CMMC Guide
What Is CMMC? A Plain-Language Guide for Defense Contractors
The Cybersecurity Maturity Model Certification (CMMC) is the Department of War’s program for verifying that defense contractors protect the sensitive unclassified information they handle. It sets three levels of security requirements and requires a self-assessment or an independent assessment before a company can win a contract involving that information.
CMMC at a glance
- Run by
- Department of War (DoW, formerly the Department of Defense), Office of the Chief Information Officer
- Legal basis
- 32 CFR Part 170 (program rule) and DFARS 252.204-7021 (contract clause)
- Protects
- Federal Contract Information (FCI) and Controlled Unclassified Information (CUI)
- Levels
- Level 1: 15 requirements · Level 2: 110 · Level 3: 110 + 24
- Assessed by
- The contractor itself, an authorized C3PAO, or DCMA DIBCAC, depending on the level
- Recorded in
- SPRS, with an annual affirmation by a senior company official
Why does CMMC exist?
CMMC exists because self-reported compliance proved unreliable. Since the end of 2017, contractors that handle controlled defense information have been required by DFARS 252.204-7012 to implement the security requirements in NIST SP 800-171. For years, however, the Department relied largely on contractors’ own statements that the work was done.
In 2019 the Department of Defense Inspector General reported that contractors were not consistently implementing those requirements, citing weaknesses in areas such as multifactor authentication, vulnerability management and removable media. Congress then directed the Department to build an assessment framework in the National Defense Authorization Act for Fiscal Year 2020. CMMC is that framework. For most contractors it adds few new security requirements. What it adds is verification, and a direct link between verified results and contract awards.
Who needs CMMC?
CMMC applies to any company, whether a prime contractor or a subcontractor at any tier, that will process, store or transmit FCI or CUI on its own information systems while performing a DoW contract that includes a CMMC requirement. The rule covers all contract and subcontract awardees in scope, regardless of company size.
- The contract sets the level. DoW program managers choose the required CMMC level for each procurement based on the information involved, and the requirement reaches contractors through the DFARS 252.204-7021 clause.
- Requirements flow down. Prime contractors must pass CMMC requirements to subcontractors that handle FCI or CUI. A subcontractor that handles only FCI needs Level 1; one that handles CUI needs at least Level 2.
- Exceptions are narrow. CMMC does not apply to contracts solely for commercially available off-the-shelf (COTS) items, to purchases at or below the micro-purchase threshold, or to federal information systems a contractor operates on the government’s behalf. The Department may also waive it in limited cases.
Working as a subcontractor? Read CMMC for subcontractors and small businesses.
What information does CMMC protect?
CMMC protects two kinds of nonpublic, unclassified information. Which kind your company handles is the main factor in deciding the CMMC level you need.
Federal Contract Information (FCI)
Information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service. Nearly every contractor handles some FCI.
Usually leads to Level 1
Controlled Unclassified Information (CUI)
Government information that is not classified but that law, regulation or government-wide policy requires to be safeguarded, such as controlled technical information and export-controlled data.
Leads to Level 2 or Level 3
Not sure which you hold? See FCI vs CUI.
What are the three CMMC levels?
Each level builds on the one below it. The level named in your contract decides both the requirements you must meet and who assesses you.
-
Level 1
Basic safeguarding of FCI through the 15 requirements in FAR 52.204-21. Verified by an annual self-assessment. Every requirement must be met; no plan of action is allowed.
CMMC Level 1 in detail -
Level 2
Protection of CUI through the 110 requirements of NIST SP 800-171 Revision 2. Verified every three years by a self-assessment or by a C3PAO certification assessment, depending on the contract.
CMMC Level 2 in detail -
Level 3
Enhanced protection of CUI for the most critical programs: Level 2 plus 24 selected requirements from NIST SP 800-172. Assessed by DCMA DIBCAC every three years, and only after the company holds a Final Level 2 (C3PAO) status.
CMMC Level 3 in detail
See all three side by side: CMMC levels compared.
How does a company achieve CMMC status?
The path is the same at every level. What changes is the number of requirements and who performs the assessment.
Confirm the level
Review current and upcoming solicitations and determine whether you will handle FCI, CUI or both.
Define the scope
Identify the systems, people, facilities and service providers that handle or protect that information. A smaller, well-defined scope is easier to secure and to assess.
Implement and document
Put the required controls in place, write a system security plan (required at Levels 2 and 3), and keep the evidence an assessor will ask to see.
Get assessed
Complete a self-assessment, or schedule an assessment with a C3PAO or DCMA DIBCAC, as your contract requires. At Levels 2 and 3, a limited number of gaps can go on a plan of action and must be closed within 180 days.
