Federal contracting glossary
CMMC
What are the CMMC levels and which one do I need?
CMMC (Cybersecurity Maturity Model Certification) is the Department of War program that verifies contractor cybersecurity. It reaches your company through a contract clause, so the level you need varies contract by contract.
CMMC (Cybersecurity Maturity Model Certification) is the Department of War program that verifies contractor cybersecurity. It has three levels:
- Level 1 covers the 15 basic safeguards for Federal Contract Information.
- Level 2 covers the 110 controls of NIST SP 800-171 Revision 2.
- Level 3 adds selected NIST SP 800-172 requirements.
32 CFR Part 170 codifies the program rule.
The requirement reaches your company through a contract clause, not through a general regulation. That is why the practical question is always "what does this solicitation require."
Where the program actually stands today
Phase 2 is suspended. On July 13, 2026 the Department of War suspended implementation of Phase 2 and established a CMMC reform task force. Phase 1 began on November 10, 2025, and the program remains paused there.
What that means in practice right now:
- Only self-assessments apply, at two levels.
- Level 1 — annual self-assessment and annual affirmation against the 15 requirements in FAR 52.204-21. A POA&M is not permitted.
- Level 2 — a self-assessment every three years with annual affirmation, against the 110 requirements of NIST SP 800-171 Revision 2, required by DFARS 252.204-7012. A POA&M is permitted under 32 CFR 170.21(a)(2) and must close within 180 days.
- Results go into SPRS. A CMMC status is valid for three years. An assessment lapses if you fail to affirm annually.
- The Department also enforces compliance through select government-led assessments.
The pause is not a reprieve
This is the part that costs companies money.
The suspension changes the verification mechanism, not the obligation. DoW states plainly that the action "does not eliminate the requirement for companies to protect information in accordance with DFARS clause 252.204-7012." That clause still applies. The 110 requirements still apply. The affirmation still applies, and it is still a False Claims Act exposure if it is false.
So the risk profile inverted rather than improved. A company that reads "suspended" as "later" now carries the same contractual duty with less external forcing function to complete it, and the annual affirmation continues to fall due the whole time.
What to do with the pause: treat it as the scoping window you did not have. Define the CUI boundary, write the SSP against the real environment, and post a score you can defend. That work is required today, it is the long pole whenever Phase 2 resumes, and it does not expire.
Check this section's date before you rely on it. This is an active policy area. The phase schedule changed on July 13, 2026, and a reform task force is sitting. Confirm the current status against the DoW CIO CMMC page before you plan against anything here.
The three levels
Level 1 — Foundational. For contractors that handle Federal Contract Information (FCI) but no Controlled Unclassified Information. The requirement is the 15 basic safeguarding requirements of FAR 52.204-21. A contractor verifies it by annual self-assessment, with an affirmation from a senior official.
Level 2 — Advanced. For contractors that handle CUI. The requirement is the full 110 security requirements of NIST SP 800-171 Revision 2, organized into 14 families:
Check which revision your contract names. NIST published Revision 3 of SP 800-171 in May 2024, and it restructures the requirements. The 110-requirement, 14-family table below is Revision 2. Confirm the revision your clause and your assessment cite before you plan against either number.
| Family | Controls | Family | Controls |
|---|---|---|---|
| Access Control (AC) | 22 | Media Protection (MP) | 9 |
| Awareness & Training (AT) | 3 | Personnel Security (PS) | 2 |
| Audit & Accountability (AU) | 9 | Physical Protection (PE) | 6 |
| Configuration Management (CM) | 9 | Risk Assessment (RA) | 3 |
| Identification & Authentication (IA) | 11 | Security Assessment (CA) | 4 |
| Incident Response (IR) | 3 | System & Communications Protection (SC) | 16 |
| Maintenance (MA) | 6 | System & Information Integrity (SI) | 7 |
The CMMC model verifies Level 2 either by self-assessment or by a certification assessment from an accredited C3PAO (Certified Third-Party Assessment Organization). Only the self-assessment applies today, because the program is paused in Phase 1 and the C3PAO requirement arrives with Phase 2. Which of the two applies is a contract-level determination, not a company-level choice.
