Asurvo
Security framework

Run CMMC 2.0 with
confidence.

CMMC 2.0 protects sensitive unclassified information shared by the Department of Defense with its contractors and subcontractors. It streamlines requirements into three certification levels aligned with NIST cybersecurity standards.

Who it's for

Defense Industrial Base contractors and subcontractors.

Scope

Levels 1–3, NIST 800-171 aligned

Category
Security

How Asurvo helps

What you get for CMMC 2.0.

Three certification levels modelled
Built on NIST 800-171 practices
Assessment readiness tracking
Evidence reuse across DoD contracts

DoD contractors

CMMC 2.0: levels, assessments, and getting ready

The Cybersecurity Maturity Model Certification program is the Department of Defense's way of verifying that contractors actually protect the information DoD shares with them. For years, defense suppliers self-attested to NIST SP 800-171 under DFARS 252.204-7012. CMMC adds assessment and affirmation requirements tied to contract award, so a gap that once sat quietly in a POA&M can now determine whether you are eligible to win or keep work.

CMMC does not invent a new control set. Level 1 draws on the basic safeguarding requirements in FAR 52.204-21, Level 2 uses the 110 requirements of NIST SP 800-171 Rev 2, and Level 3 adds selected requirements from NIST SP 800-172. What CMMC changes is who checks your work, how often, and what happens to your eligibility if the check fails.

Two kinds of information decide your level

  • Federal Contract Information (FCI) is information provided by or generated for the government under a contract that is not intended for public release. Contractors that handle only FCI need Level 1.
  • Controlled Unclassified Information (CUI) is information that law, regulation, or government-wide policy requires to be safeguarded. Contractors that handle CUI need at least Level 2.
  • Level 3 is required by DoD for a smaller set of programs where CUI is associated with the highest-priority programs and advanced persistent threats are a concern.

The level is specified in the solicitation, not chosen by the contractor. Prime contractors must flow the requirement down to subcontractors that will process, store, or transmit FCI or CUI, and the level required of a subcontractor depends on the information it will handle, which can be lower than the prime's.

The three levels compared

Level 1, Level 2, Level 3 comparison
InformationFCICUICUI on high-priority programs
Requirements15 requirements from FAR 52.204-21110 requirements of NIST SP 800-171 Rev 2Level 2 plus 24 selected requirements from NIST SP 800-172
AssessmentAnnual self-assessmentSelf-assessment or C3PAO certification assessment, as the contract specifies, every three yearsDIBCAC assessment every three years, after a Final Level 2 C3PAO certification
AffirmationAnnual affirmation in SPRSAffirmation after each assessment and annuallyAffirmation after each assessment and annually
POA&MsNot permittedLimited; conditional status must be closed out within 180 daysLimited; conditional status must be closed out within 180 days

The rules and the rollout

CMMC is implemented through two rules. The program rule, codified at 32 CFR part 170, defines the levels, assessment process, and ecosystem of assessors, and took effect on December 16, 2024. The acquisition rule amends the DFARS so contracting officers can include CMMC requirements in solicitations and contracts; it took effect on November 10, 2025, starting a phased rollout.

Phased implementation under the DFARS rule

Phased implementation under the DFARS rule
Phase 1November 10, 2025Level 1 and Level 2 self-assessments required as a condition of award in applicable solicitations
Phase 2November 10, 2026Level 2 C3PAO certification assessments required where applicable
Phase 3November 10, 2027Level 3 DIBCAC assessments required where applicable
Phase 4November 10, 2028Full implementation across applicable solicitations and contracts

DoD retains discretion to include higher requirements earlier in individual solicitations, so do not plan around the phase dates alone. Watch the solicitations you actually bid on, and ask primes what they will require of you.

Preparing for a Level 2 certification assessment

Certified Third-Party Assessor Organizations (C3PAOs) are authorized by the CMMC Accreditation Body, known as the Cyber AB, and use the NIST SP 800-171A assessment objectives. Each requirement is scored MET, NOT MET, or NOT APPLICABLE, and a requirement is only MET when every one of its objectives is satisfied. The work below assumes you already have a baseline 800-171 program.

