Skip to main content
GuidesBy Rutvi VaderaMarch 9, 202618 min read

CMMC 2.0 Compliance: The Complete Guide for Defense Contractors

CMMC 2.0 Compliance: The Complete Guide for Defense Contractors

Defense contractors working with the Department of Defense are now on the clock: CMMC requirements began appearing in DoD contracts in November 2025, when the DFARS acquisition rule implementing CMMC took effect, and Level 2 third-party certification becomes a condition of award one calendar year later, in November 2026. Those dates come from the DoD's own DFARS clause 252.204-7021 and the phased implementation schedule in 32 CFR 170.3. If your organization handles Controlled Unclassified Information (CUI) and you bid on DoD work, CMMC compliance is no longer optional, it is a contract condition. This complete CMMC 2.0 compliance guide explains the three certification levels, the 110 NIST SP 800-171 requirements at the core of Level 2, the assessment process, timelines, and how to build an audit-ready compliance program without losing months to spreadsheet chaos.

What Is CMMC 2.0? The Framework Explained

The Cybersecurity Maturity Model Certification (CMMC) is the DoD's framework for ensuring defense contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). DoD announced the restructured version 2.0 in November 2021, and the program was codified in 32 CFR part 170, published at 89 FR 83092 on October 15, 2024 and effective December 16, 2024. It streamlined the original five-level model into three levels, defined in 32 CFR 170.14:

  • Level 1 (Foundational): the 15 basic safeguarding requirements set out in FAR 52.204-21(b)(1)(i) through (xv). Annual self-assessment, with no POA&M permitted. Applies to contractors handling FCI only.
  • Level 2 (Advanced): the 110 requirements in NIST SP 800-171 Rev. 2. A C3PAO certification assessment every three years for applicable contracts, with annual affirmation; a self-assessment on the same three-year cycle where DoD designates Level 2 (Self). This is where most defense prime subcontractors operate.
  • Level 3 (Expert): the 110 Level 2 requirements plus 24 selected requirements from NIST SP 800-172, 134 in total. Assessed by DCMA DIBCAC rather than a C3PAO, and it requires Final Level 2 (C3PAO) status first. Applies to contracts involving the most sensitive CUI supporting critical programs.

For the vast majority of defense contractors, particularly small and mid-market firms, CMMC Level 2 is the target. You can review the official framework at the DoD CMMC Office.

Looking for expert cybersecurity guidance? Z Cyber's advisory team can help.

Learn More

CMMC 2.0 Compliance Requirements: The 14 Domains

CMMC Level 2 is built on the 110 security requirements in NIST SP 800-171 Rev. 2, organized into 14 domains (called "families"). The per-domain counts below are taken directly from that NIST publication and add up to 110. Here is what each domain requires at a compliance-ready level:

1. Access Control (AC), 22 practices

Limit system access to authorized users, processes, and devices. Enforce least privilege and separation of duties. Control remote access using session locking, VPN, and multi-factor authentication.

2. Awareness and Training (AT), 3 practices

Ensure all personnel are aware of security risks and trained to carry out their security responsibilities. Document training records.

3. Audit and Accountability (AU), 9 practices

Create and retain system audit logs to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized activity. Protect audit logs from unauthorized access and modification.

4. Configuration Management (CM), 9 practices

Establish and maintain baseline configurations for all systems. Control and document changes to configurations. Restrict, disable, and prevent the use of nonessential programs, functions, ports, and protocols.

5. Identification and Authentication (IA), 11 practices

Identify all system users, processes, and devices. Authenticate identities before allowing access. Enforce multi-factor authentication for privileged accounts and network access.

6. Incident Response (IR), 3 practices

Establish an operational incident-handling capability that includes preparation, detection, analysis, containment, recovery, and user response activities. Track, document, and report incidents.

7. Maintenance (MA), 6 practices

Perform maintenance on organizational systems, including controls on tools, techniques, mechanisms, and personnel for maintenance. Ensure remote maintenance is controlled and monitored.

8. Media Protection (MP), 9 practices

Protect system media containing CUI. Sanitize or destroy media before disposal or reuse. Control the use of removable media.

9. Personnel Security (PS), 2 practices

Screen individuals prior to authorizing access to CUI. Ensure CUI is protected during and after personnel actions such as terminations and transfers.

