- CMMC Requirements: What Defense Contractors Must Implement at Each Level
- What Are CMMC Requirements?
- CMMC Requirements by Level
- CMMC Level 1 Security Requirements: 15 Basic Requirements
- CMMC Level 2 Security Requirements: 14 Families and 320 Objectives
- CMMC Level 3 Security Requirements: 24 Enhanced Requirements
- Who Must Meet CMMC Requirements
- CMMC Certification, Affirmation, and Documentation Requirements
- How Isora GRC Helps with CMMC Requirements
- Key Takeaways
- CMMC Requirements FAQs
CMMC Requirements: What Defense Contractors Must Implement at Each Level
CMMC requirements set the cybersecurity standard a company must meet to win and keep Department of Defense (DoD) contracts that involve sensitive government information. The required level rises with the sensitivity of that information, from basic safeguarding at Level 1 to advanced protection at Level 3.
Two rules and a mid-2026 change define what applies today. The CMMC Program rule took effect in December 2024, and the acquisition rule that writes CMMC into defense contracts followed in November 2025. In July 2026, the DoD suspended the third-party assessment phase for a 60-day review, though the underlying controls stayed in force.
This guide explains what CMMC requirements are, the three levels and the standards behind them, the 14 families and 320 objectives at Level 2, who must comply, and the certification, affirmation, and documentation obligations that apply in 2026.
What Are CMMC Requirements?
Cybersecurity Maturity Model Certification (CMMC) requirements are the cybersecurity controls for Department of Defense (DoD) contractors to protect federal contract information (FCI) and controlled unclassified information (CUI).
CMMC requirements are the security controls a defense contractor must put in place and prove before handling FCI or CUI. The number and severity of security controls a company must implement scales with the data it holds, from CMMC Level 1 (15 basic safeguards), to CMMC Level 2 (110 requirements), and CMMC Level 3 (24 additional requirements).
CMMC is the program that verifies whether controls are in place across the Defense Industrial Base (DIB), the network of contractors and subcontractors that supply the military. Published in October 2024, the CMMC Program rule took effect in December 2024.
Two rules enforce the CMMC in 2026:
- The CMMC Program rule at 32 CFR Part 170, which defines the levels and their requirements.
- The Defense Federal Acquisition Regulation Supplement (DFARS) acquisition rule at 48 CFR, which places CMMC into defense contracts through clause 252.204-7021.
Which requirements apply depends on the type of information a contract involves.
- Federal Contract Information (FCI) is information not intended for public release that the government provides or that is generated for the government under a contract.
- Controlled Unclassified Information (CUI) is information that a law, regulation, or government-wide policy requires to be safeguarded. As the National Archives explains, all CUI held by a contractor is FCI, but not all FCI is CUI.
Three levels of CMMC exist today:
- CMMC Level 1: 15 basic safeguarding requirements for organizations handling FCI.
- CMMC Level 2: 110 NIST SP 800-171 Rev 2 requirements for organizations handling CUI.
- CMMC Level 3: 24 additional NIST SP 800-172 requirements for organizations handling high-value CUI.
CMMC Requirements by Level
At each level, CMMC sets a distinct requirement count defined by a different authority. Because the levels are cumulative, Level 2 includes every Level 1 requirement and Level 3 includes every Level 2 and Level 1 requirement.
| Level | Data protected | Requirement set (authority) | # of requirements | Assessment type | Affirmation cadence |
|---|---|---|---|---|---|
| Level 1 | FCI | Basic safeguarding (FAR 52.204-21) | 15 | Annual self-assessment + SPRS affirmation | Annual |
| Level 2 | CUI | NIST SP 800-171 Rev 2 | 110 (14 families / 320 objectives) | Self or C3PAO, every 3 years | Annual |
| Level 3 | High-value CUI | NIST SP 800-172 | +24 enhanced | DIBCAC, every 3 years | Annual |
CMMC Level 1: 15 Basic Requirements for FCI
To protect FCI (Federal Contract Information), CMMC Level 1 protects FCI with 15 basic safeguarding requirements drawn from the Federal Acquisition Regulation (FAR) clause 52.204-21. At this level, contractors run an annual self-assessment and submit a self-affirmation to the Supplier Performance Risk System (SPRS), the DoD database that stores contractor scores. The 15 requirements map to 59 assessment objectives under NIST SP 800-171A, and every safeguard must be fully in place at the time of the self-assessment.
