CMMC Guide

What Is CMMC? A Plain-Language Guide for Defense Contractors

The Cybersecurity Maturity Model Certification (CMMC) is the Department of War’s program for verifying that defense contractors protect the sensitive unclassified information they handle. It sets three levels of security requirements and requires a self-assessment or an independent assessment before a company can win a contract involving that information.

CMMC at a glance

Run by
Department of War (DoW, formerly the Department of Defense), Office of the Chief Information Officer
Legal basis
32 CFR Part 170 (program rule) and DFARS 252.204-7021 (contract clause)
Protects
Federal Contract Information (FCI) and Controlled Unclassified Information (CUI)
Levels
Level 1: 15 requirements · Level 2: 110 · Level 3: 110 + 24
Assessed by
The contractor itself, an authorized C3PAO, or DCMA DIBCAC, depending on the level
Recorded in
SPRS, with an annual affirmation by a senior company official

Why does CMMC exist?

CMMC exists because self-reported compliance proved unreliable. Since the end of 2017, contractors that handle controlled defense information have been required by DFARS 252.204-7012 to implement the security requirements in NIST SP 800-171. For years, however, the Department relied largely on contractors’ own statements that the work was done.

In 2019 the Department of Defense Inspector General reported that contractors were not consistently implementing those requirements, citing weaknesses in areas such as multifactor authentication, vulnerability management and removable media. Congress then directed the Department to build an assessment framework in the National Defense Authorization Act for Fiscal Year 2020. CMMC is that framework. For most contractors it adds few new security requirements. What it adds is verification, and a direct link between verified results and contract awards.

Who needs CMMC?

CMMC applies to any company, whether a prime contractor or a subcontractor at any tier, that will process, store or transmit FCI or CUI on its own information systems while performing a DoW contract that includes a CMMC requirement. The rule covers all contract and subcontract awardees in scope, regardless of company size.

  • The contract sets the level. DoW program managers choose the required CMMC level for each procurement based on the information involved, and the requirement reaches contractors through the DFARS 252.204-7021 clause.
  • Requirements flow down. Prime contractors must pass CMMC requirements to subcontractors that handle FCI or CUI. A subcontractor that handles only FCI needs Level 1; one that handles CUI needs at least Level 2.
  • Exceptions are narrow. CMMC does not apply to contracts solely for commercially available off-the-shelf (COTS) items, to purchases at or below the micro-purchase threshold, or to federal information systems a contractor operates on the government’s behalf. The Department may also waive it in limited cases.

Working as a subcontractor? Read CMMC for subcontractors and small businesses.

What information does CMMC protect?

CMMC protects two kinds of nonpublic, unclassified information. Which kind your company handles is the main factor in deciding the CMMC level you need.

Federal Contract Information (FCI)

Information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service. Nearly every contractor handles some FCI.

Usually leads to Level 1

Controlled Unclassified Information (CUI)

Government information that is not classified but that law, regulation or government-wide policy requires to be safeguarded, such as controlled technical information and export-controlled data.

Leads to Level 2 or Level 3

Not sure which you hold? See FCI vs CUI.

What are the three CMMC levels?

Each level builds on the one below it. The level named in your contract decides both the requirements you must meet and who assesses you.

  1. Level 1

    Basic safeguarding of FCI through the 15 requirements in FAR 52.204-21. Verified by an annual self-assessment. Every requirement must be met; no plan of action is allowed.

    CMMC Level 1 in detail
  2. Level 2

    Protection of CUI through the 110 requirements of NIST SP 800-171 Revision 2. Verified every three years by a self-assessment or by a C3PAO certification assessment, depending on the contract.

    CMMC Level 2 in detail
  3. Level 3

    Enhanced protection of CUI for the most critical programs: Level 2 plus 24 selected requirements from NIST SP 800-172. Assessed by DCMA DIBCAC every three years, and only after the company holds a Final Level 2 (C3PAO) status.

    CMMC Level 3 in detail

See all three side by side: CMMC levels compared.

How does a company achieve CMMC status?

The path is the same at every level. What changes is the number of requirements and who performs the assessment.

  1. Confirm the level

    Review current and upcoming solicitations and determine whether you will handle FCI, CUI or both.

