CMMC: The Complete Guide to Cybersecurity Maturity Model Certification
The Cybersecurity Maturity Model Certification (CMMC) is a U.S. Department of Defense (DoD) program that verifies defense contractors have put the required cybersecurity controls in place. Codified in 32 CFR Part 170, a final rule published October 15, 2024, the CMMC took effect on December 16, 2024. Today, the program applies across the Defense Industrial Base (DIB), the network of contractors and subcontractors that supply the military.
CMMC was originally created to replace self-attestation with verified evidence. For years, contractors simply attested that they protected sensitive data. CMMC makes them demonstrate it. Still, only 1% of contractors feel fully prepared, with a median self-assessment score of 60 against a required 110, according to the State of the DIB 2025 report.
The rollout is also in flux. On July 13, 2026, the Department of Defense suspended CMMC Phase II and opened a reform review, a change the government reference pages have been slow to reflect.
This guide explains what CMMC is, its three levels, the requirements and frameworks behind them, the rule-making timeline and current status, and how to become compliant.
What Is CMMC?
CMMC (Cybersecurity Maturity Model Certification) is a U.S. Department of Defense program that requires defense contractors and subcontractors to verify they have implemented the cybersecurity controls needed to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). It is codified in 32 CFR Part 170, effective December 16, 2024.
CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense’s mechanism to verify that companies in the defense supply chain have implemented the safeguards required to protect government information.
The current framework is CMMC 2.0. It reduced the original five-level model to three levels, and each level aligns with an established NIST standard, per the CMMC Model Overview. Two information types drive everything in the program:
- Federal Contract Information (FCI) is information not intended for public release, provided by or generated for the government under a contract, as defined by the National Archives.
- Controlled Unclassified Information (CUI) is information that a law, regulation, or government-wide policy requires to be safeguarded.
Any company going through the program is called an Organization Seeking Assessment or Certification (OSC). That label covers any contractor working to demonstrate its cybersecurity posture, from a small parts manufacturer to a prime contractor.
Why CMMC Matters and Who Must Comply
CMMC applies to DoD contractors and subcontractors across the Defense Industrial Base that handle FCI or CUI. Companies that supply only commercial off-the-shelf (COTS) products are excepted.
The required level depends on the type of information a given contract involves. Firms handling FCI tend to face fewer requirements than firms storing CUI. Because CMMC flows down the supply chain, prime contractors pass the same requirements to any subcontractors that handle the same information.
CMMC affects more than 200,000 organizations across the defense supply chain, according to the DoD Regulatory Impact Analysis. Many of them are small businesses without dedicated security staff.
Only 1% of contractors feel fully prepared, down from 4% in 2024 and 8% in 2023, with a median self-assessment score of 60 out of a required 110, according to the State of the DIB 2025 report. The same report found that:
- 17% of contractors carry a negative SPRS score
- 69% still rely on self-assessment
- Only 30% have completed a validated assessment
For most contractors, the biggest challenge with CMMC compliance is demonstrable evidence. Even if they’ve done the security work, they may struggle to prove it when an assessor asks.
CMMC Rulemaking and Current Status
Even though CMMC is currently live, the enforcement schedule changed in mid-2026. More specifically, a July 2026 action paused the phase that would have required third-party assessments.
- October 15, 2024 — the CMMC Program rule. 32 CFR Part 170 was published and took effect December 16, 2024.
- November 10, 2025 — the acquisition rule. The 48 CFR/DFARS acquisition rule took effect and established [DFARS 252.204-7021], the clause that requires contractors to maintain a current CMMC status, submit that status to the Supplier Performance Risk System, and file an annual affirmation of continuous compliance.
- July 13, 2026 — Phase II suspension. The DoD suspended CMMC Phase II, the phase that would have required C3PAO third-party assessment on November 10, 2026, and opened a 60-day reform review under a CMMC Reform Task Force.
The suspension paused the third-party path while leaving the program itself intact.
Phase I self-assessment obligations remain in force, and the underlying [DFARS 252.204-7012] requirement to implement NIST SP 800-171 is unchanged. In the interim, contractors handling CUI should still build and maintain their 800-171 posture.
