CMMCpedia Download

Chapter 01

What is CMMC

Practitioner Guidance

CMMC is a verification program. It adds no new security rules. It checks whether you have implemented the requirements your Department of Defense contracts already carry. It makes the result a condition of award.

What CMMC is

The Cybersecurity Maturity Model Certification is a Department of Defense (DoD) program. It verifies that a contractor has implemented the safeguarding requirements for Federal Contract Information and Controlled Unclassified Information. Federal Contract Information (FCI) is information the government provides, or you generate for the government, under a contract, and that is not intended for public release. Controlled Unclassified Information (CUI) is information the government creates, or you create for it, that a law, regulation, or government-wide policy requires or permits an agency to protect. The program rule is 32 CFR part 170. The contract clause that applies it to you is DFARS 252.204-7021. DFARS is the Defense Federal Acquisition Regulation Supplement, the set of contract clauses DoD adds to its contracts. When that clause is in your contract, you must hold a current CMMC status at the level the contracting officer names before award. You must keep that status for the life of the contract. You must also flow the correct level down to every subcontractor that will handle FCI or CUI.

The requirements themselves are older than the program. Level 1 uses the fifteen safeguards in FAR 52.204-21, a clause from the Federal Acquisition Regulation, the rulebook for all federal contracts. Level 2 uses the 110 security requirements in NIST SP 800-171 Revision 2, the government publication that lists the security requirements for protecting CUI. DFARS 252.204-7012 has required contractors to implement NIST SP 800-171, in whichever revision was current, since the end of 2017. CMMC adds a verification step. The program rule describes CMMC as a way of verifying that requirements which already apply have been implemented.

Why it exists

For years the only check on a contractor's implementation of NIST SP 800-171 was the contractor's own word. A company signed a contract carrying DFARS 252.204-7012 and agreed to implement the requirements. Nobody verified that it had. CMMC exists because the Department decided that a self-reported claim was not enough protection for the information it shares with its suppliers. Under the program, DoD verifies your implementation before it awards the contract. For contracts that handle the more sensitive information, it requires a third party to do the verifying.

How it relates to DFARS 252.204-7012

CMMC does not replace DFARS 252.204-7012, and it does not change it. The program rule states that CMMC does not alter any separately applicable requirement to protect FCI or CUI, and it names 252.204-7012 directly. That clause still requires you to implement NIST SP 800-171 and to report a cyber incident to DoD within 72 hours of discovering it. Its other obligations around cloud services and incident evidence still stand. DFARS 252.204-7019 and 252.204-7020 still require a NIST SP 800-171 DoD Assessment score in the Supplier Performance Risk System (SPRS), the DoD database that holds assessment results.

Read the two clauses as a pair. 252.204-7012 requires you to protect the information. 252.204-7021 requires you to prove that you have.

The phased rollout

The program rule brings CMMC into contracts over four phases. Each phase starts one year after the last, counted from the effective date of the acquisition rule that created the 252.204-7021 clause. Two abbreviations appear in the phase names. A C3PAO is a CMMC Third-Party Assessment Organization, a private company authorized to perform certification assessments. DIBCAC is the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center, the government's own assessment team.

  • Phase 1: DoD includes Level 1 (Self) or Level 2 (Self) as a condition of award in applicable solicitations, and may require Level 2 (C3PAO) at its discretion.
  • Phase 2: DoD includes Level 2 (C3PAO) as a condition of award in applicable solicitations, and may require Level 3 (DIBCAC).
  • Phase 3: Level 2 (C3PAO) applies to all applicable solicitations and to option periods on contracts awarded after the effective date. Level 3 (DIBCAC) becomes a condition of award where it applies.
  • Phase 4: full implementation, including option periods on contracts awarded before Phase 4 began.

That schedule is suspended. On July 13, 2026 the Department suspended the transition to Phase 2 and opened a review of the program. The suspension also covers pending and future CMMC implementation milestones in its solicitations and contracts. Phase 1 self-assessment requirements remain in place. DFARS 252.204-7012 still binds every contractor that handles covered defense information, the clause's term for the CUI a defense contract covers. The phases above remain the rule text, because 32 CFR part 170 has not changed. The program status page tracks the suspension and what the Department does next.

During the rollout the program manager or requiring activity decides which solicitations carry the clause. Do not read that discretion as a reason to wait. The rule allows a waiver only in advance of a solicitation. Once the requirement appears in a solicitation, there is no process to remove it. There is also not enough time left to earn the status it requires.

The three levels

Level 1 applies when you handle FCI and no CUI. Level 1 is the fifteen safeguards in FAR 52.204-21, assessed against the NIST SP 800-171A objectives that map to them. NIST SP 800-171A is the assessment companion to NIST SP 800-171. It breaks each requirement into the objectives an assessor checks. You assess yourself every year, enter the result in SPRS, and a senior person in your company affirms it. Every safeguard must be met. No plan of action is permitted at Level 1.

Level 2 applies when you handle CUI. It is the 110 requirements of NIST SP 800-171 Revision 2, exactly as written. The contract decides which kind of assessment you need. Level 2 (Self) is a self-assessment you enter in SPRS. Level 2 (C3PAO) is a certification assessment performed by an authorized third-party assessment organization, which uploads the result to DoD. Either way, the status lasts three years, and you affirm continuing compliance every year in between. If you are a subcontractor that will handle CUI and the prime contract requires Level 2 (C3PAO), then Level 2 (C3PAO) is your minimum too. This reference covers Level 2.

Level 3 adds selected requirements from NIST SP 800-172, a companion catalog of enhanced security requirements, on top of a Final Level 2 (C3PAO) status. DIBCAC performs the assessment. Level 3 is reserved for the Department's most critical programs and is beyond this reference.

Nobody can waive it for you

A contracting officer cannot waive CMMC for you, and neither can your prime. The rule reserves the waiver decision to a Service or Component Acquisition Executive, in very limited circumstances. A waiver applies to the solicitation as a whole, before it is issued. Even then the rule states that contractors remain obligated to comply with every applicable cybersecurity requirement. A waiver removes the verification. You still have to do the work.

Your prime is also bound the other way. Under 252.204-7021 the prime must confirm that you hold a current CMMC status at the correct level before it awards you the subcontract. A prime that tells you the requirement does not apply to you is either wrong or has already decided you will not be handling FCI or CUI. Get that decision in writing.

How the requirements are assessed

The requirements are assessed with NIST SP 800-171A, which breaks the 110 requirements into 320 assessment objectives. A requirement is scored MET only when every applicable objective is satisfied on evidence that is in final form. If one objective is not satisfied, the whole requirement is NOT MET. Drafts, working papers, and unapproved policies do not count as evidence. Two situations still score as MET. The first is an enduring exception that you describe, along with its mitigations, in your system security plan (SSP), the document that describes how your system meets each requirement. The second is a temporary deficiency that you track in an operational plan of action with progress toward the fix.

Only the requirement statement and its assessment objectives can fail you. The discussion text in NIST SP 800-171 and the further discussion in the CMMC Assessment Guide are explanatory. They exist to help you understand a requirement, not to extend it, and an assessor cannot base a finding on them. Every requirement page on this site quotes the requirement and its objectives verbatim, so you can see exactly what you are being measured against. AT.L2-3.2.1 is a good first example.

Scoring starts at 110 and subtracts one, three, or five points for each requirement NOT MET. Partial credit is available for two requirements, multifactor authentication and CUI encryption. A Plan of Action and Milestones (POA&M) is a tracked list of open items with deadlines. The rule allows one only in narrow circumstances. You may hold a Conditional Level 2 status with open items only if your score is at least 88 and every requirement on the plan is worth one point. The single exception is CUI encryption, SC.L2-3.13.11. It may sit on the plan at three points when you encrypt but the encryption is not FIPS validated, meaning the cryptographic module does not hold a government validation certificate. Six requirements can never be on the plan: AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, and PE.L2-3.10.5. You then have 180 days to close the plan and pass a closeout assessment, or the status expires. A POA&M does not make a requirement MET. It stays NOT MET until you fix it.

What to do first

Read the contract before you do anything else. Find DFARS 252.204-7012, 7019, 7020, and 7021 in it, or in the flow-down from your prime, and note the CMMC level named in 7021. That level tells you how many requirements you have to implement. No vendor or consultant can tell you what it is without reading the same clause.

Then work through the next three chapters in order. Chapter 2, CUI or FCI, tells you how to work out which kind of information you actually hold. Chapter 3, Which level applies, turns that answer into the level your contract will require. Chapter 4, Drawing your boundary, shows you how to limit where that information lives so the rest of the work stays small. Do not buy anything until you have finished chapter 4.

Next chapter 02 CUI or FCI

Chapter 02

CUI or FCI

Practitioner Guidance

One determination drives what CMMC costs you. Do you handle Controlled Unclassified Information (CUI), or only Federal Contract Information (FCI)? Make that determination deliberately, in writing, before you buy anything or scope anything. Every later chapter builds on the answer.

Why this decision comes first

If you handle FCI and no CUI, you are at Level 1. Level 1 is the fifteen safeguards of FAR 52.204-21, the basic safeguarding clause of the Federal Acquisition Regulation, and you self-assess every year. If you handle any CUI, you are at Level 2. Level 2 is the 110 requirements of NIST SP 800-171 Revision 2, the government publication that lists the security requirements for protecting CUI. Your contract sets which kind of assessment you need. There is no partial position between them. A single flow of CUI into your environment moves you from fifteen requirements to 110.