10. Physical Protection (PE), 6 practices

Limit physical access to systems, equipment, and operating environments to authorized individuals. Escort visitors and monitor physical access to facilities.

11. Risk Assessment (RA), 3 practices

Conduct risk assessments periodically and whenever major changes occur. Scan for vulnerabilities in systems and applications. Remediate vulnerabilities in accordance with risk assessments.

12. Security Assessment (CA), 4 practices

Periodically assess security controls. Develop and implement Plans of Action and Milestones (POA&Ms) to correct deficiencies. Monitor security controls on an ongoing basis.

13. System and Communications Protection (SC), 16 practices

Monitor and control communications at external boundaries and key internal boundaries. Implement subnetworks for publicly accessible system components. Use architectural designs, software development techniques, and systems engineering principles to promote security.

14. System and Information Integrity (SI), 7 practices

Identify and manage information system flaws. Provide protection from malicious code. Monitor system security alerts and advisories.

CMMC 2.0 Compliance Timeline: What to Expect in 2026

CMMC requirements are being phased into DoD contracts on a schedule written into 32 CFR 170.3, which runs four phases one calendar year apart. Key milestones:

  • Phase 1 (began November 2025): begins on the effective date of the DFARS acquisition rule. A CMMC Status of Level 1 (Self) or Level 2 (Self) is a condition of contract award for applicable solicitations, with DoD discretion to require Level 2 (C3PAO) instead. Contractors self-assess and post results in SPRS (Supplier Performance Risk System).
  • Phase 2 (November 2026): begins one calendar year after Phase 1. A CMMC Status of Level 2 (C3PAO) becomes a condition of award for applicable solicitations and contracts, with Level 3 (DIBCAC) included at DoD's option.
  • Phase 3 (November 2027): begins one calendar year after Phase 2. Level 2 (C3PAO) applies to all applicable solicitations and contracts, and Level 3 (DIBCAC) becomes a condition of award where it applies.
  • Phase 4 (November 2028): full implementation one calendar year after Phase 3. CMMC requirements appear in all applicable solicitations and contracts, including option periods on contracts awarded earlier.

For contractors at early stages of maturity, achieving audit-ready Level 2 status before Phase 2 requires starting the assessment and remediation process now. The pool of authorized C3PAOs is finite, so scheduling an assessment is not something to leave until the last quarter before award.

See How Glance Delivers This

See how Z Cyber's Glance platform delivers this.

Explore Glance →

Plans of Action and Milestones (POA&M): The CMMC Compliance Anchor

A POA&M is a formal document that identifies security weaknesses, describes how they will be remediated, and sets milestones and resource assignments for each action item. Under CMMC, a POA&M is not a sign of failure, but it is far more tightly constrained than most contractors assume. The eligibility rules are set out in 32 CFR 170.21, and they are not discretionary:

  • No POA&M is permitted at any time for a Level 1 self-assessment. Every applicable requirement must be MET.
  • At Level 2, a POA&M is only allowed if your assessment score divided by the total number of Level 2 security requirements is at least 0.8.
  • No requirement with a point value greater than 1 under the CMMC scoring methodology may go on a POA&M. The single exception is SC.L2-3.13.11 CUI Encryption, which may be included when encryption is employed but is not FIPS-validated, a 3-point condition. The commonly held belief that 5-point items can be deferred at a contracting officer's discretion is wrong.
  • Six requirements are excluded from a Level 2 POA&M outright regardless of point value: AC.L2-3.1.20 External Connections, AC.L2-3.1.22 Control Public Information, CA.L2-3.12.4 System Security Plan, PE.L2-3.10.3 Escort Visitors, PE.L2-3.10.4 Physical Access Logs, and PE.L2-3.10.5 Manage Physical Access.
  • Closure must be confirmed by a POA&M closeout assessment within 180 days of the Conditional CMMC Status Date, not 180 days from contract award. If it is not closed in that window, the Conditional CMMC Status for that information system expires.
  • For a Level 2 certification assessment, the closeout assessment must be performed by an authorized or accredited C3PAO, not by your own team.

The organizations that struggle with POA&Ms are those tracking them in spreadsheets. When a remediating control is linked to multiple 800-171 requirements, a spreadsheet quickly becomes a liability, changes are missed, milestones slip, and the documentation becomes inconsistent.