CMMC Level 2: 110 Requirements for CUI
To protect CUI (Controlled Unclassified Information), CMMC Level 2 contains the largest requirement set with 110 security requirements. In fact, CMMC Level 2 security requirements come straight from NIST SP 800-171 Rev 2, incorporated by reference in 32 CFR §170.14. Depending on the contract, defense contractors must complete:
- Either a self-assessment or an assessment by a CMMC Third-Party Assessment Organization (C3PAO) every three years.
- An annual affirmation.
CMMC Level 3: 24 Requirements for CUI
To protect the most sensitive CUI (Controlled Unclassified Information), CMMC Level 3 adds 24 selected enhanced requirements from NIST SP 800-172. At this level, the government’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) conducts the assessment.
However, a NIST publication becomes a CMMC obligation only once the DoD incorporates it through formal rule-making. CMMC Level 3, for instance, still grades against the February 2021 version of NIST SP 800-172. For the requirement-by-requirement depth behind this summary, see our NIST SP 800-171 guide.
CMMC Level 1 Security Requirements: 15 Basic Requirements
CMMC Level 1 comprises 15 basic safeguarding requirements a contractor must implement to protect FCI. Set by Federal Acquisition Regulation (FAR) clause 52.204-21, these requirements span six of the same security families used at Level 2 and map to 59 assessment objectives under NIST SP 800-171A.
The 15 requirements fall into six security families:
| Security Family | FAR Requirement |
|---|---|
| Access Control | Limit system access to authorized users, processes acting on their behalf, and devices. |
| Limit system access to the transactions and functions that authorized users are permitted to execute. | |
| Verify and control connections to and use of external systems. | |
| Control information posted or processed on publicly accessible systems. | |
| Identification and Authentication | Identify system users, processes acting on behalf of users, and devices. |
| Authenticate the identities of those users, processes, and devices before granting access to organizational systems. | |
| Media Protection | Sanitize or destroy media containing FCI before disposal or release for reuse. |
| Physical Protection | Limit physical access to systems, equipment, and operating environments to authorized individuals. |
| Escort visitors and monitor their activity, maintain audit logs of physical access, and control and manage physical access devices. | |
| System and Communications Protection | Monitor, control, and protect communications at the external boundaries and key internal boundaries of systems. |
| Separate publicly accessible system components onto subnetworks that are physically or logically isolated from internal networks. | |
| System and Information Integrity | Identify, report, and correct system flaws in a timely manner. |
| Protect against malicious code at appropriate locations across organizational systems. | |
| Update malicious code protection mechanisms when new releases become available. | |
| Perform periodic scans of the system and real-time scans of files from external sources as they are downloaded, opened, or run. |
Because Level 1 allows no Plan of Action and Milestones (POA&M), every requirement must be fully met before a contractor submits its annual self-affirmation to SPRS.
CMMC Level 2 Security Requirements: 14 Families and 320 Objectives
The 110 requirements for protecting CUI that define CMMC Level 2 come straight from NIST SP 800-171 Rev 2. Each security control is organized into a family that covers one area of a security practice. Each requirement is further proven against specific assessment objectives, for a total of 320 objectives at CMMC Level 2.
The 14 families are:
| Security Family | What It Covers |
|---|---|
| Access Control | Limits system access to authorized users, devices, and the transactions they are permitted to perform. |
| Awareness and Training | Makes sure staff and managers understand security risks and their own responsibilities. |
| Audit and Accountability | Creates and retains system logs so activity can be traced to an individual user. |
| Configuration Management | Establishes and maintains secure baseline settings for hardware, software, and systems. |
| Identification and Authentication | Verifies the identity of users, processes, and devices before granting access. |
| Incident Response | Prepares the organization to detect, report, and recover from security incidents. |
| Maintenance | Controls how systems are maintained, including remote and third-party maintenance. |
| Media Protection | Safeguards, sanitizes, and limits access to the digital and physical media that holds CUI. |
| Personnel Security | Screens individuals before access and protects CUI during transfers and terminations. |
| Physical Protection | Limits physical access to systems, equipment, and the facilities that house them. |
| Risk Assessment | Identifies and evaluates risk to operations and systems, including regular vulnerability scanning. |
| Security Assessment | Tests whether controls work as intended and tracks fixes through plans of action. |
| System and Communications Protection | Monitors and protects information at system boundaries and in transit. |
| System and Information Integrity | Identifies and corrects flaws and defends against malicious code. |
Several requirement areas sit inside these families. For example:
- Encryption falls under System and Communications Protection, where control SC.L2-3.13.11 requires cryptographic protection of CUI, which generally means Federal Information Processing Standards (FIPS)-validated cryptography. Under the CMMC scoring methodology at 32 CFR §170.24, it’s the one higher-value control that may sit on a POA&M, allowed only when encryption is in place but not yet FIPS-validated.