Getting it wrong is expensive either way. Decide you have CUI when you do not, and you fund a Level 2 program that no contract requires of you. Decide you have only FCI when CUI has already arrived, and three things follow. You are storing CUI on a system that was never scoped to protect it. You are in breach of the safeguarding obligation in DFARS 252.204-7012, the Department of Defense (DoD) contract clause that requires you to safeguard covered defense information. And you will be ineligible when a solicitation names Level 2. The determination also sets your boundary, because the systems that touch the information are the systems that get assessed. Chapter 4, Drawing your boundary, depends on you knowing which information you are drawing the boundary around.

What FCI is

FAR 4.1901 and FAR 52.204-21 define Federal Contract Information. It is information, not intended for public release, that is provided by or generated for the government under a contract to develop or deliver a product or service to the government. The definition excludes information the government has released to the public. It also excludes simple transactional information, such as what you need to process payments.

Read that definition broadly. If you hold a contract to deliver anything to the government, you hold FCI. The government provides or asks you to generate all of it under the contract. That covers the statement of work, the specifications, the delivery schedule, and the emails from the contracting officer about performance. None of it is public. A contractor that says it has no FCI is saying it sells the government nothing but off-the-shelf commercial items. This chapter does not ask whether you have FCI. It asks whether any of what you hold is also CUI.

What CUI is

32 CFR 2002.4 defines Controlled Unclassified Information as information the government creates or possesses, or that an entity creates or possesses for or on behalf of the government. To be CUI, a law, regulation, or government-wide policy must also require or permit an agency to handle it using safeguarding or dissemination controls.

That definition has two conditions, and information must meet both.

  1. A government nexus. The government created the information, or you created it for or on behalf of the government. Information you developed at your own expense, outside any government contract, does not become CUI no matter how sensitive it is.
  2. A specific authority. A law, regulation, or government-wide policy must require or permit controls on it. Sensitivity alone is not enough. If no authority covers the information, it is not CUI.

The authorities are cataloged in the CUI Registry, which the regulation establishes as the repository for every approved CUI category. The National Archives maintains the government-wide registry. DoD maintains its own registry at dodcui.mil covering the categories DoD uses. For a defense contractor two categories matter most. Controlled Technical Information covers technical data and software with military or space application. Export Controlled covers information whose export is restricted by regimes such as the International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR). If a category in the registry does not describe your information, and the government did not designate it, it is FCI and not CUI.

The regulation also splits CUI into two kinds. CUI Basic is the default, protected under the uniform handling rules of 32 CFR 2002. CUI Specified applies where the underlying law or regulation imposes its own specific handling controls. The distinction changes handling details, not your CMMC level. Either kind is CUI, and either kind puts you at Level 2.

How CUI arrives

CUI enters a contractor's environment by three routes. Check all three, because the second and third produce CUI that nobody stamped.

Marked deliverables. The government sends you documents carrying a CUI banner and designation indicator, or technical documents carrying a distribution statement. The DoD CUI Registry requires Distribution Statement B through F as the dissemination control on Controlled Technical Information. A distribution statement does not itself make a document CUI, because those statements go on technical documents whether or not the content is controlled. Treat a statement as a signal to check the document against the contract and the registry. Put the question to the contracting officer in writing when the check is unclear. This route is the easiest to spot. Contractors also rely on it too heavily, because they assume that no markings means no CUI.

The contract itself. DFARS 252.204-7012 defines covered defense information. It is controlled technical information or other CUI Registry information that is marked or otherwise identified in the contract and provided to you by or on behalf of DoD. "Otherwise identified in the contract" means the identification can live in the statement of work, a contract data requirements list, or an attachment. The identification can exist even though no document you receive carries a stamp. Read the whole contract, not just the clause list.

Information you generate. The same clause's definition has a second half. It covers information you collect, develop, receive, transmit, use, or store in support of contract performance. All of it becomes Controlled Technical Information the moment you create it. That includes drawings you produce against a military specification, test data from an article the government will field, and source code written to a DoD requirement. That holds whether or not anyone has marked it yet. Machine shops and engineering firms miss this route most often. They receive nothing marked and still produce CUI every working day.

When markings are missing or wrong

The government is responsible for telling you what is CUI. Under DFARS 252.204-7012, covered defense information the government provides must be marked or otherwise identified in the contract. Sometimes the contract carries the clause but identifies nothing. Sometimes you receive unmarked documents that match a registry category, or a marking looks wrong. Do not guess. Ask the contracting officer, in writing, to identify the CUI associated with the contract, and keep the answer. That written answer is what scopes your boundary. It is what you show an assessor when the question of what you hold comes up.

If you are a subcontractor, the same question goes up the chain to your prime, in writing. A prime that will not answer is failing its own flow-down obligations. If the prime does not answer, take the question higher. The DoD CUI program site publishes component points of contact for CUI questions, and your prime's contracting officer exists even when your prime is unresponsive. Do not accept "treat everything as CUI" as an answer either. That answer is a scoping decision made by someone who does not pay for it, and it makes your boundary and your cost larger than they need to be.

Legacy markings need a separate rule. For Official Use Only (FOUO) stopped being a valid DoD marking when DoDI 5200.48, the DoD instruction that sets its CUI policy, was signed. DoD states that legacy FOUO material is not automatically CUI. Old FOUO documents must be assessed against the CUI Registry like anything else. Treat a FOUO stamp as a signal to go check, not as a designation.

Never remove or overrule a CUI marking on your own judgement. If you believe something is overmarked, challenge it through the contracting officer. Until the designating agency answers, handle the information as marked.

The mistakes that cost the most

ITAR data is not automatically CUI. ITAR controls who may export the data. CUI status still requires the government nexus in 32 CFR 2002.4. Technical data you developed entirely at private expense, outside any government contract, is subject to ITAR and is still not CUI. The government neither created it nor had you create it on its behalf. The opposite case is just as important. ITAR technical data provided or generated under a DoD contract is CUI in the Export Controlled category, and holding it puts you at Level 2. Sort ITAR data by its contract nexus, not by its export status. ITAR data that falls outside the CUI definition is still subject to ITAR. ITAR carries its own obligations under 22 CFR parts 120 through 130 regardless of CMMC.

A 7012 clause does not mean you hold CUI. DFARS 204.7304 directs the clause into all solicitations and contracts except those solely for commercial off-the-shelf items. The clause therefore appears in contracts that involve no CUI at all. Its presence obligates you to protect covered defense information if and when you have it. Your level comes from the information you actually process, store, or transmit, and from the level your contract names. It does not come from the boilerplate section of the clause list. The same logic applies in reverse. The absence of identified CUI today does not strike the clause, and the obligation activates the day CUI arrives.

Sensitive is not the same as controlled. Your pricing, your payroll, your independently developed intellectual property, and your internal correspondence are neither FCI nor CUI. That holds no matter how sensitive they are. They lack the government nexus. Keep them out of your inventory and out of your boundary. Protecting them is good business. Counting them as CUI inflates your scope for no contractual reason.

What to do first

  1. Pull every active government contract and every flow-down from a prime. Find FAR 52.204-21, DFARS 252.204-7012, and DFARS 252.204-7021 in each one.
  2. Inventory what the government or your prime has sent you: marked documents, technical data, portal downloads, attachments. Note every CUI banner and distribution statement.
  3. Read each statement of work and contract data requirements list for identified CUI. List what you generate to perform: drawings, test results, code, reports produced against government requirements.
  4. Sort the inventory against the definitions in this chapter and the categories in the DoD CUI Registry. Write down the determination and the reasoning for each contract.
  5. Where the contract is silent or the markings look wrong, send the question to the contracting officer or your prime in writing. File the answers with the inventory.

Keep the written inventory after this chapter. It becomes the input to your boundary in chapter 4. It also feeds your training program later, because AT.L2-3.2.1 requires you to identify the security risks of activities involving CUI. You cannot identify those risks without knowing where your CUI is.

If the inventory turns up no CUI on any contract, you are at Level 1 until a contract requires otherwise. Get that conclusion confirmed in writing by each contracting officer or prime. If the inventory turns up any CUI at all, continue to chapter 3, Which level applies. That chapter turns this determination into the level and assessment type your contracts will demand.

Next chapter 03 Which level applies

Chapter 03

Which level applies

Practitioner Guidance

You do not choose your CMMC level. The type of information you handle determines it, a Department of Defense program manager selects it for the procurement, and the solicitation names it. Your job is to read what the solicitation names, understand what that status requires, and hold it before award.

Who decides which level applies

Under 32 CFR 170.3(d), the Department of Defense (DoD) program manager or requiring activity selects the CMMC status for a procurement. The selection is based on the type of information that will be processed, stored, or transmitted on contractor information systems: Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). FCI is information the government provides, or you generate for the government, under a contract, and that is not intended for public release. CUI is information the government creates, or you create for it, that a law, regulation, or government-wide policy requires or permits an agency to protect. DFARS 252.204-7021, the CMMC contract clause, then puts that status in the solicitation and the resulting contract. You must hold the status before award and keep it for the life of the contract.

A CMMC status pairs a level with an assessment type, and the solicitation names one of four: Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), and Level 3 (DIBCAC). Self means you assess yourself. A C3PAO is a CMMC Third-Party Assessment Organization, a private company authorized to perform certification assessments. DIBCAC is the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center, the government's own assessment team. The level tells you which requirements apply. The assessment type tells you who verifies that you meet them. Read both out of the clause. Level 2 (Self) and Level 2 (C3PAO) require the same work. They differ in who verifies it.

