
The Ultimate Guide to
The Cybersecurity Maturity Model Certification (CMMC): What You Need to Know
What is CMMC compliance?

The Department of War (DoW) knows that security is a foundational aspect of all purchase decisions and should not be sacrificed for cost, schedule, or performance. The Cybersecurity Maturity Model Certification (CMMC) is a framework for verifying that Defense Industrial Base (DIB) contractors have implemented the required cybersecurity practices to protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) on the DIB’s networks.
CMMC is implemented by 32 CFR Part 170 and the 48 CFR rule. CFR Title 32 is the policy regulation that describes the details of the program, levels of CMMC, what requirements are being verified by CMMC, and the roles and responsibilities of the ecosystem. This final 32 CFR rule was published in October of 2024 and officially went into effect on December 16, 2024.
Learn more about the CMMC framework and final rule from our partners at the Hotman Group.
Strengthening the Defense Industrial Base
Successfully navigating the CMMC requires a shift from trust-based self-reporting to a model of verifiable cybersecurity maturity. Because CMMC is now a prerequisite for contract award, understanding how these requirements map to your existing IT infrastructure is the first step toward securing your position within the DoD supply chain.
Who must meet CMMC requirements?
Every organization or business that sells to or services the Department of War (DoW) must meet CMMC requirements if they handle CUI or FCI in the performance of the Dow contract. Â Clauses contracting officers placed in DoD contracts will dictate the level of CMMC certification required.
What are the CMMC levels?
The CMMC program requirements are tiered; requirements are generally defined within contractual agreements for services provided to the DoD and its contractors. The nature of these contractual requirements depends on the relationship of the organization with the DoD (eg., prime, sub-contractor) and whether they process FCI or CUI. The CMMC 2.0 model identifies three maturity levels (ML) of cyber hygiene.
CMMC 2.0 Level 1
This level is intended for DIB companies that handle FCI but not CUI and requires compliance with 17 basic cyber hygiene practices. Contractors handling FCI must perform a CMMC Level 1 self-assessment annually — CMMC does not necessarily apply to all DIB contractors. This is equivalent to meeting the requirements in FAR 52.204-21.
Companies at Level 1 must submit an annual self-assessment in DoW’s Supplier Performance Risk System (SPRS) before they are awarded any CMMC Level 1 contracts or subcontracts. All security requirements within Level 1 must be fully met, so a Plan of Action and Milestones (POA&M), which identifies outstanding weaknesses in the system, cannot be submitted with the Level 1 self-assessment.
CMMC 2.0 Level 2
On July 13, 2026, the DoW suspended the Phase 2 C3PAO certification mandate, originally scheduled for November 10, 2026. All Phase I self-assessment requirements remain in place. Learn more about this decision and how your organization can navigate the CMMC pause.
This level applies to DIB companies that receive CUI and aligns with the requirements under NIST SP 800-171 Revision 2. There are 110 controls for CMMC Level 2 with 320 assessment objectives that need to be satisfied. CMMC Level 2 is triggered by the inclusion of the DFARS 252.204-7012 clause in contracts for products and services provided to the DoW. These will stipulate whether the Level 2 assessment can be self-attested or must be completed by a third-party assessment organization.
Most DoW contractors will require CMMC Third-Party Assessment Organization (C3PAO) assessments every three years with a yearly SPRS update. Level 2 assessments are generally submitted to the Enterprise Mission Assurance Support Service (eMASS) by the assessor. DFARS 252.204-7020 has a scoring methodology used by assessors in which each NIST 800-171 Revision 2 requirement is weighted based on its criticality. A Level 2 assessment by a C3PAO assigns a numerical score between -203 and 110. Organizations must achieve a minimum score (typically 88 or higher) and have an approved POA&M to pass. A failing score below the threshold with unresolved deficiencies means non-compliance. Weaknesses identified during the assessment can be submitted as part of the POA&M. Controls not met in the initial assessment can be addressed with POA&Ms within 180 days and a subsequent close-out assessment to receive certification. However, not all controls are eligible for POA&Ms, so be aware of this when preparing for assessment.
Once CMMC is fully implemented, contractors and subcontractors must have the required level certification (or completed self-assessment for Level 1) prior to contract award.
CMMC 2.0 Level 3
Level 3 companies will require a government-led certification by the Defense Contract Management Agency (DCMA) Defense Industrial Base Assessment Center (DIBCAC). DIBCAC assessments apply to Level 3 but are not always required immediately at contract award. Contractors may receive conditional certification if certain controls are incomplete, but the contractor has an approved POA&M. This level, applicable only to the most sensitive and high-risk DoW projects, includes additional requirements that contractors must meet per NIST 800-172. Only 1% of the DIB is affected at this level. Organizations that were DIBCAC High in the past are strong candidates for a Level 3 requirement.
Using subcontractors and external service providers