  1. Lock down scope. Categorize assets as CUI assets, security protection assets, contractor risk managed assets, specialized assets, or out of scope, and document the reasoning. Scope disputes are where assessments slow down.
  2. Validate external service providers. Cloud services that handle CUI must meet the FedRAMP Moderate or equivalent expectation. Collect each provider's customer responsibility matrix.
  3. Map objectives to evidence. For each of the 320 assessment objectives in 800-171A, identify the document, record, or system configuration that proves it.
  4. Run a mock assessment. Have someone independent of the implementers interview staff and test controls using the same examine, interview, and test methods.
  5. Close high-weight gaps. Requirements worth more than one point generally cannot be left on a POA&M at assessment, so fix those first.
  6. Sustain it. Certification lasts three years only if the environment stays compliant and affirmations are maintained.

Evidence assessors ask for

Artefact, Why it matters comparison
System Security PlanDefines scope and describes how every requirement is implemented
Asset inventory with CMMC asset categoriesEstablishes what is in scope and how each asset type is treated
Network and data flow diagramsShows the CUI boundary and connections to out-of-scope systems
Policies and procedures for all 14 familiesEstablishes the documented practice assessors test against
Access reviews, log reviews, scan results, training recordsProves the practices operate over time, not just on assessment day
Incident response plan and test resultsSupports incident handling and DFARS reporting obligations
External service provider documentationDemonstrates FedRAMP Moderate or equivalent and shared responsibility
SPRS score and affirmation recordsLinks your assessment result to your contract eligibility

Pitfalls specific to CMMC

  • Assuming DFARS self-attestation carries over. A historical SPRS score does not guarantee a Level 2 C3PAO result.
  • Waiting for the contract. Assessor availability and remediation time mean the certification timeline often exceeds a proposal window.
  • Under-documenting inherited controls. A managed service provider that operates security tools is part of your assessment scope.
  • Ignoring subcontractors. Primes are responsible for flowdown, and a supply chain gap can hold up award.
  • Treating Level 1 as trivial. Level 1 allows no POA&M, and the annual affirmation is still a formal statement to the government.

Because Level 2 is 800-171 and 800-171 traces back to the moderate baseline of NIST SP 800-53, work done for one maps directly to the others. Many contractors also hold ISO 27001 or use the NIST CSF, which overlap substantially in access control, logging, and incident response. Asurvo models all three CMMC levels on top of its 800-171 control set, tracks assessment readiness, and uses AI cross-mapping so evidence collected once is reused across frameworks and contracts. Contractors in the defense supply chain can see how this fits a broader program on the manufacturing page.

FAQ

Frequently asked questions

Which CMMC level do I need?

The solicitation or contract specifies the level. As a rule of thumb, contractors that only handle Federal Contract Information need Level 1, and those that handle Controlled Unclassified Information need Level 2. Level 3 is required by DoD for a smaller set of programs. Subcontractors need the level that matches the information flowed down to them.

Is CMMC Level 2 always a third-party assessment?

No. Level 2 can require either a self-assessment or a certification assessment by a C3PAO, depending on the contract. DoD expects most contracts involving CUI to require the C3PAO assessment. Both are valid for three years and require affirmation in SPRS, so you should prepare to the same evidence standard regardless.

When does CMMC start appearing in contracts?

The DFARS acquisition rule took effect on November 10, 2025, beginning Phase 1, in which Level 1 and Level 2 self-assessments are required in applicable solicitations. Phase 2, adding Level 2 C3PAO certifications, begins November 10, 2026, with Level 3 following a year later. DoD can include requirements earlier in specific solicitations.

Can I pass CMMC with open POA&M items?

At Level 1, no. At Levels 2 and 3, a limited POA&M is allowed for conditional status: at Level 2 you need a score of at least 80 percent of the maximum, only certain lower-weight requirements may be open, and all items must be closed and verified within 180 days. Otherwise the conditional status expires.

How is CMMC different from NIST 800-171?

NIST 800-171 is the set of security requirements; CMMC is the DoD program that verifies contractors meet them. Level 2 uses the same 110 requirements, but adds formal assessment by a C3PAO where required, scoring rules, limits on POA&Ms, a three-year validity period, and senior official affirmations tied to contract eligibility.

Ready to run CMMC 2.0 on Asurvo?

Book a walkthrough and see the framework live.