You cannot argue the named status down, and nobody can waive it for you. The only legitimate way to a lower status is to handle less sensitive information. That is a decision the government or your prime makes about the contract, not one you make about your appetite for compliance. If you believe a solicitation names a level the information does not justify, raise it before proposals are due. After award you are bound by the clause as written.

Level 1 (Self): FCI and nothing else

Level 1 applies when you handle FCI and no CUI. If chapter 2 told you that FCI is all you hold, this section is everything the program asks of you.

Implement the fifteen safeguards of FAR 52.204-21, the basic safeguarding clause of the Federal Acquisition Regulation. Assess yourself against the NIST SP 800-171A objectives that map to them, reading FCI wherever an objective says CUI. NIST SP 800-171A is the assessment companion to NIST SP 800-171. It breaks each requirement into the objectives an assessor checks. Every safeguard must be MET. A POA&M, a Plan of Action and Milestones for open items, is never permitted at Level 1, so one failed safeguard means no status at all. Enter the result in SPRS, the Supplier Performance Risk System, the DoD database that holds assessment results. Have your Affirming Official, the senior company official who signs the affirmation, affirm it there. Repeat both every year. Keep the evidence you relied on for six years from the status date. Before any award that requires Level 1 (Self), both the self-assessment result and the affirmation must already be in SPRS.

Those steps are all the program asks of you at Level 1. The rest of this reference covers Level 2, so once your fifteen safeguards are implemented, assessed, and affirmed, you are done here.

Level 2: one set of requirements, two assessment types

Level 2 applies when you handle CUI. It is the 110 requirements of NIST SP 800-171 Revision 2, the government publication that lists the security requirements for protecting CUI. The assessment type changes nothing about what you must implement.

Level 2 (Self) means you assess your own implementation, enter the results in SPRS, and repeat the self-assessment every three years. Level 2 (C3PAO) means an authorized or accredited C3PAO performs a certification assessment. The C3PAO submits the results into the CMMC instantiation of eMASS, a DoD assessment records system, which transmits them to SPRS. A new certification assessment must be completed within three years. Under either type you affirm continuing compliance in SPRS every year.

Either type can begin as a conditional status under the narrow POA&M rules of 32 CFR 170.21. Your score must be at least 88. Only one-point requirements may sit on the plan. The exception is SC.L2-3.13.11, CUI encryption, where encryption is in place but not FIPS validated, meaning the cryptographic module does not hold a government validation certificate. The six requirements the rule bars from any plan, which chapter 1 lists, can never be on it. You then have 180 days to pass a closeout assessment or the status expires. An expired conditional status leaves you ineligible for further awards requiring it until you earn a new one.

The contract decides which type you need. Nothing in the rule lets you substitute a self-assessment where the clause requires certification.

Level 3 (DIBCAC) requires Level 2 (C3PAO) first

Level 3 adds selected requirements from NIST SP 800-172, a companion catalog of enhanced security requirements, for the Department's most critical programs. It is not a separate track. Under 32 CFR 170.18 you must hold a Final Level 2 (C3PAO) status on the Level 3 assessment scope before DIBCAC will assess you. You maintain both statuses afterward, each reassessed every three years and each affirmed annually. If a solicitation names Level 3 (DIBCAC), your path still runs through a Level 2 certification assessment first. Level 3 is beyond this reference.

The minimum level for subcontractors

CMMC applies at every tier of the supply chain that handles FCI or CUI, and 32 CFR 170.23 sets the minimum status your prime must require of you:

  • You handle only FCI under the subcontract: Level 1 (Self).
  • You handle CUI under the subcontract: Level 2 (Self) at minimum.
  • You handle CUI and the prime contract requires Level 2 (C3PAO): Level 2 (C3PAO) at minimum.
  • You handle CUI and the prime contract requires Level 3 (DIBCAC): Level 2 (C3PAO) at minimum.

Two things set the floor. They are the information you handle and the status in the prime contract. Your size, your tier, and your relationship with the prime do not change it. A prime may require more than this floor. It may not accept less, and under 252.204-7021 it must confirm you hold the required status before it awards you the subcontract. If a prime tells you CMMC does not apply to your subcontract, it is telling you that you will not handle FCI or CUI in performing it. Get that in writing. The written statement is what keeps you out of scope, and you cannot rely on the prime's goodwill instead.

Where you are in the rollout

The program enters contracts over the four phases of 32 CFR 170.3(e). Phase 1 began on November 10, 2025, when the revised DFARS 252.204-7021 took effect. During Phase 1 the Department includes Level 1 (Self) or Level 2 (Self) as a condition of award in applicable solicitations. The rule also lets it include Level 2 (C3PAO) in place of Level 2 (Self) at its discretion. Phase 2 was scheduled to begin on November 10, 2026 and to make Level 2 (C3PAO) a condition of award in applicable solicitations. Phase 2 carried the discretion to delay that requirement to an option period and to require Level 3 (DIBCAC). Phase 3 and Phase 4 would then extend certification requirements to option periods and to full implementation.

That schedule is suspended. On July 13, 2026 the Department suspended the transition to Phase 2 while a reform task force reviews the program. The suspension also covers pending and future CMMC implementation milestones in its solicitations and contracts. Phase 1 obligations continue. Self-assessments, SPRS entries, and annual affirmations are still conditions of award where the clause names them. DFARS 252.204-7012 still applies to every contract that carries it. The program status page tracks what the Department announces next.

Read the suspension carefully before you change course. The Department paused the schedule and did not repeal the rule. 32 CFR part 170 remains in force, and your self-assessment and affirmation obligations continue. The Department has said nothing about abandoning third-party verification, only that it is reviewing it. There is also still no mechanism to earn a status after you win an award, because eligibility is checked before award.

What to do while the suspension holds

Ask your customers what they will require of you, and let their answers set your plan. The suspension removed the Department's deadline. It did not tell you what the prime on your largest contract expects, and that is the question that decides your next move. Put it to each customer in writing. Ask whether they will require a certification assessment, at what level, and by when.

Treat the answers one contract at a time, because they will differ. A customer that has no certification expectation of you removes the reason to hold an assessment date, and canceling it is a reasonable decision. A customer that tells you it still expects a certificate gives you a date to work back from. Get both kinds of answer in writing and keep them with your contract file.

Ask the primes as well as the contracting officers. The suspension paused the Department's schedule and not your prime's. Primes remain obligated to verify that their supply chain protects the information they flow down. Throughout the program they have set their own expectations ahead of the Department's deadlines. Their answer may not match the Department's timing either way.

Implement Level 2 whatever the answers are, because the requirements are identical under both assessment types. The self-assessment you enter in SPRS is a representation to the federal government, and the annual affirmation puts a senior official's name on it. Certification readiness adds evidence good enough for someone outside your company to examine, which is what lets the official sign knowing the evidence would hold up.

Keep four facts in mind as you read the answers. C3PAOs are still performing certification assessments, because the suspension removed the contract requirement rather than the assessors. A certification lasts three years. Assessor capacity did not grow when the schedule paused, and C3PAOs were booked months ahead before the suspension. A slot you give up now rejoins that queue at the end. The suspension has no announced end, and the review reporting to the Department has a 60-day clock.

Building for certification changes how you work. What you implement stays the same. Evidence must be in final form, policies must be approved, and every assessment objective must hold up when someone outside your company examines it. Chapter 6, Assessing yourself, shows you how to run that examination on your own system first.

What to do first

  1. Find DFARS 252.204-7021 in the solicitation, the contract, or the flowdown from your prime. Write down the exact status it names, level and assessment type both.
  2. If you hold only FCI, run the Level 1 self-assessment. Enter it in SPRS with your affirmation. Put the annual repeat on the calendar. Then stop reading this reference.
  3. If you hold CUI, ask your prime and your contracting officer in writing which status their contract will require of you and by when. Implement Level 2 while you wait for the answer, because the requirements are the same under both assessment types.
  4. Read what Level 2 actually measures. Every requirement page in the requirement reference quotes the requirement and its assessment objectives verbatim. AT.L2-3.2.1 shows you the shape of what an assessor will hold you to.

Then go to chapter 4, Drawing your boundary, and reduce where that information lives before you buy any tools.

Next chapter 04 Drawing your boundary

Chapter 04

Drawing your boundary

Practitioner Guidance

The assessment does not cover your whole company by default. It covers the boundary you draw, and 32 CFR 170.19 gives you that decision. Every asset inside the boundary must be documented and defended. The assets that touch CUI or protect it are assessed against the Level 2 requirements. CUI is Controlled Unclassified Information: information the government creates, or you create for it, that a law, regulation, or government-wide policy requires or permits an agency to protect. Every asset outside the boundary is not assessed at all. Drawing that line is the single decision that most changes what CMMC costs you, and it comes before you buy anything.

You define the scope, the assessor tests it

32 CFR 170.19(c) requires you to specify the CMMC Assessment Scope before any assessment begins. The scope names the assets that will be assessed. It is recorded in your asset inventory, your network diagram, and your system security plan (SSP), the document that describes how your system meets each requirement. The assessor does not draw your boundary. The assessor tests the boundary you drew and challenges the parts of it that do not hold.

The 110 requirements are the same whether your scope is one enclave of twelve machines or a flat network of four hundred. An enclave is one separated environment where all the CUI lives and works. What changes is the number of places each requirement must be implemented and evidenced. Access control on twelve machines produces evidence one person can manage. Access control on four hundred machines takes a team. Every requirement costs more as the scope grows, so settle the scope before you spend money on tools.

