Cybersecurity requirements have become a central part of doing business with the U.S. Department of Defense. For organizations in the Defense Industrial Base, understanding whether CMMC compliance applies is no longer something that can be left until an assessment date approaches.
The Cybersecurity Maturity Model Certification, or CMMC, is designed to verify that contractors and subcontractors are protecting Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) appropriately. Whether your organization needs CMMC depends primarily on the information involved in the contract, the systems that handle that information, your role in the defense supply chain, and the CMMC status specified for the procurement.
One terminology point is important. “CMMC certification” is often used broadly, but not every organization subject to CMMC needs a third-party certification assessment. Level 1 uses self-assessment, and some Level 2 requirements use self-assessment. Other Level 2 procurements can require a C3PAO assessment under the regulatory framework, while Level 3 uses a DIBCAC assessment. In 2026, implementation is currently paused in Phase I following the suspension of Phase II.
In This Guide
- 01
Who Needs CMMC Certification? - 02
How FCI and CUI Determine Whether CMMC Applies - 03
Does Company Size Affect CMMC Requirements? - 04
Does Location Affect CMMC Requirements? - 05
Which Organizations Need CMMC Certification? - 06
Who Does Not Need CMMC Certification? - 07
How to Determine If Your Organization Needs CMMC - 08
Which CMMC Level Does Your Organization Need? - 09
Who Determines Your Required CMMC Level? - 10
Do Subcontractors Need CMMC Certification? - 11
Who Is Responsible for CMMC Compliance Within an Organization? - 12
What Happens If Your Organization Needs CMMC but Is Not Compliant? - 13
When Does Your Organization Need CMMC Certification? - 14
What to Do If CMMC Applies to Your Organization - 15
How Nexeris Helps DoD Contractors Determine CMMC Requirements - 16
FAQs
Who Needs CMMC Certification?
CMMC applies to DoD contractors and subcontractors that process, store, or transmit FCI or CUI on contractor information systems while performing an applicable DoD contract or subcontract. The rules can reach organizations throughout the defense supply chain rather than stopping with the company that holds the prime contract.
The central questions are therefore not simply, “Are we a defense contractor?” or “How large is our company?” The better questions are:
- Does the contract involve FCI or CUI?
- Which systems will handle that information?
- What CMMC status does the solicitation or contract require?
- Are those requirements being flowed down through a prime contractor?
How FCI and CUI Determine Whether CMMC Applies
FCI and CUI are the foundation of CMMC applicability.
Federal Contract Information (FCI) is nonpublic information provided by or generated for the federal government under a contract to develop or deliver a product or service. Publicly released information and simple transactional information, such as information needed to process payments, are excluded from the FCI definition.
Controlled Unclassified Information (CUI) is information that is not classified but requires safeguarding or dissemination controls under applicable laws, regulations, or government-wide policy.
An organization handling FCI may need CMMC Level 1. An organization that processes, stores, or transmits CUI will generally need a Level 2 status at minimum, subject to the specific procurement and current implementation rules.
Understanding what information your organization actually receives, creates, accesses, and shares is therefore one of the first steps in determining your CMMC responsibilities.
Does Company Size Affect CMMC Requirements?
CMMC does not provide a general exemption simply because a contractor is small.
A ten-person manufacturer handling CUI can have significant cybersecurity obligations just as a much larger defense company can. The regulations focus on the contract, protected information, contractor systems, and required CMMC status rather than employee count or annual revenue.
Company size can certainly affect how an organization approaches compliance. Smaller businesses may have fewer IT personnel, smaller budgets, or greater reliance on outsourced technology providers. Those practical differences do not remove applicable security obligations.
Does Location Affect CMMC Requirements?
Location alone does not create a general exemption from CMMC.
The regulations apply broadly to DoD contract and subcontract awardees whose contractor systems will process, store, or transmit FCI or CUI in performance of applicable work.
