What Is CMMC? The Cybersecurity Maturity Model Certification, Explained
A plain-language guide for defense contractors and subcontractors. Who has to comply, what each level requires, where the program stands after the July 2026 pause, and what the work actually costs.
Take the free CMMC readiness assessmentCMMC in plain terms
The Cybersecurity Maturity Model Certification (CMMC) is how the Department of War checks that defense contractors are actually doing the cybersecurity work their contracts already require.
Two kinds of government information trigger it. Federal Contract Information (FCI) is the everyday paperwork of a government contract: schedules, progress reports, specifications, supplier lists. If you hold a government contract, you almost certainly have it. Controlled Unclassified Information (CUI) is more sensitive material the government requires you to protect, like technical drawings or export-controlled data.
Which one you handle decides which level you need.
None of the security requirements are new. They've been in defense contracts since 2016 and 2017. What CMMC adds is verification. Before it, you signed a contract saying you met them and nobody checked.
On July 13, 2026, the Department paused the part of the rollout that would have required an outside assessor. Everything else still applies, and the sections below cover what that means for your contracts.


Who must comply with CMMC
CMMC compliance covers the entire defense industrial base, not just the primes. Requirements flow down. If your customer holds a covered DoW contract and shares FCI or CUI with you, the requirement lands on you, whether you're a 5-person machine shop or a 200-person engineering firm.
Under 32 CFR 170.23, the prime is responsible for identifying which suppliers touch that data and flowing the right level down. The main carve-out is suppliers of only commercially available off-the-shelf items.
You cannot rely on your prime's certification. You demonstrate compliance for your own systems.
The Department estimated roughly 80,000 contractors would need Level 2. Fewer than 1,400 had earned it as of May 2026.
Which level applies to you depends on where sensitive information actually sits in your systems, which is the first decision worth getting right. It drives your cost and your timeline more than anything else.
The three CMMC levels
The level you need depends on the data you handle, not your size. Most small and mid-size defense suppliers land at Level 2. Full breakdown of the three levels and the phase-in.
Level 1
FCI only. The 15 basic safeguarding requirements in FAR 52.204-21, self-assessed annually.
Learn more about Level 1Level 2
CUI. All 110 requirements in NIST SP 800-171 Rev 2 and 320 assessment objectives, assessed every three years. Self-assessment applies to CUI in non-Defense registry categories. Third-party (C3PAO) assessment applies to Defense categories such as Controlled Technical Information, and is on hold pending review.
Learn more about Level 2Level 3
A small set of high-priority programs facing advanced persistent threats. The 110 requirements plus 24 enhanced requirements from NIST SP 800-172, assessed by the government. On hold pending review.
Learn more about Level 3Under the current pause, new solicitations can require the self-assessment form of Level 2. The 110 requirements are the same either way. The only thing that changes is who checks.
Where Secureframe fits
Most of the cost and difficulty in CMMC sits in implementing and maintaining the security requirements, not in the assessment. Secureframe Defense was built for that work.
We deploy a compliant CUI environment in Google Workspace or Microsoft GCC High, configured with the access management, logging, monitoring, and segmentation NIST 800-171 Rev 2 requires, in under 30 minutes. The conventional enclave build runs 8 to 10 weeks and usually a consultant.
Defense Navigator
Turns the 110 requirements and 320 assessment objectives into a guided workflow, and generates your SSP, implementation statements, and policies from your actual configured environment rather than from a template.
Continuous monitoring
Flags a control the moment it drifts and keeps your SPRS score current, so the executive signing the annual affirmation has an operational record behind it.
Audit Module and C3PAO network
Compiles your evidence and documentation into one exportable package, and connects you with vetted CMMC Registered Practitioners and C3PAO partners at preferred pricing.
Frequently Asked Questions
No. The pause applies to the transition to Phase 2 and to third-party assessment requirements. DFARS 252.204-7012 and the 110 requirements in NIST SP 800-171 Rev 2 are in your contract today. Phase 1 self-assessments, SPRS scores, and annual affirmations are all still required.
The data you handle. Level 1 covers Federal Contract Information and requires 15 basic safeguards, self-assessed annually. Level 2 covers Controlled Unclassified Information and requires all 110 requirements in NIST SP 800-171 Rev 2, assessed every three years. If you hold a government contract you almost certainly have FCI. Whether you have CUI depends on what your prime or contracting officer sends you.
The 7012 clause has required full NIST 800-171 Rev 2 implementation, 72-hour incident reporting, and flowdown since 2017. That obligation exists independently of which assessment type your solicitation calls for. If 7012 is in your contract, the underlying work is already required.
Level 2 scores run from -203 to 110. You start at 110 and lose 5, 3, or 1 point per requirement not fully implemented, depending on severity. There's generally no partial credit. You need 110 for final Level 2 status and at least 88 to qualify for conditional status, and every gap on your POA&M has to be closed and verified within 180 days. A low score is not disqualifying on its own, but it's visible to primes and program managers, and an inflated one carries False Claims Act exposure.
No. Primes must flow CMMC requirements into every subcontract where FCI or CUI is processed, stored, or transmitted, and cannot send that data to a supplier that hasn't demonstrated compliance at the required level. You demonstrate compliance for your own systems. In practice, primes are the real enforcement arm here. Their deadlines are supply chain risk decisions and do not move when the government's rollout does.
Most organizations spend 8 to 17 months preparing for a Level 2 self-assessment. Preparation dominates the timeline, not the assessment. Scoping aggressively, starting with a real gap analysis instead of an estimate, and building your SSP as you implement are the three things that shorten it most.