The boundary also commits you to something. A system left outside the scope of your CMMC status cannot be used to process, store, or transmit FCI or CUI during contract performance. FCI is Federal Contract Information: information the government provides, or you generate for the government, under a contract, and that is not intended for public release. If your engineers will need a system to do the work, put that system inside the boundary.

The five asset categories

32 CFR 170.19(c)(1) sorts every asset in your environment into one of five categories. An asset takes the most demanding category it fits. The test that runs through all of them is whether the asset can process, store, or transmit CUI. Process means the asset can use CUI: access it, enter it, edit it, change it, generate it, or print it. Store means CUI is at rest on it, including paper. Transmit means CUI moves through it.

CUI Assets process, store, or transmit CUI. They are assessed against all Level 2 security requirements. The other four categories are defined by how they relate to this one.

Security Protection Assets provide security functions or capabilities to your scope. Your SIEM, the system that collects your security logs in one place for review, is a Security Protection Asset. So are your identity provider, your firewalls, the administrators who run them, and the building that houses them, even when no CUI ever touches them. They are assessed against the Level 2 requirements relevant to the capability they provide. A tool is still assessed even when no CUI is on it. If it protects the environment, it is in scope.

Contractor Risk Managed Assets can process, store, or transmit CUI but are not intended to, because your security policies, procedures, and practices keep CUI off them. They do not have to be separated from CUI Assets. The assessor reviews how your SSP documents them. If the documentation is sufficient, they are not assessed further. If the documentation is weak, or other findings raise questions, the assessor can run a limited check against the Level 2 requirements. The rule states that limited checks shall not materially increase the assessment's duration or cost.

Specialized Assets can touch CUI but cannot be fully secured. The rule names six kinds: Internet of Things devices, Industrial Internet of Things devices, operational technology, government furnished equipment, restricted information systems, and test equipment. A CNC machine that consumes a controlled drawing is the classic case. You document them in the inventory, the SSP, and the diagram, and you show they are managed under your risk-based policies. The assessor reviews the SSP and does not assess them against the other Level 2 requirements.

Out-of-Scope Assets cannot process, store, or transmit CUI and provide no security protection to the assets that do. They are not assessed and carry no documentation requirement. You must still be prepared to justify why each one is incapable of touching CUI. An asset that fits any in-scope category can never be declared out of scope.

How separation keeps an asset out of scope

Only Out-of-Scope Assets require separation, and separation has a definition. Logical separation means data transfer between connected assets is prevented by non-physical means: a firewall, a router with access control, a virtual private network (VPN) boundary. Physical separation means no connection at all, wired or wireless, so that data moves only by hand.

Check your architecture against that definition honestly. A VLAN, a virtual segment of your network, that routes freely to the CUI network separates nothing. It bounds a broadcast domain, which is the set of machines that hear each other's network traffic. It does not stop data from moving. Encryption alone does not create logical separation either, because encrypting data does not prevent it from moving. The claim you must be able to defend is deny by default, with every permitted flow being one that cannot carry CUI. You can still call an asset out of scope when the only permitted flow is tightly constrained, such as a time sync or a license check. A path that could move a file, a share, a mail route, a remote session, does not. The asset on the far end of that path is a Contractor Risk Managed Asset at best.

A policy does not separate anything. A rule telling users not to put CUI on a machine makes that machine a Contractor Risk Managed Asset. The machine can still hold CUI the day someone breaks the rule. The regulation says the asset cannot process, store, or transmit CUI, and only the architecture can make that true.

Prefer a small enclave to the whole network

The cheapest approach is an enclave, which is one separated environment where all CUI lives and works, with everything else out of scope. The scoping guidance published with the rule supports this directly. An enterprise service can serve the enclave without bringing the whole enterprise into scope. When a central IT group maintains the anti-malware tool your enclave uses, the tool, the people who run it, and its management server can come into scope, and the rest of the enterprise does not. An enclave with no direct internet connection can send its traffic across the shared enterprise network. Whether that shared network stays out of scope is a question you will have to argue, and the answer is not settled. The scoping guidance's definition of transmitting CUI has no carve-out for encrypted traffic. The Department of Defense (DoD) has stated publicly that encrypted CUI is still CUI, and a formal scope determination on the question is pending. Expect the transit path to draw evidence under SC.L2-3.13.11 and SC.L2-3.13.10 at a minimum. Satisfy both by encrypting the traffic before it reaches the shared gear, using FIPS-validated cryptography, meaning the cryptographic module holds a government validation certificate.

The enclave also removes the separate Level 1 work. A Level 2 assessment satisfies the Level 1 self-assessment for the same scope, so FCI handled inside the CUI enclave needs no separate treatment.

Draw the boundary so that ordinary change does not force a new assessment. A new assessment is required when the architecture or boundary changes significantly, such as a network expansion or a merger. Adding and removing resources inside the existing boundary under the existing SSP is an operational change covered by your annual affirmation. If the boundary is a stable enclave, you can add and remove systems inside it without a new assessment. If the boundary is the whole company, every acquisition and office move changes it.

How cloud and service providers come into scope

A cloud service that processes, stores, or transmits your CUI must meet the FedRAMP requirements in DFARS 252.204-7012. FedRAMP is the federal program that authorizes cloud services to hold government data. DFARS 252.204-7012 is the Department of Defense contract clause that sets safeguarding obligations for that data. Your own infrastructure connecting to the cloud service stays in your scope. So does the responsibility split documented in the provider's customer responsibility matrix, the document that says which security duties the provider performs and which stay yours. A managed service provider or managed security service provider whose people administer your in-scope systems, or whose systems hold your security protection data such as logs and configurations, is assessed as part of your assessment. It does not need its own certification. A provider counts as an external service provider only when your CUI or your security protection data resides on its systems. Staff augmentation, where you supply all the processes, technology, and facilities and the provider's people work on your systems, requires no assessment of the provider. Judge each vendor by what its systems hold. The name on the contract does not decide it.

The VDI exception

Virtual desktop infrastructure (VDI) is the only way the rule lets you keep an endpoint out of scope. VDI runs the desktop session on a server, and the endpoint only displays it. An endpoint hosting a VDI client configured to allow nothing beyond keyboard, video, and mouse is an Out-of-Scope Asset, because the CUI stays in the hosted session. The configuration is the whole exception, and it will be verified. Clipboard redirection, drive mapping, printing to the endpoint, and local caching each break it. The moment CUI can reach the endpoint, the exception is gone and the endpoint is in scope. The exception does not apply if the same device also opens CUI attachments in a local mail client. Configure the server side to block the data paths. Require multifactor authentication performed separately from the unmanaged endpoint, such as a hardware token or an authenticator on another device. Keep evidence of both.

Document the boundary in the SSP and network diagram

An assessor can only test the boundary you wrote down. The asset inventory lists every in-scope asset with its category. The SSP describes how each category is treated. A Contractor Risk Managed or Specialized designation holds only if the SSP describes it well enough. The network diagram shows the boundary and what sits on each side of it. The assessment team works from it when you agree the scope before the assessment starts. Under 32 CFR 170.24, arriving without a current SSP does not produce a low score. It produces a finding that the assessment could not be completed. The SSP is itself a requirement, CA.L2-3.12.4, and scoping is where it starts.

Scoping also feeds applicability. A requirement whose subject does not exist in your scope is assessed as not applicable, which counts the same as met. 32 CFR 170.24 gives SC.L2-3.13.5 as the example when no publicly accessible system sits inside the boundary. A smaller scope makes more requirements not applicable, so you never have to evidence them.

The two ways to get it wrong

Overreach is declaring the entire network in scope because that feels safer. It is not safer, and it costs more. Every laptop you include has to satisfy every applicable objective of all 110 requirements. Each one is another line in your inventory that an assessor can find a problem with. Put only what the CUI work needs inside the boundary, and separate the rest so it falls out of scope.

Underreach is pretending a connected system is out of scope because you would rather not deal with it. Three connected systems catch people out. The file server shares a flat network with your CUI workstations. The print path could carry a drawing. The backup system copies a CUI share without anyone thinking about it. Each of these can process, store, or transmit CUI, so none of them can be out of scope. Categorize each one honestly. The honest answer for a connected asset you have not separated is a Contractor Risk Managed Asset, which costs you an SSP narrative. A false out-of-scope claim fails when the assessor tests it.

What to do first

  1. Follow the CUI before you touch the network diagram. Trace where it enters, where people work on it, where it is stored, and where it leaves, including email, file shares, backups, and paper.
  2. Draw the smallest boundary that honestly contains that flow. If the flow reaches many systems today, work out what it would take to move it into an enclave.
  3. Categorize every remaining asset into one of the five categories. Apply the capability test to decide what is in scope, and the intent test to separate CUI Assets from Contractor Risk Managed Assets.
  4. Write the asset inventory, the SSP treatment for each category, and the network diagram. Make the separation you claim real in firewall rules before an assessor asks.

Do this before you buy tools and before you schedule anything, because every quote you receive is priced against a scope. What is CMMC told you the level sets which requirements apply. The boundary sets how many systems each one applies to. The requirements you implement next apply inside this line and nowhere else.

Next chapter 05 Reading a requirement

Chapter 05

Reading a requirement

Practitioner Guidance

You are not assessed against the requirement sentence. You are assessed against its assessment objectives, one at a time, and every applicable objective must be satisfied for the requirement to be MET. Read a requirement the way an assessor reads it, as a list of objectives that each need their own evidence.