- Physical protection and media protection, including media sanitization, are their own families in the list above.
Each of the 320 objectives calls for evidence that’s retrievable on demand, from configuration screenshots to logs and signed policies. For more about how to scope these controls, see the FCI and CUI scoping guide.
CMMC Level 3 Security Requirements: 24 Enhanced Requirements
To protect the most sensitive CUI, CMMC Level 3 adds 24 enhanced security requirements on top of the 110 a contractor already meets at Level 2. Targeting the tradecraft of advanced persistent threats, the DoD selected these requirements from NIST SP 800-172 and set them out in Table 1 to 32 CFR §170.14(c)(4).
To begin CMMC Level 3, a contractor must already hold a Level 2 certification, with DIBCAC assessments every three years. CMMC Level 3 also permits a limited POA&M, so long as open items are closed within 180 days.
The 24 requirements span 10 security families:
| Security Family | Enhanced Requirement |
|---|---|
| Access Control | Restrict access to only the information resources the organization owns, provisions, or issues. |
| Employ secure information transfer solutions to control information flows between security domains. | |
| Awareness and Training | Provide threat-focused awareness training at hire, after a significant cyber event, and at least annually. |
| Include role-based practical exercises aligned with current threat scenarios. | |
| Configuration Management | Maintain an authoritative source and repository for approved, implemented system components. |
| Employ automated mechanisms to detect and quarantine or remove misconfigured or unauthorized components. | |
| Employ automated discovery and management tools to keep a current, complete component inventory. | |
| Identification and Authentication | Authenticate systems and components before a network connection using cryptographic, replay-resistant bidirectional authentication. |
| Block components from connecting until they are known, authenticated, and properly configured. | |
| Incident Response | Maintain a security operations center capability that operates 24/7. |
| Maintain a cyber incident response team deployable within 24 hours. | |
| Personnel Security | Protect organizational systems when adverse information develops about individuals with CUI access. |
| Risk Assessment | Employ threat intelligence to guide security architecture, monitoring, threat hunting, and response. |
| Conduct cyber threat hunting on an aperiodic basis to find and disrupt threats that evade existing controls. | |
| Apply advanced automation and analytics to predict and identify risk. | |
| Document the selected security solution, its rationale, and the risk determination in the SSP. | |
| Assess security solution effectiveness at least annually or after relevant threat information or an incident. | |
| Assess, respond to, and monitor supply chain risk across systems and components. | |
| Maintain a supply chain risk management plan and update it at least annually. | |
| Security Assessment | Conduct penetration testing at least annually using automated tools and expert-led ad hoc tests. |
| System and Communications Protection | Apply physical isolation, logical isolation, or both across systems and components. |
| System and Information Integrity | Verify the integrity of security-critical and essential software using roots of trust or cryptographic signatures. |
| Include specialized assets such as IoT, OT, and government-furnished equipment in scope, or segregate them onto purpose-specific networks. | |
| Use threat indicator information to guide intrusion detection and threat hunting. |
Each selected requirement counts as one point. So, a perfect Level 3 score equals the 24 enhanced requirements, on top of the maximum Level 2 score a contractor must already hold.
Who Must Meet CMMC Requirements
CMMC requirements apply to all DoD contractors and subcontractors that handle FCI or CUI. More specifically, [DFARS 252.204-7021](https://www.acquisition.gov/dfars/252.204-7021-contractor-compliance-cybersecurity-maturity-model-certification-level-requirements.) requires a prime contractor to pass CMMC requirements down to any subcontractor that handles FCI or CUI.
CMMC Certification, Affirmation, and Documentation Requirements
CMMC adds assessment, affirmation, and documentation obligations, on top of technical controls. However, the specifics vary by level.
At CMMC Level 1, contractors must:
- Run a self-assessment against the 15 basic safeguards each year.
- Submit an annual affirmation to SPRS through a senior company official.
- Meet all 15 requirements fully before filing that affirmation.
Level 1 permits no POA&M, requires no third-party assessment, and carries no System Security Plan requirement, which begins at Level 2.
At CMMC Level 2, organizations must:
- Conduct a self-assessment or C3PAO assessment every three years.