  2. Define the scope

    Identify the systems, people, facilities and service providers that handle or protect that information. A smaller, well-defined scope is easier to secure and to assess.

  3. Implement and document

    Put the required controls in place, write a system security plan (required at Levels 2 and 3), and keep the evidence an assessor will ask to see.

  4. Get assessed

    Complete a self-assessment, or schedule an assessment with a C3PAO or DCMA DIBCAC, as your contract requires. At Levels 2 and 3, a limited number of gaps can go on a plan of action and must be closed within 180 days.

  5. Report and affirm

    Results are recorded in SPRS, where a senior company official affirms continuing compliance, then again every year.

Each step explained: How to get CMMC certified.

Who performs CMMC assessments?

Three kinds of assessors exist, and your required level decides which one applies.

Your own company
Performs Level 1 self-assessments, and Level 2 self-assessments where the contract allows them.
A C3PAO
A Certified Third-Party Assessment Organization authorized by The Cyber AB. Its CMMC Certified Assessors (CCAs) conduct Level 2 certification assessments.
DCMA DIBCAC
The Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center, a government team that conducts Level 3 certification assessments.

Consultants and readiness providers can help a company prepare, but they cannot certify it. The rule also bars anyone who consulted for a company from taking part in that company’s Level 2 certification assessment for three years.

Learn more: CMMC assessments explained · Who’s who in CMMC

What are SPRS, POA&Ms and affirmations?

Four terms come up in every CMMC conversation:

SPRS
The Supplier Performance Risk System. Self-assessment results and affirmations are recorded here, and contracting officers check it before award. C3PAO and DIBCAC results reach SPRS through the CMMC instance of eMASS. How SPRS scores work
CMMC Status
The recorded outcome of an assessment, such as “Final Level 2 (C3PAO)”. A Conditional status is possible when limited requirements remain open; it expires if they are not closed within 180 days.
POA&M
A plan of action and milestones for requirements that were not met. CMMC allows one only for certain lower-weighted requirements, only when at least 80% of requirements are met, and never at Level 1. Assessment and POA&M rules
Affirmation
A statement entered in SPRS by the company’s Affirming Official, a senior representative, confirming that the required controls are implemented and will be maintained. It is due after each assessment and every year after that.

More definitions in the CMMC glossary.

How does CMMC relate to NIST SP 800-171 and DFARS 252.204-7012?

They answer three different questions:

  • What must be done? NIST SP 800-171 Revision 2 lists the security requirements for protecting CUI. FAR 52.204-21 does the same, at a basic level, for FCI.
  • Who must do it? DFARS 252.204-7012 requires contractors that handle covered defense information to implement NIST SP 800-171 and to report cyber incidents.
  • How is it verified? CMMC, through 32 CFR Part 170 and DFARS 252.204-7021, checks that the work was done before a contract is awarded.

CMMC does not replace these obligations. A company with a DFARS 252.204-7012 clause must meet it whether or not the contract also includes a CMMC requirement. Note also that CMMC Level 2 is based on Revision 2 of NIST SP 800-171, not the newer Revision 3.

In depth: CMMC rules explained · CMMC vs other frameworks

Why is CMMC an ongoing obligation, not a one-time project?

Passing an assessment is a milestone, not the finish line. Under the rule, a company must:

  • affirm its compliance in SPRS every year;
  • repeat its assessment on schedule: every year at Level 1 and every three years at Levels 2 and 3;
  • keep the evidence used in its assessment for six years; and
  • keep its controls working between assessments, because the government can still review a contractor’s security on its own.

This is where process discipline matters. In our view, organizations that run security as a defined, repeatable process (with clear owners, routine reviews and measured results) keep their CMMC status with far less disruption than those that prepare in a rush before each assessment. It is the same principle behind the CMMI model, which is why CMMCMARK looks at CMMC and CMMI together. Our CMMC training helps your people keep these routines running between assessments.

Explore the CMMC guide

Each topic below has its own page, written to answer one question in depth.

Basics

Getting certified

Reference

Get ready for CMMC with CMMCMARK

CMMCMARK, a LAYERMARK company, helps defense contractors prepare for CMMC assessments and trains the people who keep them compliant.

Prefer the phone? Call +1 (202) 867-8444.

Sources