CMMC 2.0 Compliance: The Complete Defense Contractor Guide
The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense framework verifying that defense contractors and subcontractors implement adequate cybersecurity controls when handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). CMMC 2.0 is codified at 32 CFR Part 170 (final rule effective December 16, 2024) and enforced through DFARS clause 252.204-7012. Phased rollout in DoD contracts began in 2025 — every new defense contract eventually requires CMMC certification at the level appropriate to the contract's data sensitivity. This guide covers all three certification levels, the 110 NIST SP 800-171 controls, the assessment ecosystem (C3PAO and DIBCAC), required artifacts (SSP and POAM), and operational compliance for defense contractors.
CMMC 2.0 At a Glance
- Level 1 Foundational — FCI handlers — 17 practices — annual self-assessment — 1-year validity
- Level 2 Advanced — CUI handlers — 110 NIST 800-171 r2 controls — C3PAO or self-assessment — 3-year validity
- Level 3 Expert — Highest-priority CUI — 110 + NIST 800-172 enhanced — DIBCAC government assessment — 3-year validity
CMMC Topics
- CMMC Level 1 Foundational: 17 Practices, Self-Assessment Procedure, and FCI Handler Requirements
- CMMC Level 2 Advanced: 110 NIST 800-171 Controls, C3PAO Assessment, and CUI Protection
- CMMC Level 3 Expert: NIST 800-172 Enhanced Controls, DIBCAC Government Assessment, and Highest-Priority CUI
- System Security Plan (SSP) for CMMC: Required Content, Format, and Common Findings
- Plan of Action & Milestones (POAM) for CMMC: Required Format, Acceptable Items, and 180-Day Rule
- C3PAO Assessment Process for CMMC Level 2: Selection, Timeline, and What Assessors Evaluate
- FCI vs CUI: How to Tell the Difference and Why It Determines Your CMMC Level
- DFARS 252.204-7012: Safeguarding CUI, NIST 800-171, Cyber Incident Reporting, and CMMC Alignment
Free check — no signup, no credit card. See your gaps in 3 minutes.
Free: 28-page CMMC Level 1 vs Level 2 Self-Assessment Workbook
17 Level 1 practices with self-rating, 110 NIST 800-171 controls quick-rate, SSP template, POAM template, evidence library structure.
Delivered free to your inbox · No commitment, no sales calls without your permission · Unsubscribe anytime