Organizations operating internationally may also need to consider separate requirements involving export controls, data access, contract restrictions, cloud locations, or other legal obligations. Those issues should be reviewed independently rather than assuming that a foreign office or overseas supplier is automatically outside CMMC.
Which Organizations Need CMMC Certification?
CMMC can affect a wide range of organizations because the Defense Industrial Base extends far beyond traditional weapons manufacturers.
DoD Prime Contractors
Prime contractors have a direct contractual relationship with the Department of Defense.
If an applicable solicitation requires a particular CMMC status, the contractor must have the required current status for the information systems that will process, store, or transmit FCI or CUI during contract performance. The current DFARS framework also requires applicable affirmations of continuous compliance.
Prime contractors also have responsibilities involving downstream suppliers because applicable CMMC requirements must be flowed to subcontractors that will handle protected information.
Defense Subcontractors
A company does not need a direct DoD contract to fall within the CMMC framework.
Subcontractors throughout the defense supply chain may need to meet CMMC requirements when they process, store, or transmit FCI or CUI. The required status depends on what information is shared through the subcontract and, in certain cases, the assessment requirement associated with the prime contract.
Understanding CMMC flow-down requirements is therefore important before accepting sensitive information from a prime contractor or passing it to another supplier.
Manufacturers and Defense Suppliers
Machine shops, component manufacturers, electronics suppliers, aerospace companies, engineering firms, materials suppliers, and other manufacturers may encounter CMMC requirements.
For example, a manufacturer might receive technical drawings, specifications, engineering data, or other CUI as part of a defense subcontract. The company may be relatively small and may never communicate directly with DoD, yet the systems receiving and using that CUI can still fall within CMMC scope.
Operational technology, test equipment, industrial systems, and specialized manufacturing assets can also create additional scoping questions that need to be documented properly.
Software and Technology Providers
Software developers and technology companies may become part of the defense supply chain when they build applications, maintain systems, support government programs, or receive protected contract information.
The key issue is not whether the company considers itself a “defense contractor.” It is whether its systems process, store, or transmit FCI or CUI in connection with applicable DoD work.
A software company supporting a defense program may therefore have CMMC obligations even if most of its customers are commercial organizations.
Managed Service Providers and External Service Providers
Managed Service Providers, Managed Security Service Providers, IT support companies, security operations providers, and similar businesses require careful analysis.
Under CMMC rules, an External Service Provider is an outside organization that provides IT or cybersecurity services when CUI or Security Protection Data, such as security logs or configuration data, is processed, stored, or transmitted on the provider’s assets.
An ESP does not automatically need a completely separate CMMC certification simply because it serves a defense contractor. However, the ESP’s services and relevant assets may become part of the contractor’s assessment scope and must be documented appropriately. For Level 2, relevant ESP services used to satisfy requirements are assessed within the organization’s assessment scope.
Cloud and SaaS Providers Handling CUI
Cloud environments can also play an important role in CMMC scope.
When an organization uses a Cloud Service Provider to process, store, or transmit CUI for Level 2 work, the applicable cloud offering must meet the CMMC framework’s cloud requirements. The regulations provide for FedRAMP Moderate authorization or security requirements equivalent to the FedRAMP Moderate baseline, depending on the circumstances.
Contractors remain responsible for understanding shared responsibilities between their own organization and the cloud provider. Simply moving CUI into a SaaS platform does not move the compliance responsibility away from the contractor.
Professional Services and Consulting Firms
Engineering consultants, research organizations, accountants, legal support firms, project management companies, technical consultants, and other professional services businesses may also encounter CMMC requirements.
If a consulting firm receives CUI to complete a defense subcontract, for example, the systems used by its employees to access and work with that information may fall within the applicable CMMC scope.
The service itself does not determine applicability. The information and contractual relationship do.
Who Does Not Need CMMC Certification?
Not every organization selling to the government or doing business with a defense contractor automatically needs CMMC.
