defense contracting · in plain English

CMMC
in plain English

What the Cybersecurity Maturity Model Certification is, how Levels 1 and 2 differ, and how you actually get assessed.

CMMC (Cybersecurity Maturity Model Certification) is the Defense Department's program for verifying that its contractors and subcontractors actually protect sensitive government information on their systems. If your company does business with the DoD and handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), CMMC decides whether you are eligible to win and keep those contracts. The program is now in force: the rule that created it (32 CFR Part 170) took effect on December 16, 2024, and the rule that puts CMMC requirements into actual contracts (the 48 CFR acquisition rule) took effect on November 10, 2025.

Run the NIST 800-171 / CMMC self-assessment →

The three levels

Level 1

Protects FCI

Requirements
15 requirements (FAR 52.204-21)
Assessment
Annual self-assessment; company enters results and an annual affirmation into SPRS, no third party involved

Level 1 is the entry tier for companies that only handle Federal Contract Information, meaning basic non-public information tied to a government contract. It covers 15 fundamental safeguards drawn straight from the FAR 52.204-21 basic safeguarding clause, things like using passwords, limiting who can access systems, and running antivirus. You check your own systems once a year, then a senior company official affirms in the government's SPRS database that all 15 are met. There is no partial credit and no plan to fix things later: every requirement has to be fully in place.

Level 2

Protects CUI

Requirements
110 requirements (NIST SP 800-171 Rev 2)
Assessment
Every three years, self-assessment or certified third party (C3PAO) depending on the contract, plus an annual SPRS affirmation

Level 2 applies once you store, process, or transmit Controlled Unclassified Information, which is more sensitive government data. It maps to the full set of 110 security requirements in NIST SP 800-171 Revision 2 (broken into 320 detailed assessment objectives). Some contracts let you self-assess against these controls; higher-stakes contracts require a certified independent assessor, called a C3PAO, to verify them. Either way the assessment is renewed every three years, and a senior official must sign an affirmation in SPRS every year that the controls remain in place.

Level 3

Protects high-priority CUI

Requirements
110 plus 24 selected from NIST SP 800-172
Assessment
Government-led DIBCAC (DCMA) assessment, after a Level 2 C3PAO certification

Level 3 is reserved for the most sensitive programs facing advanced threats, and it layers 24 selected enhanced requirements from NIST SP 800-172 on top of the full Level 2 baseline. It is assessed by the government itself through DCMA's DIBCAC, and only after you already hold a Level 2 certification for that scope.

FCI vs CUI

The level you need depends on the kind of government information you touch. Federal Contract Information (FCI) is non-public information provided by or generated for the government under a contract, but not intended for public release; think of routine contract details that are not published.

Controlled Unclassified Information (CUI) is more sensitive. It is government information that laws, regulations, or policies say must be safeguarded, even though it is not classified. Examples include certain technical drawings, specifications, and other data marked as controlled.

The rule of thumb: if you only handle FCI, you are looking at Level 1; once CUI is in the picture, you move up to Level 2 (or Level 3 for the highest-priority programs).

How you get assessed

There are three ways your compliance can be checked, and the contract tells you which one applies. A self-assessment means you evaluate your own systems and record the result. A C3PAO assessment means a Certified Third-Party Assessment Organization, an accredited independent company, verifies your Level 2 controls. A DIBCAC assessment means the government's own assessors (part of the Defense Contract Management Agency) review you, which is how Level 3 is handled.

Level 1 is always an annual self-assessment. Level 2 is done every three years, either as a self-assessment or by a C3PAO, depending on the contract. Level 3 is a government-led DIBCAC assessment that comes after a Level 2 certification is in place.

Each solicitation states the exact requirement using standard options: Level 1 Self-Assessment, Level 2 Self-Assessment, Level 2 C3PAO assessment, or Level 3 DIBCAC assessment.

Affirmations, POA&Ms, and scores

At Level 2, your compliance is expressed as a score in the government's Supplier Performance Risk System (SPRS). A perfect score is 110, one point for every NIST SP 800-171 requirement met, with points subtracted for gaps (some requirements are weighted more heavily than one point).

A Plan of Action and Milestones (POA&M) is a documented plan to close remaining gaps. At Level 2 you can only qualify for a POA&M if your score is at least 88 out of 110, and only lower-weighted (1-point) requirements are eligible to be deferred; the most critical controls cannot be placed on a POA&M. Level 1 does not allow POA&Ms at all: every requirement must be met.

If you qualify with open items, you receive a Conditional certification and have 180 days to close everything on the POA&M and pass a closeout check; otherwise the conditional status expires. Regardless of level, a senior company official must submit an affirmation in SPRS confirming ongoing compliance, and that affirmation has to be renewed every year.

The phased rollout

CMMC is being introduced gradually rather than all at once. The acquisition rule that adds CMMC to contracts took effect on November 10, 2025, which started Phase 1.

Phase 1 (beginning November 10, 2025) generally introduces Level 1 and Level 2 self-assessment requirements into new contracts. Phase 2, about one year later, phases in Level 2 C3PAO certification requirements. Phase 3, the following year, brings in Level 3 DIBCAC assessments. Phase 4, one year after that (around November 2028), reflects full implementation across applicable DoD contracts.

Which contracts carry a CMMC requirement, and at which level, is decided contract by contract, so the timeline above is the broad ramp rather than a hard switch for every company at once.

Where to start

The most practical first step is to figure out whether you handle FCI, CUI, or both, since that determines your target level. If you are aiming at Level 2, download NIST SP 800-171 Revision 2 and work through its 110 requirements, using the DoD self-scoring methodology to calculate your SPRS score out of 110 and to see where your gaps are.

From there, build a plan to close the gaps before an assessment window, and remember that only lower-weighted items can sit on a POA&M and only if you already score at least 88. To get oriented quickly, run the NIST 800-171 / CMMC self-assessment on this site to gauge roughly where you stand, then dig into the official NIST and DoD source material for the details.

Sources

An unofficial plain-English companion. The official DoD and NIST source material above is the authority for compliance.