CMMC Levels
CMMC has three levels, each tied to information sensitivity and a specific control set. Each level includes all the requirements of the levels beneath it, plus additional controls of its own.
- CMMC Level 1 covers basic safeguarding of FCI and relies on an annual self-assessment.
- CMMC Level 2 is where most contractors handling CUI land, and it can be met through a self-assessment or a third-party assessment depending on the contract.
- CMMC Level 3 is reserved for the most sensitive programs and is assessed by the government.
| Level | Protects | Control basis | Assessment type | Frequency |
|---|---|---|---|---|
| Level 1 | FCI | 15 basic safeguarding requirements from FAR 52.204-21 | Self-assessment | Annual, with affirmation |
| Level 2 | CUI | 110 requirements of NIST SP 800-171 Rev 2 | Self-assessment or C3PAO assessment | Every 3 years, plus annual affirmation |
| Level 3 | CUI (highest-priority programs) | A subset (24) of NIST SP 800-172 enhanced requirements | Government-led | Every 3 years |
CMMC Requirements and Frameworks
CMMC requirements are controls drawn from existing federal standards. The CMMC program is what verifies whether a contractor has met them.
- Level 1 draws its 15 requirements from FAR 52.204-21.
- Level 2 security requirements are identical to the 110 requirements of NIST SP 800-171 Rev 2, incorporated by reference in 32 CFR §170.14.
Each requirement breaks down into individual assessment objectives (about 320 for CMMC Level 2 per NIST SP 800-171A) and each objective calls for retrievable, timestamped evidence, not written policies alone.
Notably, NIST withdrew SP 800-171 Rev 2 on May 14, 2024 and superseded it with Rev 3, yet CMMC still references Rev 2 as the normative basis for Level 2.
CMMC Phases
The DoD defines a phased approach for implementing CMMC requirements under 32 CFR §170.3. The four phases are:
- Phase 1 — November 10, 2025: DoD includes Level 1 and Level 2 self-assessment requirements in applicable solicitations and contracts.
- Phase 2 — scheduled for November 10, 2026. Adds Level 2 third-party (C3PAO) certification requirements to applicable contracts.
- Phase 3 — scheduled for November 10, 2027. Adds Level 3 certification requirements, assessed by the government through DIBCAC.
- Phase 4 — scheduled for November 10, 2028. Full implementation, with CMMC requirements in all applicable solicitations and contracts, including option periods on awards made earlier.
The rollout is currently paused in Phase 1. The July 13, 2026 suspension froze the transition to Phase 2 and the pending Phase 3 and Phase 4 milestones while a reform review runs. As of now, no later phase carries a firm date.
The CMMC Ecosystem
CMMC runs through a defined set of organizations and credentials, each with a distinct role. Knowing who does what prevents a common mistake, which is assuming a consultant can grant certification.
- The Cyber AB is the accreditation body for the CMMC ecosystem.
- A C3PAO (CMMC Third-Party Assessment Organization) conducts Level 2 certification assessments and must itself pass a DCMA DIBCAC Level 2 assessment to be authorized.
- A CCP and a CCA (Certified CMMC Professional and Certified CMMC Assessor) are individual credentials held by the people who staff and support assessments.
- An RP or RPO (Registered Practitioner / Registered Provider Organization) provides consulting and advisory support but cannot issue a certification.
- DIBCAC, the Defense Contract Management Agency’s assessment center, performs government-led assessments.
Notably, counts of authorized C3PAOs and credentialed assessors change month to month.
How to Become CMMC Compliant
Becoming CMMC compliant follows a repeatable path from scoping to affirmation.
- Scope the environment. Identify every system, user, and location that handles FCI or CUI.
- Gap-assess against the applicable level. Measure the current state against the official Assessment Guides for the target level.
- Remediate and document. Fix the gaps, then capture the work in a System Security Plan (SSP) and a Plan of Action and Milestones (POA&M).
- Submit an SPRS score. Post the self-assessment score to the Supplier Performance Risk System (SPRS).
