What Federal Contractors Need to Know About CMMC Compliance

Introduction

Miss a CMMC requirement and you don't just lose a certification — you lose the contract. As of November 10, 2025, the DoD's acquisition rule under 48 CFR is active, meaning CMMC requirements now appear directly in solicitations and must be satisfied before award.

This guide is written for prime contractors, subcontractors, compliance officers, and program managers across the Defense Industrial Base (DIB). If your organization stores, processes, or transmits Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) under a DoD contract, this affects you directly.

This guide covers what CMMC 2.0 is, who must comply, what each level requires, where the rollout timeline stands today, and the concrete steps to get your organization audit-ready.

Key Takeaways

  • Phase 1 enforcement is live under 48 CFR as of November 10, 2025 — CMMC is no longer pending
  • 337,968 entities are estimated to be affected, with ~118,000 requiring Level 2 C3PAO certification
  • Only 1,391 final Level 2 certificates had been issued as of May 2026 — assessor capacity is the binding constraint
  • Compliance takes 6–18 months to achieve — start before the contract language arrives, not after
  • Flowdown requirements bind every subcontractor tier, not just prime contractors

What Is CMMC 2.0 and Why Federal Contractors Must Act Now

The Framework in Plain Terms

The Cybersecurity Maturity Model Certification is a DoD-mandated framework that verifies defense contractors are meeting cybersecurity requirements to protect FCI and CUI within the DIB. A common misconception: CMMC doesn't introduce new cybersecurity requirements. It enforces and verifies compliance with standards — primarily NIST SP 800-171 — that DIB contractors were already obligated to meet under DFARS 252.204-7012.

The critical shift is in verification: contractors previously self-reported compliance, and now they must demonstrate it.

The Shift from CMMC 1.0 to 2.0

The framework was streamlined from five maturity levels to three. Key changes:

  • Existing NIST standards were aligned more cleanly to each level
  • Self-assessment became allowable at Level 1 (and in limited Level 2 cases)
  • Enforcement was tightened for contractors handling sensitive CUI

What 48 CFR Actually Changed

The DFARS acquisition rule published September 10, 2025, effective November 10, 2025, made CMMC enforceable inside actual contracts. CMMC level requirements now appear in solicitations. Meeting them is a condition of award — not a future obligation.

The current clause landscape:

  • DFARS 252.204-7012 (safeguarding and incident reporting) — remains in force
  • DFARS 252.204-7021 (the CMMC clause) — remains in force
  • DFARS 252.204-7019 — eliminated by a February 2026 class deviation
  • DFARS 252.204-7020 — replaced by a new deviation clause consolidating self-assessment and SPRS upload requirements under the CMMC framework

Your SPRS Score Is Already Visible

Those clause changes have a direct operational consequence. Contractors must submit their NIST SP 800-171 assessment score to the Supplier Performance Risk System (SPRS). Contracting officers check SPRS for required CMMC status before award, option exercise, or performance extension. A missing or low score is visible to every contracting officer evaluating your bids.


Who Needs to Comply with CMMC?

Scope: The Entire Supply Chain

CMMC applies to all entities in the DoD supply chain — primes and subcontractors at every tier — who store, process, or transmit FCI or CUI. The 2025 acquisition rule estimates 337,968 affected entities in year four and beyond, including 118,289 requiring Level 2 C3PAO certification.

The Subcontractor Flowdown Problem

Prime contractors must ensure their subcontractors hold a current CMMC certificate or completed self-assessment at the level appropriate to the information flowing down to them. Many small and mid-size subcontractors assume CMMC only applies to primes. That assumption can disqualify an entire contract award.

Who Is Exempt

  • Contracts exclusively for Commercially Available Off-the-Shelf (COTS) items
  • Contracts below the micro-purchase threshold
  • No exemption exists for FAR Part 12 commercial product or service contracts

What Triggers Your Required Level

The type of information you handle determines your level:

Information Type Required Level
FCI only Level 1
CUI within the Defense Organizational Index Grouping Level 2 C3PAO certification
CUI outside the Defense Organizational Index Level 2 self-assessment
Most sensitive CUI / advanced technologies Level 3

CMMC 2.0 compliance level requirements by information type comparison table

CMMC 2.0 Levels Explained

Level 1 — Foundational

Applies to organizations handling FCI only. Requires compliance with 15 basic safeguarding practices from FAR 52.204-21. Organizations self-assess annually and a senior official must affirm compliance in SPRS each year. No POA&M is permitted at this level.

