- CMMC Compliance: How to Achieve and Maintain It
- What’s the Difference Between Being CMMC Compliant and CMMC Certified?
- What Do the CMMC Compliance Levels Require?
- What Does a CMMC Compliance Program Include?
- How to Achieve CMMC Compliance
- How to Maintain CMMC Compliance
- How to Simplify CMMC Compliance
- Key Takeaways
- CMMC Compliance FAQs
CMMC Compliance: How to Achieve and Maintain It
CMMC compliance means a Department of Defense (DoD) contractor has implemented the cybersecurity safeguards its contracts require and can prove it on demand, and that requirement is now written into federal regulation. The program behind it, the Cybersecurity Maturity Model Certification (CMMC), took effect through 32 CFR Part 170 on December 16, 2024, and the DFARS acquisition rule that writes it into individual contracts followed on November 10, 2025.
Still, most of the defense industrial base is not there yet. The 2025 State of the DIB report found that only 1% of contractors feel fully prepared, with a median self-assessment score of 60 against a required 110. For most of them, the harder task is not implementing the controls but demonstrating that work to an assessor, with the documentation and score to prove it.
This guide covers what separates being CMMC compliant from being CMMC certified, what each of the three levels requires, the operational plan to reach compliance, and the obligations that keep it current. For the full definition of the program and its history, see the complete CMMC guide.
What’s the Difference Between Being CMMC Compliant and CMMC Certified?
Being CMMC compliant and being CMMC certified are not the same thing. CMMC compliance means the required controls are implemented and documented, with a self-assessment score submitted to the Supplier Performance Risk System (SPRS). CMMC certification means a CMMC Third-Party Assessment Organization (C3PAO) has independently assessed those controls and confirmed the result.
CMMC compliance means a defense contractor has implemented — and can demonstrate — the cybersecurity safeguards its contracts require under the Department of Defense’s Cybersecurity Maturity Model Certification program. Depending on the data it handles, that means meeting CMMC Level 1 or Level 2 requirements.
Which controls a contractor must implement depend on its level:
- Level 1 covers the 15 basic safeguarding requirements of FAR 52.204-21.
- Level 2 covers the 110 controls of NIST SP 800-171 Rev 2, incorporated by reference in 32 CFR §170.14.
Two paths prove that compliance. The self-assessment path, which applies to Level 1 and Level 2, relies on self-attestation plus an annual affirmation in SPRS. The third-party path adds an independent C3PAO assessment.
As of the July 13, 2026 Department of War suspension of CMMC Phase II, contracting officers may require only Level 1 (Self) or Level 2 (Self) assessments, and they may not require Level 2 (C3PAO) or Level 3 (DIBCAC) during the review. [DFARS 252.204-7012](https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.), which requires contractors handling Controlled Unclassified Information (CUI) to implement the 110 NIST SP 800-171 Rev 2 controls, remains in force.
What Do the CMMC Compliance Levels Require?
CMMC compliance requirements scale across three levels, set by the type and sensitivity of the data a contract involves. For most organizations, the first task is identifying the applicable level.
- Federal Contract Information (FCI) is information not intended for public release.
- CUI is information that a law or policy requires to be safeguarded.
As the National Archives explains, all CUI held by a government contractor is also FCI, but not all FCI is CUI. Per the DoD’s CMMC Model Overview, the CMMC levels are also cumulative. So, Level 3 builds on everything in Level 2. The following table maps each level to its data type, control basis, and assessment path.
| CMMC Level | Data type | Control basis | Assessment path |
|---|---|---|---|
| CMMC Level 1 | FCI | 15 requirements (FAR 52.204-21) | Annual self-assessment and affirmation |
| CMMC Level 2 | CUI | 110 requirements (NIST SP 800-171 Rev 2) | Self or C3PAO, every 3 years, plus annual affirmation |
| CMMC Level 3 | CUI (highest-priority programs) | Level 2 + selected NIST SP 800-172 enhanced requirements | Government-led (DIBCAC) |
Note: Even though NIST withdrew SP 800-171 Rev 2 on May 14, 2024 and superseded it with Rev 3, CMMC still pins Level 2 requirements to Rev 2.
What Does a CMMC Compliance Program Include?
A CMMC compliance program breaks into four workstreams, each with its own focused resource. Together they cover what a contractor must do, how it proves the work, and who has to comply.
- Requirements define what a contractor must do to meet its level.
- Controls and domains are the 110 controls organized across 14 domains at Level 2.
- A checklist turns the requirements into a step-by-step readiness list.
- Applicability determines who must comply, from prime contractors down to subcontractors handling FCI or CUI.
How to Achieve CMMC Compliance
Achieving CMMC compliance follows a sequential plan from scoping to affirmation. Full CMMC compliance means every applicable control is met, so the plan below is the operational path to get there.
- Define the CMMC assessment scope. Identify where FCI and CUI live and categorize the assets that store, process, or transmit it.
- Run a gap assessment. It produces a current SPRS score and a prioritized remediation list. The score starts at 110 and deducts points for each unmet control under the DoD weighting table.
- Build the SSP and a POA&M. The System Security Plan (SSP) describes the environment, the CUI boundary, and how each of the 110 controls is met. The Plan of Action and Milestones (POA&M) tracks the gaps still open.
