CMMC 2.0, finalized in Title 32 CFR (October 2024) and Title 48 CFR (effective November 10, 2025), mandates cybersecurity certification for all DOD contractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), with phased rollout starting November 10, 2025, for contract awards. Level 1 (self-attestation for FCI) requires 17 NIST SP 800-171 practices; Level 2 (110 practices for CUI) allows limited self-assessment or third-party certification via C3PAOs; Level 3 adds 24 DOD-assessed practices for high-priority programs. Certifications last three years, with Plans of Action and Milestones (POAMs) permitted for up to 22 one-point Level 2 practices.
Evolution from DFARS to CMMC 2.0
Post-9/11, Executive Order 13556 (2010) created the CUI program; DFARS 252.204-7012 (2016) required NIST 800-171 compliance via self-attestation, later enhanced by scored SPRS reporting (DFARS 7019/7020). CMMC 1.0 (2020) introduced third-party assessments across five levels but faced pushback; 2.0 streamlined to three levels, eliminated maturity processes, and reduced third-party scope to ~80,000 CUI-handling contractors.
Key CMMC 2.0 Requirements and Assessment
Level 2 assessments cover 320 objectives across 14 domains (e.g., access control, incident response), scoped by five asset categories: Security Protection Assets (SPAs), Contractor Risk Managed Assets (CRMAs), Specialized Assets, External Service Providers (ESPs), and Out-of-Scope Assets. C3PAOs (83 authorized) issue certificates but prohibit consulting due to conflict rules. Primes often demand Level 2 certification pre-bid.
| Level | Info Type | Assessment | Practices | POAMs Allowed |
| 1 | FCI | Self | 17 | No |
| 2 | CUI | Self/Third-party | 110 | Up to 22 (1-pt) |
| 3 | Critical CUI | Third-party + DOD Delta | 110+24 | Limited |
7-Step Roadmap to Certification
- Determine applicability: Exclude COTS; assess FCI/CUI flow-down.
- Define CUI environment scope using DOD Scoping Guide.
- Conduct gap assessment against NIST 800-171 Rev 2.
- Remediate gaps; build POAMs for allowable practices.
- Select accredited C3PAO; perform mock assessment.
- Pursue certification with officer affirmation.
- Maintain annually; recertify every 3 years.
Next Steps for Compliance
Prepare gap assessments and mock audits now to meet November 2025 contract deadlines; use SPRS for Level 1/2 self-attestations with officer sign-off. Review DOD Scoping Guide for asset categorization to avoid unnecessary implementation.
CMMC 2.0, finalized in Title 32 CFR (October 2024) and Title 48 CFR (effective November 10, 2025), mandates cybersecurity certification for all DOD contractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), with phased rollout starting November 10, 2025, for contract awards. Level 1 (self-attestation for FCI) requires 17 NIST SP 800-171 practices; Level 2 (110 practices for CUI) allows limited self-assessment or third-party certification via C3PAOs; Level 3 adds 24 DOD-assessed practices for high-priority programs. Certifications last three years, with Plans of Action and Milestones (POAMs) permitted for up to 22 one-point Level 2 practices.
Evolution from DFARS to CMMC 2.0
Post-9/11, Executive Order 13556 (2010) created the CUI program; DFARS 252.204-7012 (2016) required NIST 800-171 compliance via self-attestation, later enhanced by scored SPRS reporting (DFARS 7019/7020). CMMC 1.0 (2020) introduced third-party assessments across five levels but faced pushback; 2.0 streamlined to three levels, eliminated maturity processes, and reduced third-party scope to ~80,000 CUI-handling contractors.
Key CMMC 2.0 Requirements and Assessment
Level 2 assessments cover 320 objectives across 14 domains (e.g., access control, incident response), scoped by five asset categories: Security Protection Assets (SPAs), Contractor Risk Managed Assets (CRMAs), Specialized Assets, External Service Providers (ESPs), and Out-of-Scope Assets. C3PAOs (83 authorized) issue certificates but prohibit consulting due to conflict rules. Primes often demand Level 2 certification pre-bid.
| Level | Info Type | Assessment | Practices | POAMs Allowed |
| 1 | FCI | Self | 17 | No |
| 2 | CUI | Self/Third-party | 110 | Up to 22 (1-pt) |
| 3 | Critical CUI | Third-party + DOD Delta | 110+24 | Limited |
7-Step Roadmap to Certification
- Determine applicability: Exclude COTS; assess FCI/CUI flow-down.
- Define CUI environment scope using DOD Scoping Guide.
- Conduct gap assessment against NIST 800-171 Rev 2.
- Remediate gaps; build POAMs for allowable practices.
- Select accredited C3PAO; perform mock assessment.
- Pursue certification with officer affirmation.
- Maintain annually; recertify every 3 years.
Next Steps for Compliance
Prepare gap assessments and mock audits now to meet November 2025 contract deadlines; use SPRS for Level 1/2 self-attestations with officer sign-off. Review DOD Scoping Guide for asset categorization to avoid unnecessary implementation.