The parts of a requirement

Every Level 2 requirement arrives in the same four parts.

The identifier. AC.L2-3.1.1 reads as family, level, and number. AC is the family, Access Control. L2 is the CMMC level. 3.1.1 is the requirement's number in chapter 3 of NIST SP 800-171 Revision 2, the government publication that lists the security requirements for protecting Controlled Unclassified Information (CUI). Use the full identifier when you write about a requirement, so there is never a question which requirement you mean. That holds in your system security plan, the document that describes how your system meets each requirement, and everywhere else.

The requirement statement. One or two sentences, verbatim from NIST SP 800-171 Revision 2. The statement is the obligation. The objectives are what an assessor tests.

The assessment objectives. NIST SP 800-171A, the assessment companion to NIST SP 800-171, breaks each requirement into lettered objectives under the words "Determine if:". The 110 requirements break into 320 objectives. The objectives are the test. The CMMC Assessment Guide for Level 2 reproduces them, and an assessor works through them one letter at a time.

The discussion. NIST SP 800-171 carries discussion text, and the CMMC Assessment Guide adds further discussion and examples. All of it is explanatory. It exists to help you understand the requirement, not to extend it, and an assessor cannot base a finding on it. Read it for ideas. Do not treat its examples as mandates.

The objectives are the unit of assessment

32 CFR 170.24 gives each requirement one of three findings. MET means all applicable objectives are satisfied based on evidence, and the evidence is in final form. Drafts, working papers, and unapproved policies do not count. NOT MET means one or more applicable objectives are not satisfied. The assessor documents, objective by objective, why the evidence does not conform. N/A means the requirement does not apply at the time of the assessment. A requirement assessed as N/A counts the same as MET.

There is no partial credit at the level of a requirement. Satisfy seven objectives out of eight and the requirement is NOT MET. It costs its full point value, one, three, or five points, exactly as if you had satisfied none. The two partial-credit cases in the scoring methodology, multifactor authentication and CUI encryption, adjust points for specific implementation states. They do not change the finding.

Two situations still score MET with a known gap. An enduring exception described in your system security plan along with its mitigations is assessed as MET. A temporary deficiency addressed in an operational plan of action, with deficiency reviews and visible progress toward the fix, is assessed as MET. Everything else that misses an objective is NOT MET until you fix it.

How to read a Determine if list

Each objective is a separate yes or no. Read the verb. "Identified" and "defined" call for a document or a record. "Made aware" and "provided" call for proof of delivery. "Enforced", "implemented", and "restricted" call for the system actually doing it. The verb tells you what kind of evidence the objective wants.

The list is conjunctive. The word "and" before the last objective means all of them. Satisfying most of the objectives is never enough.

Do not over-read. The objective demands what its words demand and nothing more. If it does not name a tool, no tool is required. If it does not name a frequency, the frequency is yours to define. An assessor cannot fail you for missing something the objective does not say. Do not build something the objective does not ask for. Chapter 8, Implementing without overbuilding, rests on this point.

Do not under-read. Every noun in an objective counts. If an objective names managers, systems administrators, and users, evidence that covers users alone fails it. If it says policies, standards, and procedures, a policy alone does not answer for the other two. Read each objective twice and account for every word.

Examine, interview, and test

NIST SP 800-171A gives assessors three methods. Examine means reviewing things: policies, plans, records, configurations, and activities. Interview means asking people. An assessor puts questions to the people who run the safeguard and the people who live under it. Test means exercising the safeguard and comparing what actually happens with what is supposed to happen.

The assessment guide lists potential objects for each method under the words "SELECT FROM". The assessor selects. Nothing obliges an assessor to use every method or every object on the list, so prepare evidence that survives all three. The document exists in final form. The people named in the objective can say what the document says and where it lives. The system actually does what the document claims. A policy that your own administrators cannot describe fails the interview even though it passes the examine.

What organization-defined phrasing means

NIST SP 800-171 Revision 2 leaves many parameters to you. Requirements say "periodically", "authorized users", "defined subset", and similar phrases without numbers attached. The requirement is not vague. It leaves the definition to you, and you have to defend the one you choose. Write the definition into your policy or your system security plan, and the assessor assesses against your definition. Leave it undefined and you fail the objective that asks whether it is defined, because there is nothing to assess against.

The program rule pins one of these down. Under 32 CFR 170.4, "periodically" means occurring at a regular interval you determine, and the interval may not exceed one year. Define your own intervals at least that tight, and keep them regular.

Define an interval you can keep. A quarterly review you perform every quarter satisfies the objective. A monthly review you miss does not. The assessor reads your definition and then asks for the records that prove you followed it. The assessor scores the definition and the practice together. AT.L2-3.2.2 shows the shape, because its first objective is satisfied by a document defining the security duties before anyone is assigned to them or trained to carry them out.

How this site presents each requirement

Every requirement page on this site presents the parts described above in the same order. The page opens with the identifier and title. The Official Source Material section quotes the requirement statement and the Determine if objectives verbatim from the CMMC Assessment Guide for Level 2, and cites the document and revision. Below it sits the Practitioner Guidance section, How to meet it. That section is the Editorial Authority's own judgement about the cheapest honest way to satisfy the objectives.

Keep the two sections distinct. Only the official section can fail you. The guidance tells you how to pass it, and it binds no assessor. When guidance and official text disagree, the official text wins. The editorial policy says how to report a conflict and how corrections are made. The published requirements are listed at /requirements/.

A worked example: AT.L2-3.2.1

Open AT.L2-3.2.1 and read it alongside this section. The requirement statement says to ensure that managers, systems administrators, and users are made aware of the security risks associated with their activities and of the applicable policies, standards, and procedures. One sentence. Then four objectives.

Objectives [a] and [b] use "identified". They are documents: a written record of the security risks tied to your CUI activities, and a list of the policies, standards, and procedures that govern the system. Objectives [c] and [d] use "made aware". They are delivery: proof that all three named audiences received the risks and the documents. That split shows the method. You satisfy two objectives at a desk before any training happens, and you satisfy the other two only by reaching people.

Now apply the findings. Train every employee thoroughly but never write down the risks, and objective [a] is not satisfied, so AT.L2-3.2.1 is NOT MET. It is a basic security requirement worth five points under 32 CFR 170.24, so that one missing document costs the full five. Read the other direction and the same objectives protect you. Nothing in them demands a learning management system or a training platform. A slide deck, a sign-in record, and a signed acknowledgment answer every letter. People who under-read [a] fail this requirement. People who over-read [c] and [d] spend money they did not need to spend.

How to read the next one

Work through every requirement the same way.

  1. Read the requirement statement once, for scope: what activity and whose systems it covers.
  2. Read each objective and classify its verb as document, delivery, or technical behavior. The classification tells you what evidence to gather.
  3. For each objective, name the evidence that satisfies it today and check that it is in final form. A draft satisfies nothing.
  4. Define every organization-defined parameter in your policy or system security plan before you assess yourself, at intervals you will actually keep.
  5. Only then read the discussion and the guidance, for ideas about how, never for additions to what.

Chapter 6, Assessing yourself, turns this reading discipline into a full self-assessment. Do not start scoring until you can read an objective this way without thinking about it.

Next chapter 06 Assessing yourself

Chapter 06

Assessing yourself

Practitioner Guidance

A self-assessment is the same assessment a C3PAO, a CMMC Third-Party Assessment Organization, would run. You cannot fill it in from memory. You perform it yourself, against the same objectives, on the same standard of evidence. Its output is a score you enter in a federal system and an affirmation a named person in your company signs. Run it as if someone outside your company will check your work. The rule gives DoD the right to do that.

What the rule requires

32 CFR 170.16 defines the Level 2 self-assessment under CMMC, the Cybersecurity Maturity Model Certification program. You assess the information systems in your CMMC Assessment Scope against NIST SP 800-171A, the companion document that breaks each security requirement into assessment objectives. You score the result using the CMMC Scoring Methodology in 32 CFR 170.24. You submit the results in the Supplier Performance Risk System, SPRS. The scope is the boundary you drew in chapter 4, Drawing your boundary, around the information you identified in chapter 2, CUI or FCI: Controlled Unclassified Information, or only Federal Contract Information. To keep the status you repeat the self-assessment every three years. Your Affirming Official, the senior person who signs for your compliance, affirms continuing compliance annually in between. Both the status and a current affirmation must be in SPRS before you are eligible for award of a contract that requires Level 2 (Self).

The methodology mirrors the NIST SP 800-171 DoD Assessment Methodology, with the same one, three, and five point values. Two contract clauses, DFARS 252.204-7019 and 252.204-7020, already hold you to that methodology. DFARS is the Defense Federal Acquisition Regulation Supplement, the source of the cybersecurity clauses in DoD contracts. The assessment you run for CMMC is the assessment those clauses have expected all along. If a score is sitting in SPRS today that nobody in your company can trace to an objective-by-objective assessment, treat it as wrong. Replace it with one you can defend.

Work objective by objective

NIST SP 800-171A breaks the 110 requirements into 320 assessment objectives, and the objectives are the unit of work. A requirement is MET only when every applicable objective under it is satisfied. One unsatisfied objective makes the whole requirement NOT MET. If you assess at the requirement level, you are guessing. Open the requirement, read its objectives, and record a finding for each one before you conclude anything about the requirement.