- Remediate, train, and gather evidence. Fix the gaps, train staff, and collect retrievable, timestamped evidence. The 110 controls map to 320 assessment objectives, each needing evidence, so a written policy alone fails.
- Run an internal readiness review. Confirm the environment holds up, then move to a self-assessment or, when the contract requires and the mechanism is available, a C3PAO assessment.
- Affirm the result. According to the DoD’s official CMMC guidance, a passing status is either full compliance, where every applicable control is met, or conditional status, which requires a score of at least 88 out of 110 (80%) with only eligible gaps left on a POA&M and closed within 180 days.
A GRC Assessment Platform™ lets teams run the gap and readiness assessments and capture evidence alongside each response, so the audit trail becomes a byproduct of the work.
How to Maintain CMMC Compliance
Maintaining CMMC compliance is a continuing obligation that runs for the life of the contract. Under DFARS 252.204-7021, a contractor must keep a current CMMC status for the duration of the contract and file an annual affirmation of continuous compliance in SPRS. The recurring obligations are:
- Reassess on schedule. Level 2 and Level 3 require reassessment every three years, and POA&M items must close within 180 days.
- Keep the SSP a living document. Update it as the environment changes so it still describes the current CUI boundary.
- Monitor and flow down. Run continuous monitoring and recurring internal assessments, and flow CMMC requirements down to subcontractors handling FCI or CUI.
The third-party assessment mechanism is paused during Phase II suspension, but the DFARS 252.204-7012 obligation and the annual affirmation continue. Requirements could return in modified form after the 60-day CMMC Reform Task Force review, with responses to the request for information due August 14, 2026.
How to Simplify CMMC Compliance
For most teams, the most challenging part of CMMC compliance is running the assessments and holding onto defensible evidence — precisely the work most contractors struggle to organize.
Isora GRC is the GRC Assessment Platform™ that gives security teams one connected workspace to run assessments, manage assets, track risks, and prove compliance. It supports readiness and self-assessment. With Isora GRC, teams can:
- Launch a CMMC assessment from a prebuilt questionnaire library that covers CMMC out of the box, so a new requirement moves from “build an assessment” to “launch an assessment”.
- Capture evidence as the work happens, which addresses the “can’t prove it” problem by attaching evidence to the response it supports.
- Route findings into a risk register with full lineage, then generate reports and scorecards from live assessment data.
Isora GRC does not issue a CMMC certification, replace a C3PAO, or guarantee an SPRS score.
See the GRC Assessment Platform in action →
Key Takeaways
The first move toward CMMC compliance is a gap assessment. It produces the SPRS score and remediation list that anchor every step after it, from the SSP to the evidence behind the 320 assessment objectives.
Compliance then holds through annual affirmation, triennial reassessment, and continuous monitoring, even while the Phase II third-party mechanism sits under review as of July 2026.
The complete CMMC guide covers the program’s full definition and history. To run CMMC assessments and hold the supporting evidence in one connected workspace, see the GRC Assessment Platform in action.
CMMC Compliance FAQs
What Is CMMC Compliance?
CMMC compliance means a Department of Defense contractor has implemented the cybersecurity requirements its contracts specify and can prove it through documentation and a score. The required controls depend on the data handled: FAR 52.204-21 for Federal Contract Information, or the 110 NIST SP 800-171 Rev 2 controls for Controlled Unclassified Information. Compliance is verified by self-assessment or, for higher assurance, by a third-party assessor.
Is CMMC Compliance Mandatory?
The underlying cybersecurity obligations are mandatory now: DFARS 252.204-7012 already requires contractors handling Controlled Unclassified Information to implement the 110 NIST SP 800-171 Rev 2 controls. The formal CMMC assessment program is phasing in through the DoD acquisition process, but on July 13, 2026 the Department of War suspended CMMC Phase II, so contracting officers may currently require only Level 1 (Self) or Level 2 (Self) assessments.
What Is the Difference Between Being CMMC Compliant and CMMC Certified?
Being compliant means the required controls are implemented and documented, with a score submitted to SPRS. Being certified means a CMMC Third-Party Assessment Organization (C3PAO) has independently assessed and confirmed that compliance. Level 1 and Level 2 (Self) rely on self-assessment and annual affirmation; a certification comes only from the third-party path.
What Are the CMMC Compliance Levels?
There are three levels tied to data sensitivity. Level 1 covers Federal Contract Information and requires the 15 FAR 52.204-21 safeguarding requirements. Level 2 covers Controlled Unclassified Information and requires all 110 NIST SP 800-171 Rev 2 controls; Level 3 adds 24 selected NIST SP 800-172 enhanced requirements assessed by the government (DIBCAC).
How Do You Become CMMC Compliant?
Start by defining your assessment scope and running a gap assessment, which produces a current SPRS score and a prioritized remediation list. Build a System Security Plan and a Plan of Action and Milestones, implement the controls, and gather retrievable evidence for each of the 320 assessment objectives. Finish with an internal readiness review, then a self-assessment or C3PAO assessment depending on your required level.
How Long Does CMMC Compliance Take?
Timelines vary by level and starting posture, but Level 2 efforts commonly run 12 to 30 months from gap assessment to a passing result. Organizations starting from spreadsheets and ad hoc processes take longer than those with an existing NIST SP 800-171 program. Building evidence collection into daily operations early shortens the path, because retroactive documentation is impractical.
This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.