Report and affirm
Results are recorded in SPRS, where a senior company official affirms continuing compliance, then again every year.
Each step explained: How to get CMMC certified.
Who performs CMMC assessments?
Three kinds of assessors exist, and your required level decides which one applies.
- Your own company
- Performs Level 1 self-assessments, and Level 2 self-assessments where the contract allows them.
- A C3PAO
- A Certified Third-Party Assessment Organization authorized by The Cyber AB. Its CMMC Certified Assessors (CCAs) conduct Level 2 certification assessments.
- DCMA DIBCAC
- The Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center, a government team that conducts Level 3 certification assessments.
Consultants and readiness providers can help a company prepare, but they cannot certify it. The rule also bars anyone who consulted for a company from taking part in that company’s Level 2 certification assessment for three years.
Learn more: CMMC assessments explained · Who’s who in CMMC
What are SPRS, POA&Ms and affirmations?
Four terms come up in every CMMC conversation:
- SPRS
- The Supplier Performance Risk System. Self-assessment results and affirmations are recorded here, and contracting officers check it before award. C3PAO and DIBCAC results reach SPRS through the CMMC instance of eMASS. How SPRS scores work
- CMMC Status
- The recorded outcome of an assessment, such as “Final Level 2 (C3PAO)”. A Conditional status is possible when limited requirements remain open; it expires if they are not closed within 180 days.
- POA&M
- A plan of action and milestones for requirements that were not met. CMMC allows one only for certain lower-weighted requirements, only when at least 80% of requirements are met, and never at Level 1. Assessment and POA&M rules
- Affirmation
- A statement entered in SPRS by the company’s Affirming Official, a senior representative, confirming that the required controls are implemented and will be maintained. It is due after each assessment and every year after that.
More definitions in the CMMC glossary.
How does CMMC relate to NIST SP 800-171 and DFARS 252.204-7012?
They answer three different questions:
- What must be done? NIST SP 800-171 Revision 2 lists the security requirements for protecting CUI. FAR 52.204-21 does the same, at a basic level, for FCI.
- Who must do it? DFARS 252.204-7012 requires contractors that handle covered defense information to implement NIST SP 800-171 and to report cyber incidents.
- How is it verified? CMMC, through 32 CFR Part 170 and DFARS 252.204-7021, checks that the work was done before a contract is awarded.
CMMC does not replace these obligations. A company with a DFARS 252.204-7012 clause must meet it whether or not the contract also includes a CMMC requirement. Note also that CMMC Level 2 is based on Revision 2 of NIST SP 800-171, not the newer Revision 3.
In depth: CMMC rules explained · CMMC vs other frameworks
Why is CMMC an ongoing obligation, not a one-time project?
Passing an assessment is a milestone, not the finish line. Under the rule, a company must:
- affirm its compliance in SPRS every year;
- repeat its assessment on schedule: every year at Level 1 and every three years at Levels 2 and 3;
- keep the evidence used in its assessment for six years; and
- keep its controls working between assessments, because the government can still review a contractor’s security on its own.
This is where process discipline matters. In our view, organizations that run security as a defined, repeatable process (with clear owners, routine reviews and measured results) keep their CMMC status with far less disruption than those that prepare in a rush before each assessment. It is the same principle behind the CMMI model, which is why CMMCMARK looks at CMMC and CMMI together. Our CMMC training helps your people keep these routines running between assessments.
Explore the CMMC guide
Each topic below has its own page, written to answer one question in depth.
Basics
- CMMC status and timelineWhat is in force today and what is paused
- CMMC levels comparedWhich level your company needs
- FCI vs CUIThe information that triggers CMMC
- Requirements by domainThe 14 security families explained
Getting certified
- How to get CMMC certifiedThe path from scoping to affirmation
- CMMC scopingDefining your assessment boundary
- CMMC assessmentsScores, POA&Ms and CMMC Status
- SPRS scoreHow the NIST SP 800-171 score works
Reference
Get ready for CMMC with CMMCMARK
CMMCMARK, a LAYERMARK company, helps defense contractors prepare for CMMC assessments and trains the people who keep them compliant.
- CMMC certification supportReadiness assessment, scoping, documentation and assessment preparation
- CMMC trainingCourses for your workforce, your leaders and aspiring CMMC professionals
Prefer the phone? Call +1 (202) 867-8444.
Sources
- 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program (eCFR)
- DFARS 252.204-7021, Contractor Compliance with CMMC Level Requirements
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems
- NIST SP 800-171 Revision 2 and NIST SP 800-172
- DoW CIO, Cybersecurity Maturity Model Certification program page
- DoD Inspector General, DODIG-2019-105: Audit of Protection of DoD CUI on Contractor-Owned Networks and Systems (2019)
