What It Is

CMMC does not invent new security controls. It verifies requirements that already exist in defense contracts, and it adds three things: defined assessment levels, required assessments, and a signed affirmation of compliance filed in the Supplier Performance Risk System (SPRS).

Under CMMC 2.0 there are three levels:

  • Level 1 (Foundational): basic safeguarding of FCI - the 15 requirements of FAR 52.204-21. An annual self-assessment with results in SPRS, plus an affirmation. 32 CFR 170.15 permits no POA&Ms at Level 1 - every requirement must be met.
  • Level 2 (Advanced): protection of CUI through the security requirements of NIST SP 800-171. Depending on the contract, a self-assessment or a certification assessment by a C3PAO (an authorized third-party assessment organization). New third-party certification requirements are currently suspended with Phase II; Level 2 self-assessments continue.
  • Level 3 (Expert): enhanced requirements drawn from NIST SP 800-172 for the highest-risk programs, assessed by the government (DIBCAC). Rare, and limited to critical programs.

Most defense contractors that handle CUI fall under Level 2 - that is what the level is scoped to (32 CFR 170.17).

In short: NIST SP 800-171 defines the controls. CMMC verifies and enforces them.

What Information Is Regulated

CMMC protects two data types, and the distinction drives your level.

Federal Contract Information (FCI) is information provided by or generated for the government under a contract and not intended for public release. FCI triggers Level 1.

Controlled Unclassified Information (CUI) is sensitive government information that requires safeguarding under law, regulation, or government-wide policy. CUI triggers Level 2 and includes:

  • Technical drawings and specifications: the engineering core of most defense work.
  • Export-controlled data: technical data that also sits under ITAR or EAR jurisdiction.
  • Defense-related intellectual property: designs, processes, and research tied to DoD programs.
  • Operational and logistics data: schedules, quantities, and movement information.
  • Certain personal and financial data: where tied to defense programs.

From an IT perspective, CUI rarely sits in one system. It lives across email, file storage, endpoints, cloud platforms, and vendor systems - which is why scoping is where most CMMC efforts succeed or fail.

IT Requirements

CMMC is control-heavy, technical, and evidence-driven. The requirement areas:

  • Access control and identity: role-based access, least-privilege permissions, multi-factor authentication, secure remote access, and account monitoring and reviews.
  • Asset and data management: inventory of systems and users, identification of systems handling CUI, data flow documentation, and secure storage and transmission.
  • System and endpoint security: secure configurations, endpoint protection, patch and vulnerability management, and malware protection.
  • Logging, monitoring, and incident response: audit logging, monitoring for security events, incident response plans, and cyber incident reporting to DoD within the 72-hour window DFARS 252.204-7012 sets.
  • Configuration and change management: baseline configurations, controlled changes, and documented modifications.
  • Vendor and supply chain risk: identifying vendors with CUI access, flowing requirements down to subcontractors, and holding them accountable.
  • Policies, procedures, and evidence: written policies, implemented procedures, and technical proof - screenshots, logs, and configurations.

Controls must exist and be provable. Two paperwork mechanics carry legal weight. First, a senior official affirms compliance in SPRS annually and after every assessment (32 CFR 170.22). Second, POA&Ms are restricted: none are permitted at Level 1, and at Levels 2 and 3 they are limited to select requirements and must close out within 180 days (32 CFR 170.21).

How It Fits Into Cyber Risk Management

CMMC aligns closely with the NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001, and SOC 2. The control language differs; the fundamentals do not.

Organizations that implement CMMC well typically see real improvements in overall security posture, not just compliance readiness. The work you do for CMMC is the same work that stops ransomware and passes insurance reviews.

How We Help With CMMC Compliance

Our Cyber Risk & Compliance Gap Assessment helps organizations:

  • Comprehensive Compliance & Security Review: evaluate your environment against the requirements that apply to you
  • Plain-Language Gap Analysis & Roadmap: see exactly where you stand and what to fix first
  • Corrective Action Plan & Progress Tracker (CART): turn findings into tracked, prioritized work
  • POA&M (Plan of Action & Milestones): the documented remediation record auditors and contract officers expect

Our assessment maps your environment against NIST SP 800-171 and the 32 CFR Part 170 assessment criteria, so your SPRS score and affirmation rest on evidence.

How to Prepare

  1. Determine your CMMC level and scope

    Identify the level your contracts require, which contracts are affected, which systems handle FCI or CUI, and which vendors are in scope. Scoping errors here cascade into everything downstream.

  2. Perform a CMMC readiness and gap assessment

    Evaluate control implementation, documentation gaps, technical weaknesses, and evidence availability. This step prevents failed assessments and inaccurate SPRS scores later.

  3. Implement and harden required controls

    Focus on MFA and access management, secure configurations, endpoint and email security, logging and monitoring, and incident response readiness. These areas decide most assessments.

  4. Build documentation and evidence

    Prepare policies and procedures, a System Security Plan (SSP), and evidence artifacts. Where POA&Ms are permitted, use them correctly: none at Level 1, time-limited with a 180-day closeout at Level 2 (32 CFR 170.21).

  5. Prepare for assessment and affirmation

    Confirm controls are consistently enforced, evidence is current, staff understand the processes, and vendors meet flow-down requirements. The affirmation a senior official signs should be one they can defend.

CMMC in Florida

Defense work is not remote from the Treasure Coast - it surrounds it. The corridor running from the Space Coast's launch, avionics, and defense electronics operations south through the Treasure Coast's aviation and precision manufacturing base puts DoD primes, subcontractors, and specialty shops within an hour of our Hobe Sound office. Many are small firms holding flowed-down DFARS clauses they have never fully scoped. /* FLAG: named-employer specifics (e.g., individual primes or installations) intentionally omitted - would need a qualifying source before naming */

Florida also adds a state notification layer on top of federal incident reporting. The Florida Information Protection Act (F.S. 501.171) requires notice to affected individuals no later than 30 days after determining a breach of personal information. Breaches affecting 500 or more Florida residents must also be reported to the Florida Department of Legal Affairs within the same 30 days, with one 15-day extension available on written request. Third-party agents - including IT providers - are required by the statute to notify the covered entity within 10 days of determining a breach.

Those clocks run separately from the 72-hour DoD cyber incident report under DFARS 252.204-7012. A breach at a Florida defense contractor can start both timers on the same day.

By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25