- Key Takeaways
- What Does CMMC 2.0 Require?
- When Did the CMMC 2.0 Final Rule Take Effect?
- What Systems and Contractors Are in Scope for CMMC?
- How Do You Assess Your Organization's Current Maturity Level?
- What Is the CMMC Compliance Checklist?
- CMMC Level 1 vs Level 2 vs Level 3: How Do They Compare?
- Update Log: What Changed in This Refresh
- What Are the Limitations of CMMC Compliance?
- What Would Encryption Consulting Recommend?
- Frequently Asked Questions About CMMC Compliance
- Conclusion
Quick answer: The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense’s framework for verifying that contractors handling Controlled Unclassified Information (CUI) meet required cybersecurity standards. It matters because, as of November 10, 2025, DoD contracts are being awarded only to companies that meet their required CMMC level. The recommended first action is a gap analysis against NIST SP 800-171 to find out where your organization stands before a contracting officer or assessor does.
Key Takeaways
- CMMC 2.0 has three levels: Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert), tied to whether a contractor handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).
- The CMMC Program rule (32 CFR Part 170) took effect December 16, 2024, and the DFARS acquisition rule that puts CMMC clauses into contracts (48 CFR, DFARS Case 2019-D041) took effect November 10, 2025.
- CMMC is rolling out in phases over three years, so the level a contract requires depends on when it is awarded, not just what it covers.
- Level 2 maps to the 110 security requirements in NIST SP 800-171 Rev 2; a self-assessment or a third-party C3PAO assessment is required depending on the CUI involved.
- A gap analysis against your applicable level, done before a contracting officer or assessor requires one, is the single most useful step an organization can take right now.
Published: September 2022. Updated: August 2026. Reviewed by Encryption Consulting’s Compliance Advisory team.
If your company touches a Department of Defense contract in any way, direct or through a prime contractor, CMMC is no longer a future requirement to plan around. It is a live acquisition rule. This guide explains what CMMC 2.0 actually requires, when the rule took effect, which systems are in scope, and how to assess and close your organization’s own compliance gaps before it costs you a contract.
What Does CMMC 2.0 Require?
The Cybersecurity Maturity Model Certification (CMMC) is a Department of Defense (DoD) program that verifies a contractor’s cybersecurity practices before it can win or keep a contract involving sensitive information. CMMC 2.0, the current version of the program, requires organizations in the Defense Industrial Base (DIB) to implement and, depending on their level, prove they have implemented a defined set of security controls built primarily on NIST SP 800-171 (National Institute of Standards and Technology Special Publication 800-171).
Two categories of information drive the requirement:
- Federal Contract Information (FCI), information provided by or generated for the government under a contract that is not intended for public release, triggers Level 1.
- Controlled Unclassified Information (CUI), information the government creates or owns that requires safeguarding under law, regulation, or government-wide policy but is not classified, triggers Level 2 or Level 3.
Unlike its 2020 predecessor, CMMC 2.0 dropped the original five-tier structure to three levels, aligned Level 2 directly to the existing NIST SP 800-171 controls contractors already had to self-attest to under DFARS 252.204-7012, and allowed most Level 2 contractors to self-assess rather than requiring a third-party assessment for every contract. The goal, according to the DoD, was to reduce cost and complexity for small and mid-size contractors while keeping the assessment teeth for programs handling the most sensitive CUI.
When Did the CMMC 2.0 Final Rule Take Effect?
Two separate federal rules had to be finalized before CMMC became enforceable in contracts, and the gap between them is a common source of confusion.
| Rule | What It Does | Published | Effective Date |
|---|---|---|---|
| 32 CFR Part 170 (CMMC Program rule) | Establishes the CMMC Program itself: the three levels, the assessment types, and the scoring methodology. | October 15, 2024 (Federal Register) | December 16, 2024 |
| 48 CFR DFARS rule, DFARS Case 2019-D041 | Adds the contract clause (DFARS 252.204-7021) that requires offerors to hold the applicable CMMC level before contract award. | September 10, 2025 (Federal Register) | November 10, 2025 |
November 10, 2025 is the date that matters operationally: DFARS 252.204-7021 started appearing in solicitations and contracts from that date forward. The DoD is phasing CMMC in over roughly three years rather than requiring every contractor to be certified on day one, so whether your specific contract requires CMMC today depends on when it is solicited, not just what it covers. Contracting officers have discretion to include the requirement earlier than the phase schedule calls for, so a contractor should not assume a later phase date guarantees more time.
What Systems and Contractors Are in Scope for CMMC?
CMMC applies to any system, network, or cloud environment that processes, stores, or transmits FCI or CUI on behalf of the DoD. In practice, that means:
- Prime contractors and subcontractors at any tier who handle FCI or CUI, including small businesses that only touch a narrow slice of a larger program.
- Cloud services and managed service providers hosting CUI on a contractor’s behalf, which must meet FedRAMP Moderate equivalency or better.