For most contractors without CUI exposure, Level 1 is the ceiling — and the annual self-affirmation is the primary compliance obligation.

Level 2 — Advanced

Applies to organizations handling CUI. Requires implementation of all 110 security controls in NIST SP 800-171 Rev. 2. Two tracks exist:

  • Self-assessment track: For contractors handling CUI outside the Defense Organizational Index Grouping. Assessed every three years with annual affirmations.
  • C3PAO certification track: Required for contractors handling defense-organizational CUI. A CMMC Third Party Assessment Organization (C3PAO) — authorized by the Cyber AB to conduct formal CMMC assessments — performs the evaluation every three years, with annual affirmations in between.

The capacity problem is real. As of May 2026, only 1,391 final Level 2 certificates had been issued, against an estimated 118,000+ organizations subject to CMMC requirements. The Cyber AB reported approximately 104 authorized C3PAOs as of May 2026 — with one assessor noting capacity of roughly 250 assessments annually. Assessment slots are already constrained, with National Defense reporting a significant capacity squeeze across the ecosystem.

Level 3 — Expert

Level 3 applies to contractors handling the most sensitive CUI: breakthrough technologies, significant aggregations, or systems where a single compromise creates broad DoD exposure. Requires:

  • All 110 NIST SP 800-171 controls
  • 24 additional enhanced controls from NIST SP 800-172
  • Assessment conducted directly by DCMA's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) every three years

Level 3 is not a standalone path. Organizations must hold a final Level 2 C3PAO certification before DIBCAC will schedule a Level 3 assessment.


CMMC Rollout Timeline: Four Phases Through 2028

The phased implementation began November 10, 2025. Important update: On July 13, 2026, DoD suspended the transition to Phase 2 to conduct a program review. CMMC remains in Phase 1; no replacement Phase 2 date has been announced. The original phase structure is below, with current status noted.

Phase Dates Scope
Phase 1 (Active) Nov 10, 2025 – Nov 10, 2026 Level 1 and Level 2 self-assessments required as award conditions; DoD may require C3PAO at discretion
Phase 2 (Suspended) Beginning Nov 10, 2026 Level 2 C3PAO intended as standard award condition; Level 3 begins appearing in limited contracts
Phase 3 Beginning Nov 10, 2027 Level 2 C3PAO extends to existing contracts; Level 3 required on applicable contracts
Phase 4 Beginning Nov 10, 2028 Full CMMC enforcement across all applicable contracts above micro-purchase threshold

CMMC rollout four-phase implementation timeline from 2025 to 2028 enforcement

The Practical Reality

The Phase 2 suspension buys time on paper — it does not reduce the readiness work ahead. Industry guidance from National Defense puts readiness timelines at 6–18 months or longer, depending on current readiness level. Subcontractors may receive flowdown requirements from primes before any formal phase deadline applies to them directly. Contractors waiting for explicit contract language will find certified assessors already booked when the requirement lands.


How to Achieve CMMC Compliance: A Practical Roadmap

Step 1: Determine Your Required Level

Review current and anticipated contracts to identify whether you handle FCI or CUI. Consult the DoD CUI Registry to determine whether your CUI falls under the Defense Organizational Index Grouping — this determines whether you need a C3PAO assessment or can self-assess.

Step 2: Conduct a Gap Assessment Against NIST SP 800-171

Map your current security controls against all 110 requirements in NIST SP 800-171 Rev. 2. Document gaps in a Plan of Action and Milestones (POA&M). Key considerations:

  • Identify inherited controls from cloud service providers vs. controls your team must independently implement
  • Cloud providers handling CUI must meet the FedRAMP Moderate baseline or equivalent
  • POA&M items must be closed within 180 days to convert conditional assessment status to final

Step 3: Build Your Required Documentation

For Level 2, contractors must maintain:

  • System Security Plan (SSP) — the first artifact a C3PAO assessor reviews
  • POA&M — reflecting actual gap closure status, not a template
  • Standard Operating Procedures (SOPs) — as assessment evidence objects
  • Customer Responsibility Matrix — required when external service providers share control responsibility

Documentation is where most contractors are caught unprepared. Having controls in place is not sufficient without organized evidence proving implementation. Assessors use Examine, Interview, and Test methodology — all applicable assessment objectives must be supported by final, non-draft evidence.

