[email protected]
CMMC

CMMC 2.0: What Defense Contractors Must Know

September 25, 20267 min read

What CMMC Is

CMMC (Cybersecurity Maturity Model Certification) is the U.S. Department of Defense's cybersecurity verification program for the defense industrial base. Under CMMC 2.0 — now in effect following the final rule — contractors that handle Controlled Unclassified Information (CUI) must demonstrate a defined level of cybersecurity maturity to compete for DFARS-covered contracts. The program is organized into three levels of increasing rigor. Non-compliance is not a paperwork issue: it means loss of contract eligibility.

Who Must Comply

CMMC applies to any prime contractor or sub-contractor that handles, processes, or stores CUI. This includes aerospace and defense manufacturers, IT and managed service providers, engineering firms, staffing companies with facility or system access, and technology companies with DoD relationships. The trigger is contractual: if your contract contains DFARS clause 252.204-7012, CMMC applies to you. Flow-down obligations mean sub-contractors are not exempt simply because they do not contract directly with the government.

The Three Levels — What Each Requires

  • Level 1 (Foundational): 17 basic cyber hygiene practices drawn from FAR 52.204-21, verified by annual self-assessment. This is a low bar focused on basic access control, identification and authentication, and media protection.
  • Level 2 (Advanced): 110 practices aligned with NIST SP 800-171. For contracts involving CUI, a third-party assessment by an accredited C3PAO (Certified Third-Party Assessment Organization) is required. This is where most DoD prime and sub-contractors land.
  • Level 3 (Expert): Advanced practices drawn from NIST SP 800-172, verified by a government-led assessment conducted by DCSA. This level is required for the most sensitive CUI programs.

Assessment Timelines and Costs

C3PAO assessments are neither free nor quick. Organizations should budget 6 to 18 months of preparation before a Level 2 assessment, depending on current cybersecurity posture. Preparation is where the real cost sits: policy development, System Security Plan documentation, technical remediation, and evidence collection. Factor remediation costs into your program budget — closing gaps against 110 practices routinely requires investment in tooling, logging, and access management.

ISO 27001 Overlap

Organizations with a mature ISO 27001 implementation already have substantial CMMC Level 2 coverage, because both frameworks address information security controls. The most efficient starting point is a gap assessment that maps your ISO 27001 posture — specifically your Statement of Applicability — against the 110 practices in NIST SP 800-171. For a deeper comparison, see CMMC Level 2 vs ISO 27001.

Need help with CMMC gap assessment or implementation? Exceleor provides consulting, gap assessments, and implementation support. Learn more at exceleor.com/cmmc →

Need an EHS Audit?

Veteran-led, certified lead auditors covering ISO 14001, ISO 45001, RC14001, CFATS and more. Get a tailored proposal within 24 hours.

Request Your Assessment

Free EHS Compliance Checklist

Download our 50-point EHS Audit Readiness Checklist — the same framework our auditors use.

Download Free Checklist

Fortify Your Compliance Today

Don't wait for an audit finding to reveal your gaps. Partner with the Southeast's most comprehensive EHS and security audit team.