What is CMMC? A complete guide for defense contractors
The Cybersecurity Maturity Model Certification is the Department's framework for checking that defense contractors protect the information they are trusted with. What it is, who it reaches, the three levels, and where things stand after the July 2026 suspension.
Key takeaways
- CMMC is the Department's way of checking that contractors meet the security requirements their contracts already impose. The requirements come from FAR 52.204-21 and NIST SP 800-171.
- Since 13 July 2026 the third-party assessment rollout is suspended and under review. Self-assessments, SPRS scores and affirmations continue.
- The standard in force is NIST SP 800-171 Revision 2, held there by a standing class deviation. Revision 3 is published, not adopted.
- Which level you need is set by the solicitation. Most contractors handling CUI are Level 2.
What CMMC is
CMMC, the Cybersecurity Maturity Model Certification, is the Department of War's program for verifying that defense contractors actually meet the cybersecurity requirements written into their contracts. The requirements themselves are older than the program: the basic safeguarding clause at FAR 52.204-21 and the CUI clause at DFARS 252.204-7012, which points at NIST SP 800-171.
CMMC exists because self-attestation alone was not working. Reviews found that many contractors who claimed compliance had not implemented what they claimed. The program's answer was an assessment regime: self-assessment at Level 1, third-party assessment by a C3PAO at Level 2, and government assessment at Level 3. In July 2026 the Department suspended the third-party rollout pending a program review, so verification currently runs on documented self-assessments affirmed in SPRS, with the legal responsibility for accuracy resting on the contractor.
Who it reaches
If your organization holds DoD contracts, or supplies a company that does, you are inside the program's reach. That includes:
- Prime contractors, who contract directly with the Department.
- Subcontractors, who supply goods or services to primes and receive the clauses by flow-down.
- Supply chain vendors of any size that process, store or transmit CUI or FCI in support of a contract.
During the suspension
Contracts require a current Level 1 or Level 2 self-assessment with a senior official's affirmation in SPRS. If your score and affirmation are not current when a contract requires them, you are not eligible to bid. Roughly 220,000 companies sit inside the defense industrial base.
The three levels
CMMC 2.0 reduced the original five levels to three. Each builds on the one below it, and the level is set by the solicitation, not chosen by you.
Level 1: Foundational
For organizations that handle Federal Contract Information only.
- The 15 basic safeguarding requirements of FAR 52.204-21, assessed as 17 practices drawn from NIST SP 800-171.
- Annual self-assessment with an affirmation in SPRS. No third-party assessment.
- Basic hygiene: who may log in, passwords, malware protection, physical access.
Level 2: Advanced
For organizations that handle Controlled Unclassified Information. This is where most contractors land.
- All 110 security requirements of NIST SP 800-171 Revision 2, in 14 families.
- Assessed by a C3PAO under the Phase 2 rollout, which is suspended; self-assessment applies during the suspension, and voluntary C3PAO assessments continue.
- Triennial assessment with annual affirmations.
See the 110 requirements by domain, or read every one of them in plain language in our free guide.
Level 3: Expert
For programs judged to face advanced persistent threats.
- Everything in Level 2 plus selected requirements from NIST SP 800-172.
- Government-led assessment by DCMA DIBCAC. Level 2 certification is a prerequisite.
Which standard applies today
This is the question that costs money when it is answered wrong. NIST SP 800-171 Revision 2 is what a contract requires today. DFARS 252.204-7012 points at it, the CMMC rule at 32 CFR 170 points at it, and a standing DoD class deviation keeps contractors on Revision 2 even though NIST published Revision 3 in 2024. Publishing a revision does not change an obligation; a change to the deviation or an amendment to the rule would.
Two things are worth knowing about the road ahead. The Department has published its own values for Revision 3's organization-defined parameters, which is preparation for an eventual move, not adoption. And outside DoD, the proposed FAR CUI rule for civilian agencies points at Revision 3, so a contractor with both civilian and defense CUI work may one day carry two baselines. Our guide keeps the status and the differences current, requirement by requirement.
Terms you will meet
CUI
Controlled Unclassified Information. Information the government creates or possesses that law, regulation or policy says must be safeguarded: technical drawings, specifications, test results and the like. Whether something is CUI is the government's decision. Not sure what you are holding?
FCI
Federal Contract Information. Provided by or generated for the government under a contract, not intended for public release, and not CUI. Level 1 territory.
C3PAO
Certified Third Party Assessment Organization. The independent assessors authorized to conduct Level 2 certification assessments.
SSP
The system security plan. It describes your boundary, your environment and how each requirement is met. An assessment cannot proceed without one. Bedrock CMMC generates it from your control implementations, so it never drifts from what you actually do.
POA&M
Plan of action and milestones. The dated list of what is not yet met, who owns it and by when. The full guide.
SPRS score
Your score in the Supplier Performance Risk System, from 110 down to a floor of minus 203, reflecting which of the 110 requirements are met. Required for DoD contracts and visible to contracting officers.
How to get started
-
Find out which level your contracts set
Read the clauses. FAR 52.204-21 alone points at Level 1. DFARS 252.204-7012 means CUI, and almost always Level 2. If the information itself is the puzzle, work it through.
-
Run a gap assessment
Evaluate your environment against every requirement at your level, objective by objective. Bedrock CMMC shows met and not-met status across all 14 families and calculates the SPRS score as you go.
-
Close the gaps and write it down
Implement what is missing, collect evidence, and build the system security plan and the POA&M. This is the work compliance software exists to accelerate.
-
Post an honest score and affirm it
Submit your self-assessment score to SPRS and have a senior official affirm it. During the suspension this is the record contracts check, and it is a representation to the government.
-
Consider a voluntary assessment
C3PAO assessments continue on a voluntary basis. Many primes value them, and a completed assessment is the strongest evidence behind your affirmation if the mandate returns in reformed shape.
Questions people ask
What is CMMC?
CMMC is the Department of War's framework for verifying that defense contractors protect Controlled Unclassified Information and Federal Contract Information. Since the July 2026 suspension of Phase 2, verification runs on documented self-assessments affirmed in SPRS while a task force reviews the third-party assessment model.
Who needs CMMC?
Any company that holds DoD contracts or sits in the defense supply chain and handles FCI or CUI. During the suspension that means a current Level 1 or Level 2 self-assessment with an SPRS affirmation.
Which version of NIST 800-171 applies?
Revision 2. A standing DoD class deviation keeps it in force for DFARS 252.204-7012 contracts. Revision 3 is published by NIST but not adopted for defense contracts.
How long does it take?
Organizations starting from nothing typically need 12 to 18 months to implement the requirements and prepare an assessment record. Those with an existing 800-171 program may need three to six months.
What is the difference between CMMC and NIST 800-171?
NIST SP 800-171 defines the 110 requirements. CMMC is the verification framework layered on top: self-assessment affirmed in SPRS today, and certified C3PAO assessment if the suspended mandate returns. Implementing 800-171 is a binding contract condition under DFARS 252.204-7012 either way.
What happens if I ignore it?
Compliance is a condition of doing business with the Department. Without a current self-assessment and affirmation you are not eligible to bid, an inaccurate affirmation carries False Claims Act exposure, and many primes require third-party certification from subcontractors regardless of the mandate.
Keep the proof, not just the plan.
Bedrock CMMC tracks every objective, links the evidence behind it, calculates the SPRS score and keeps the POA&M honest, in one package with a chain of custody an assessor can follow.