Skip to main content

What Is CMMC? The Cybersecurity Maturity Model Certification, Explained

A plain-language guide for defense contractors and subcontractors. Who has to comply, what each level requires, where the program stands after the July 2026 pause, and what the work actually costs.

Take the free CMMC readiness assessment

Request a CMMC demo

CMMC in plain terms

The Cybersecurity Maturity Model Certification (CMMC) is how the Department of War checks that defense contractors are actually doing the cybersecurity work their contracts already require.

Two kinds of government information trigger it. Federal Contract Information (FCI) is the everyday paperwork of a government contract: schedules, progress reports, specifications, supplier lists. If you hold a government contract, you almost certainly have it. Controlled Unclassified Information (CUI) is more sensitive material the government requires you to protect, like technical drawings or export-controlled data.

Which one you handle decides which level you need.

None of the security requirements are new. They've been in defense contracts since 2016 and 2017. What CMMC adds is verification. Before it, you signed a contract saying you met them and nobody checked.

On July 13, 2026, the Department paused the part of the rollout that would have required an outside assessor. Everything else still applies, and the sections below cover what that means for your contracts.

CMMC emblem
Technician in safety glasses operating manufacturing equipment

Who must comply with CMMC

CMMC compliance covers the entire defense industrial base, not just the primes. Requirements flow down. If your customer holds a covered DoW contract and shares FCI or CUI with you, the requirement lands on you, whether you're a 5-person machine shop or a 200-person engineering firm.

Under 32 CFR 170.23, the prime is responsible for identifying which suppliers touch that data and flowing the right level down. The main carve-out is suppliers of only commercially available off-the-shelf items.

You cannot rely on your prime's certification. You demonstrate compliance for your own systems.

The Department estimated roughly 80,000 contractors would need Level 2. Fewer than 1,400 had earned it as of May 2026.

Which level applies to you depends on where sensitive information actually sits in your systems, which is the first decision worth getting right. It drives your cost and your timeline more than anything else.

The three CMMC levels

The level you need depends on the data you handle, not your size. Most small and mid-size defense suppliers land at Level 2. Full breakdown of the three levels and the phase-in.

Level 1

FCI only. The 15 basic safeguarding requirements in FAR 52.204-21, self-assessed annually.

Learn more about Level 1

Level 2

CUI. All 110 requirements in NIST SP 800-171 Rev 2 and 320 assessment objectives, assessed every three years. Self-assessment applies to CUI in non-Defense registry categories. Third-party (C3PAO) assessment applies to Defense categories such as Controlled Technical Information, and is on hold pending review.

Learn more about Level 2

Level 3

A small set of high-priority programs facing advanced persistent threats. The 110 requirements plus 24 enhanced requirements from NIST SP 800-172, assessed by the government. On hold pending review.

Learn more about Level 3

Under the current pause, new solicitations can require the self-assessment form of Level 2. The 110 requirements are the same either way. The only thing that changes is who checks.

Where Secureframe fits

Most of the cost and difficulty in CMMC sits in implementing and maintaining the security requirements, not in the assessment. Secureframe Defense was built for that work.

We deploy a compliant CUI environment in Google Workspace or Microsoft GCC High, configured with the access management, logging, monitoring, and segmentation NIST 800-171 Rev 2 requires, in under 30 minutes. The conventional enclave build runs 8 to 10 weeks and usually a consultant.

Defense Navigator

Turns the 110 requirements and 320 assessment objectives into a guided workflow, and generates your SSP, implementation statements, and policies from your actual configured environment rather than from a template.

Continuous monitoring

Flags a control the moment it drifts and keeps your SPRS score current, so the executive signing the annual affirmation has an operational record behind it.

Audit Module and C3PAO network

Compiles your evidence and documentation into one exportable package, and connects you with vetted CMMC Registered Practitioners and C3PAO partners at preferred pricing.

Frequently Asked Questions

No. The pause applies to the transition to Phase 2 and to third-party assessment requirements. DFARS 252.204-7012 and the 110 requirements in NIST SP 800-171 Rev 2 are in your contract today. Phase 1 self-assessments, SPRS scores, and annual affirmations are all still required.

The certification requirement paused.The one in your contract did not.

Request a CMMC demo