Organizations working in the Defense Industrial Base handle information that can directly affect government operations, defense programs, and national security. Protecting that information requires more than having cybersecurity policies on paper. Contractors need to demonstrate that the required safeguards are actually implemented and maintained.
The Cybersecurity Maturity Model Certification, or CMMC, was created to provide that verification framework. It establishes cybersecurity requirements and assessment methods for organizations that handle Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) while performing defense contracts.
CMMC has also changed significantly over time. In 2026, the program remains in Phase 1 following the suspension of the transition to Phase 2. Contractors therefore need to understand both the underlying CMMC framework and the requirements that are being enforced today.
In This Guide
- 01
What Is CMMC and What Does CMMC Mean? - 02
Who Needs CMMC Compliance? - 03
What Are the Three CMMC Levels? - 04
What Are the Main CMMC Compliance Requirements? - 05
How CMMC Assessments and Certification Work - 06
What Is the Current CMMC Timeline in 2026? - 07
How CMMC Relates to NIST SP 800-171 and DFARS - 08
How to Prepare for CMMC Compliance - 09
Common CMMC Compliance Challenges - 10
How Nexeris Helps Organizations Prepare for CMMC - 11
FAQs
What Is CMMC and What Does CMMC Mean?
CMMC is a cybersecurity assessment framework designed to verify whether organizations in the Defense Industrial Base have implemented appropriate safeguards for sensitive federal information.
Rather than relying only on a contractor stating that it meets cybersecurity requirements, CMMC establishes defined assessment procedures tied to the sensitivity of the information an organization handles.
The CMMC model incorporates requirements from FAR 52.204-21, NIST SP 800-171 Revision 2, and selected enhanced requirements from NIST SP 800-172.
What Does CMMC Stand For?
CMMC stands for Cybersecurity Maturity Model Certification.
The framework establishes three cybersecurity levels:
- Level 1 for basic safeguarding of Federal Contract Information
- Level 2 for protecting Controlled Unclassified Information
- Level 3 for organizations requiring enhanced protections against more advanced threats
Each level increases the cybersecurity requirements and, under the full regulatory model, the level of assessment required to demonstrate compliance.
Why the Department of Defense Created CMMC
Defense contractors have long been required to safeguard government information. Requirements such as NIST SP 800-171 and DFARS 252.204-7012 existed before CMMC.
The challenge was verification.
A contractor could have policies stating that controls were implemented, but the government needed stronger assurance that cybersecurity requirements were actually operating throughout the Defense Industrial Base.
CMMC was developed to create a more consistent assessment structure. Instead of treating cybersecurity as a one-time documentation exercise, the framework focuses on demonstrable implementation, defined assessment scopes, evidence, recurring assessments, and ongoing affirmations of compliance.
FCI vs. CUI: Why the Difference Matters
Understanding the difference between FCI and CUI is one of the first steps in determining CMMC requirements.
Federal Contract Information (FCI) generally includes nonpublic information provided by or generated for the government under a federal contract. Organizations handling FCI may fall under CMMC Level 1.
Controlled Unclassified Information (CUI) is more sensitive. It is unclassified information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy. Organizations that process, store, or transmit CUI generally need to meet Level 2 requirements.
The distinction affects the required controls, systems that fall within scope, assessment method, documentation, and third-party dependencies.
Who Needs CMMC Compliance?
CMMC primarily affects organizations participating in the defense supply chain when applicable contract requirements involve FCI or CUI.
The required CMMC level is not simply chosen by the contractor. The applicable solicitation or contract identifies the required CMMC status based on the information and risks associated with the work.
DoD Prime Contractors
Prime contractors working directly with the federal government may need CMMC when their systems process, store, or transmit FCI or CUI associated with a defense contract.
A prime contractor handling only FCI may require Level 1. Contractors handling CUI generally need to meet Level 2 requirements, while particularly sensitive programs may ultimately require Level 3 under the full CMMC framework.
Prime contractors must also consider what information they share with their subcontractors.
Defense Subcontractors
CMMC is not limited to large defense companies.