DoW prime contractors must ensure that all subcontractors in their supply chain meet or exceed the minimum CMMC certification level specified in the contract before award. This flow-down requirement guarantees that all tiers — from prime contractors to small subcontractors — maintain the appropriate cybersecurity safeguards. In addition, when contractors engage external service providers (ESPs), such as managed service providers (MSPs) or cloud service providers (CSPs), these vendors must also meet the relevant CMMC requirements if they have access to, process, store, or transmit CUI. Specifically, ESPs handling CUI are generally required to achieve at least CMMC Level 2 certification. Moreover, a 2024 memo from the DoD clarifies that CSPs must either maintain compliance with DFARS 252.204-7012 requirements or demonstrate FedRAMP Moderate status. This comprehensive approach to vendor management helps protect the integrity of the DIB and ensures that cybersecurity standards are consistently enforced across all entities involved in the contract.
Misrepresentations in CMMC documentation and implementation
Under the current CMMC framework, accurate documentation and honest representation of your cybersecurity posture are absolutely critical. The DoW enforces compliance through the False Claims Act (FCA) and other legal avenues. Contractors and subcontractors who knowingly misrepresent their cybersecurity practices, provide deficient controls, or fail to monitor and report cyber incidents put U.S. information and systems at risk and may face severe consequences. These can include substantial fines, contract penalties, criminal charges, and the issuance of stop-work orders if an audit reveals non-compliance. While FCA enforcement is a risk, misrepresentations regarding cybersecurity compliance are more commonly pursued under DFARS breach penalties and contract fraud provisions.
All DoW contractors subject to CMMC requirements must submit annual attestations via the SPRS, confirming that their cybersecurity programs fully meet these requirements. Maintaining transparent and accurate records is both a regulatory necessity and a fundamental part of safeguarding the defense industrial base.
Determining your CMMC level
The DoW contract solicitation defines the minimum CMMC level and assessment type required. The solicitation or requiring activity will specify the cybersecurity maturity level you must achieve (and whether it should be a self-assessment or a C3PAO assessment) to bid on and receive the contract. While you may choose to pursue a higher level if it aligns with your strategic goals, you must at least meet the level specified in the solicitation to be eligible for award.
In practical terms:
FCI-only contracts: If your contract covers only Federal Contract Information (FCI), you will likely need to achieve CMMC Level 1 through a self-assessment.
CUI contracts: If your contract involves Controlled Unclassified Information (CUI) under DFARS 252.204-7012, you must meet CMMC Level 2. Depending on the solicitation, this could be either a self-assessment or a third-party C3PAO certification.
High-sensitivity contracts: For contracts that require additional safeguards—typically involving a more critical subset of DoD programs—you will need to achieve CMMC Level 3, which generally entails a government-led DIBCAC assessment.
Meeting the minimum CMMC level indicated in the contract is a prerequisite for award, ensuring that all contractors in the Defense Industrial Base meet uniform cybersecurity standards
What you can do to prepare for CMMC
In preparation for a CMMC assessment, organizations handling Controlled Unclassified Information (CUI) should begin by adopting the security requirements outlined in NIST SP 800-171 Revision 2—the foundation for CMMC Level 2 compliance. Forward-thinking organizations may also review NIST SP 800-171 Revision 3 (currently in draft) to anticipate future changes, ensuring they can map those requirements back to Revision 2 for their assessment.
Keep in mind that while you can estimate your expected CMMC level based on the nature of the information your systems process, the final required level will be specified in your DoW contract solicitation. With that in mind, here are some essential steps to become CMMC-ready:
What are the most critical CMMC control families?
NIST SP 800-171 Revision 2—the primary standard underpinning CMMC assessments—divides its requirements into 14 families of controls (or domains). Although every family plays an important role in protecting sensitive information, many experts and industry best practices emphasize these five as especially critical:
Access Control (AC):
Account management and authentication: Implement strong controls to ensure that only authorized users gain access. This includes managing user accounts effectively and enforcing robust authentication mechanisms.
Least privilege and separation of duties: Limit user permissions to only what is necessary, reducing the risk of unauthorized actions or insider threats.
Audit logging: Collect and preserve detailed logs to support forensic analysis and ensure accountability.
Audit and Accountability (AU):
Event logging and monitoring: Maintain comprehensive logs of system activities to detect anomalies and support investigations.
Accountability measures: Ensure actions on systems are traceable to specific users, which is crucial for both compliance and incident investigations.
Configuration Management (CM):
Baseline configuration and change control: Establish secure configuration baselines for systems and enforce change management procedures to prevent unauthorized modifications.
Vulnerability management: Regularly assess and update system configurations to address emerging vulnerabilities and maintain a hardened environment.
Incident Response (IR):
Incident response planning: Develop and document a robust incident response plan that outlines clear roles, responsibilities, and procedures for managing cybersecurity events.
Training and testing: Conduct regular drills and training sessions to ensure the response team is well-prepared to handle incidents effectively when they occur.
System and Information Integrity (SI):
Malicious code protection: Deploy anti-malware solutions and other defenses to detect, block, and remediate malicious software that targets critical systems.
Continuous monitoring and integrity checks: Use automated tools to monitor system integrity and verify that data changes are properly authorized.
Data recovery and business continuity: Ensure that processes are in place to quickly recover data and maintain operations in the event of a breach or system failure.
Focusing on these five control families can provide a strong foundation for an effective cybersecurity program that addresses the prevention, detection, and response to threats targeting sensitive defense-related information. While all 14 control domains are integral to achieving full compliance, emphasizing these areas helps organizations build a robust defense that aligns with both CMMC requirements and overall cybersecurity best practices.
What is involved in a CMMC assessment?
A CMMC assessment is a comprehensive evaluation of your organization’s cybersecurity posture designed to verify compliance with DoW-mandated standards. The CMMC Assessment Process (CAP) guide, published by the DoW, provides detailed instructions for how these assessments should be conducted. This authoritative guide outlines everything from assessment planning and execution to evidence collection and reporting requirements. Preparing for an assessment is similar to other IT compliance reviews, but has unique aspects tailored to the defense industrial base.
Key steps include:
Common challenges businesses face with CMMC certification