Commercial Off-the-Shelf (COTS) Providers
The CMMC regulations exclude acquisitions that are exclusively for Commercial Off-the-Shelf items from general CMMC program applicability.
The distinction matters because commercial products and COTS products are not always the same thing. CMMC can apply to acquisitions of commercial items when the applicable conditions are met, but contracts exclusively for COTS items receive a specific exception.
Businesses should confirm that their offering actually meets the applicable COTS definition rather than relying on the fact that a product is commercially available.
Organizations That Do Not Handle FCI or CUI
Organizations whose contractor information systems do not process, store, or transmit FCI or CUI generally fall outside the core applicability described in 32 CFR Part 170.
Similarly, assets that cannot process, store, or transmit relevant protected information may be considered out of scope when the regulatory scoping requirements are satisfied.
This is why accurate information mapping is so important. A company cannot determine whether CMMC applies by looking only at its industry or customer list.
Businesses Outside the DoD Supply Chain
A purely commercial company with no relevant DoD contracts, subcontracts, or protected defense information does not need CMMC simply because it operates in cybersecurity, manufacturing, technology, or another industry commonly associated with government work.
Other federal cybersecurity frameworks or customer requirements may still apply, but those should be evaluated separately.
How to Determine If Your Organization Needs CMMC
Organizations that are unsure about CMMC should work through the contract and data systematically.
Review Your DoD Contract or Solicitation
Start with the actual contract, solicitation, task order, or delivery order.
Current DFARS provisions allow the contracting officer to identify the required CMMC level in a solicitation. Where applicable, the required status must be in place for each contractor information system that will process, store, or transmit FCI or CUI during performance.
Do not rely only on assumptions based on similar contracts.
Check Your DFARS Clauses
Review the cybersecurity clauses incorporated into your contract.
DFARS 252.204-7012 addresses safeguarding covered defense information and cyber incident reporting, while other clauses address NIST SP 800-171 assessments and CMMC requirements.
Existing DFARS cybersecurity obligations continue independently of the CMMC Phase II suspension. The CMMC rule does not replace otherwise applicable requirements for protecting FCI, CUI, or covered defense information.
Determine Whether You Handle FCI or CUI
Identify the information you receive or create during contract performance.
Ask practical questions:
- What files does the government or prime contractor send us?
- Are documents marked as CUI?
- Do we receive drawings, technical data, specifications, or program information?
- Do employees create CUI during contract performance?
- Does FCI appear in email, collaboration platforms, or business applications?
Do not limit the analysis to a single document repository.
Map Where FCI and CUI Are Stored, Processed or Transmitted
Once the information is identified, follow it through the environment.
Map endpoints, servers, email, cloud storage, collaboration tools, backup systems, security tools, remote access systems, manufacturing assets, third-party services, and personnel that interact with the information.
For Level 2, CUI assets and security protection assets can fall within the assessment scope, while specific conditions apply to contractor risk-managed, specialized, and out-of-scope assets.
Confirm Flow-Down Requirements With Your Prime Contractor
Subcontractors should confirm requirements directly with the prime contractor rather than assuming the prime’s own CMMC level automatically applies to every supplier.
Ask what information will be shared, what CMMC status is required for the subcontract, and whether additional contract-specific cybersecurity conditions apply.
Getting this information before receiving FCI or CUI can prevent expensive redesign later.
Which CMMC Level Does Your Organization Need?
CMMC includes three levels that reflect increasing cybersecurity requirements.
CMMC Level 1 for Organizations Handling FCI
Level 1 focuses on protecting FCI.
It uses the basic safeguarding requirements associated with FAR 52.204-21 and requires an annual self-assessment and annual affirmation under the current framework.
Level 1 is typically relevant where an organization handles FCI but not CUI.
CMMC Level 2 for Organizations Handling CUI
Level 2 is designed for organizations handling CUI and aligns with the 110 security requirements in NIST SP 800-171 Revision 2 under the current CMMC regulatory model.
