Y’all, I have spent TIME wrapping my head around CMMC and let me tell ya – it is a LOT. I’m not an expert by any means (if that’s what you’re looking for, go talk to my man Mike Shughrue), but I’ve been able to learn a bit and thought it might be helpful to have some consolidated info. Are you new to Agile IT? Are you new to CMMC? Are you just trying to remember how to find the results of the DoD’s audit of ISOO? I GOTCHU. Sit down, buckle up, and get ready to get PUMPED on CMMC.

Let’s start with what it is, right?
That seems like a good place to start. CMMC is the Cybersecurity Maturity Model Certification. Katie Arrington calls it The CMMC. The rest of us just call it CMMC. CMMC has a pretty bitchin mission statement:
- Safeguard sensitive information to enable and protect the warfighter
- Enforce DIB cybersecurity standards to meet evolving threats
- Ensure accountability while minimizing barriers to compliance with DoD requirements
- Perpetuate a collaborative culture of cybersecurity and cyber resilience
- Maintain public trust through high professional and ethical standards
(Heads up we love an acronym around here. I’ll stick a reference down at the bottom. For now, know that DIB = Defense Industrial Base)
Now we do timeline! This baby has been 15 years in the making.
2010, November: Once upon a time, President Obama was like “I’m sick of all these different markings for our information. FOUO? How about GTFO? We’re standardizing and calling all controlled unclassified information exactly that. We can shorten it to CUI. People will love this.” Executive Order 13556 — Controlled Unclassified Information | whitehouse.gov
2015, June: NIST says something like “ok we’ve had the CUI marker for a while now. But how do we protect it? Where are the standards?” It was a good question, and luckily, NIST is the institute that can help with stuff like that. They release NIST SP 800-171: “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations”. Note that this is specific to Industry, since our Fed homies are already aligned to NIST 800-53. NIST SP 800-171 is a derivative of that publication, comprised of 110 security requirements. We’ll get into version history, assessment objectives, and class deviations a bit later. SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations | CSRC
2016, October: The DoD takes things into their own hands. No one is enforcing the protection of CUI, and national security is at stake. We MUST ask the defense supply chain to shore up cybersecurity. DFARS clause 252.204-7012 goes into the FAR. This clause starts hitting contracts the DoD is sending out, and says “We’re giving you CUI. You’re creating CUI. You had better be protecting that CUI by implementing the 110 security requirements in NIST SP 800-171. You have until December 31st, 2017 to be 100% in compliance. P.S. if you have a cyber incident, you have to tell us within 72 hours AND you have to flow down this requirement to any of your subcontractors that are going to be storing, processing, or transmitting CUI”. 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting. | Acquisition.GOV
2017 – 2019: DIB contractors did not do the thing that they very explicitly said they were doing.
2019, July: The DoD’s Office of Inspector General releases a report after an audit of DIB adherence to NIST 800-171. Their findings? It ain’t happening. Turns out self-attestation isn’t a great way to get organizations into compliance. The results are pretty damning, and pretty frustrating for folks that care about safeguarding our national interests. Audit of Protection of DoD Controlled Unclassified Information on Contractor-Owned Networks and Systems DODIG-2019-105 > Department of Defense > DoD OIG Reports
2020, January: CMMC 1.0 is released. It’s not being enforced, but the model now exists and this is cool. Again, only going to be applicable to DIB, but it is a START at keeping our stuff safe from foreign adversaries. There are five levels, it’s not super well defined, it’s definitely too complex, but again – it’s a start. This is v cool. Things are supposed to go rapidly and we think we’re going to see CMMC requirements in contracts by like, the end of 2020.
2020, March: you remember. This kind of derails… gestures broadly at everything
2020, June: Pilot program begins. Gradual implementation, DoD is ready and willing to work with Industry to make this happen.
2021, March: Industry feedback comes in. “This is expensive. This is complex. This is time consuming.” DoD graciously takes this into consideration (and I do legit mean graciously, since contractors are currently complaining about something that they have said they were doing for three entire years now).
