The Cybersecurity Maturity Model Certification program is the Department of Defense's way of verifying that contractors actually protect the information DoD shares with them. For years, defense suppliers self-attested to NIST SP 800-171 under DFARS 252.204-7012. CMMC adds assessment and affirmation requirements tied to contract award, so a gap that once sat quietly in a POA&M can now determine whether you are eligible to win or keep work.
CMMC does not invent a new control set. Level 1 draws on the basic safeguarding requirements in FAR 52.204-21, Level 2 uses the 110 requirements of NIST SP 800-171 Rev 2, and Level 3 adds selected requirements from NIST SP 800-172. What CMMC changes is who checks your work, how often, and what happens to your eligibility if the check fails.
Two kinds of information decide your level
- Federal Contract Information (FCI) is information provided by or generated for the government under a contract that is not intended for public release. Contractors that handle only FCI need Level 1.
- Controlled Unclassified Information (CUI) is information that law, regulation, or government-wide policy requires to be safeguarded. Contractors that handle CUI need at least Level 2.
- Level 3 is required by DoD for a smaller set of programs where CUI is associated with the highest-priority programs and advanced persistent threats are a concern.
The level is specified in the solicitation, not chosen by the contractor. Prime contractors must flow the requirement down to subcontractors that will process, store, or transmit FCI or CUI, and the level required of a subcontractor depends on the information it will handle, which can be lower than the prime's.
The three levels compared
The rules and the rollout
CMMC is implemented through two rules. The program rule, codified at 32 CFR part 170, defines the levels, assessment process, and ecosystem of assessors, and took effect on December 16, 2024. The acquisition rule amends the DFARS so contracting officers can include CMMC requirements in solicitations and contracts; it took effect on November 10, 2025, starting a phased rollout.
Phased implementation under the DFARS rule
DoD retains discretion to include higher requirements earlier in individual solicitations, so do not plan around the phase dates alone. Watch the solicitations you actually bid on, and ask primes what they will require of you.
Preparing for a Level 2 certification assessment
Certified Third-Party Assessor Organizations (C3PAOs) are authorized by the CMMC Accreditation Body, known as the Cyber AB, and use the NIST SP 800-171A assessment objectives. Each requirement is scored MET, NOT MET, or NOT APPLICABLE, and a requirement is only MET when every one of its objectives is satisfied. The work below assumes you already have a baseline 800-171 program.
- Lock down scope. Categorize assets as CUI assets, security protection assets, contractor risk managed assets, specialized assets, or out of scope, and document the reasoning. Scope disputes are where assessments slow down.
- Validate external service providers. Cloud services that handle CUI must meet the FedRAMP Moderate or equivalent expectation. Collect each provider's customer responsibility matrix.
- Map objectives to evidence. For each of the 320 assessment objectives in 800-171A, identify the document, record, or system configuration that proves it.
- Run a mock assessment. Have someone independent of the implementers interview staff and test controls using the same examine, interview, and test methods.
- Close high-weight gaps. Requirements worth more than one point generally cannot be left on a POA&M at assessment, so fix those first.
- Sustain it. Certification lasts three years only if the environment stays compliant and affirmations are maintained.
Evidence assessors ask for
Pitfalls specific to CMMC
- Assuming DFARS self-attestation carries over. A historical SPRS score does not guarantee a Level 2 C3PAO result.
- Waiting for the contract. Assessor availability and remediation time mean the certification timeline often exceeds a proposal window.
- Under-documenting inherited controls. A managed service provider that operates security tools is part of your assessment scope.
- Ignoring subcontractors. Primes are responsible for flowdown, and a supply chain gap can hold up award.
- Treating Level 1 as trivial. Level 1 allows no POA&M, and the annual affirmation is still a formal statement to the government.
Related frameworks and how Asurvo supports CMMC
Because Level 2 is 800-171 and 800-171 traces back to the moderate baseline of NIST SP 800-53, work done for one maps directly to the others. Many contractors also hold ISO 27001 or use the NIST CSF, which overlap substantially in access control, logging, and incident response. Asurvo models all three CMMC levels on top of its 800-171 control set, tracks assessment readiness, and uses AI cross-mapping so evidence collected once is reused across frameworks and contracts. Contractors in the defense supply chain can see how this fits a broader program on the manufacturing page.