- Self-assess or engage a C3PAO. Complete a self-assessment or, when the contract requires it, engage a third-party assessor.
- Maintain with an annual affirmation. Submit the annual affirmation of continuous compliance and keep evidence current.
How to Simplify CMMC Readiness
CMMC readiness comes down to running structured assessments and holding onto defensible evidence, which is exactly the work most contractors struggle to organize. Isora GRC, the GRC Assessment Platform, gives DIB security teams one connected workspace for that work. It supports readiness and self-assessment. It does not issue CMMC certification or replace a C3PAO assessment.
With Isora GRC, teams can:
- Launch a CMMC assessment from a prebuilt questionnaire library. The library supports CMMC alongside NIST, CIS, HIPAA, GLBA, and HECVAT out of the box, so a new requirement moves from “build an assessment” to “launch an assessment”.
- Bring control owners into the process without training. Collaborative questionnaires let the people closest to each control respond directly, which drives the participation a real program needs.
- Capture evidence alongside each response. Evidence attaches to the response it supports, creating a defensible, audit-ready record without manual assembly, which addresses the “can’t prove it” problem head-on.
See the GRC Assessment Platform in action.
Key Takeaways
CMMC is the DoD’s way of verifying that the defense supply chain protects FCI and CUI, and for most contractors that means meeting NIST SP 800-171 Rev 2 at Level 2. The single most useful move right now is to keep building that 800-171 posture and the evidence behind it. Phase I self-assessment is active, Phase II third-party assessment is under review as of July 2026, and the DFARS 252.204-7012 obligation never went away.
To operationalize CMMC readiness in one connected workspace, see the GRC Assessment Platform in action.
CMMC FAQs
What does CMMC stand for?
CMMC stands for Cybersecurity Maturity Model Certification. It is a U.S. Department of Defense program that verifies defense contractors have implemented the security controls required to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
What is CMMC compliance?
CMMC compliance means a defense contractor has implemented, documented, and can demonstrate the cybersecurity controls required for its CMMC level. For most contractors handling CUI, that is Level 2, which maps to the 110 security requirements of NIST SP 800-171 Rev 2. Compliance is proven through a self-assessment or a third-party assessment, plus an annual affirmation in the Supplier Performance Risk System (SPRS).
Who needs CMMC certification?
CMMC applies to Department of Defense contractors and subcontractors across the Defense Industrial Base that handle FCI or CUI; providers of commercial off-the-shelf (COTS) products are excepted. The DoD’s Regulatory Impact Analysis estimates the rule affects over 200,000 organizations. The required level depends on the type of information the contract involves.
What are the CMMC levels?
CMMC 2.0 has three levels. Level 1 covers basic safeguarding of FCI using the 15 requirements in FAR 52.204-21; Level 2 covers CUI using the 110 requirements of NIST SP 800-171 Rev 2; Level 3 adds a subset of NIST SP 800-172 enhanced requirements for the most sensitive programs. The levels are cumulative.
Is CMMC still required in 2026?
Yes, but the rollout changed. On July 13, 2026, the Department of Defense suspended CMMC Phase II — the phase that would have required third-party (C3PAO) assessments — and opened a 60-day reform review. Phase I self-assessment obligations and the underlying DFARS 252.204-7012 requirement to implement NIST SP 800-171 remain in force.
What is the difference between CMMC and NIST 800-171?
NIST SP 800-171 Rev 2 is the control framework; CMMC is the DoD program that verifies a contractor has actually implemented it. CMMC Level 2 security requirements are identical to the 110 requirements in NIST SP 800-171 Rev 2, incorporated by reference in 32 CFR §170.14. In short, NIST 800-171 defines the controls and CMMC confirms a contractor meets them.
How much does CMMC cost?
Cost depends on level and assessment path. The DoD estimates a Level 2 self-assessment at roughly $37,000–$49,000 and a Level 2 C3PAO certification at roughly $105,000–$118,000 over a three-year cycle — figures that cover the assessment, reporting, and affirmation only, not the cost of implementing controls.
This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.