How Glance Handles POA&M Tracking

Z Cyber's Glance platform treats POA&M tracking as a first-class function. Every gap identified in the Current State Assessment generates a tracked action item with an assigned owner, milestone date, and framework control mapping. Because Glance maps controls to both NIST SP 800-171 and CMMC simultaneously, a single remediation item closes gaps across both frameworks. Your advisory team at Z Cyber monitors POA&M progress continuously, so when a C3PAO assessment arrives, your documentation reflects your actual current state, not a snapshot from six months ago.

This approach also applies to flow-down compliance: when a prime contractor requires their subcontractors to demonstrate CMMC compliance, the Framework Scorecards in Glance provide the kind of always-current evidence packages that satisfy both the prime's requirements and eventual C3PAO scrutiny.

CMMC 2.0 Compliance: Building Your Audit-Ready Program

A CMMC compliance program is not a one-time project. It is an ongoing security program that happens to be measured against a framework. Here is how Z Cyber's advisory team approaches it:

  1. Current State Assessment: Map your existing controls against all 110 NIST SP 800-171 practices. Produce a scored SPRS value and identify all gaps.
  2. System Security Plan (SSP): Document your CUI environment, system boundaries, and how each 800-171 practice is implemented or planned. The SSP is the primary artifact a C3PAO assessor reviews.
  3. POA&M Development: Assign owners, resources, and milestones to every gap. Prioritize by SPRS impact and contract risk.
  4. Cyber Blueprint Remediation: Execute the prioritized roadmap. Z Cyber advisors work alongside your team to implement controls, test them, and document evidence.
  5. Continuous Monitoring: Maintain your CMMC posture between assessments. Technology changes, personnel changes, and new threat indicators all affect your compliance status.
  6. C3PAO Assessment Preparation: Organize evidence packages by domain. Conduct a pre-assessment review to identify any remaining gaps before the formal C3PAO engagement.

CMMC 2.0 Scope Definition: The Most Underestimated Step

Before any organization begins implementing CMMC Level 2 controls, it must define its assessment scope, specifically, what systems, networks, and personnel are part of the CUI environment. This step has more impact on your compliance cost and timeline than any other single decision, yet it is frequently rushed or skipped.

The CUI boundary determines which assets fall under every CMMC requirement: which systems need audit logs, which endpoints need endpoint detection, which personnel need security training records, and which networks need segmentation. An organization that fails to define its CUI boundary clearly will either over-scope (applying CMMC requirements to systems that do not process CUI, driving up cost unnecessarily) or under-scope (missing systems that do handle CUI, creating compliance gaps that will surface during C3PAO assessment).

Effective scope definition requires a data flow analysis: trace exactly how CUI enters your organization, which systems it touches during processing, where it is stored, and how it exits (to primes, to government, or to other subcontractors). The resulting CUI data flow map becomes the foundation for your System Security Plan's system boundary description. Time spent getting the boundary right before implementation begins is time you do not spend re-scoping and re-documenting later.

Network segmentation, isolating CUI systems from general corporate IT, is the most powerful scope-reduction strategy available. If your CUI environment is a clearly bounded segment of your network, non-CUI systems fall outside CMMC scope entirely. For small and mid-market contractors, this can take a substantial share of the environment out of scope.

CMMC 2.0 Compliance Costs: What to Budget

We are not going to publish a price range we cannot source. Cost varies enormously with organization size, how much of NIST SP 800-171 you already implement, how large your CUI boundary is, and whether you need a C3PAO certification assessment or a self-assessment. Ask any vendor quoting you a tidy number which of those variables they have actually measured in your environment. The budget lines that matter are these:

  • Assessment and gap analysis: driven by the size of your CUI boundary and the number of distinct environments in scope, not by headcount
  • Remediation (technology): highly variable; common investments include endpoint detection, MFA, log management, and encrypted email or file transfer
  • C3PAO certification assessment: a separate fee paid to the assessor, quoted per engagement based on scope and assessment duration. Note that this is a recurring cost, since the certification assessment is required every three years, with an affirmation each year in between
  • Ongoing compliance management: depends on advisory model; Z Cyber's managed advisory approach bundles assessment, remediation guidance, platform access, and continuous monitoring into a single engagement

Scope your CUI boundary first, then collect quotes. A gap analysis and a C3PAO quote priced against an undefined boundary are guesses, and they are usually guesses in the vendor's favor.