Cybersecurity obligations can flow from a prime contractor to subcontractors throughout the supply chain. A smaller manufacturer, engineering company, technology provider, or professional services company may therefore have CMMC obligations even if it does not contract directly with the government.
The required level depends on the information involved in the subcontract. Organizations should understand the applicable CMMC flow-down requirements before accepting or transmitting FCI or CUI to downstream suppliers.
Under the CMMC regulations, subcontracting requirements are tied to the information the subcontractor will process, store, or transmit rather than automatically matching the prime contractor’s level.
Managed Service Providers and External Service Providers
Managed Service Providers, Managed Security Service Providers, cloud platforms, and other External Service Providers can materially affect CMMC scope.
If a non-cloud External Service Provider processes, stores, or transmits CUI, the services it provides can become part of the contractor’s assessment scope. The relationship, services, and shared responsibilities should be documented appropriately.
Cloud Service Providers handling CUI are subject to specific requirements, including applicable FedRAMP Moderate or equivalent requirements. Using a third-party provider does not transfer the contractor’s responsibility for protecting CUI.
What Are the Three CMMC Levels?
The CMMC framework contains three levels intended to match cybersecurity requirements to information sensitivity and risk.
CMMC Level 1: Foundational
Level 1 is designed for organizations that handle FCI but do not require Level 2 protection for CUI.
Level 1 incorporates the 15 basic safeguarding requirements in FAR 52.204-21. Current regulations require an annual self-assessment, submission of results into the Supplier Performance Risk System (SPRS), and an affirmation of compliance.
All Level 1 requirements must be met. Plans of Action and Milestones, or POA&Ms, are not permitted for Level 1.
CMMC Level 2: Advanced
Level 2 is the primary CMMC level for organizations that process, store, or transmit CUI.
It aligns directly with the 110 security requirements in NIST SP 800-171 Revision 2 across areas such as access control, configuration management, incident response, authentication, risk assessment, system integrity, and communications protection.
Organizations working toward Level 2 often benefit from structured NIST 800-171 consulting because technical implementation is only part of readiness. Scope, documentation, evidence, cloud dependencies, policies, procedures, and control ownership also need to align with the standard.
Under the full CMMC model, some Level 2 programs use self-assessments while others require certification assessments conducted by a CMMC Third-Party Assessment Organization (C3PAO). However, the current 2026 Phase 2 suspension limits government procurement designations to Level 2 self-assessments during the suspension period.
CMMC Level 3: Expert
Level 3 is designed for a narrower group of organizations supporting highly sensitive defense programs and facing elevated cybersecurity threats.
An organization must satisfy the applicable Level 2 requirements and then implement 24 additional enhanced security requirements selected from NIST SP 800-172. These include capabilities involving threat hunting, advanced security analytics, supply chain risk, penetration testing, isolation techniques, and incident response.
Under the regulatory framework, Level 3 assessments are performed by the Defense Industrial Base Cybersecurity Assessment Center, commonly known as DIBCAC. During the current Phase 2 suspension, however, requiring activities may not designate Level 3 DIBCAC assessments in procurement requirements.
What Are the Main CMMC Compliance Requirements?
CMMC readiness involves much more than installing cybersecurity software. Organizations need to establish a defensible security program and demonstrate how their controls operate.
Security Controls and the 14 NIST SP 800-171 Requirement Families
CMMC Level 2 maps to the 110 requirements in NIST SP 800-171 Revision 2, organized across 14 requirement families:
- Access Control
- Awareness and Training
- Audit and Accountability
- Configuration Management
- Identification and Authentication
- Incident Response
- Maintenance
- Media Protection
- Personnel Security
- Physical Protection
- Risk Assessment
- Security Assessment
- System and Communications Protection
- System and Information Integrity
These requirements address how CUI is accessed, protected, monitored, transmitted, stored, and managed throughout the environment.
System Security Plan and Required Documentation
A System Security Plan, or SSP, is one of the most important components of Level 2 readiness.