Level 3 — Expert. A narrow set of programs that support the most critical technology. It adds selected enhanced requirements from NIST SP 800-172 on top of Level 2. DCMA DIBCAC performs the assessment rather than a C3PAO. Level 3 arrives with Phase 3 and is not in effect today.
CMMC practices carry the notation AC.L2-3.1.1: family, level, and the underlying NIST 800-171 requirement number.
The clauses that carry it
- FAR 52.204-21 — basic safeguarding of contractor information systems. This is the substance of Level 1.
- DFARS 252.204-7012 — safeguarding covered defense information. It requires NIST SP 800-171 implementation and cyber incident reporting to DoW within 72 hours of discovery.
- DFARS 252.204-7019 — notice of the requirement to hold a current NIST SP 800-171 assessment on file.
- DFARS 252.204-7020 — the NIST SP 800-171 DoD Assessment Requirements. It covers government access for higher-level assessments and flowdown to subcontractors.
- DFARS 252.204-7021 — the CMMC requirement itself. It states the level the contract requires and mandates flowdown.
If a solicitation contains DFARS 252.204-7012, or otherwise contemplates CUI, plan for Level 2 regardless of what the solicitation says today.
SSP, POA&M, and the SPRS score
Three artifacts sit at the center of compliance:
- The System Security Plan (SSP) documents how your environment implements each of the 110 requirements. There is no compliance without one.
- The Plan of Action and Milestones (POA&M) documents unimplemented requirements and the dated plan to close them. CMMC restricts which requirements may sit on a POA&M, and for how long.
- The SPRS score is the self-assessment result that you post to the Supplier Performance Risk System through PIEE. Contracting officers can see it. A score posted years ago, against an environment that has since changed, is a live risk rather than a historical footnote.
CUI itself falls under 32 CFR Part 2002, the marking, handling and dissemination rules. That is a separate obligation from the security controls that protect the information.
The mistake that makes this term matter
CMMC arrives as a control count, so it gets treated as a shopping list. Somebody finds the 110 requirements and hands them to IT. IT then buys and configures against the whole company network, because that network is what IT owns.
The question nobody asked first is where the CUI actually lives. A company that asks it early often finds a small answer: a handful of people, one file share and one mail flow. A bounded enclave holds all of it. A company that asks it late has already paid to drag printers, guest wifi and a second office into the assessment boundary. The controls are the same either way. What changes is how much of the company those controls have to cover, and a decision sets that, not the standard.
What goes wrong in practice
Teams scope it last. The single biggest cost driver is how much of your environment falls in scope. An enclave architecture that isolates CUI to a defined boundary is dramatically cheaper to assess than a whole-company scope. Make that decision before you spend money on controls.
Teams treat self-attestation as compliance. A high self-assessed score with no supporting evidence is exposure, not readiness. A false affirmation is a False Claims Act risk, which is the reason this program has teeth.
Teams ignore flowdown. DFARS 252.204-7012 and the CMMC clause flow down to subcontractors that handle the same information. A certification held by the prime does not cover its supply chain, and a gap at a subcontractor becomes a problem for the prime.
Nobody checks the cloud assumptions. Where a cloud service stores or processes CUI, that service must meet the FedRAMP-related requirements in DFARS 252.204-7012. An assumption that a commercial tenant qualifies is a common and expensive error.
What to do
- Define the CUI boundary first.
- Perform an honest self-assessment against all 110 requirements.
- Write the SSP against your actual environment.
- Post a score you can defend with evidence.
- Read the clause list of every solicitation you pursue.
- Take the level you need from that clause list, because it varies contract by contract.
What CMMC is not
CMMC is not a new set of security requirements. Level 2 is NIST SP 800-171. DoW contractors that handle CUI have carried a contractual obligation to implement it for years. What CMMC adds is verification and consequence.
CMMC is also not a permanent status. A certification has a defined term with annual affirmations. DoW phases the program into contracts on a schedule that the acquisition rule sets. So the correct answer to "when does this hit me" is the effective date of the clause in your next contract.
Silas™ reads the clause set of a solicitation and surfaces the cybersecurity level it implies before the bid decision.
Last reviewed .
This page is reference material about federal contracting terminology. It is not legal advice, not a compliance determination, and not a substitute for professional judgement or for the authoritative text. Regulations change; verify any citation against the current FAR/DFARS text before relying on it. See our Terms of Service.