Depending on the procurement and implementation stage, Level 2 can involve either a self-assessment or a C3PAO certification assessment.
However, the current 2026 Phase II suspension has paused the planned broader implementation of third-party certification requirements. Phase I self-assessment requirements remain in place.
CMMC Level 3 for High-Priority DoD Programs
Level 3 is intended for a smaller group of highly sensitive programs.
It builds on Level 2 and incorporates additional enhanced security requirements from NIST SP 800-172. The regulations indicate that Level 3 is generally expected for solicitations and contracts supporting the Department’s most critical programs and technologies.
Level 3 assessments are associated with the Defense Industrial Base Cybersecurity Assessment Center, or DIBCAC, under the regulatory framework.
Who Determines Your Required CMMC Level?
The contractor does not simply choose the CMMC level it prefers.
DoD program managers and requiring activities are responsible for identifying the CMMC status applicable to a procurement based on factors such as information sensitivity, mission criticality, technology, threats, and potential impact from cybersecurity weaknesses.
Subcontract requirements are then determined according to the applicable flow-down rules.
Organizations unfamiliar with the three levels should first understand the broader CMMC compliance requirements before designing their readiness program.
Do Subcontractors Need CMMC Certification?
Yes, subcontractors can need CMMC even when they have no direct relationship with DoD.
How CMMC Requirements Flow Down From Prime Contractors
CMMC requirements apply throughout the supply chain at all tiers when subcontractors process, store, or transmit FCI or CUI in performing the subcontract.
Under the regulatory flow-down model:
- A subcontractor handling only FCI generally requires Level 1 (Self).
- A subcontractor handling CUI requires at least Level 2 (Self).
- If the associated prime contract requires Level 2 (C3PAO) and the subcontractor handles CUI, Level 2 (C3PAO) becomes the minimum under the full framework.
- When the prime contract requires Level 3 and a subcontractor handles CUI, Level 2 (C3PAO) is generally the minimum for that subcontractor unless additional requirements apply.
Current 2026 implementation limitations must also be considered when determining which assessment type can presently be required.
Second-Tier and Third-Tier Subcontractors
Flow-down does not stop with the first subcontractor.
If a first-tier subcontractor passes relevant FCI or CUI to another supplier, requirements can continue through the second, third, or additional tiers.
Each organization should therefore know not only what it receives but what protected information it passes downstream.
When a Subcontractor May Need a Different CMMC Level Than the Prime
A subcontractor does not automatically need the exact same level as the prime contractor.
For example, if a prime contractor handles CUI but a particular supplier only receives FCI, Level 1 may be appropriate for that subcontractor under the regulatory flow-down framework.
Similarly, a Level 3 prime does not automatically mean every downstream supplier must achieve Level 3. The information handled and applicable flow-down requirements determine the minimum status.
Who Is Responsible for CMMC Compliance Within an Organization?
CMMC should not be treated as an IT-only project. Multiple functions need to work together.
Executive Leadership
Leadership is responsible for ensuring cybersecurity receives sufficient authority, funding, and organizational support.
An appropriate senior official must also provide required affirmations of continuous compliance. CMMC regulations require affirmations at specified points, including annually following applicable final CMMC status dates.
That makes leadership involvement more than a ceremonial approval at the end of the process.
IT and Cybersecurity Teams
IT and security teams typically handle much of the technical implementation.
Their responsibilities may include identity and access management, multifactor authentication, endpoint security, logging, configuration management, network architecture, vulnerability management, encryption, incident response, backups, and security monitoring.
They also need to preserve evidence showing that required practices are actually operating.
Compliance and GRC Teams
Compliance and Governance, Risk and Compliance teams help connect technical safeguards to policies, procedures, contractual requirements, evidence, risk decisions, and assessment preparation.
They often play a central role in maintaining the System Security Plan, evidence repositories, policies, POA&Ms where permitted, and readiness tracking.