Many organizations embarking on the CMMC certification journey confront a multifaceted set of challenges. One of the foremost issues is the lack of a mature, enterprise-wide information security compliance program. Often, companies lack not only formal CMMC certification but also experience with legacy frameworks — such as NIST SP 800-171 and NIST SP 800-53 — that underpin today’s cybersecurity requirements.
In many cases, businesses struggle with outdated security-centric architectures and insufficient compliance management tools. Without the right technology and dedicated in-house expertise, building and sustaining an effective cybersecurity program becomes a steep uphill battle. This resource gap frequently forces companies to rely on ad hoc measures rather than a systematic approach to security, making it difficult to meet CMMC’s rigorous standards.
Another significant hurdle is the disconnect at the leadership level. Many executives underestimate the complexity of CMMC requirements and the critical importance of robust cybersecurity measures. This lack of understanding often results in insufficient budget allocations and poor strategic planning, leaving compliance gaps unaddressed. The consequences of these oversights range from the loss of DoW contracts and personal or corporate liability to lasting damage to a company’s brand and reputation.
For organizations facing these challenges, partnering with external cybersecurity consultants or managed security service providers (MSSPs) is a practical solution. These experts can help narrow the scope of remediation, prioritize critical controls, and guide companies efficiently through the audit process — saving time, reducing costs, and ultimately fortifying the organization’s cybersecurity posture.
Who are the best firms for CMMC gap analysis and remediation in 2026?
The best firms for CMMC gap analysis and remediation in 2026 are typically specialized cybersecurity consultancies and managed security providers that:
Rather than relying on generic lists, many DIB contractors look for vetted CMMC partners through trusted ecosystems. Hyperproof works with experienced CMMC advisory and remediation firms that help organizations run CMMC gap analyses, prioritize fixes, and get audit-ready efficiently.

Kayne McGladrey
Kayne McGladrey, CISSP is the field CISO for Hyperproof and a senior member of the IEEE. He has over two decades of experience in cybersecurity and has served as a CISO and advisory board member, and focuses on the policy, social, and economic effects of cybersecurity lapses to individuals, companies, and the nation.

Paula Biggs
Paula Biggs is a cybersecurity professional specializing in Governance, Risk, and Compliance (GRC) with experience guiding organizations through regulatory and cybersecurity frameworks. As a Certified CMMC Professional (CCP), Paula provides expert consulting services to help defense contractors and organizations within the Defense Industrial Base successfully prepare for CMMC Level 2 assessments.
Hyperproof for CMMC compliance
Hyperproof can help you get ready for the CMMC in the most streamlined and efficient way:

Hyperproof partners with professional service firms with proven track records and deep expertise in helping organizations get CMMC ready. Our partners help customers design their compliance programs, build them out, and conduct readiness assessments to ensure there are no surprises when the audit occurs. If you need a referral, we’d love to talk.
Ready to see
Hyperproof in action?