- Enclaves and segmented environments built specifically to scope CUI handling down to a smaller, more defensible boundary rather than the whole enterprise network.
- Cryptographic infrastructure protecting CUI at rest and in transit, including certificate authorities, key management systems, and hardware security modules (HSMs), which must use validated, DoD-approved cryptography.
A common and expensive mistake is scoping CMMC to the entire company network by default. Most organizations are better served by isolating CUI into a dedicated enclave with its own access controls, encryption, and logging, which shrinks both the assessment boundary and the ongoing compliance burden.
How Do You Assess Your Organization’s Current Maturity Level?
Assessing your maturity level starts with a structured gap analysis, not a certification audit. Before engaging a C3PAO (CMMC Third-Party Assessment Organization) or committing to a level, work through these detection steps:
- Classify your data. Identify every place FCI or CUI enters, moves through, or leaves your environment. This determines whether you need Level 1, Level 2, or Level 3.
- Score yourself against NIST SP 800-171. Run a control-by-control self-assessment using the DoD’s official 110-point scoring methodology and record your Supplier Performance Risk System (SPRS) score honestly, gaps included.
- Review your System Security Plan (SSP) and Plan of Action and Milestones (POA&M). Confirm both exist, are current, and actually reflect your environment, not a template that was never updated.
- Audit your cryptographic controls specifically. Confirm encryption for CUI at rest and in transit uses validated modules, and that key and certificate management is not relying on manual, undocumented processes.
- Identify your assessment path. Determine whether your contracts require self-assessment or a third-party C3PAO assessment, based on the sensitivity of the CUI involved and your target level.
The output of this process should be a scored gap list, not a pass or fail verdict. Every unmet control becomes an input to the remediation checklist below.
What Is the CMMC Compliance Checklist?
Once you know your gaps, work through remediation in this order. Each step builds on the one before it.
- Confirm your target level. Do not default to Level 2 because it sounds safer; over-scoping wastes budget and under-scoping fails an assessment.
- Scope and, where possible, shrink your CUI boundary. Move CUI processing into a dedicated enclave rather than leaving it spread across the full enterprise network.
- Close access control and identity gaps. Multi-factor authentication, least-privilege access, and session logging are consistently among the most-cited findings in real assessments.
- Fix cryptographic gaps. Replace ad hoc key storage and self-managed certificates with a managed PKI and key management program that can produce audit-ready evidence.
- Document everything. Update your SSP, POA&M, and policies so they match what assessors will actually observe, not what was true a year ago.
- Flow requirements down. Confirm subcontractors handling FCI or CUI on your behalf meet the same level; a prime’s CMMC status does not cover an unassessed subcontractor.
- Choose and schedule your assessment path. Book a C3PAO early if a third-party assessment applies; assessor availability is tightening as the phased rollout continues.
- Plan for continuous compliance. CMMC is not a one-time event. Annual affirmations and periodic reassessment mean controls have to hold up on an ongoing basis, not just on assessment day.
CMMC Level 1 vs Level 2 vs Level 3: How Do They Compare?
| Level | Protects | Requirements | Assessment Type | Typical Contracts |
|---|---|---|---|---|
| Level 1 (Foundational) | FCI | 15 basic safeguarding practices (FAR 52.204-21) | Annual self-assessment | Most standard DoD contracts touching FCI only |
| Level 2 (Advanced) | CUI | 110 security requirements aligned to NIST SP 800-171 Rev 2 | Self-assessment or third-party C3PAO assessment, depending on the contract | Contracts involving CUI, the largest share of DIB awards |
| Level 3 (Expert) | CUI at highest risk | Level 2 requirements plus a subset of enhanced requirements from NIST SP 800-172 | Government-led assessment by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) | Programs supporting the DoD’s highest-priority technologies |
Levels are cumulative in effect: an organization certifying at Level 2 must also satisfy the Level 1 practices relevant to its FCI handling, and Level 3 builds directly on Level 2 rather than replacing it.
Update Log: What Changed in This Refresh
This post originally described CMMC under its 2020 framework, which used five certification levels and required third-party assessment for every level. That framework was withdrawn. This August 2026 update reflects CMMC 2.0 as it stands today:
- Replaced the five-level model with the current three-level structure (Foundational, Advanced, Expert).
- Added the confirmed effective dates for both the CMMC Program rule (32 CFR Part 170) and the DFARS acquisition rule that enforces it in contracts.
- Corrected the assessment model: most Level 2 contracts allow self-assessment, not mandatory third-party assessment for every organization.
- Added a practical maturity self-assessment and remediation checklist in place of general framework description.
What Are the Limitations of CMMC Compliance?
CMMC certification is a floor, not a guarantee. A few limitations are worth stating plainly:
- Certification confirms that required controls were in place at the time of assessment. It does not certify that an organization is immune to breach or that every control will remain effective as systems change.
- Phased rollout means two contractors on similar contracts can face different requirements today depending on when their contract was solicited.
