# CMMC 2.0 Requirements | Secureframe

> Learn how to assess your CMMC 2.0 compliance level, determine which type of assessment you need, and the key documentation you’ll need to prepare.

canonical: https://secureframe.com/hub/cmmc/requirements

Navigating the complexities of CMMC compliance is essential for any organization aiming to secure contracts with the Department of Defense (DoD). 

We’ve designed this section to help you understand CMMC requirements and how they apply to your organization so you can begin your journey toward achieving and maintaining CMMC certification to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) and meet the demands of government contracts.

Here’s everything you need to know about preparing for a CMMC assessment.

# Intermediate: I’m preparing for CMMC compliance

**So you’re preparing for CMMC 2.0 compliance.**

If your organization contracts with the U.S. Department of Defense (DoD), achieving CMMC 2.0 compliance is essential to securing and maintaining contracts. CMMC 2.0 streamlines the previous version, reducing the number of maturity levels and focusing more on aligning with existing cybersecurity frameworks like NIST SP 800-171.

Here’s a breakdown of key CMMC 2.0 elements to help guide your readiness efforts.

## What are CMMC 2.0 compliance requirements?

CMMC 2.0 is a three-level framework that matches the security needs of organizations based on the sensitivity of the information they handle. The requirements align more closely with the controls outlined in NIST SP 800-171 and NIST SP 800-172.

The number of requirements and the assessment processes differ depending on the level of certification your organization needs to achieve.

## What type of data does CMMC 2.0 protect?

CMMC 2.0 primarily focuses on protecting:

1. **Federal Contract Information (FCI)**: Information generated for or provided by the government under federal contracts that is not intended for public release, such as supplier information and technical specifications.
2. **Controlled Unclassified Information (CUI)**: Information that requires protective measures according to laws, regulations, or government-wide policies, but is not classified under national security standards. Examples include PII, critical infrastructure data, and proprietary business information.

The level of certification required depends on the type and volume of this information your organization handles.

## What are the CMMC 2.0 levels?

CMMC 2.0 features three levels of certification, compared to the five levels in the original CMMC 1.0 model.

Each level has specific practices, controls, and assessment requirements based on the type of data and cybersecurity needs:

- **Level 1: Foundational **(15 practices) — Protects FCI and requires annual self-assessments. These basic cybersecurity practices are based on FAR 52.204-21. 
- **Level 2: Advanced** (110 practices) — Protects CUI with more advanced cybersecurity requirements, directly aligned with NIST SP 800-171 Revision 2. Organizations must undergo third-party assessments every three years for critical national security information, while others can self-assess annually for non-critical information.
- **Level 3: Expert** (134 practices) — Targets the highest level of CUI protection, building on the full implementation of NIST 800-171 R2 for Level 2 and incorporating 24 additional practices from a subset of NIST SP 800-172 controls. Organizations will be required to undergo government-led assessments.

## Streamline CMMC 2.0 compliance with automation

Preparing for CMMC 2.0 compliance can be a complex and resource-intensive process. Compliance automation tools can help significantly reduce manual tasks by identifying and tracking security gaps and providing real-time monitoring of your controls and systems.

Look for solutions that integrate seamlessly with your existing infrastructure to automate compliance tasks, manage risk assessments, and continuously monitor for compliance issues. Additionally, these tools can provide remediation guidance and help you stay compliant with evolving CMMC 2.0 requirements.

By using automation, your organization can maintain compliance more efficiently, reduce the risk of human error, and meet CMMC 2.0 requirements with greater confidence.