For small defense contractors, the advisory model is often more cost-effective than hiring full-time compliance staff or engaging a large consulting firm for a point-in-time engagement. See our CMMC Level 2 guide for small businesses for specific guidance on affordable compliance paths.

The Role of External Service Providers in CMMC Compliance

Many defense contractors rely on managed service providers (MSPs), cloud platforms, or other external service providers as part of their technology environment. Under CMMC 2.0, the use of External Service Providers (ESPs) for CUI handling or security functions does not transfer CMMC compliance responsibility. The contractor remains responsible for ensuring that all applicable CMMC practices are met, including practices implemented by or through the ESP.

Cloud Service Providers (CSPs) that store, process, or transmit covered defense information on behalf of a contractor must meet security requirements equivalent to the FedRAMP Moderate baseline. That obligation comes from DFARS 252.204-7012, which requires the contractor to ensure the cloud provider meets it. This is a common gap for mid-market contractors who use commercial cloud platforms without verifying their federal data handling authorization status. Confirming and documenting the authorization status of every service provider that touches your CUI environment is a required element of your System Security Plan and is reviewed during C3PAO assessments.

If your organization relies heavily on an MSP for IT management, ensure your MSP relationship includes a clear delineation of which CMMC practices they implement and maintain on your behalf, documented in your SSP. Your C3PAO assessor will verify that documented controls actually operate as described, which means verifying ESP-managed controls with the same rigor as internally managed ones.

CMMC 2.0 and NIST 800-171: Understanding the Relationship

CMMC Level 2 is built directly on NIST SP 800-171 Rev. 2. Every CMMC Level 2 practice maps to a corresponding 800-171 requirement. If you have already conducted an 800-171 self-assessment and uploaded a score to SPRS, you have completed a significant portion of your CMMC Level 2 groundwork. The key difference: CMMC 2.0 adds a third-party verification requirement that 800-171 does not. You can read a detailed comparison in our NIST 800-171 vs. CMMC guide.

For defense contractors with existing 800-171 documentation, Z Cyber's advisory team can overlay your current SSP and SPRS score against CMMC requirements and identify the specific gaps that exist for formal certification, without starting from scratch.

Conclusion

CMMC 2.0 compliance is a multi-step program that demands both technical control implementation and disciplined documentation. Defense contractors that start early, build a live POA&M, and maintain continuous monitoring of their CUI environment will reach audit readiness faster and with less disruption to their contracts. Z Cyber's advisory team works with defense contractors to assess, remediate, and document every step of the CMMC journey, with Glance providing the always-current framework scorecards and POA&M tracking that auditors expect.

Ready to map your CMMC readiness? Z Cyber's advisors can conduct your Current State Assessment, calculate your current SPRS score, and build your remediation roadmap in a single engagement.

Ready to strengthen your security posture?

Talk to Z Cyber's advisory team about building your Cyber Blueprint.

Frequently Asked Questions: CMMC 2.0 Compliance

When do CMMC 2.0 requirements take effect for my contracts?

CMMC requirements began appearing in DoD contracts in November 2025, when the DFARS acquisition rule implementing CMMC took effect. In Phase 1, a CMMC Status of Level 1 (Self) or Level 2 (Self) is a condition of award for applicable solicitations. Under the phased implementation in 32 CFR 170.3, Phase 2 begins one calendar year after Phase 1 starts, in November 2026, and adds Level 2 (C3PAO) certification as a condition of award for applicable solicitations. Your prime contractor may impose earlier flow-down requirements, so check your specific contract language and consult with your contracting officer if uncertain.

What is SPRS and how does my CMMC score relate to it?

SPRS (Supplier Performance Risk System) is the DoD portal where contractors submit their NIST SP 800-171 self-assessment scores. Under the CMMC scoring methodology in 32 CFR 170.24, the maximum score equals the total number of Level 2 security requirements, which is 110. Each requirement scored NOT MET subtracts 5, 3, or 1 point depending on its effect on the network, so the score can go negative. Contracting officers can view your SPRS score when evaluating bids. For Level 2 certification assessments, your C3PAO posts the assessment results on your behalf.

