The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense program that verifies contractors and subcontractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). It is codified at 32 CFR Part 170, published as a final rule on October 15, 2024 (89 FR 83214), and applied to contracts through DFARS clause 252.204-7021.
CMMC is not guidance and not optional. If your organization does business with the DoD, or supports a prime contractor in the defense supply chain, CMMC determines whether you can bid on or retain covered contracts.
One thing changed recently, and it matters. The rollout is partially paused: Phase II, the stage that would have made third-party certification a condition of award, was suspended on July 13, 2026. Phase I self-assessment requirements remain firmly in place. The status note on this page has the details.
CMMC does not invent new security controls. It verifies requirements that already exist in defense contracts, and it adds three things: defined assessment levels, required assessments, and a signed affirmation of compliance filed in the Supplier Performance Risk System (SPRS).
Under CMMC 2.0 there are three levels:
Most defense contractors that handle CUI fall under Level 2 - that is what the level is scoped to (32 CFR 170.17).
In short: NIST SP 800-171 defines the controls. CMMC verifies and enforces them.
CMMC applies to every organization in the DoD supply chain that handles FCI or CUI, including:
Company size does not matter. If you handle covered DoD information, CMMC applies.
CMMC protects two data types, and the distinction drives your level.
Federal Contract Information (FCI) is information provided by or generated for the government under a contract and not intended for public release. FCI triggers Level 1.
Controlled Unclassified Information (CUI) is sensitive government information that requires safeguarding under law, regulation, or government-wide policy. CUI triggers Level 2 and includes:
From an IT perspective, CUI rarely sits in one system. It lives across email, file storage, endpoints, cloud platforms, and vendor systems - which is why scoping is where most CMMC efforts succeed or fail.
CMMC sits at the end of a chain that starts with the data itself:
CUI is the what. NIST defines the how. DFARS and CMMC enforce it.
The Phase II suspension paused the certification tier, not the chain. Contractors still owe full NIST SP 800-171 implementation under DFARS 252.204-7012 today, exactly as before.
CMMC also builds on FAR 52.204-21 for basic FCI safeguarding, and it runs parallel to ITAR, which controls who may access export-controlled technical data rather than how systems are secured.
CMMC is control-heavy, technical, and evidence-driven. The requirement areas:
Controls must exist and be provable. Two paperwork mechanics carry legal weight. First, a senior official affirms compliance in SPRS annually and after every assessment (32 CFR 170.22). Second, POA&Ms are restricted: none are permitted at Level 1, and at Levels 2 and 3 they are limited to select requirements and must close out within 180 days (32 CFR 170.21).
Failure to meet CMMC requirements can result in:
Most CMMC failures share the same causes: poor scoping of CUI, weak MFA or access controls, missing documentation, over-reliance on informal processes, and assuming IT vendors handle compliance. None of these are exotic. All of them are fixable before an assessment instead of during one.
CMMC aligns closely with the NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001, and SOC 2. The control language differs; the fundamentals do not.
Organizations that implement CMMC well typically see real improvements in overall security posture, not just compliance readiness. The work you do for CMMC is the same work that stops ransomware and passes insurance reviews.
Here is the key takeaway: CMMC is not about intent or effort. It is about demonstrable control.
Most requirements are known cybersecurity practices, technically achievable, and already required under DFARS. What CMMC added is verification and accountability - and neither was suspended. The July 2026 pause changed who checks your work at Level 2. It did not change what you owe.
Our Cyber Risk & Compliance Gap Assessment helps organizations:
Our assessment maps your environment against NIST SP 800-171 and the 32 CFR Part 170 assessment criteria, so your SPRS score and affirmation rest on evidence.
Identify the level your contracts require, which contracts are affected, which systems handle FCI or CUI, and which vendors are in scope. Scoping errors here cascade into everything downstream.
Evaluate control implementation, documentation gaps, technical weaknesses, and evidence availability. This step prevents failed assessments and inaccurate SPRS scores later.
Focus on MFA and access management, secure configurations, endpoint and email security, logging and monitoring, and incident response readiness. These areas decide most assessments.
Prepare policies and procedures, a System Security Plan (SSP), and evidence artifacts. Where POA&Ms are permitted, use them correctly: none at Level 1, time-limited with a 180-day closeout at Level 2 (32 CFR 170.21).
Confirm controls are consistently enforced, evidence is current, staff understand the processes, and vendors meet flow-down requirements. The affirmation a senior official signs should be one they can defend.
If you hold DoD contracts or support a prime contractor, and you handle Federal Contract Information or Controlled Unclassified Information, yes. Company size does not matter, and outsourcing IT does not transfer the obligation. The contract clauses tell you definitively - look for DFARS 252.204-7012, 7019, 7020, and 7021.
Partially, and the distinction matters. Phase I remains fully in effect: Level 1 and Level 2 self-assessments, SPRS submissions, and affirmations are still conditions of award in covered contracts. What is suspended is Phase II - the rollout of third-party C3PAO certification requirements - while DoD reviews the program. NIST SP 800-171 protection of CUI is still required under DFARS 252.204-7012 regardless.
It depends on the data. Handling only FCI points to Level 1. Handling CUI points to Level 2, which is where most contractors with CUI land. Level 3 is limited to the highest-risk programs and is government-assessed. Your contracts and your data inventory determine it - not your preference.
NIST SP 800-171 is the control set - the specific security requirements for protecting CUI. CMMC is the verification program that assesses whether you actually implemented them. You have owed 800-171 under DFARS 252.204-7012 since before CMMC existed; CMMC adds the checking.
Only within limits. 32 CFR Part 170 permits no POA&Ms at Level 1 - every requirement must be met. At Level 2, POA&Ms are allowed only for select requirements and must be closed out within 180 days. A POA&M is a short bridge, not a parking lot.
A senior company official affirms in the Supplier Performance Risk System that your organization is compliant with its CMMC requirements, annually and after each assessment. It is a signed representation to the government. If it overstates your compliance, it becomes a legal problem, not a paperwork problem.
It depends on your current posture, your CUI footprint, and your level. We publish no pricing - you get a firm quote before any work begins, and the conversation costs nothing. The assessment tells you the real scope before you spend on remediation.
Start by finding your CUI - what it is, where it lives, and who touches it. Then get a gap assessment against NIST SP 800-171 before an assessor or a prime does it for you. Our Cyber Risk & Compliance Gap Assessment is built for exactly that first step.
Defense work is not remote from the Treasure Coast - it surrounds it. The corridor running from the Space Coast's launch, avionics, and defense electronics operations south through the Treasure Coast's aviation and precision manufacturing base puts DoD primes, subcontractors, and specialty shops within an hour of our Hobe Sound office. Many are small firms holding flowed-down DFARS clauses they have never fully scoped. /* FLAG: named-employer specifics (e.g., individual primes or installations) intentionally omitted - would need a qualifying source before naming */
Florida also adds a state notification layer on top of federal incident reporting. The Florida Information Protection Act (F.S. 501.171) requires notice to affected individuals no later than 30 days after determining a breach of personal information. Breaches affecting 500 or more Florida residents must also be reported to the Florida Department of Legal Affairs within the same 30 days, with one 15-day extension available on written request. Third-party agents - including IT providers - are required by the statute to notify the covered entity within 10 days of determining a breach.
Those clocks run separately from the 72-hour DoD cyber incident report under DFARS 252.204-7012. A breach at a Florida defense contractor can start both timers on the same day.
Official source: DoD CIO, CMMC Program
Secondary source: eCFR, 32 CFR Part 170
Source verified 2026-07-24
By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25