2021, November: CMMC 2.0 is here! Kinda. Like the program gets unveiled (now with three levels and much more clarity) but it’s still not in the federal register. DoD and Industry collab on program implementation, develop a phased roll out, all the good stuff that’s needed to turn this into a working model for us all.
2024, December: OK NOW IT’S REALLY ACTUALLY HERE. Kinda. CFR Title 32 part 170 goes into effect, firmly establishing the CMMC program. It’s official, it’s real, it’s in the federal register. This is VERY exciting. Much hubbub ensues. There is now a real, defined framework and program for ensuring Industry compliance with NIST 800-171. BUT WAIT. There are two rules in play, and 32 is only one of them. It establishes the program, it does not incorporate CMMC into contracts. Federal Register :: Cybersecurity Maturity Model Certification (CMMC) Program
2025, November: OK THIS TIME I MEAN IT, IT IS HERE LFG. CFR Title 48 parts 204, 212, 217, and 252 enter the federal register on the Marine Corps’ 250th birthday. This is it, this is the Final Rule that means CMMC is beginning its phased roll out and there ain’t no turnin back now. This rule amends the DFARS to incorporate contractual requirements for DoD contractors. So what Industry sees in their contracts is DFARS clause 252.204-7021. What makes that possible is the publication of Title 48 in the federal register. 252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements. | Acquisition.GOV and Federal Register :: Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)
July 13, 2026: lol jk, self-assessment is fine again. Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements > U.S. Department of War > Release | U.S. Department of War
Reference Docs
I spend a lot of time going back to what other folks have written. I’ve got these all bookmarked, but to save you the trouble, I thought I’d go ahead and make ya a little URL library for what I’ve got saved and why.
Part One: Source Documentation
This is stuff that’s been put out by Fed or the CyberAB (performing a no-cost contract with the DoD to oversee the CMMC program). When it comes down to “truth”, this is where we go. Everything else comes from experience, opinion, and speculation. FWIW, the only CyberAB doc is the CAP. Everything else (including scoping and assessment guides) comes straight from DoD.
Rules, regulations, and publications
- Why this matters: It’s literally THE rule.
- Like 48 matters too (bc that’s where it says “you gotta put this in contracts”), but 32 gives the nitty gritty on how the program is meant to work, who the players are in the program, and what it takes to pass assessment. We also refer to “32 CFR” a lot, but the thing we actually care about is “32 CFR part 170”. We don’t need to refer to part 170 every time we discuss, but it’s important that we keep it in the back of our heads.
- You want the definitions for CUI, CUI Specified, and CUI Basic? This is where you go. This is the actual establishment of the Executive CUI program.
- Why this matters: This baby puts the whole dang thing into effect. Contractors don’t care about 48 CFR, they care about the fact that 48 CFR put DFARS 7021 into place.
- DFARS 7012: 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting. | Acquisition.GOV
- Why this matters: Contractors already see this in their contracts with DoD and Primes. You know the False Claims Act? It comes up when Industry does NOT meet the security requirements in NIST 800-171. Again, Industry has been told to be compliant with NIST 800-171 since DECEMBER 31st of FREAKING 2017. Yeah, if you get slapped with a False Claims Act, it sucks, but it shouldn’t be unexpected.
- Why this matters: Ta-da! CMMC requirements are IN contracts, and you must meet compliance at the time of contract award.
Scoping and assessment
- CMMC Scoping Guide for Level 2: CMMC Scoping Guide Level 2
- Why this matters: When you’re establishing boundaries, this is your bible. You want to keep your CMMC scope as small as possible, and this doc will help you do that.
- CMMC Assessment Guide for Level 2: CMMC Assessment Guide Level 2
- Why this matters: As you prep for either self-assessment or assessment by a C3PAO, you want to be damn sure that you’ve crossed your Ts and dotted your Is. This is THE thing that will help. Heads up that there are scoping guides and assessment guides for Levels 1 and 3 as well, but since we deal mostly with folks looking to get Level 2, that’s what I’m sticking in here.