Contracts and Procurement Teams
Contracts and procurement professionals need to understand which cybersecurity clauses are present, what information will be exchanged, and what obligations need to flow to suppliers.
A technical team cannot scope CMMC correctly if it does not know what the contract requires.
Cross-functional communication is therefore essential.
What Happens If Your Organization Needs CMMC but Is Not Compliant?
Failing to prepare can create contractual, operational, financial, and legal problems.
Loss of DoD Contract Eligibility
Where an applicable solicitation requires a CMMC status, an offeror may be ineligible for award if the required current status and affirmation are not present for the contractor systems that will process, store, or transmit FCI or CUI.
CMMC can therefore become a direct business eligibility issue rather than simply an internal cybersecurity goal.
Subcontract and Supply Chain Risks
Prime contractors need compliant suppliers to support their own contract obligations.
A subcontractor that cannot satisfy required cybersecurity conditions may become difficult to use on a program, particularly when another qualified supplier can meet those conditions.
Likewise, a prime contractor that fails to manage flow-down obligations can create risk across its entire supply chain.
False Claims Act and Misrepresentation Risks
Organizations should be particularly careful about representing cybersecurity compliance inaccurately.
The Department of Justice has used the False Claims Act in cases involving alleged failure to meet federal contractual cybersecurity requirements or inaccurate cybersecurity representations. In September 2025, for example, the government announced an $875,000 settlement resolving allegations involving cybersecurity requirements on Air Force and DARPA contracts, including allegations concerning an inaccurately submitted cybersecurity assessment score. The claims were allegations, and the settlement did not constitute a determination of liability.
The risk is therefore not simply having a gap. Knowingly misrepresenting compliance can create much more serious exposure. Organizations facing potential legal issues should obtain appropriate legal advice.
Cost and Business Impact of Delayed Preparation
Waiting can also make CMMC significantly more disruptive.
Common remediation projects may require changes to identity systems, network architecture, cloud services, endpoints, security tooling, logging, vendor agreements, policies, and employee workflows.
Trying to complete all of this immediately before a contract deadline can increase cost and create unnecessary pressure.
When Does Your Organization Need CMMC Certification?
The answer depends on both the solicitation or contract and the current implementation phase.
CMMC Requirements in Current Contracts and Solicitations
CMMC requirements became part of the acquisition framework through the phased implementation approach.
When an applicable solicitation includes a CMMC requirement, the specified status is generally required prior to award for each contractor information system that will handle FCI or CUI for the resulting contract.
Contractors should read each new solicitation rather than assuming requirements remain identical from one opportunity to another.
How the 2026 Phase II Suspension Affects Certification Requirements
An important change occurred on July 13, 2026, when the Department announced the immediate suspension of CMMC Phase II, which had originally been scheduled to begin on November 10, 2026.
The program currently remains in Phase I. Phase I self-assessment requirements remain in effect, while the planned expansion of Phase II certification requirements has been suspended during the government’s review of the program.
The CMMC Phase 2 suspension does not mean organizations can ignore cybersecurity requirements. Applicable NIST SP 800-171 and DFARS obligations continue, and the Department has stated that cybersecurity compliance will continue to be enforced through self-assessments and selected government-led assessments during the suspension.
Why Contractors Should Confirm Requirements Before Bidding
A company should know its cybersecurity obligations before committing to perform the work.
Before bidding, confirm:
- The required CMMC level or status
- Whether the environment already satisfies that requirement
- Which systems will handle FCI or CUI
- Which third-party providers are involved
- What requirements must flow to subcontractors
- Whether additional remediation will be needed
Finding these issues after award can lead to unexpected expenses, implementation delays, or difficulty performing the contract.
What to Do If CMMC Applies to Your Organization
Once you determine that CMMC applies, readiness should become a structured project.
Determine Your Required CMMC Level
Review the solicitation, contract language, data involved, and instructions from the contracting officer or prime contractor.
