What Is CMMC?
CMMC stands for Cybersecurity Maturity Model Certification. It's a Department of Defense (DoD) program that requires defense contractors to meet specific cybersecurity standards before they can bid on or perform DoD contracts.
CMMC was created because unverified self-attestation wasn't working — studies found that the vast majority of contractors claiming compliance weren't actually meeting the requirements. The program's answer was independent assessments by C3PAOs (Certified Third Party Assessment Organizations). In July 2026, the Department of War (formerly DoD) suspended that third-party mandate (Phase 2) pending a top-to-bottom program review — which means verification currently runs on documented self-assessments affirmed in SPRS, with the legal responsibility for accuracy resting squarely on the contractor. Read our full breakdown of what the suspension actually changes.
Who Needs CMMC Certification?
If your organization handles DoD contracts or is part of the Defense Industrial Base (DIB) supply chain, you are likely subject to CMMC requirements. This includes:
- Prime contractors — Companies that contract directly with the DoD
- Subcontractors — Companies that supply goods or services to prime contractors
- Supply chain vendors — Any organization that processes, stores, or transmits CUI or FCI
Approximately 220,000 defense contractors are subject to CMMC requirements. During the Phase 2 suspension, contracts require current Level 1 or Level 2 self-assessments— if your SPRS score and affirmation aren't current when a contract requires them, you won't be eligible to bid.
The Three CMMC Levels
CMMC 2.0 simplified the original five-level model into three levels, each building on the previous:
Level 1 — Foundational
For organizations handling Federal Contract Information (FCI) only.
- 15 basic cybersecurity practices from FAR 52.204-21
- Annual self-assessment (no third-party audit)
- Covers basic cyber hygiene: passwords, antivirus, access control
Level 2 — Advanced Most Common
For organizations handling Controlled Unclassified Information (CUI).
- All 110 NIST SP 800-171 Revision 2 security practices
- C3PAO third-party assessment (mandate suspended July 2026 — self-assessment currently applies)
- Triennial certification with annual affirmations
- Covers 14 security domains: Access Control, Audit, Incident Response, and more
Level 3 — Expert
For organizations handling the most sensitive CUI (high-value assets, advanced persistent threats).
- All Level 2 requirements plus select NIST SP 800-172 practices
- Government-led assessments (DCMA DIBCAC)
- Designed for programs with nation-state threat exposure
Key Terms You Need to Know
CUI (Controlled Unclassified Information)
Information the government creates or possesses that requires safeguarding — technical drawings, specifications, test results, etc.
FCI (Federal Contract Information)
Information provided by or generated for the government under contract, not intended for public release.
C3PAO
Certified Third Party Assessment Organization — the independent assessors authorized to conduct CMMC Level 2 assessments.
SSP (System Security Plan)
A document describing your security controls, how they're implemented, and the boundaries of your information system. Bedrock CMMC generates your SSP directly from your control implementations.
POA&M (Plan of Action & Milestones)
A document tracking security weaknesses and your remediation plan with target completion dates. Bedrock CMMC includes a built-in POA&M tracker with status workflows and deadline monitoring.
SPRS Score
Your Supplier Performance Risk System score (-203 to 110) reflecting NIST 800-171 implementation status. Required for DoD contracts.
How to Get Started with CMMC
Determine your required CMMC level
Check your contracts for DFARS clauses. If you handle CUI, you'll likely need Level 2. FCI only? Level 1 may suffice.
Conduct a gap assessment
Evaluate your current cybersecurity posture against the required practices. Identify which controls you've implemented and which have gaps. Bedrock CMMC shows your MET/NOT MET status across all 14 domains and calculates your SPRS score automatically.
Remediate gaps and document controls
Implement missing controls, collect evidence, and build your SSP and POA&M. This is where compliance software like Bedrock CMMC accelerates the process.
Consider a voluntary C3PAO assessment
The third-party mandate is suspended, but voluntary Level 2 assessments remain available — many primes value them, and a certification is the strongest evidence behind your affirmation. The Bedrock C3PAO Marketplace connects you directly with available assessors.
Get certified and maintain compliance
After passing your assessment, you receive your CMMC certification. Level 2 certification is valid for 3 years with annual affirmations required.
Frequently Asked Questions
What is CMMC?
CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense's framework for verifying that defense contractors have adequate cybersecurity practices to protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). As of the July 2026 suspension of Phase 2, verification runs on documented self-assessments affirmed in SPRS while a Department of War task force reviews the third-party assessment model.
Who needs CMMC certification?
Any company that handles DoD contracts or is part of the Defense Industrial Base (DIB) supply chain is subject to CMMC requirements — during the July 2026 Phase 2 suspension, that means current Level 1 or Level 2 self-assessments with SPRS affirmations. This includes prime contractors, subcontractors, and any organization that processes, stores, or transmits CUI or FCI. Approximately 220,000 defense contractors are affected.
What are the CMMC levels?
CMMC has three levels: Level 1 (Foundational) requires 15 basic cybersecurity practices with annual self-assessment. Level 2 (Advanced) requires all 110 NIST SP 800-171r2 practices — verified by C3PAO third-party assessment under the Phase 2 mandate suspended in July 2026, and by self-assessment during the suspension. Level 3 (Expert) adds NIST SP 800-172 requirements with government-led assessments.
How long does CMMC certification take?
Timeline varies based on your current cybersecurity posture. Organizations starting from scratch typically need 12-18 months to implement all controls and prepare for assessment. Those with existing NIST 800-171 compliance may need 3-6 months for gap remediation and assessment preparation.
What is the difference between CMMC and NIST 800-171?
NIST SP 800-171 defines the 110 security requirements. CMMC is the certification framework that verifies you've actually implemented those requirements — through structured self-assessments affirmed in SPRS today, and through certified C3PAO assessments if the suspended third-party mandate returns. Implementing NIST 800-171 remains a binding contract condition under DFARS 252.204-7012 either way.
What happens if I don't get CMMC certified?
Compliance is still a condition of doing business with the DoD. During the Phase 2 suspension, contracts require current Level 1 or Level 2 self-assessments with SPRS affirmations — without them you are not eligible to bid. Inaccurate affirmations carry False Claims Act exposure, and many primes continue to prefer or contractually require third-party certification from their subcontractors.