CMMC Level 2 required documentation artifacts SSP POA&M SOPs and evidence overview

Step 4: Build Internal Compliance Capability

CMMC is not a one-time certification. It requires ongoing adherence, annual affirmations, and the organizational capacity to maintain and evidence controls between assessments. Contractors who rely entirely on external consultants to pass an assessment but have no internal capability to sustain controls will face the same gaps at reassessment.

Building that internal capability means assigning named owners, maintaining live documentation, and practicing the assessment process before it happens. QMS Learning's Defense Cybersecurity Readiness pathway — covering CMMC, NIST 800-171, ISO 27001, and SOC 2 — is built specifically for this. The pathway trains CISOs, IT directors, compliance officers, and program managers to:

  • Own all 14 NIST SP 800-171 control families with named internal owners
  • Build and maintain live SSPs and POA&Ms that reflect the actual environment
  • Practice the specific questions a C3PAO assessor will ask — before the assessment
  • Generate compliant artifacts using an AI Workbench trained on NIST SP 800-171, CMMC assessment guides, and DFARS clause requirements

The Manager Dashboard exports an indexed Audit-Evidence Package PDF — training records, completed scenario logs, AI-generated artifacts, and timestamped activity — structured as objective evidence a C3PAO assessor can review directly. A pilot cohort opens Q3 2026. The goal: internal teams that own the process at reassessment, not just at initial certification.

QMS Learning Defense Cybersecurity Readiness training dashboard showing audit evidence package

Step 5: Select a C3PAO and Schedule Early

Given the limited number of authorized assessors relative to demand, contractors needing C3PAO certification should begin selection immediately — not after remediation is complete. Key factors in evaluating a C3PAO:

  • Federal framework experience and CMMC-specific assessment history
  • Quality and completeness of assessment reporting
  • Timeline availability (slots are constrained well in advance)

Frequently Asked Questions

What does CMMC compliant mean?

CMMC compliance means an organization has met the DoD's cybersecurity requirements for its applicable level — verified through self-assessment (Level 1 and some Level 2) or third-party certification by an authorized C3PAO (most Level 2 and all Level 3). Compliance is required to receive and perform DoD contracts involving FCI or CUI.

Is CMMC compliance mandatory?

Yes. As of November 10, 2025, CMMC requirements are mandatory conditions of award for applicable DoD contracts under 48 CFR. Prime contractors and subcontractors handling FCI or CUI must meet their required level to win or renew contracts. COTS-only contracts are exempt.

How much does it cost to get CMMC compliant?

DoD estimates Level 2 C3PAO certification for a small entity — including planning, assessment, reporting, C3PAO fees, and three years of annual affirmations — at approximately $104,670 in 2023 dollars. Costs vary significantly based on your current compliance posture and how much remediation is needed before assessment.

How do I become CMMC compliant?

The path to compliance follows five steps:

  1. Determine your required level (Level 1, 2, or 3) based on the data you handle
  2. Conduct a gap assessment against NIST SP 800-171
  3. Remediate gaps and build required documentation — SSP, POA&M, and SOPs
  4. Train your team to manage and evidence controls on an ongoing basis
  5. Complete self-assessment or engage a C3PAO for certification, depending on your level

Does CMMC apply to subcontractors?

Yes — CMMC flows down through the supply chain. Prime contractors must ensure subcontractors hold a current certificate or self-assessment at the level appropriate to the information being passed to them. Subcontractors should not wait for prime notification — assess your exposure now.

What is the difference between CMMC Level 1, Level 2, and Level 3?

Level 1 covers 15 basic practices for FCI-only contractors with annual self-assessment. Level 2 requires all 110 NIST SP 800-171 controls for CUI contractors, with most requiring C3PAO certification every three years. Level 3 adds 24 enhanced NIST SP 800-172 controls for the most sensitive CUI, assessed directly by DIBCAC every three years.