What is CMMC 2.0?
CMMC is a cybersecurity maturity assessment framework created by the US Department of Defense (DoD) for companies in the Defense Industrial Base (DIB). The program was created because the previous model — self-attesting compliance with NIST SP 800-171 under DFARS clause 252.204-7012 — did not deliver real protection of information. CMMC adds an independent verification mechanism on top of the existing requirements.
Version 2.0 simplified the original model from five levels to three and based the requirements directly on NIST standards. The program was formally established by the 32 CFR Part 170 rule (effective December 2024), and the 48 CFR contract clause (DFARS 252.204-7021) phases the CMMC requirement into contracts over several years from the program start. Two categories of information are protected: FCI (Federal Contract Information — contract information not intended for public release) and CUI (Controlled Unclassified Information — unclassified but legally protected information, for example weapons technical data).
Who is it for?
CMMC applies to any company performing DoD contracts or acting as a subcontractor in such a chain — regardless of where it is headquartered. The requirement flows down the supply chain: a prime contractor must require the appropriate CMMC level from its subcontractors when passing them FCI or CUI. This means European and Polish companies supplying components, software or services into US defence programs can also fall under CMMC.
In practice CMMC covers parts and electronics manufacturers, engineering firms, software and IT service providers, logistics companies and research organisations working with the DoD. The level required in a given contract depends on the information involved: FCI alone means Level 1, CUI means Level 2, and the most sensitive programs require Level 3.
The three CMMC levels
CMMC 2.0 defines three levels with increasing requirements and increasing verification rigour. The key difference between levels is the scope of practices and who confirms compliance — the company itself, an independent assessor, or the government.
- Level 1 (Foundational) — 15 basic safeguarding practices for FCI (from FAR 52.204-21). An annual self-assessment with a leadership affirmation submitted to SPRS is sufficient.
- Level 2 (Advanced) — the 110 practices of NIST SP 800-171 protecting CUI. Most contracts require certification by an independent accredited C3PAO, valid for 3 years; some contracts allow an annual self-assessment.
- Level 3 (Expert) — Level 2 plus 24 additional requirements from NIST SP 800-172 (defence against advanced persistent threats). The assessment is performed by the government DIBCAC team, and a valid C3PAO Level 2 certification is a prerequisite.
- The Level 2 self-assessment score (a scale from -203 to 110 points under the DoD methodology) must be reported to SPRS — contracting officers check it before award.
- Conditional certification is possible with a score of at least 80% and a POA&M; the highest-weighted practices cannot be placed on a POA&M, and the plan must be closed within 180 days.
What does the assessment look like?
The Level 2 certification assessment is performed by a C3PAO (CMMC Third-Party Assessment Organization) accredited by the Cyber AB — the accreditation body for the CMMC ecosystem. The assessment follows the NIST SP 800-171A methodology: for each of the 110 practices, assessors gather evidence from three angles — examining documentation and records, interviewing personnel, and testing mechanisms in operation.
Scoping is the foundation of the assessment: before the assessment the company must categorise its assets per the CMMC Scoping Guide (CUI assets, security protection assets, contractor risk managed assets, specialized assets and out-of-scope assets). A well-designed CUI enclave can significantly reduce the scope and cost of the assessment. Two documents are effectively mandatory: the System Security Plan (SSP), describing how each practice is implemented, and — for gaps — the Plan of Action and Milestones (POA&M). A Level 2 certificate is valid for 3 years, with an annual affirmation of compliance submitted by leadership in SPRS.
How long does it take and what does it cost?
Preparing for Level 2 typically takes 6 to 18 months depending on the starting point. Companies that have genuinely applied NIST SP 800-171 for years mainly need to organise evidence and documentation; companies starting from scratch must implement MFA, network segmentation, central logging, FIPS 140 validated encryption and operational processes — and then let them run long enough to generate records an assessor can examine.
Costs include your own team’s and any consultants’ time, technical investments (for example a CUI enclave, identity, SIEM), and for certification the C3PAO assessment, priced commercially and driven by scope size and number of sites. DoD estimates published with the 32 CFR rule indicate that for small and medium businesses a Level 2 certification assessment runs on the order of ~$100-120k over the three-year cycle (assessment plus affirmations), while the biggest cost remains implementing the requirements themselves — which have been contractually required for years under DFARS 252.204-7012. Narrowing the scope to a CUI enclave is the most effective cost-reduction lever.
How does Guardiso help?
Guardiso guides you through CMMC 2.0 preparation — from the first self-assessment and SPRS score to a complete evidence set ready for a C3PAO assessment.
- All 110 Level 2 practices (NIST SP 800-171) seeded automatically when you enable the standard — with descriptions, implementation statuses and owners.
- A maturity self-assessment that surfaces gaps before the assessment — you know what to fix before paying an assessor.
- Policies and procedures generated from templates — a ready documentation base for your System Security Plan.
- Evidence collected per practice in one place: documents, recurring tasks and automated evidence from integrations.
- A risk register and remediation plan for gaps — a natural foundation for your POA&M with deadlines and owners.
- Cross-mapping to ISO 27001, SOC 2 and NIST — work done for other standards counts towards overlapping CMMC practices.
- An assessor portal: controlled access to documentation and evidence without emailing files around.