Take AT.L2-3.2.1 as a worked example. The requirement is one sentence about security awareness, but its objectives ask four separate questions: whether the risks are identified, whether the policies are identified, whether people are made aware of the risks, and whether people are made aware of the policies. A company with a polished training module and no written identification of its CUI-related risks fails objective [a], and with it the whole requirement. You find that out by reading the objectives, not the requirement statement.

A requirement can be N/A when it does not apply to anything in your scope at the time of the assessment, and 32 CFR 170.24 treats an N/A requirement as equivalent to MET. The rule's own example is SC.L2-3.13.5, which can be N/A when there are no publicly accessible systems in scope. Record why it is N/A. An assessor will ask you for that reasoning.

Examine, interview, test

NIST SP 800-171A gives you three assessment methods. For every requirement, the assessment guide lists the objects each method draws from, under the words SELECT FROM.

  • Examine means reviewing the things that exist: policies, procedures, plans, configurations, records, and the mechanisms themselves.
  • Interview means talking to the people who do the work and checking that what they describe matches what the documents claim.
  • Test means exercising the mechanism and comparing what actually happens with what is supposed to happen.

Use all three on every requirement where they apply, because each one catches a different kind of failure. The document can be perfect while the administrator has never read it. The administrator can describe the safeguard perfectly while the mechanism has been misconfigured for a year. For AU.L2-3.3.1 that means three steps. Read the audit policy. Ask the administrator which events are logged and where. Then pull live log records to confirm the events are actually being captured on every system in scope.

The evidence standard comes from 32 CFR 170.24, which requires all evidence to be in final form. Drafts, working papers, and unofficial or unapproved policies are unacceptable. A policy your team wrote but nobody approved satisfies nothing. Finish the document, get it signed, and then count it.

How the score works

The scoring methodology in 32 CFR 170.24 starts you at the maximum score, which is the total number of requirements, 110. Every requirement is MET, NOT MET, or N/A. For each NOT MET requirement you subtract its value. A requirement costs five points when its absence could lead to significant exploitation of the network or exfiltration of CUI. It costs three points when its absence has a specific and confined effect. It costs one point otherwise. The score can go negative.

Two requirements carry partial credit. For multifactor authentication, IA.L2-3.5.3, you subtract three points when MFA covers only remote and privileged users, and five when it covers nobody. For CUI encryption, SC.L2-3.13.11, you subtract three points when you encrypt but the encryption is not FIPS validated, meaning validated under the government's Federal Information Processing Standards program for cryptographic modules. You subtract five when you do not encrypt at all.

One requirement is a precondition rather than a point value. You must have a system security plan, the SSP required by CA.L2-3.12.4, in place at the time of the assessment. Without an up-to-date SSP the assessment cannot be completed at all, and the rule records that as noncompliance with DFARS 252.204-7012. Chapter 7, Policy and your SSP, covers how to write one that carries an assessment.

A POA&M, a Plan of Action and Milestones, changes none of these findings. 32 CFR 170.24 states that a requirement not implemented is NOT MET whether it is described in a POA&M or not. Under narrow conditions the plan gives you more time. It never raises your score.

The 88-point minimum for a Conditional status

32 CFR 170.21 sets three conditions for a Conditional Level 2 status. The first is a minimum score. Your score divided by 110 must be at least 0.8, which means 88 or higher. Below 88 you cannot hold a conditional status, and the only result you can enter is a failed assessment. At 88 or above you may hold a Conditional Level 2 (Self) status only if every requirement on your POA&M is worth one point. The single exception is SC.L2-3.13.11, which may sit on the plan at three points when you encrypt but the encryption is not FIPS validated. Six requirements may never appear on the plan at all: AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, and PE.L2-3.10.5.

You have 180 days, and the deadline is fixed. You must remediate, run a POA&M closeout self-assessment covering the NOT MET requirements, and post the results to SPRS. All of that must happen within 180 days of the CMMC Status Date of the conditional status. Miss the window and the status expires, and you are ineligible for further awards requiring it until you earn a new one. Chapter 9, Gaps and your POA&M, covers how to run that half year. For this chapter the point is simpler. The 88 threshold and the one-point limit together mean a POA&M can hold only a few of the easiest requirements. You cannot use it to defer the hard ones.

Score only what is already implemented

Do not mark a requirement MET because the fix is ordered, the project is funded, or the policy is nearly approved. None of those is an implementation. If the objective is not satisfied today, on evidence in final form, the requirement is NOT MET today. The only exceptions are the two chapter 5 describes: an enduring exception documented in your system security plan with mitigations, and a temporary deficiency addressed in an operational plan of action. A purchase order is not one of those exceptions.

Enter a low score rather than an inflated one. A low score is true, and it gives you a POA&M and a remediation plan. An inflated score is a false statement in a federal system that DoD relies on for award decisions. Your Affirming Official then attests to it by name, in writing, every year. The False Claims Act attaches liability to knowingly false representations made to the government. The Department of Justice pursues cybersecurity misrepresentations under its Civil Cyber-Fraud Initiative, including misstated NIST SP 800-171 scores. The rule also gives DoD its own check. 32 CFR 170.16 reserves the right to run an assessment of your environment by DCMA DIBCAC, the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center. If its results contradict your self-assessment, the DIBCAC results take precedence and standard contractual remedies apply. You are then ineligible for further awards requiring that level or higher until you earn a new status.

Nobody can tell an honest 90 from an inflated 110 until someone reads the evidence behind it. An honest 90 with plan-eligible gaps costs you 180 days of remediation. An inflated 110 costs you the ability to say you believed it was true.

Entering the result in SPRS

32 CFR 170.16 lists what the SPRS entry must include. The entry carries the CMMC level, the CMMC Status Date, and the CMMC Assessment Scope. It carries every CAGE code, the Commercial and Government Entity code that identifies a company to the government, associated with the information systems in that scope. It carries the overall score, for example 105 out of 110, and whether a POA&M is in use and its compliance status. The score you enter counts requirements, not objectives. The 320 objectives are how you reach each finding. The number in SPRS is out of 110.

Enter the result promptly. Then put both recurring dates on the calendar. A new self-assessment with results in SPRS is due every three years, and an affirmation is due every year in between.

The annual affirmation

32 CFR 170.22 requires an Affirming Official, the senior level representative responsible for your compliance with the CMMC Program requirements and holding the authority to affirm it. That person affirms continuing compliance after every assessment, including a POA&M closeout, and annually thereafter, electronically in SPRS. The affirmation names the official. It attests that you have implemented, and will maintain, all applicable security requirements for every information system in the assessment scope. Primes and subcontractors each affirm for their own organizations, and DoD verifies the affirmation is in SPRS.

Choose this person deliberately and brief them honestly. When they affirm, your score stops being an internal number and becomes a signed representation to the government. An Affirming Official who has never seen the objective-level findings cannot know whether the affirmation is true. Show them the findings, the POA&M, and what changed since last year. Put the annual date on their calendar, not just yours.

Collect the evidence a C3PAO would ask for

If a future contract requires Level 2 (C3PAO), the self-assessment is your practice run for it. The evidence you gather now is the evidence a C3PAO will ask for later. 32 CFR 170.16 requires you to retain the assessment artifacts for six years from the CMMC Status Date, so build the habit once and keep it.

  • File evidence by requirement and objective, so that AT.L2-3.2.1 objective [c] names one artifact rather than pointing at a folder called Training.
  • Keep only final, approved versions, with the approval visible: a signature, a date, a named owner.
  • Date-stamp captured evidence such as screenshots and exports, and name the system it came from.
  • For anything the requirements make recurring, keep each occurrence. The program rule defines "periodically" as an interval you set that may not exceed one year, so a recurring requirement needs evidence at least that often.
  • Record your N/A reasoning and your scoping decisions next to the findings they affect.

A C3PAO charges by the hour, and most of those hours go to finding evidence. If you can answer every objective with a named, dated, final artifact, the assessment takes less time and costs less. If you assemble evidence the month before, you pay assessors to wait while you search.

What to do first

Name your Affirming Official and get their agreement to the honest-score rule before you record a single finding, because their signature is the output of everything that follows. Then run a small pilot to learn the method: assess the three Awareness and Training requirements, AT.L2-3.2.1, AT.L2-3.2.2, and AT.L2-3.2.3, objective by objective, filing evidence as you go. The pilot shows you how long the work actually takes and where your evidence is missing, across three requirements instead of 110. Then work through the rest by family, score the result under 32 CFR 170.24, and enter what is true in SPRS, whatever the number is. Chapter 1, What is CMMC, tells you what that status is worth. The chapters after this one turn the NOT MET findings into an SSP, an implementation plan, and a POA&M.

Next chapter 07 Policy and your SSP

Chapter 07

Policy and your SSP

Practitioner Guidance

Your system security plan, the SSP, is the document that describes how your system meets each security requirement. Your Level 2 assessment under CMMC, the Cybersecurity Maturity Model Certification program, is planned from it. It is also the one requirement that can stop the assessment from happening at all. Write it to describe the system you run today. Every interview, examination, and test that follows checks whether reality matches what the plan says.

What CA.L2-3.12.4 requires

CA.L2-3.12.4 requires you to develop, document, and periodically update a system security plan that describes four things.

  • The system boundary: which assets make up the environment that processes, stores, or transmits Controlled Unclassified Information, CUI, and where its edge sits.
  • The environment of operation: the physical and technical surroundings the system runs in. The offices, the cloud tenant, the server room, the remote laptops.
  • How the security requirements are implemented: for each of the 110 requirements, what you actually do and with what.
  • The relationships with or connections to other systems: every network connection, external service, and dependency that crosses the boundary.