- NIST published SP 800-171 Revision 3 in 2024, but the CMMC assessment baseline currently in force still uses Revision 2. Contractors should watch for a future rulemaking that could shift the baseline and plan controls with that transition in mind.
- C3PAO capacity is limited relative to the size of the DIB, so organizations that wait until a contract deadline forces the issue risk long assessment queues.
What Would Encryption Consulting Recommend?
Start with the gap analysis, not the assessment booking. Most organizations we talk to underestimate how much of their CMMC gap is cryptographic: unmanaged encryption keys, self-signed or expired certificates, and no consistent record of what is protecting CUI in transit or at rest. That is exactly the kind of finding that turns a routine assessment into a failed one.
Encryption Consulting’s Compliance Advisory services help DoD contractors map NIST SP 800-171 and CMMC requirements against their actual environment, close cryptographic and key management gaps, and produce the documentation a C3PAO or DIBCAC assessor expects to see. We hold ISO/IEC 27001:2022 and SOC 2 attestations ourselves and are certified as a Texas minority-owned business, credentials that matter when you are choosing a partner to stand behind your compliance posture. For the underlying certificate and key management architecture that most CMMC gap analyses surface as a weak point, our PKI-as-a-Service and HSM-as-a-Service offerings give contractors a validated, audit-ready foundation instead of a patchwork of manually managed keys and certificates.
For the deeper technical relationship between CMMC and DoD cryptographic requirements, including CNSA 2.0, see our related guide, CNSA 2.0 Compliance Guide for Defense Contractors and the DIB. If your CUI environment spans multiple regions or cloud providers, our post on Data Sovereignty and Regional Compliance Challenges in PKIaaS covers how CMMC and ITAR obligations interact with where your data and keys actually live. For a deeper definitional breakdown of CMMC 2.0’s control structure, see our Education Center article, CMMC 2.0 and Cryptography: What Defense Contractors Need to Know.
Frequently Asked Questions About CMMC Compliance
Is CMMC required right now, or is it still being phased in? Both. The rule requiring CMMC in contracts has been in effect since November 10, 2025, but the DoD is phasing full enforcement in over roughly three years. Whether a specific contract requires it today depends on when that contract is solicited, so check each solicitation rather than assuming based on the phase timeline alone.
Can my organization self-certify for CMMC? It depends on your level and the sensitivity of the CUI involved. Level 1 is always a self-assessment. Level 2 can be either a self-assessment or a third-party C3PAO assessment, depending on what the specific contract requires. Level 3 always requires a government-led assessment by DIBCAC.
What happens if my organization does not meet the required CMMC level? You become ineligible for the award or renewal of contracts that carry the DFARS 252.204-7021 clause at your required level. For many contractors, that means losing eligibility for an entire category of DoD work, not just one contract.
Does CMMC apply to subcontractors, or only prime contractors? It applies to any tier that handles FCI or CUI on the government’s behalf. A subcontractor several tiers removed from the DoD can still be required to hold the applicable CMMC level, and a prime’s certification does not cover an unassessed subcontractor.
How long does it take to become CMMC compliant? There is no fixed timeline; it depends on how large your gap is and which level you need. Organizations with mature NIST SP 800-171 programs already in place have closed gaps in a few months. Organizations starting from scratch, especially those with unmanaged cryptographic infrastructure, more commonly need six to twelve months to remediate and schedule an assessment.
Conclusion
CMMC 2.0 is now an enforceable acquisition requirement, not a framework on the horizon. The DFARS rule that puts it into contracts took effect November 10, 2025, and the DoD is rolling enforcement out over roughly three years, which means the safest assumption for any DIB contractor is that the requirement applies sooner than the phase schedule suggests. Cybercrime and supply chain compromise remain the core reason the DoD built this program in the first place: a single unassessed subcontractor can become the weak link in a much larger defense program. Run the gap analysis now, close the cryptographic and access control findings first, and treat CMMC as a continuous discipline rather than a one-time certification event.
References
- U.S. Department of Defense, CMMC official program site
- Federal Register, Cybersecurity Maturity Model Certification (CMMC) Program, 32 CFR Part 170
- Federal Register, Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements, DFARS Case 2019-D041
- Acquisition.gov, DFARS 252.204-7021, Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements
- NIST, Special Publication 800-171 Revision 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- Key Takeaways
- What Does CMMC 2.0 Require?
- When Did the CMMC 2.0 Final Rule Take Effect?
- What Systems and Contractors Are in Scope for CMMC?
- How Do You Assess Your Organization's Current Maturity Level?
- What Is the CMMC Compliance Checklist?
- CMMC Level 1 vs Level 2 vs Level 3: How Do They Compare?
- Update Log: What Changed in This Refresh
- What Are the Limitations of CMMC Compliance?
- What Would Encryption Consulting Recommend?
- Frequently Asked Questions About CMMC Compliance
- Conclusion
