The CMMC Program aligns with the Department’s existing information safeguarding requirements for the defense industrial base. It gives the Department increased assurance that prospective contractors and subcontractors have implemented contractually required cybersecurity standards for nonfederal information systems that will process, store, or transmit FCI or CUI during contract performance.
Tiered Model:
CMMC assesses compliance with cybersecurity standards at progressively advanced levels, depending on the type and sensitivity of the FCI or CUI. The program also outlines protection requirements for information flowed down to subcontractors.
Assessment Requirement:
CMMC assessments allow the Department to verify DIB implementation of foundational cybersecurity standards.
Implementation Through Contracts:
Department contractors and subcontractors entrusted with FCI or CUI must achieve a specific CMMC level as a condition of contract award.
The CMMC model is designed to enforce the protection of FCI and CUI.
FCI
(Federal Contract Information):
Information, not intended for public release, provided by or generated for the Government under a contract to develop or deliver a product or service to the Government (excluding information provided by the Government to the public, such as that on public websites, or simple transactional information such as that necessary to process payments) (FAR 4.1901).
CUI
(Controlled Unclassified Information):
Information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls (32 CFR 2002.4(h)).
The CMMC Program provides assessments at three levels, each incorporating security requirements from existing regulations and guidelines.
LEVEL 1
Basic Safeguarding of FCI
15 requirements · FAR 52.204-21
LEVEL 2
Broad Protection of CUI
110 requirements- NIST SP 800-171 R2.
LEVEL 3
Protection Against APTs
+24 requirements – NIST SP 800-172
Passing a C3PAO assessment isn’t the endpoint. Annual attestations, documentation maintenance, configuration drift, and evidence integrity are ongoing obligations. Certification that can’t be sustained creates its own exposure.
CMC Status
Security Requirements
Assessment Requirements
POA&M Requirements
Affirmation Requirements
LEVEL 1 (self)
15 required by FAR clause 52.204-21
Conducted by Organization Seeking Assessment (OSA) annually; results entered into the Supplier Performance Risk System (SPRS)
Not permitted
After each assessment; entered into SPRS
LEVEL 2 (self)
110 NIST SP 800-171 R2 required by DFARS clause 252.204-7012
Conducted by OSA every 3 years; results entered into SPRS; CMMC Status valid for three years from the CMMC Status Date (32 CFR §170.4)
Permitted per 32 CFR §170.21(a)(2); must close within 180 days; Final CMMC Status valid for three years from the Conditional CMMC Status Date
After each assessment and annually thereafter; assessment lapses if not affirmed; entered into SPRS
LEVEL 2 (C3PAO)
CMC 110 NIST SP 800-171 R2 required by DFARS clause 252.204-7012
Conducted by C3PAO every 3 years; results entered into CMMC Enterprise Mission Assurance Support Service (eMASS); CMMC Status valid for three years from the CMMC Status Date (32 CFR §170.4)
Permitted per 32 CFR §170.21(a)(2); must close within 180 days; Final CMMC Status valid for three years from the Conditional CMMC Status Date
After each assessment and annually thereafter; assessment lapses if not affirmed; entered into SPRS
LEVEL 3 (DIBCAC)
110 NIST SP 800-171 R2 (DFARS 252.204-7012) plus 24 selected from NIST SP 800-172 Feb 2021, as detailed in table 1 to 32 CFR §170.14(c)(4)
Requires prerequisite CMMC Status of Level 2 (C3PAO) for the same CMMC Assessment Scope, for each Level 3 certification assessment; conducted by the Defense Contract Management Agency’s (DCMA) Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) every 3 years; results entered into CMMC eMASS; valid for three years from the CMMC Status Date (32 CFR §170.4)
Permitted per 32 CFR §170.21(a)(3); must close within 180 days; Final CMMC Status valid for three years from the Conditional CMMC Status Date
After each assessment and annually thereafter; assessment will lapse upon failure to annually affirm; Level 2 (C3PAO) affirmation must also continue annually; entered into SPRS
The CMMC Program allows limited use of Plans of Action and Milestones. A POA&M closeout assessment evaluates only the requirements marked NOT MET in the initial assessment, and must be confirmed within 180 days of the Conditional CMMC Status Date, or the conditional status expires.
The first phase of CMMC implementation began November 10, 2025. Requirements roll out using a four-phase plan over three years. The phases add CMMC level requirements incrementally, starting with self-assessments in Phase 1 and ending with full implementation of program requirements in Phase 4, so assessors have time to train and companies have time to prepare.
PHASE 1
Initial Implementation
Begins 10 Nov 2025 Where applicable, solicitations require Level 1 or Level 2 self-assessment.
Phase 2
Level 2 Certification
Begins 10 Nov 2026 Where applicable, solicitations require Level 2 Certification. The Department may opt to delay the Level 2 certification requirement in a contract to an option period.
Phase 3
Level 3 Certification
Begins 10 Nov 2027 Where applicable, solicitations require Level 3 Certification. The Department may opt to delay the Level 3 certification requirement in a contract to an option period.
Phase 4
Full Implementation
Begins 10 Nov 2027 Full program requirements apply across all applicable solicitations and contracts.
The Department may implement CMMC Level 2 (C3PAO) requirements in some Phase 1 procurements, or Level 3 requirements in some Phase 2 procurements, which may limit competitors or drive cost.
Phase 1 requirements are already in effect. Whether you land at Level 1 or Level 2 depends on what you handle: FCI or CUI. Agile IT builds the environment, runs the GRC program, and gets you through assessment either way.