CMMC Compliance for the Defense Industrial Base.
Built, Not Just Advised.

CMMC Isn't One Requirement. It's a Program With Three Moving Parts.

The CMMC Program aligns with the Department’s existing information safeguarding requirements for the defense industrial base. It gives the Department increased assurance that prospective contractors and subcontractors have implemented contractually required cybersecurity standards for nonfederal information systems that will process, store, or transmit FCI or CUI during contract performance.

Tiered Model:

CMMC assesses compliance with cybersecurity standards at progressively advanced levels, depending on the type and sensitivity of the FCI or CUI. The program also outlines protection requirements for information flowed down to subcontractors.

Assessment Requirement:

CMMC assessments allow the Department to verify DIB implementation of foundational cybersecurity standards.

Implementation Through Contracts:

Department contractors and subcontractors entrusted with FCI or CUI must achieve a specific CMMC level as a condition of contract award.

FCI and CUI Aren't the Same Thing. CMMC Treats Them Differently.

The CMMC model is designed to enforce the protection of FCI and CUI.

FCI

(Federal Contract Information):

Information, not intended for public release, provided by or generated for the Government under a contract to develop or deliver a product or service to the Government (excluding information provided by the Government to the public, such as that on public websites, or simple transactional information such as that necessary to process payments) (FAR 4.1901).

CUI

(Controlled Unclassified Information):

Information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls (32 CFR 2002.4(h)).

Not Every Contractor Needs the Same Level of CMMC.

The CMMC Program provides assessments at three levels, each incorporating security requirements from existing regulations and guidelines.

LEVEL 1

Basic Safeguarding of FCI

15 requirements · FAR 52.204-21 

LEVEL 2

Broad Protection of CUI 

110 requirements- NIST SP 800-171 R2.

LEVEL 3

Protection Against APTs

+24 requirements – NIST SP 800-172

The Full Breakdown, Status by Status

Passing a C3PAO assessment isn’t the endpoint. Annual attestations, documentation maintenance, configuration drift, and evidence integrity are ongoing obligations. Certification that can’t be sustained creates its own exposure.

CMC Status

Security Requirements

Assessment Requirements

POA&M Requirements

Affirmation Requirements

LEVEL 1 (self)

15 required by FAR clause 52.204-21

Conducted by Organization Seeking Assessment (OSA) annually; results entered into the Supplier Performance Risk System (SPRS) 

Not permitted

After each assessment; entered into SPRS

LEVEL 2 (self)

110 NIST SP 800-171 R2 required by DFARS clause 252.204-7012 

Conducted by OSA every 3 years; results entered into SPRS; CMMC Status valid for three years from the CMMC Status Date (32 CFR §170.4) 

Permitted per 32 CFR §170.21(a)(2); must close within 180 days; Final CMMC Status valid for three years from the Conditional CMMC Status Date 

After each assessment and annually thereafter; assessment lapses if not affirmed; entered into SPRS 

LEVEL 2 (C3PAO)

CMC 110 NIST SP 800-171 R2 required by DFARS clause 252.204-7012 

Conducted by C3PAO every 3 years; results entered into CMMC Enterprise Mission Assurance Support Service (eMASS); CMMC Status valid for three years from the CMMC Status Date (32 CFR §170.4) 

Permitted per 32 CFR §170.21(a)(2); must close within 180 days; Final CMMC Status valid for three years from the Conditional CMMC Status Date 

 After each assessment and annually thereafter; assessment lapses if not affirmed; entered into SPRS 

LEVEL 3 (DIBCAC)

110 NIST SP 800-171 R2 (DFARS 252.204-7012) plus 24 selected from NIST SP 800-172 Feb 2021, as detailed in table 1 to 32 CFR §170.14(c)(4) 

 Requires prerequisite CMMC Status of Level 2 (C3PAO) for the same CMMC Assessment Scope, for each Level 3 certification assessment; conducted by the Defense Contract Management Agency’s (DCMA) Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) every 3 years; results entered into CMMC eMASS; valid for three years from the CMMC Status Date (32 CFR §170.4) 

Permitted per 32 CFR §170.21(a)(3); must close within 180 days; Final CMMC Status valid for three years from the Conditional CMMC Status Date 

After each assessment and annually thereafter; assessment will lapse upon failure to annually affirm; Level 2 (C3PAO) affirmation must also continue annually; entered into SPRS 

POA&Ms Give You a Path Forward. They Don't Give You Forever.

The CMMC Program allows limited use of Plans of Action and Milestones. A POA&M closeout assessment evaluates only the requirements marked NOT MET in the initial assessment, and must be confirmed within 180 days of the Conditional CMMC Status Date, or the conditional status expires.

CMMC Doesn't Arrive All at Once. Here's the Sequence.

The first phase of CMMC implementation began November 10, 2025. Requirements roll out using a four-phase plan over three years. The phases add CMMC level requirements incrementally, starting with self-assessments in Phase 1 and ending with full implementation of program requirements in Phase 4, so assessors have time to train and companies have time to prepare.

PHASE 1

Initial Implementation 

Begins 10 Nov 2025 Where applicable, solicitations require Level 1 or Level 2 self-assessment.

Phase 2

Level 2 Certification 

Begins 10 Nov 2026 Where applicable, solicitations require Level 2 Certification. The Department may opt to delay the Level 2 certification requirement in a contract to an option period.

Phase 3

Level 3 Certification 

Begins 10 Nov 2027 Where applicable, solicitations require Level 3 Certification. The Department may opt to delay the Level 3 certification requirement in a contract to an option period.

Phase 4

Full Implementation

Begins 10 Nov 2027 Full program requirements apply across all applicable solicitations and contracts.

The Department may implement CMMC Level 2 (C3PAO) requirements in some Phase 1 procurements, or Level 3 requirements in some Phase 2 procurements, which may limit competitors or drive cost.

You Know CMMC Is Coming.
Now You Know Which Level Applies to You.

Phase 1 requirements are already in effect. Whether you land at Level 1 or Level 2 depends on what you handle: FCI or CUI. Agile IT builds the environment, runs the GRC program, and gets you through assessment either way.