- CMMC Assessment Process (CAP): CMMC Assessment Process v2.0.pdf
- Why this matters: This is a huge piece of what CCPs and CCAs get grilled on when taking their tests. This is what your clients want to know as they get ready to go into Assessment.
Memos and class deviations
- Determining CMMC level: Implementing the Cybersecurity Maturity Model Certification Program: Guidance for Determining Appropriate CMMC Compliance Assessment Levels and Process for Waiving CMMC Assessment Requirements
- Listen, it’s ok to not just accept markings or determinations. It’s ok to ask questions. You can save yourself and your subcontractors a lot of headaches if you make sure that what you’re getting is appropriately marked.
- ODPs for Rev 3: Department of Defense Organization-Defined Parameters for National Institute of Standards and Technology Special Publication 800-171 Revision 3
- We’re not on NIST SP 800-171 rev 3 yet (we’re still working off of rev 2). BUT it’s def coming, probably in the next year and a half or so. Preparing now just makes sense. An ODP is an Organizationally Defined Parameter, and in our case, the “organization” is DoD. They get to say (for example) what kind of audit logs we need to keep. This memo highlights alla that.
- Sticking with NIST 800-171 R2: MEMORANDUM FOR
- Speaking of R2, there was confusion there for a while if we should be on R2 or R3. This class deviation clears it up for us.
Additional resources
- NARA CUI Registry: CUI Registry | National Archives
- Yeah, DoD has their own registry. But NARA’s is the official, real, legit, one. The Organizational Index Groupings that we pay attention to are Defense and Export Control.
- When DoD puts out a list of FAQs, mind their answers.
- PPT from DoD on technical application: Topics For CIO Summit: External Service Providers (ESPs), Asset Categories, SPA/SPD, and VDI
- This is helpful if (when) you want to get deep into asset types and applicability for security requirements. It’s also got some info on VDI that’s gonna be nice to have on hand.
- Obama’s EO said “make me a CUI program”. 32 CFR 2002 said “cool, here’s your CUI program”. DoDI 5200.48 said “nice, here’s instruction for DoD on how to adopt the CUI program”.
Part Deux: Reference Material
So like YES always go back to our source material, BUT there are a whole lot of really smart people out there (Amira Armond is a personal hero of mine, for example). Below are some of my go-tos.
- This blog from Richard Wakeman: Understanding Compliance Between Commercial, Government, DoD & Secret Offerings – July 2025 Update | Microsoft Community Hub
- It’s an intense read, but it is the best thing I’ve found to talk customers through “do I need GCC or GCC High”.
- Reference architectures for DIB: Microsoft-Reference-Identity-Architectures-ND-ISAC-MSCloud-Whitepaper.pdf
- Comes complete with pretty pictures so we don’t have to start from scratch!
- Speaking of reference architectures: KRA-Datasheet.pdf
- Have I mentioned my love for Amira Armond? I stand by it. She is a brilliant OG and everyone should listen to her. The KRA is WILDLY helpful in that it’s designed around GCC High. Use this for scoping.
- Technical reference guide from Microsoft: Download Microsoft Technical Reference Guide for CMMC 2.0 from Official Microsoft Download Center
- It’s a doozy, but where NIST 800-171 says “achieve this”, this doc says “and here’s how”.
Part Trois: Catch-Alls
Helpful catch-alls. Like bookmark these and know these and love these.
- CMMC Wiki: CMMC Toolkit Wiki
- Has everything. I mean EVERYTHING. I mostly use this for CCP exam practice.
- DoD CUI Program: DoD CUI Program
OKKKKKKKKKKKKKKKKKKKKKKKK I am le tired and legit, you need to go read this source documentation. Let’s consider this a work in progress?
Notes to self on stuff I still wanna tell you about: NARA and ISOO. CyberAB and CAICO. CMMC L1 vs L2. Ethics for the ecosystem. Tailoring for 171 from 53. Hashing guidance for assessment evidence. Specialized assets.
THERE’S SO DANG MUCH but again…