The SSP should accurately describe the system boundary, environment, relevant assets, security controls, system connections, and how security requirements are implemented.
Policies and procedures should support what the SSP says. Documentation that describes an ideal process while employees and systems operate differently can create problems during an assessment.
Scoping the CUI Environment
CMMC does not automatically require an organization to assess every system it owns.
The objective is to establish the correct assessment boundary.
Level 2 scoping considers several asset categories, including CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets.
Systems that process, store, or transmit CUI are within the Level 2 assessment scope and must be appropriately documented.
Accurate scoping can reduce unnecessary complexity while making sure systems that actually affect CUI security are not overlooked.
Evidence, Testing, and Continuous Compliance
An assessor does not simply ask whether a security control exists. The organization needs evidence demonstrating that it is implemented.
Depending on the requirement, evidence may include configurations, screenshots, logs, tickets, policies, procedures, training records, access reviews, vulnerability reports, system records, or interviews with responsible personnel.
Evidence also needs to reflect current operations. A policy written several years ago provides little value if the underlying process has changed.
CMMC should therefore be treated as an operating cybersecurity program rather than a documentation project completed shortly before an assessment.
How CMMC Assessments and Certification Work
CMMC uses different assessment methods depending on the required level and contract.
The regulatory framework remains in place, although the types of assessments contracting activities may currently require have been narrowed by the 2026 Phase 2 suspension.
CMMC Self-Assessments
Level 1 requires an annual self-assessment.
Under the regulatory framework, certain Level 2 programs may also use a Level 2 self-assessment. Level 2 self-assessment status is generally valid for three years, provided the organization completes the required annual affirmation.
During the current Phase 1 implementation period, government procurement requirements are limited to Level 1 and Level 2 self-assessments.
C3PAO Assessments
Under the full CMMC model, a Level 2 certification assessment is performed by an authorized or accredited C3PAO.
The assessor reviews the organization’s implementation against the applicable Level 2 requirements and assessment objectives. Assessment results are then submitted through the CMMC ecosystem and reflected in the government’s systems.
Level 2 C3PAO status is normally valid for three years, with annual affirmation requirements.
As of August 2026, contracting activities may not designate Level 2 C3PAO assessments during the Phase 2 suspension.
DIBCAC Assessments for Level 3
Level 3 assessments are performed by DCMA DIBCAC under the regulatory CMMC model.
Organizations pursuing Level 3 must first satisfy the required Level 2 certification prerequisite. DIBCAC then evaluates the enhanced Level 3 requirements applicable to the assessment scope.
Government designation of these Level 3 assessments is currently suspended along with the Phase 2 implementation changes.
Conditional Status and POA&Ms
CMMC allows limited use of Plans of Action and Milestones at Levels 2 and 3.
A POA&M documents an eligible requirement that has not yet been fully satisfied, along with the corrective action, owner, and planned completion.
Not every security requirement can be placed on a POA&M. Where conditional status is allowed, outstanding requirements generally must be remediated and successfully closed within 180 days or the conditional status expires. Level 1 does not allow POA&Ms.
Annual Affirmation and Maintaining CMMC Status
Passing an assessment does not end the compliance obligation.
Applicable CMMC statuses require an authorized affirming official to confirm continuing compliance. For Level 2 and Level 3 statuses under the regulatory model, that affirmation is required at assessment and annually thereafter.
Organizations therefore need processes that keep controls functioning between formal assessments rather than allowing compliance to deteriorate once an assessment is complete.
What Is the Current CMMC Timeline in 2026?
The CMMC timeline changed significantly in July 2026.
Phase 1 Requirements Currently in Effect
Phase 1 began on November 10, 2025.
Following the 2026 suspension announcement, implementation remains paused in Phase 1.
During this period, procurement requirements may include:
- CMMC Level 1 self-assessment
- CMMC Level 2 self-assessment
The government continues to enforce baseline cybersecurity requirements for protecting FCI and CUI.
CMMC Phase 2 Suspension
On July 13, 2026, the Department of Defense announced the immediate suspension of the transition to CMMC Phase 2, which had been scheduled for November 10, 2026.