Do not assume Level 2 simply because another company in your industry uses Level 2.
Define Your FCI and CUI Environment
Identify the people, systems, applications, facilities, networks, and providers that interact with protected information.
Your goal is to understand the actual data flow from the moment FCI or CUI enters the organization until it is stored, transmitted, used, archived, or destroyed.
Conduct a CMMC Gap Assessment
Compare the current environment with the applicable CMMC requirements.
For Level 2, this involves assessing implementation against NIST SP 800-171 Revision 2 requirements under the current regulatory model.
A useful gap assessment should look beyond written policies and examine whether processes are functioning in practice.
Address Security and Documentation Gaps
Prioritize remediation according to risk, implementation difficulty, and assessment importance.
Technical improvements may involve access controls, authentication, encryption, logging, network segmentation, endpoint protection, vulnerability management, or incident response.
Documentation may include the System Security Plan, policies, procedures, asset inventories, network diagrams, risk records, vendor responsibilities, and assessment evidence.
Prepare for the Required Assessment
Before the applicable assessment, verify that the environment described in the SSP matches the environment employees actually use.
Organize evidence by requirement, identify responsible personnel, validate configurations, review external provider dependencies, and make sure leadership understands its affirmation responsibilities.
Organizations that need assistance with scoping, gap assessment, remediation planning, documentation, or assessment readiness can use professional CMMC consulting services to create a more structured path toward compliance.
How Nexeris Helps DoD Contractors Determine CMMC Requirements
Determining whether CMMC applies can be surprisingly complex. Contract language, FCI and CUI identification, subcontract relationships, cloud services, MSP dependencies, assessment scope, and the current implementation timeline can all affect the answer.
Nexeris helps DoD contractors and subcontractors evaluate these requirements before they become an obstacle to contract eligibility. The process can include reviewing the organization’s CMMC exposure, identifying the likely required level, mapping FCI and CUI, defining assessment boundaries, evaluating NIST SP 800-171 implementation, identifying security gaps, reviewing third-party dependencies, improving documentation, and organizing assessment evidence.
This is especially important in 2026. The Phase II suspension has changed the timing of broader third-party certification requirements, but it has not removed Phase I requirements or existing cybersecurity obligations.
Organizations that expect to continue participating in the Defense Industrial Base should use the current period to understand what applies to them and address weaknesses before a specific opportunity turns cybersecurity readiness into a contract deadline.
FAQs
1. Who is required to have CMMC certification?
DoD contractors and subcontractors that process, store, or transmit FCI or CUI on contractor information systems may be required to achieve the applicable CMMC status. The precise level and assessment type depend on the procurement, information involved, supply-chain role, and current implementation phase.
2. Do all DoD contractors need CMMC certification?
No. CMMC applicability depends on factors including whether contractor systems handle FCI or CUI and whether the procurement falls within the program’s requirements. Acquisitions exclusively for COTS items are specifically excluded from general CMMC applicability.
3. Do subcontractors need CMMC certification?
Yes, subcontractors can need CMMC. Requirements flow through the supply chain at all tiers when subcontractors process, store, or transmit FCI or CUI. A subcontractor handling only FCI generally requires Level 1, while one handling CUI requires at least the applicable CMMC compliance checklist-verified Level 2 status under the regulatory framework.
4. Does a small business need CMMC certification if it handles CUI?
Potentially, yes. There is no general small-business exemption in the CMMC applicability rules. If a small company handles CUI under an applicable DoD contract or subcontract, it may need the required Level 2 status regardless of its number of employees or revenue.
5. How do I know which CMMC level my organization needs?
Review the applicable solicitation or contract and determine whether your systems will handle FCI or CUI. DoD program managers and requiring activities determine the CMMC status for procurements, while subcontract requirements are established through applicable flow-down rules. If the requirement is unclear, confirm it with the contracting officer or your prime contractor before bidding or accepting protected information.