- Complete an annual affirmation.
- Earn conditional certification with a passing score of 88 out of 110 (80%).
- Close any Plan of Action and Milestones within 180 days, under the scoring and POA&M rules at 32 CFR §170.21.
Level 3 follows the same three-year cadence under DIBCAC.
Two documents are required artifacts at Level 2 and Level 3.
- A System Security Plan (SSP) describes how a contractor meets each requirement.
- A Plan of Action and Milestones (POA&M) tracks the gaps still open and the milestones to close them.
The Program rule also expects a defined assessment scope and asset inventory alongside the annual affirmation submitted through SPRS.
But the enforcement timeline shifted in mid-2026.
On July 13, 2026, the Department of Defense suspended CMMC Phase II, the milestone set for November 10, 2026 that would have required C3PAO third-party assessments, along with other pending CMMC implementation milestones. The DoD also stood up a CMMC Reform Task Force for a 60-day review, with recommendations expected around mid-September 2026.
Still, the underlying requirements stayed the same. Phase I self-assessment obligations and the [DFARS 252.204-7012](https://www.acquisition.gov/dfars/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.) requirement to implement NIST SP 800-171 Rev 2 remain in force. During the suspension, contracting officers may require only Level 1 (Self) or Level 2 (Self).
How Isora GRC Helps with CMMC Requirements
Isora GRC is the GRC Assessment Platform™ that gives security teams one connected workspace to run assessments, manage vendors and assets, track risks, and prove compliance. For CMMC, that means a structured way to work through NIST SP 800-171 Rev 2 instead of managing the effort across spreadsheets and email.
Security teams use Isora GRC to:
- Run self-assessments against the 110 NIST SP 800-171 Rev 2 requirements from a prebuilt, framework-aligned questionnaire.
- Capture evidence alongside each response, building a defensible, audit-ready record without manual assembly.
- Track open gaps as findings in a connected risk register, each with an owner and remediation plan, ahead of a C3PAO assessment.
See how Isora GRC simplifies CMMC compliance →
Key Takeaways
The fastest path to CMMC compliance is to map the data to a level and then to its requirement set. A structured assessment platform like Isora GRC keeps that readiness work organized.
See the GRC Assessment Platform™ in action →
CMMC Requirements FAQs
What are the CMMC requirements?
CMMC requirements are the cybersecurity controls a defense contractor must meet to handle federal contract information (FCI) and controlled unclassified information (CUI). They scale by level: 15 basic safeguarding requirements at Level 1, the 110 NIST SP 800-171 Rev 2 requirements at Level 2, and 24 added NIST SP 800-172 requirements at Level 3. The required level is set by the type of information in the contract.
How many controls does CMMC Level 2 require?
CMMC Level 2 requires the 110 security requirements of NIST SP 800-171 Rev 2, organized into 14 families. Each requirement is tested against specific assessment objectives, for a total of 320 objectives to evidence. A passing score of 88 out of 110 (80%) earns a conditional certification with a limited plan of action.
Do CMMC requirements apply to small businesses?
Yes. CMMC requirements follow the data a contract involves, so a small business or subcontractor that handles FCI or CUI meets the same requirements as a large prime. Prime contractors flow CMMC requirements down to subcontractors that handle this information. The controls apply regardless of company size.
What are the CMMC encryption requirements?
Level 2 requires cryptographic protection of CUI under control SC.L2-3.13.11, which generally calls for FIPS-validated encryption. This is the one higher-value control that may sit on a plan of action and milestones (POA&M), allowed only when encryption is in place but not yet FIPS-validated. Encryption sits within the System and Communications Protection family of NIST SP 800-171 Rev 2.
Which NIST standard sets the CMMC Level 2 requirements?
CMMC Level 2’s requirements are identical to NIST SP 800-171 Rev 2, as incorporated by reference in 32 CFR §170.14. NIST withdrew Rev 2 in May 2024 in favor of Rev 3, but CMMC still points to Rev 2, so contractors scope CMMC against Rev 2 rather than the newest revision.
Have CMMC requirements changed in 2026?
The underlying requirements have not changed, but the enforcement timeline has. On July 13, 2026, the Department of Defense suspended CMMC Phase II, the milestone that would have required third-party (C3PAO) assessments, and opened a 60-day review. Self-assessment obligations and the NIST SP 800-171 Rev 2 and DFARS 252.204-7012 requirements remain in effect.
This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.