Skip to content
ActaCyber

CMMC: requirements, process, and how to automate it

CMMC, the Cybersecurity Maturity Model Certification, is the Department of Defense's tiered program for verifying that a company in the defense industrial base protects federal contract information and controlled unclassified information at a level that matches what it actually handles. Three levels scale the expectation from a short self-assessment up to an independent certification, and which level applies to a given contractor depends entirely on what kind of information crosses its systems, a question CMMC Level 2 exists specifically to answer for CUI-handling contractors.

What CMMC is

CMMC exists because the Department of Defense concluded that asking contractors to self-attest to NIST SP 800-171 compliance, the standard that has governed protection of controlled unclassified information since 2017, was not producing consistent results across the defense industrial base. The program layers a certification structure on top of that existing standard: three levels, each with its own assessment mechanism, so the government can calibrate how much verification a contract requires to how sensitive the information actually is.

Level 1, Foundational, covers the 17 basic safeguarding practices in FAR 52.204-21 and applies to contractors handling only federal contract information, verified through an annual self-assessment the company performs itself. Level 2, Advanced, is built directly on the 110 security requirements in NIST SP 800-171 and applies where controlled unclassified information is involved; most CUI-handling contracts eventually require a certification assessment from an accredited third party rather than self-attestation, though a smaller subset of programs qualify for self-assessment. Level 3, Expert, adds the enhanced requirements in NIST SP 800-172 on top of Level 2 and is reserved for the highest-priority programs, assessed directly by the Defense Industrial Base Cybersecurity Assessment Center rather than a commercial assessor.

The requirement is being written into contracts in phases rather than all at once. The CMMC Program rule at 32 CFR Part 170 and its associated DFARS clause, 252.204-7021, are being phased into new solicitations over a schedule the Department of Defense has structured in stages, and that schedule has moved before. Treat CMMC as coming rather than optional, but confirm the current phase and which of your own contracts carry the clause against the latest DFARS and CMMC Program guidance rather than assuming a fixed date.

Who needs CMMC

CMMC reaches further than the primes signing contracts directly with the Department of Defense. Flow-down clauses push the same requirement through subcontractors, parts suppliers, and any vendor whose product or service touches a covered contract, so a shop three tiers removed from the prime can find itself needing a CMMC level it never budgeted for.

  • Prime contractors and their direct subcontractors performing work that involves federal contract information or controlled unclassified information.
  • Software, cloud, and managed service vendors whose platforms process, store, or transmit CUI on behalf of a defense program, even if the vendor does not think of itself as a traditional contractor.
  • Small and mid-size suppliers newly encountering the requirement because a prime has started flowing CMMC obligations into its own subcontracts ahead of the DoD-wide phase-in.

Which level applies is a separate question from whether CMMC applies at all: a company that only ever sees federal contract information needs Level 1, while a company that receives, generates, or stores information marked as, or that should be treated as, controlled unclassified information needs Level 2. CMMC Level 2 walks through that boundary in detail. Level 3 only reaches the small population of suppliers on the department's highest-priority programs.

CMMC requirements, by level

LevelSource standardAssessment mechanism
Level 1, Foundational17 practices in FAR 52.204-21Annual self-assessment
Level 2, Advanced110 requirements in NIST SP 800-171Self-assessment or C3PAO certification, contract-dependent
Level 3, ExpertNIST SP 800-172 enhanced requirements, added to Level 2Government-led assessment by DIBCAC

Level 2 carries the most operational weight because it is where the largest share of the defense industrial base lands, and it is detailed enough to warrant its own page: see CMMC Level 2 requirements for the full breakdown of the 110 requirements across their fourteen families, the self-assessment versus certification-assessment split, and the rules governing open items. The scoring methodology behind Level 2, an implementation of the underlying NIST 800-171 self-assessment approach, produces the same numeric result whether it is run for CMMC purposes or for a standalone DFARS assessment obligation.

Where CMMC differs from a plain NIST 800-171 assessment is the certification layer: an accredited C3PAO, working through assessors credentialed by the program's accreditation body, independently verifies the required controls before the government treats the contractor as certified at that level, rather than accepting the contractor's own attestation.

The CMMC certification process, step by step

A CMMC certification is not one event; it is a sequence that starts with a scoping decision and ends with a recurring maintenance obligation. The path below reflects a Level 2 effort, the most common path through the program.