The requirement carries eight assessment objectives, and they are specific. The plan must exist. The boundary and the environment of operation must each be described and documented in it. Security requirements approved as non-applicable must be identified. The method of implementation for every requirement must be described and documented. Connections and relationships to other systems must be described and documented. And the plan must carry a defined update frequency that you then actually keep to.

Two of those objectives need explaining. Objective [d] covers requirements "identified and approved by the designated authority as non-applicable." For that adjudicated kind of non-applicability, the authority is not you. 32 CFR 170.24 states that a favorable adjudication from the DoD Chief Information Officer that a security requirement is not applicable must be included in the system security plan. Only then does it receive consideration during an assessment. The adjudication must be made in accordance with 48 CFR 252.204-7008 or 48 CFR 252.204-7012. This is separate from the N/A finding chapter 5 describes, where a requirement's subject simply does not exist in your scope at assessment time. That finding is the assessor's and needs no adjudication. A permanent claim of non-applicability credited through the plan does. Objective [g] asks you to define the plan's update frequency. The requirement statement says "periodically," and 32 CFR 170.4 governs that word: a regular interval, determined by you, that may not exceed one year. Pick a frequency of one year or shorter, write it in the plan, and keep the records that show you met it.

The assessment cannot proceed without an SSP

A C3PAO plans a certification assessment from your SSP. The assessment team reads it before testing anything. The team confirms the scope against its boundary description and builds its schedule of interviews and tests from its implementation statements. When the SSP is missing or out of date, the assessment does not go ahead anyway. 32 CFR 170.24 requires you to have an SSP in place at the time of assessment, describing each information system within the CMMC assessment scope. It states that the absence of an up-to-date SSP would result in a finding that an assessment could not be completed, due to incomplete information and noncompliance with 48 CFR 252.204-7012.

There is no conditional path around it either. Chapter 1, What is CMMC, explains the narrow Plan of Action and Milestones, the POA&M, that lets you hold a conditional status while you close out low-value gaps. CA.L2-3.12.4 is one of the six requirements 32 CFR 170.21 bars from that plan outright. A missing or inadequate SSP cannot be deferred. It cannot be conditionally passed, and it cannot be fixed inside a 180-day window after the fact.

The plan also carries everything the assessor credits you on paper for. An enduring exception, a system that cannot feasibly meet a requirement, is assessed MET only when it is described in the SSP along with its mitigations. A DoD CIO adjudication counts only when it is included in the SSP. If a fact about your environment affects your score and the plan does not state it, the assessor cannot credit it.

What policy covers that the SSP does not

An assessor asks two questions about every requirement. Is it implemented here, and is it deliberate and repeatable? The SSP answers the first. It states your boundary, your environment, and how each requirement is met in this system. Policy answers the second. It states the rule you set, who it applies to, and who is accountable for it. A configuration with no policy behind it is one administrator's habit, and nobody maintains it once that person leaves. A policy with no implementation behind it describes something you do not do. The assessor wants both documents because the two together prove the safeguard is real and will still be real next year.

The assessment methods are built on that split. Look at what the Level 2 assessment guide tells an assessor to examine for a requirement: the family's policy, the procedures addressing the requirement, the system security plan, and then the records and configurations. For CA.L2-3.12.4 itself the examine list opens with the security planning policy and the procedures for developing and updating the plan, before the plan itself. The SSP likewise appears in the examine list of requirement after requirement across the guide. An assessor examines these documents directly. They are assessment objects in their own right.

The objectives make the split visible in their grammar. An objective written "are identified," "is defined," "is specified," or "are documented" is satisfied by a document, not by technology. AT.L2-3.2.1 requires that security risks and the applicable policies, standards, and procedures are identified before anyone is trained on them. AU.L2-3.3.1 requires that the event types to be logged are specified and the retention period is defined before any log is examined. Each of these objectives fails on a missing document no matter how good the configuration is. One failed objective makes the whole requirement NOT MET.

Keep the terms straight, because your document set follows from them. A policy states the rule. It says what must happen, who it applies to, and who is accountable. A procedure states the steps. It says how the rule is carried out, by whom, and in what order. The SSP states the implementation. It says what is in place in this system, with which products, in what configuration. Each document answers a different question.

The documents you need, and the ones you do not

The document set a small contractor needs is short.

  1. One system security plan covering the assessment scope.
  2. A compact policy set covering the fourteen requirement families of NIST SP 800-171 Revision 2. One policy per family works. So does a handful of documents that group related families: an access control and identification policy, an operations policy, a personnel and physical policy. Each one approved, signed, and dated, because a draft is not evidence.
  3. Procedures where a requirement or your own policy calls for defined steps: responding to an incident, provisioning and removing accounts, sanitizing media, reviewing audit logs.
  4. The records those documents generate as they run: training completions, access approvals, log reviews, plan updates. Chapter 10, What assessors ask for, covers these.

The official assessment guidance for CA.L2-3.12.4 states that a security plan need not be a single document. It adds that effective plans make extensive use of references to policies and procedures, because references reduce what you must document. Use that, and go further. Reference your policies rather than restating them. An implementation statement that says multifactor authentication is enforced through your identity provider, per your access control policy, is complete. Copying the policy text into the SSP gives you two copies of the same rule. They will contradict each other the day you update one of them.

You do not need the template pack of forty policies sold to contractors starting this work. A bought template fails in two ways. It describes practices you do not perform, and every one of those statements is something the assessor can test and you will fail. It also describes structures you do not have, such as a change advisory board in a five-person machine shop. If a policy names roles your company does not have, the assessor can see you bought the document rather than wrote it. The interview that follows the examination will show that nobody in the building has read it. A small set of documents that describe what you do is worth more than a large set that does not.

Write what is true

The assessor has three methods: examine, interview, and test. Documents are only the first. The people the policy governs get interviewed, and the mechanisms the SSP describes get tested. Every statement in your document set is therefore a claim you are inviting someone to check against reality. Where the SSP says one thing and the firewall config says another, the objective is unsatisfied and the requirement is NOT MET.

Write implementation statements an assessor can test and pass you on. A statement like "access is restricted in accordance with the principle of least privilege" names no system, no mechanism, and no scope. The assessor then has to find the facts you did not state. Write instead: multifactor authentication is enforced for all user accounts through Microsoft Entra ID Conditional Access, with no exclusions, and the policy applies to the entire tenant. That statement names the product, the mechanism, and the scope. It passes testing because you wrote it from the configuration rather than from what you wish were true.

Do not write the environment you plan to have. A statement that a requirement "will be implemented" documents a gap in the present tense. The requirement is NOT MET today regardless of the plan's optimism. When you cannot write a truthful statement that meets a requirement, you have found a gap. Record it and carry it into chapter 9, Gaps and your POA&M. An honest SSP shows you your gaps while you can still fix them. An SSP that overstates your position turns each overstatement into a finding at the assessment.

Keep the plan current

The SSP describes configuration, and configuration changes. Each of these makes part of your plan untrue. A migration to a new file server. A new managed service provider. A new office. A change of identity platform. The requirement anticipates this. That is why objectives [g] and [h] exist, and why 32 CFR 170.24 says "up to date," not merely "present," at the time of assessment.

Update the plan on two triggers. The first is change. When the boundary, the environment, a connection, or an implementation changes, update the plan in the same piece of work. The change is not done until the plan matches it. The second is the schedule. At the frequency the plan defines, one year at most, an owner reads the plan against the environment. The owner records the review with a date and a name. Those dated records are the evidence for objective [h]. If the last review date is three years old, the assessor sees that on page one.

What to do first

  1. Gather every security document you have and sort each one into plan, policy, procedure, or record. Discard nothing yet. Note what is approved and dated, what is draft, and what describes a company that is not yours.
  2. Write the boundary and environment of operation sections first. They come straight from the CUI inventory you built in chapter 2, CUI or FCI, and chapter 4, Drawing your boundary, shapes them. List every connection to another system while the inventory is open.
  3. Write one implementation statement per requirement, naming the actual product, mechanism, and scope. Browse the published requirement pages with their objectives in front of you as you write. Mark every requirement where a truthful statement falls short. That list is your gap list.
  4. Set the update frequency at one year or shorter, name the plan's owner in the plan, and put the review date on that person's calendar.
  5. Read each policy against what your people actually do. Where they disagree, change whichever one is wrong, and date the change.

Do this work yourself or stay close to whoever does it for you. If someone else writes the SSP without you, you will not know your own system well enough to answer questions about it. The interviews are where that shows.

Next chapter 08 Implementing without overbuilding

Chapter 08

Implementing without overbuilding

Practitioner Guidance

The 320 assessment objectives are both the minimum and the maximum. Every applicable objective must be satisfied, and only the requirement statement and its objectives can fail you. No objective names a product. Hold every purchase against that fact before you make it. Companies waste money on CMMC by buying tools that no objective requires, and they often still fail the objectives those tools were meant to cover.

You never need more than the objectives ask

Chapter 1, What is CMMC, explains that a requirement is MET only when every applicable objective in NIST SP 800-171A is satisfied. NIST SP 800-171A is the assessment companion to NIST SP 800-171. It breaks the 110 requirements into the objectives an assessor checks. Only the requirement statement and its objectives can fail you. That rule works in both directions. You cannot argue your way past an objective you have not satisfied. An assessor also cannot fail you for lacking a tool, a platform, or a job title that no objective names.

