Framework guide

CMMC 2.0 compliance, level by level

If you sell to the US Department of Defense, or to a contractor who does, CMMC decides whether you can keep the contract. Here is which level applies, what each requires, how assessment works, and how to get there without a year-long project.
What is CMMC? The Cybersecurity Maturity Model Certification is the US Department of Defense’s programme for verifying that contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). CMMC 2.0 has three levels. Level 1 is a self-assessment of 15 basic safeguards. Level 2 requires the 110 controls of NIST SP 800-171 and, for most contracts, a third-party assessment by a C3PAO. Level 3 adds a subset of NIST SP 800-172 with government-led assessment. Requirements are phased into contracts from 2025.

Which level do you need?

The contract clause tells you. If you handle only FCI, Level 1 applies. If you handle CUI, which is most engineering, manufacturing and IT subcontracts, Level 2 applies. Level 3 is reserved for programmes with the highest sensitivity. Prime contractors flow the requirement down to every subcontractor that touches the data, so a 20-person SaaS vendor to a prime can be in scope.
LevelDataControlsAssessmentRenewal
Level 1 (Foundational)FCI15 safeguards from FAR 52.204-21Annual self-assessment with executive affirmationAnnually
Level 2 (Advanced)CUI110 controls, NIST SP 800-171 Rev 2C3PAO third-party assessment for most contracts; self-assessment for a limited setEvery three years, annual affirmation
Level 3 (Expert)CUI on critical programmesLevel 2 plus 24 controls from NIST SP 800-172Government-led (DIBCAC)Every three years

What Level 2 actually asks for

NIST SP 800-171 groups its 110 controls into 14 families: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity. You need a System Security Plan (SSP) describing how each control is met, a Plan of Action and Milestones (POA&M) for any gaps, and evidence that the controls operate.

How assessment works

A certified third-party assessment organisation (C3PAO) reviews your SSP, interviews control owners and examines evidence for each of the 110 controls, scoring them met or not met. A limited number of controls may sit on a POA&M for up to 180 days; the rest must be met at assessment. Results are recorded in the DoD’s SPRS system, and a conditional or final certificate is issued.

Timeline and cost

From a reasonable starting point (cloud infrastructure, SSO, some policies) a Level 2 programme is typically audit-ready in 12 to 16 weeks with a named compliance lead, because the hardest work is scoping the CUI environment and writing an SSP that matches reality. The C3PAO fee is paid directly to the assessor and depends on the size of the CUI boundary; enclave strategies that keep CUI in a small, well-controlled environment reduce both time and assessment cost.

Weeks 1 to 2

Scope the CUI boundary

Where CUI is stored, processed and transmitted. A small enclave is cheaper to assess than the whole company.

Weeks 2 to 4

SSP and gap plan

Map each of the 110 controls to how you meet it. Gaps become a POA&M with owners and dates.

Weeks 4 to 12

Implement and evidence

Controls built with your team; integrations collect configuration and access evidence continuously.

Weeks 12 to 16

Assessment

C3PAO engaged early; assessor works from the same evidence record through the Auditor Workspace.

Reusing SOC 2 or ISO 27001 work

Roughly 60 to 70 percent of NIST SP 800-171 controls overlap with ISO 27001 Annex A and SOC 2 Security criteria: access control, logging, configuration, incident response, vulnerability management. In Certifyi they are mapped once, so an existing programme becomes a CMMC head start rather than a separate project. The CUI-specific pieces (FIPS-validated encryption, media marking, CUI training, the SSP itself) are added on top.

CMMC questions we hear most

Yes, in phases. The CMMC programme rule took effect in late 2024 and the contract clause is being phased into new DoD solicitations from 2025, with Level 2 C3PAO assessments required for most CUI contracts as the phases progress. Primes are already flowing the requirement down.

Only for a limited set of contracts the DoD designates. Assume a C3PAO assessment unless your contracting officer confirms otherwise.

If you store or process CUI in a cloud service, that service must meet FedRAMP Moderate or equivalent. Commercial cloud regions can qualify; check the provider’s attestation for the specific services you use.

Not as a certificate, but the controls and evidence carry over. Certifyi maps SOC 2 and ISO 27001 controls onto NIST SP 800-171 so the CMMC gap is the CUI-specific remainder.

NIST SP 800-171 is the control set. CMMC is the DoD programme that verifies you meet it, through self-assessment or third-party assessment, and records the result.

Selling into the defence supply chain?

Bring the contract clause. A compliance lead will confirm your level, scope the CUI boundary and give you a realistic assessment date.
Scroll to Top