
A company does not simply choose its preferred CMMC level.
The required level and assessment type are established through the DoD contracting process and identified in the applicable solicitation or contract.
The decision is based on factors such as:
Whether the contractor will handle FCI
Whether the contractor will handle CUI
The sensitivity of the information
The systems used to perform the contract
Program-specific cybersecurity risk
Applicable FAR and DFARS clauses
Prime contractors must also communicate and flow down applicable CMMC requirements to subcontractors.
CMMC Applies Beyond Prime Contractors
CMMC is not limited to large companies contracting directly with the Department of Defense.
Requirements can extend throughout the supply chain to organizations such as:
Subcontractors
Machine shops
Manufacturers
Engineering companies
Software developers
Managed service providers
Cloud service providers
Logistics providers
Testing laboratories
Professional service providers
The important question is not simply whether the company considers itself a defense contractor.
The important question is whether its people, systems, or service providers process, store, transmit, or protect FCI or CUI for a DoD contract or subcontract.
Understanding CMMC Scope
CMMC does not automatically require every device, location, and business system in the company to be assessed.
The assessment scope is based on the systems, assets, people, facilities, and service providers connected to the contract information.
Depending on the required level, scope may include:
Workstations
Servers
Networks
Cloud environments
Business applications
Security tools
Employees
Physical locations
External service providers
Systems that provide security protection
Poor scoping can make a CMMC project unnecessarily expensive.
It can also create serious assessment problems if systems or service providers that should have been included are left out.
Scope should be defined before major technology or compliance decisions are made.
The Basic CMMC Process
A typical CMMC readiness effort follows several stages.
1. Review the Contract
Identify the applicable FAR and DFARS clauses, required CMMC level, assessment type, and information-handling requirements.
2. Identify FCI and CUI
Determine what protected information the organization receives, creates, stores, processes, and transmits.
3. Define the Assessment Scope
Identify the systems, users, locations, service providers, and security assets connected to the protected information.
4. Assess the Current Environment
Compare the organization’s existing practices against the requirements for the applicable CMMC level.
5. Remediate Gaps
Implement missing technical, physical, and administrative safeguards.
6. Document the Environment
Develop the policies, procedures, system security plan, diagrams, inventories, and supporting documentation needed to explain how the requirements are met.
7. Collect Evidence
Confirm that the safeguards are operating and that objective evidence is available.
8. Complete the Required Assessment
Conduct the applicable self-assessment, C3PAO assessment, or government-led assessment.
9. Affirm and Maintain Compliance
Submit the required affirmation and continue operating, monitoring, and maintaining the safeguards after the assessment.
CMMC Is More Than Documentation
Policies and procedures are important, but documents alone do not establish compliance.
An assessor may examine:
System configurations
User accounts
Access permissions
Security logs
Technical settings
Network diagrams
Training records
Incident-response activities
Interviews with employees
Evidence that procedures are followed
A written policy that does not match the real environment can create more problems than having no policy at all.
The documented process, technical implementation, employee explanation, and assessment evidence must support the same conclusion.
CMMC Is Not a One-Time Project
Achieving the required CMMC status does not end the organization’s responsibility.
Cybersecurity requirements must continue to operate throughout the life of the contract.
Organizations must maintain:
Required security controls
Accurate system documentation
Current assessment scope
Supporting evidence
Annual affirmations
Employee awareness
Incident-reporting capabilities
Oversight of external service providers
Changes to systems, locations, cloud services, personnel, or contract scope can affect continued compliance.
Current Implementation Status
As of August 2026, CMMC Phase I self-assessment requirements remain in effect. The Department of Defense suspended the planned implementation of Phase II while it reviews the program.
Organizations should not interpret that suspension as the end of CMMC or the removal of existing cybersecurity obligations.
NIST SP 800-171, FAR, DFARS, SPRS, incident-reporting, and contract-specific requirements may still apply independently of a future third-party CMMC assessment.
Because implementation policy can change, organizations should verify current requirements against official guidance and the language in each solicitation or contract.
The Main Takeaway
CMMC is a contract-driven cybersecurity assessment program for organizations supporting the Department of Defense.
The required level depends on the information handled and the requirements included in the contract.
The most important early steps are to:
Review the contract
Determine whether FCI or CUI is involved
Identify the required CMMC level and assessment type
Define the correct scope
Understand the current gaps
Build evidence before the assessment
If your organization supports defense work and is unsure where it stands, start with the contract and the information flow.
Those two areas usually determine whether CMMC applies and what the organization must do next.