Does CMMC apply to subcontractors?

Yes. CMMC requirements flow down to subcontractors who handle FCI or CUI as part of a covered contract. Prime contractors are required to include CMMC clauses in their subcontracts when CUI will be shared. Subcontractors must meet the same CMMC level required by the prime for the relevant work. This means many small businesses in the defense industrial base are subject to Level 2 requirements even if they have not directly contracted with the DoD.

What happens if my organization does not achieve CMMC compliance?

Without the required CMMC certification or self-assessment on file, your organization will be ineligible to bid on or be awarded DoD contracts that include CMMC requirements. Existing contracts may include cure notice provisions if compliance is not achieved within the required timeframe. For organizations whose revenue is substantially dependent on DoD contracting, non-compliance is a significant business risk, not just a regulatory one.

How is CMMC Level 2 different from CMMC Level 1?

CMMC Level 1 covers the 15 basic safeguarding requirements set out in FAR 52.204-21(b)(1)(i) through (xv) and applies to contractors handling FCI (Federal Contract Information). It requires an annual self-assessment, and under 32 CFR 170.21 no POA&M is permitted at Level 1. CMMC Level 2 covers all 110 requirements in NIST SP 800-171 Rev. 2 and applies to contractors handling CUI. For applicable contracts, Level 2 requires a certification assessment by an authorized or accredited C3PAO every three years, with annual affirmation. The documentation, controls, and verification requirements are substantially more demanding at Level 2.

Frequently Asked Questions

When do CMMC 2.0 requirements take effect for my contracts?

CMMC requirements began appearing in DoD contracts in November 2025, when the DFARS acquisition rule implementing CMMC took effect. In Phase 1, a CMMC Status of Level 1 (Self) or Level 2 (Self) is a condition of award for applicable solicitations. Under the phased implementation in 32 CFR 170.3, Phase 2 begins one calendar year after Phase 1 starts, in November 2026, and adds Level 2 (C3PAO) certification as a condition of award for applicable solicitations. Your prime contractor may impose earlier flow-down requirements, so check your specific contract language and consult with your contracting officer if uncertain.

What is SPRS and how does my CMMC score relate to it?

SPRS (Supplier Performance Risk System) is the DoD portal where contractors submit their NIST SP 800-171 self-assessment scores. Under the CMMC scoring methodology in 32 CFR 170.24, the maximum score equals the total number of Level 2 security requirements, which is 110. Each requirement scored NOT MET subtracts 5, 3, or 1 point depending on its effect on the network, so the score can go negative. Contracting officers can view your SPRS score when evaluating bids. For Level 2 certification assessments, your C3PAO posts the assessment results on your behalf.

Does CMMC apply to subcontractors?

Yes. CMMC requirements flow down to subcontractors who handle FCI or CUI as part of a covered contract. Prime contractors are required to include CMMC clauses in their subcontracts when CUI will be shared. Subcontractors must meet the same CMMC level required by the prime for the relevant work. This means many small businesses in the defense industrial base are subject to Level 2 requirements even if they have not directly contracted with the DoD.

What happens if my organization does not achieve CMMC compliance?

Without the required CMMC certification or self-assessment on file, your organization will be ineligible to bid on or be awarded DoD contracts that include CMMC requirements. Existing contracts may include cure notice provisions if compliance is not achieved within the required timeframe. For organizations whose revenue is substantially dependent on DoD contracting, non-compliance is a significant business risk, not just a regulatory one.

How is CMMC Level 2 different from CMMC Level 1?

CMMC Level 1 covers the 15 basic safeguarding requirements set out in FAR 52.204-21(b)(1)(i) through (xv) and applies to contractors handling FCI (Federal Contract Information). It requires an annual self-assessment, and no POA&M is permitted at Level 1. CMMC Level 2 covers all 110 requirements in NIST SP 800-171 Rev. 2 and applies to contractors handling CUI. For applicable contracts, Level 2 requires a certification assessment by an authorized or accredited C3PAO every three years, with annual affirmation. The documentation, controls, and verification requirements are substantially more demanding at Level 2.

Subscribe for Updates

Get cybersecurity insights delivered to your inbox.