  1. Determine the required level: Identify whether contracts involve only federal contract information (Level 1) or controlled unclassified information (Level 2), and check whether any contract calls out Level 3; typically one to two weeks with contract and data-flow review.
  2. Scope the environment: Draw the boundary around the systems, users, and facilities that actually touch FCI or CUI, since certifying a larger boundary than necessary multiplies cost with no security benefit; commonly four to eight weeks.
  3. Run a gap assessment against NIST SP 800-171: Compare the current environment to the 110 requirements (or the 17 FAR practices for Level 1), documenting what is implemented, partially implemented, or missing; six to ten weeks is typical.
  4. Remediate and document: Close what can be closed, write the System Security Plan and supporting policies, and build the Plan of Action and Milestones for what remains open; usually the longest step, three to nine months.
  5. Submit the self-assessment score to SPRS: Post the resulting score to the Supplier Performance Risk System, a prerequisite for contract award under existing DFARS assessment clauses regardless of which CMMC level ultimately applies; a few days once the assessment is done.
  6. Undergo the C3PAO certification assessment (Level 2 and above): An accredited third-party assessment organization independently tests the implemented requirements and issues the certification decision; fieldwork commonly takes eight to sixteen weeks once a C3PAO is engaged, longer where the regional assessor pool is backed up.
  7. Maintain the certification with annual affirmation: Affirm continued compliance annually in SPRS between assessments, and plan for reassessment on the cycle the level requires; this phase does not end and is where certifications quietly lapse if nobody owns it.

How long does CMMC take and what does it cost?

Cost and timeline depend heavily on which level applies and how mature the environment already is, so the ranges below assume a mid-size supplier starting close to zero rather than a company already running a mature NIST 800-171 program.

Level 1 is the cheapest and fastest path: since it is a self-assessment against 17 practices, most companies complete the gap-to-affirmation cycle in six to twelve weeks with minimal outside spend beyond internal labor. Level 2 is longer and more expensive. A gap assessment and remediation program commonly runs six to twelve months for a company starting without a mature 800-171 program already in place, sometimes longer where significant technical remediation, such as replacing unsupported systems or building out logging, is required.

Advisory support to build the System Security Plan and prepare for assessment commonly runs $20,000 to $80,000 depending on environment size and how much is done in-house. C3PAO certification assessment fees for Level 2 scale with environment size and boundary complexity, commonly $30,000 at the small end to $250,000 or more for a large, complex environment; see CMMC Level 2 for the fee breakdown by company size. Level 3 assessments, run by the government's own assessment center rather than a commercial C3PAO, are priced differently and reached only by the small population of suppliers whose contracts require that level.

ACTA's own pricing is licensed per environment, and every engagement starts with a conversation. The deterministic artifact generation described later on this page is aimed at the scoping, gap-assessment, and evidence-preparation work above, not the C3PAO's independent certification fee, which ACTA does not and cannot replace.

Common failure points

The same handful of mistakes shows up across most CMMC efforts, whether the company is certifying for the first time or renewing.

  • Self-selecting the wrong level, usually assuming Level 1 covers a system that actually handles controlled unclassified information.
  • Drawing the CUI or FCI boundary too broadly, pulling systems into scope that never needed to be there and inflating both cost and assessment time.
  • Waiting until a contract explicitly requires a score before starting scoping and remediation, leaving no runway before an award decision.
  • Underestimating C3PAO scheduling lead time given the still-limited, if growing, pool of accredited assessors.
  • A policy binder that describes an environment the actual configuration no longer matches by the time an assessor looks at it.
  • Assuming a subcontractor's flow-down obligations are handled without ever verifying that subcontractor's own compliance status.

How ACTA automates CMMC

ACTA's pack library includes CMMC alongside the rest of the federal set, and every pack ships with every license: there is no separate CMMC tier or per-level surcharge for a company that needs Level 1 today and Level 2 next year. Each pack is editable YAML, so control narratives can be tuned to how a specific supplier's environment is actually built rather than left as a generic template.

ACTA runs on goRapide, BMD's deterministic causal engine, with no LLMs, no agents, and nothing probabilistic anywhere in the compliance path, a property that is particularly useful going into a C3PAO assessment: run the same environment through the same journey on two different days and the artifacts, the score, and the underlying evidence come out identical both times, with an inspectable causal chain behind every control decision an assessor might question.

