What Is CMMC? The DoD's Cybersecurity Certification, Explained
CMMC, the Cybersecurity Maturity Model Certification, is the Department of Defense program that verifies defense contractors have implemented the cybersecurity requirements their contracts already carry. The program rule, 32 CFR Part 170, took effect December 16, 2024. The contract clause that writes CMMC into solicitations, DFARS 252.204-7021, took effect November 10, 2025, and new contracts now carry CMMC requirements. The program has three levels. Level 1 is an annual self-assessment covering 15 basic requirements for companies that handle Federal Contract Information. Level 2 covers all 110 requirements of NIST SP 800-171 for companies that handle Controlled Unclassified Information. Level 3 adds 24 requirements from NIST SP 800-172 for the most sensitive programs. If you sell to the DoD, directly or through a prime, one of these levels applies to you.
Why the DoD created it
Contractors have been contractually required to implement NIST SP 800-171 since DFARS 252.204-7012 became mandatory at the end of 2017. Compliance was self-attested, and the honor system did not hold. When the Defense Industrial Base Cybersecurity Assessment Center, DIBCAC, began checking contractor self-assessments against evidence, the scores collapsed on contact. The Department of Justice started prosecuting the gap under the False Claims Act: Aerojet Rocketdyne settled for $9 million in 2022 over misrepresented NIST 800-171 compliance, and Penn State paid $1.25 million in 2024 over its attestations. CMMC adds almost no new security requirements. It adds verification, and it moves the verification in front of contract award instead of leaving it as a promise inside the contract. That reordering is the entire point of the program, and it changes who has to care: winning the work now depends on a compliance status posted in a government system before the award decision.
The three levels and who needs which
Level 1 applies when you handle FCI and no CUI. It covers 15 basic safeguarding requirements taken from FAR 52.204-21, verified by an annual self-assessment posted in SPRS and affirmed by a senior company official. No third party is involved, and no POA&M is permitted: all 15 requirements must be met on the day you assess. The mechanics are in our CMMC Level 1 requirements guide.
Level 2 applies once CUI is stored, processed, or transmitted in your environment, which describes most manufacturers, engineering firms, and integrators in the defense supply chain. It requires all 110 security requirements of NIST SP 800-171 Revision 2, assessed against roughly 320 objectives from NIST SP 800-171A. Depending on the contract, verification is either a self-assessment or a certification assessment by a C3PAO, a CMMC Third Party Assessment Organization authorized by the Cyber AB, and DoD has signaled that most CUI contracts will eventually require the C3PAO path. Certification lasts three years with annual affirmations. The control families and POA&M rules are in CMMC Level 2 requirements.
Level 3 applies to a small set of contractors supporting the most sensitive programs. It adds 24 requirements from NIST SP 800-172, is assessed by the government itself through DIBCAC, and requires a final Level 2 certification first.
Which level you need is decided by your contracts and your data. If a solicitation cites the 7021 clause, it names the level. If your existing contracts carry DFARS 252.204-7012, you are handling covered defense information and Level 2 is the realistic planning target.
How CMMC relates to NIST SP 800-171 and the DFARS clauses
CMMC verifies NIST SP 800-171 rather than replacing it. Level 2 is the 110 requirements of Revision 2, unchanged. DoD held assessments at Revision 2 by class deviation even after NIST published Revision 3 in 2024, so Revision 2 remains the standard your System Security Plan and your assessment run against until DoD formally moves.
Four DFARS clauses do the contractual work. 252.204-7012 requires implementing NIST SP 800-171, reporting cyber incidents to DoD within 72 hours, and using cloud services that hold FedRAMP Moderate authorization or documented equivalency wherever they touch covered defense information. 252.204-7019 requires a current self-assessment score, no more than three years old, posted in SPRS before award. 252.204-7020 gives the government the right to conduct its own assessment of your environment and flows the obligations down to subcontractors. 252.204-7021 is the CMMC clause: it names the required level in the contract and makes the corresponding CMMC status in SPRS a condition of award. The first three have been in force for years. The fourth is the one now arriving in new solicitations.
FCI versus CUI
Federal Contract Information is information provided by or generated for the government under contract and not intended for public release: statements of work, schedules, performance information. Nearly every defense contract creates some, which is why Level 1 is the program floor. Controlled Unclassified Information is a defined category under 32 CFR Part 2002, information that law, regulation, or government-wide policy requires be safeguarded, catalogued in the government's CUI Registry. In the defense supply chain it looks like technical drawings, specifications, export controlled data, and program details. The distinction decides your level, so make it deliberately: inventory what you receive and create under each contract, read the markings, and ask the contracting officer or the prime when the markings are ambiguous, which they frequently are. Guessing low is the expensive mistake, because a Level 1 affirmation does not cover an environment that turns out to hold CUI.
What changes now that the rule is live
The rollout is phased, and as of August 2026 it stands in an unusual place. Phase 1 began November 10, 2025: new contracts require Level 1 or Level 2 self-assessment status, posted in SPRS with an annual affirmation. Phase 2, which was scheduled to put Level 2 C3PAO certification requirements into new solicitations starting November 10, 2026, was suspended on July 13, 2026 while a DoD task force reviews the program and takes industry comment. The department stated that Phase 1 self-assessment obligations remain fully in force, and DFARS 252.204-7012 never paused.
Read the suspension carefully before slowing anything down. The obligation to implement NIST SP 800-171 is contractual today under 7012, independent of any CMMC phase. A self-assessed score posted in SPRS is a federal representation with False Claims Act exposure attached, whether or not an assessor ever visits. And primes are already writing CMMC expectations into subcontracts and teaming decisions ahead of the clause, because their own eligibility depends on their supply chain. The verification calendar moved. The requirements did not.
A realistic timeline and where to start
From a standing start, reaching Level 2 assessment readiness takes 6 to 12 months for most small and mid-sized contractors, and the sequence matters more than the pace. Scope comes first: decide where CUI lives and shrink that boundary, because every requirement applies to every in-scope asset, and a contained enclave routinely removes more than half the company from scope. A gap assessment against all 110 requirements comes next, producing a System Security Plan, a POA&M, and a defensible SPRS score. Remediation follows, usually the largest budget line, commonly $20,000 to $150,000 depending on the gap and the boundary. Then the controls need to operate long enough to generate evidence, because assessors sample logs, tickets, and reviews, and a quarter of operating history is a reasonable floor. First-cycle totals run from roughly $90,000 for a tightly scoped small environment to $300,000 and beyond for enterprise-wide programs.
The first steps cost little and decide a lot. Confirm with your contracting officers and primes, in writing, what data types your current contracts carry, because the FCI versus CUI answer sets your level. Name an owner inside the company, since programs without one stall at the first hard tradeoff. Resist buying tools or starting cloud migrations before the boundary is decided, because platforms purchased for the whole company get repriced and reconfigured once scope shrinks to an enclave. Then get a real baseline. Most contractors who believe they are close discover a score below zero on first honest measurement, and it is far better to learn that from a readiness partner than from an assessor, a prime, or an investigator.
Who prepares you, and who certifies you
The roles are separate by design. A C3PAO performs the Level 2 certification assessment, and the program's conflict of interest rules bar the assessor from consulting for the company it assesses. BD Emerson works the other side of that line: scoping, CMMC gap assessment, remediation, SSP development, and mock assessment through our CMMC consulting practice. We are not a C3PAO and do not certify anyone, and that independence is the point: the firm preparing you has no stake in how you are scored, which means it can tell you plainly what is broken. The certificate comes from the assessor. Whether you earn it is decided by the work done before they arrive.