The suspension means government program managers and requiring activities may not currently designate Level 2 C3PAO or Level 3 DIBCAC assessment requirements. The program remains in Phase 1 while CMMC is reviewed and potential reforms are considered.
For a detailed explanation of the change, see Nexeris’s guide to the CMMC Phase 2 suspension.
What the Phase 2 Suspension Does Not Change
The suspension does not mean defense contractors can stop protecting CUI.
DFARS 252.204-7012 remains in effect, and organizations subject to it must continue meeting applicable safeguarding and cyber incident reporting requirements. Level 2 self-assessment requirements remain in effect during Phase 1, and the current Department guidance specifically states that baseline NIST SP 800-171 Revision 2 compliance continues to be enforced.
Organizations should therefore view the suspension as a change to the implementation and assessment timeline, not permission to stop their cybersecurity work.
How CMMC Relates to NIST SP 800-171 and DFARS
CMMC, NIST SP 800-171, and DFARS are closely connected, but they serve different purposes.
CMMC vs. NIST SP 800-171
NIST SP 800-171 defines security requirements for protecting CUI in nonfederal systems and organizations.
CMMC Level 2 uses the 110 requirements from NIST SP 800-171 Revision 2 as its cybersecurity foundation. CMMC then adds a formal framework for scoping, assessing, recording status, handling limited POA&Ms, and affirming continued compliance.
In simple terms, NIST SP 800-171 describes what security requirements must be implemented, while CMMC establishes a structured mechanism for demonstrating that those requirements have been implemented.
CMMC vs. DFARS
DFARS is the Defense Federal Acquisition Regulation Supplement. Clauses such as DFARS 252.204-7012 establish contractual cybersecurity obligations for organizations handling covered defense information.
CMMC works alongside those obligations by providing an assessment and status framework.
Organizations subject to DFARS compliance should not assume the CMMC Phase 2 suspension removes existing contract requirements. The July 2026 implementation guidance specifically confirms that DFARS 252.204-7012 remains in effect.
How to Prepare for CMMC Compliance
Preparation should begin well before a solicitation creates an immediate deadline.
Identify Which CMMC Level Applies
Start by reviewing existing and expected contracts, subcontracts, solicitation language, and the types of information your organization handles.
FCI-only environments may fall under Level 1, while organizations handling CUI generally need to prepare for Level 2 requirements.
Define Your CUI and FCI Scope
Map where FCI and CUI enter the organization, where they are stored, how they move between systems, who accesses them, and which third parties support those environments.
A clear data flow makes it easier to identify the appropriate CMMC assessment boundary.
Perform a CMMC Gap Assessment
Compare current safeguards against the requirements for the applicable CMMC level.
A gap assessment should evaluate both technical implementation and operational evidence. A control that appears configured correctly can still become an assessment problem if there is no documentation or repeatable process supporting it.
Prioritize and Remediate Security Gaps
Not all cybersecurity gaps require the same amount of time to resolve.
Issues involving identity architecture, network segmentation, cloud environments, multifactor authentication, logging, encryption, incident response, or third-party providers can require significant planning.
Address complex dependencies early instead of leaving them until the assessment window approaches.
Build the SSP and Organize Assessment Evidence
Develop or update the SSP so it accurately describes the current environment.
Then organize evidence by requirement and assessment objective. Assign an owner to each control and verify that employees responsible for those controls understand both the process and the evidence used to demonstrate it.
Complete the Required Assessment and Affirmation
Once controls, scope, documentation, and evidence are ready, complete the assessment required by the applicable contract and current CMMC implementation rules.
Organizations that need help determining their scope, identifying NIST SP 800-171 gaps, developing documentation, or preparing evidence can use professional CMMC consulting services to build a structured path toward assessment readiness.
Common CMMC Compliance Challenges
CMMC projects often become difficult because organizations underestimate how much the environment, documentation, vendors, and day-to-day processes matter.
Incorrect CUI Scoping
An overly broad scope can increase cost and complexity. An overly narrow scope can leave important systems outside the assessment boundary.