For a Level 2 effort, ACTA generates the SPRS package alongside the System Security Plan, POA&M, control narratives, and evidence binder, drawn from the live environment rather than a point-in-time snapshot, and can provision the environment itself as code, on AWS commercial, AWS GovCloud, Microsoft GCC High, Azure, Google Cloud, or bare metal, with a small environment standing up in roughly 25 minutes.

Once certified, continuous monitoring tracks credential health, evidence freshness, endpoint posture, and drift from previously passing requirements between assessment cycles, refreshing a stale posture to current in two clicks, the same continuous-monitoring capability behind FedRAMP authorization and every other framework in the pack library. Evidence never leaves the supplier's own boundary: the standard build phones home only for a license heartbeat, and the air-gapped build does not phone home at all.

CMMC and adjacent frameworks

CMMC Level 2's 110 requirements are not a separate control set: they are NIST 800-171 itself, wrapped in a certification and assessment structure the underlying standard does not impose on its own. A contractor already running a disciplined 800-171 self-assessment program is most of the way to CMMC Level 2 readiness; what changes is who verifies the result, not what is being verified.

Level 2 is significant enough on its own that it is covered in depth on the CMMC Level 2 requirements page, including the self-assessment versus C3PAO-certification split, the rules for keeping requirements open on a POA&M, and the do-I-need-Level-2 decision in full.

CMMC governs how a contractor protects information in its own environment; it says nothing, by itself, about which cloud a contractor is allowed to build that environment on. A contractor hosting CUI in the cloud still has to confirm the cloud service offering's own authorization under the DoD Cloud Computing SRG, since CMMC compliance and cloud impact-level authorization are evaluated separately even when they cover overlapping data.

For the wider landscape this program sits inside, from the underlying NIST catalogs to the authorization concepts that apply across the rest of the defense and civilian government, see the full compliance framework library.

Frequently asked questions

What are the three CMMC levels?

Level 1, Foundational, covers 17 basic practices for federal contract information, verified by annual self-assessment. Level 2, Advanced, covers the 110 NIST SP 800-171 requirements for controlled unclassified information, usually verified by an accredited third-party assessor. Level 3, Expert, adds NIST SP 800-172 enhanced requirements for the highest-priority programs, assessed by the government's own assessment center.

What is the difference between CMMC Level 1 and Level 2?

Level 1 applies to companies that only handle federal contract information and is satisfied with an annual self-assessment against 17 practices. Level 2 applies once controlled unclassified information is involved, covers 110 requirements drawn from NIST SP 800-171, and most contracts at this level eventually require an independent certification assessment rather than self-attestation.

What is a C3PAO?

A C3PAO, Certified Third-Party Assessment Organization, is a firm accredited by the CMMC program's accreditation body to independently assess a defense contractor against Level 2 or above. C3PAO assessors review evidence, interview staff, and test implemented controls before issuing a certification decision the contractor cannot issue for itself.

Is CMMC the same as NIST 800-171?

No, though Level 2 uses the same 110 requirements as NIST SP 800-171. CMMC adds a certification and assessment structure on top of that standard, verifying compliance through an accredited third party for most contracts rather than accepting the contractor's own self-assessment as the final word.

When does CMMC become a contract requirement?

The requirement is being phased into new DoD solicitations under the CMMC Program rule and its DFARS clause, and the phase-in schedule has changed before as the program matured. Confirm which of your specific contracts carry the clause today against current DFARS and CMMC Program guidance rather than assuming a fixed date.

How is a C3PAO different from a general security auditor?

A C3PAO is accredited specifically by the CMMC program's own accreditation body to assess against the program's defined levels, using assessors who hold a program-specific credential. A general security auditor, even a highly qualified one, cannot issue a CMMC certification without that specific accreditation.

What happens if I fail a C3PAO assessment?

A C3PAO does not simply pass or fail a company; it documents which requirements are met and which are not, and the contractor addresses gaps through remediation or an eligible Plan of Action and Milestones item within the allowed window. Certification is withheld until the outstanding requirements are resolved.

How often do I need to renew CMMC certification?

Level 2 certification runs on a triennial cycle, with a full reassessment roughly every three years, and an annual affirmation of continued compliance required in the years between assessments. Missing an affirmation, not just failing a reassessment, is one of the more common ways a certification lapses.

Does CMMC apply to subcontractors?

Yes. CMMC obligations flow down through prime contracts into subcontracts and further down the supply chain to any vendor whose work touches covered federal contract information or controlled unclassified information, regardless of contract size or how many tiers removed the supplier is from the Department of Defense.

Request a quote

Related frameworks