Organizations should understand where CUI actually travels and which assets provide security functions to that environment before finalizing scope.
Missing or Weak Assessment Evidence
A technically implemented security control is not always enough.
Assessors need objective evidence showing that the requirement is satisfied. Teams that wait until immediately before assessment to collect artifacts often discover that historical evidence was never retained.
Outdated Policies and SSP Documentation
Documentation needs to describe reality.
If a policy says access is reviewed quarterly but the organization cannot show those reviews taking place, the documentation may expose rather than solve the compliance gap.
SSPs, policies, procedures, diagrams, and asset inventories should therefore be maintained as living documents.
Cloud and Third-Party Provider Dependencies
Cloud providers, MSPs, MSSPs, and other external services can affect the CMMC assessment scope.
Organizations need to understand who handles CUI, who handles security protection data, which requirements are inherited from providers, and which responsibilities remain with the contractor.
The CMMC regulations specifically require relevant provider relationships and responsibilities to be reflected in assessment scoping and documentation.
Waiting Until a Contract Requires CMMC
CMMC readiness can involve changes to networks, identities, endpoints, cloud services, security tools, documentation, vendor relationships, and business processes.
These changes take time.
Even with Phase 2 currently suspended, contractors that expect to continue handling CUI should use the additional time to improve NIST SP 800-171 alignment rather than waiting for another implementation deadline.
How Nexeris Helps Organizations Prepare for CMMC
CMMC preparation requires coordination between cybersecurity, compliance, operations, leadership, and third-party providers.
Nexeris helps defense contractors and subcontractors establish a practical path from their current cybersecurity posture to CMMC readiness. This can include identifying the appropriate level, defining the FCI or CUI environment, performing NIST SP 800-171 gap assessments, prioritizing remediation, developing an accurate SSP, reviewing policies and procedures, organizing assessment evidence, and preparing teams for the required assessment process.
The goal is not simply to create compliance documents. It is to build an environment where security controls can be demonstrated, maintained, and supported with evidence when an assessor, prime contractor, customer, or government agency asks for proof.
The current Phase 2 suspension provides additional time, but it does not eliminate the underlying cybersecurity obligations. Organizations that use that time to resolve scope, technical controls, documentation, and evidence gaps will be better positioned as CMMC requirements continue to evolve.
FAQs
1. What does CMMC stand for and what does it mean?
CMMC stands for Cybersecurity Maturity Model Certification. It is the federal defense cybersecurity framework used to verify that contractors and subcontractors have implemented required safeguards for Federal Contract Information and Controlled Unclassified Information.
2. Who is required to comply with CMMC?
CMMC may apply to DoD prime contractors and subcontractors when applicable contracts require protection of FCI or CUI. The required level depends on contract requirements and the type of information the organization handles. Service providers supporting the protected environment can also affect assessment scope.
3. What is the difference between CMMC Level 1, Level 2, and Level 3?
Level 1 focuses on basic protection of FCI and incorporates 15 FAR safeguarding requirements. Level 2 protects CUI and aligns with all 110 requirements in NIST SP 800-171 Revision 2. Level 3 builds on Level 2 with 24 selected enhanced requirements from NIST SP 800-172 for higher-risk environments.
4. Is CMMC still required after the 2026 Phase 2 suspension?
Yes. CMMC has not been eliminated. Implementation is currently paused in Phase 1. Level 1 and Level 2 self-assessment requirements remain in effect, while the planned Phase 2 expansion to Level 2 C3PAO and Level 3 DIBCAC procurement requirements has been suspended. NIST SP 800-171 Revision 2 and applicable DFARS 252.204-7012 obligations also remain in effect.
5. What is the difference between CMMC, NIST SP 800-171, and DFARS?
NIST SP 800-171 establishes cybersecurity requirements for protecting CUI in nonfederal systems. DFARS places applicable cybersecurity obligations into defense contracts. CMMC provides an assessment and verification framework for demonstrating that required safeguards have been implemented and maintained.