Read the verbs the objectives use, the skill chapter 5 teaches. A document satisfies an objective whose verb is defined, identified, documented, or specified. A procedure and a record that the procedure ran satisfy an objective whose verb is reviewed, updated, or tracked. Only a working mechanism satisfies an objective whose verb is implemented, enforced, or employed. Sort the objectives by their verbs, and pay for a mechanism only where an objective requires one.

A procedure you follow produces better evidence than a tool you own and never operate. An assessor scores you on evidence in final form, and an unconfigured platform produces none. A purchase order shows only that you spent money.

Common purchases you do not need

A learning management system for awareness and training. AT.L2-3.2.1 has four objectives: risks identified, policies identified, and both communicated to managers, administrators, and users. A slide deck that names your risks and your policies, a session, and a signed, dated acknowledgment satisfy all four. The same shape covers AT.L2-3.2.2, which asks that security duties be defined, assigned, and trained to. It also covers AT.L2-3.2.3, which asks for training on recognizing and reporting insider threat indicators. A learning management system (LMS), a platform for delivering and tracking training, is worth buying once you have too many people to track training by hand. At twenty people it is a subscription that produces the same evidence a folder of signed acknowledgments produces.

A SIEM before anyone reads logs. A SIEM is a security tool that collects logs from your systems into one place and correlates them. AU.L2-3.3.1 requires you to create and retain audit logs to the extent needed to enable monitoring, analysis, investigation, and reporting of unlawful or unauthorized activity. AU.L2-3.3.5 requires review processes aimed at suspicious activity that work as one system with your response. A SIEM can serve the correlation AU.L2-3.3.5 asks for, but only when its output feeds a defined review process that someone actually runs. If nobody opens the dashboards, a SIEM fails AU.L2-3.3.5 just as owning no SIEM does. Start with the logs your systems already produce, a named person, a defined cadence, and a dated record of each review. Buy aggregation when one person can no longer review every source. Buy it to serve the correlation AU.L2-3.3.5 asks for, not to substitute for reading.

A GRC platform to track a fixed scope. GRC stands for governance, risk, and compliance. A GRC platform is software for tracking compliance work. Level 2 is 110 requirements and 320 objectives, and that number does not grow. A spreadsheet with a row per objective, a status, an evidence location, and an owner tracks all of it. CA.L2-3.12.4 requires a system security plan (SSP) that describes your boundary, your environment, and how each requirement is implemented, with a defined update frequency. Its objectives are satisfied by a document you maintain, not by a platform. A platform that generates the SSP from templates hands you hundreds of pages you must still verify sentence by sentence. An assessor tests the system against what the SSP says. Generated text describes a company you do not run.

A full-time hire for a fractional role. The requirements assign work, not headcount. No objective requires a security officer on payroll. A fractional or managed provider can run your log review, your vulnerability scanning, and your patching. Three conditions apply. The responsibility is documented. The records belong to you. The person who does the work is available to be interviewed at the assessment. What you cannot delegate is accountability. The annual affirmation comes from your own senior official. And the determination of what Controlled Unclassified Information (CUI) you hold, from chapter 2, CUI or FCI, is a decision about your contracts that no provider can make for you.

Where spending is necessary

You cannot satisfy an objective written with a mechanism verb using a document. Spend your budget here.

  • Identity and MFA. IA.L2-3.5.3 requires multifactor authentication (MFA), a second proof of identity beyond a password. It applies to local and network access to privileged accounts, and to network access to non-privileged accounts. Three of its four objectives say implemented, and only a working authentication system satisfies those. The scoring methodology in 32 CFR 170.24 weights this requirement at five points. Three points are still lost when MFA covers only remote and privileged users. This is the single purchase with the largest scoring consequence.
  • Endpoint control. CM.L2-3.4.1 requires established and maintained baseline configurations and inventories. CM.L2-3.4.2 requires security configuration settings that are established and enforced. Enforced means a mechanism applies the settings and puts them back when they drift. On more than a handful of machines, that is management tooling, not a checklist.
  • Backup. MP.L2-3.8.9 requires the confidentiality of backup CUI to be protected at storage locations. The assessment guide accepts encryption, access management, or physical security as the method. Choose a backup system with encryption anyway. Working backups are what let a company recover from ransomware. Spend here even where the objective could be met more cheaply.
  • FIPS-validated encryption. SC.L2-3.13.11 requires FIPS-validated cryptography wherever cryptography is what protects the confidentiality of CUI. FIPS validated means the cryptographic module has passed government testing and holds a validation certificate. Under 32 CFR 170.24, encrypting without FIPS validation costs three points and not encrypting costs five. Validation is a property of the cryptographic module, so this is a selection problem. Choose products whose modules hold certificates, and record the certificate numbers.
  • The enclave. Chapter 4, Drawing your boundary, presents the decision to concentrate CUI into an enclave, one small, controlled environment, instead of certifying everything you own. Every requirement applies to fewer systems once the boundary is smaller, so money spent shrinking it reduces the cost of all 110 requirements. Evaluate this spending before anything else.

Configure what you own before you buy

Before pricing any new product, inventory the licenses you already hold and the security features inside them. A Microsoft 365 subscription with Microsoft Entra ID already carries MFA enforcement, sign-in logging, and device and configuration management at the license tiers that include them. Windows already carries disk encryption. Companies buy standalone MFA tokens, log collectors, and endpoint agents that duplicate features they are already paying for.

These are examples, not requirements. The objectives are product-neutral, an assessor cannot require any vendor, and the same objectives are satisfied on any stack. Run two checks before you lean on an existing subscription. First, confirm your tier actually includes the feature. Second, where a cloud service stores, processes, or transmits CUI, confirm the service meets the conditions that DFARS 252.204-7012, the Department of Defense safeguarding clause, places on cloud providers. An existing subscription is not automatically an eligible home for CUI.

Do the cheap evidence first

  1. Write first. The CUI determination, the boundary, the policies, the SSP. Writing satisfies every objective whose verb is defined, identified, or documented, and it costs time, not licenses.
  2. Operate second. Stand up the procedures with records: log review, account review, training and acknowledgments, backup verification. A procedure that has run three times with dated records is finished evidence.
  3. Configure third. Turn on what your existing licenses already provide: MFA, logging, device control, encryption.
  4. Buy last. Whatever gaps survive the first three passes are the real purchases. For each one, write the objective identifiers the purchase satisfies before you sign. If you cannot name the objectives a purchase satisfies, it is not a compliance purchase.

This order also keeps you on schedule. Documents and procedures need weeks of history to be credible evidence, so starting them first means they are aged by the time an assessment is booked. A tool bought late can be configured in days. If you start a recurring review late, you cannot backdate the records.

What a CMMC package cannot do for you

Packages sold as CMMC in a box range from genuinely useful enclaves to rebranded licenses. Judge them all the same way. After the purchase, an assessor still scores all 320 objectives against your organization. For each objective the package claims to cover, you need a shared responsibility matrix: the document that records which duties the provider performs and which stay yours. You also need evidence that the provider actually performs its share. No package covers these objectives, whatever you spend on it. You identify your CUI. You write policies that describe your operation. You train people on your risks. You update your SSP. You make the annual affirmation. A vendor that promises certification is promising something the rule gives it no power to deliver. Buy the parts of the box that map to named objectives, and staff the rest.

What to do first

  1. Take the 110 requirements from the requirements reference and sort their objectives into three piles: satisfied by a document or record, satisfied by configuring something you already own, satisfied only by something you do not yet own.
  2. Inventory your current licenses and the security features each tier includes, in writing.
  3. For the third pile, write one line per gap naming the objective identifiers a purchase would satisfy. Price a fractional provider against a hire for any gap that is labor rather than tooling.
  4. Delete every planned purchase that no line justifies. Put the recovered budget against identity, endpoint control, backup, and the boundary.

Next chapter 09 Gaps and your POA&M

Chapter 09

Gaps and your POA&M

Practitioner Guidance

One name, POA&M, gets used for two very different documents, and confusing them is expensive. POA&M is short for Plan of Action and Milestones. The gap list you build while preparing is a working document that exists to reach zero. The POA&M in 32 CFR 170.21, one section of the rule behind CMMC, the Cybersecurity Maturity Model Certification program, is a regulatory instrument. It exists only in relation to an assessment. It holds a small set of low-value gaps under strict conditions, and it expires in 180 days. Use the first every day. Use the second only if an assessment leaves you short.

The two documents called a POA&M

Your internal gap list is yours. You create it the moment your first self-assessment scores a requirement NOT MET. You add to it every time you find a weakness, and no regulation governs what it contains. It can hold anything: a five-point requirement you have not started, a policy that exists only in draft, a requirement implemented in one office and not the other. It exists to drive the work, and nobody outside your company sees it.

The regulatory POA&M is a different sort of document. 32 CFR 170.4 defines it as a document that identifies tasks needing to be accomplished, the resources required, the milestones, and the scheduled completion dates for those milestones. It comes into existence through an assessment. When your Level 2 assessment ends with open items that meet the conditions in 32 CFR 170.21, the POA&M is what lets you hold a Conditional CMMC status while you finish. The rule limits what it may contain and gives it a fixed deadline.

Keep the two separate in your files. Everything in this chapter about eligibility, point limits, and the 180-day clock applies to the regulatory POA&M. None of it limits what your internal gap list can track. A thorough gap list is how you avoid ever needing a regulatory POA&M.

What a POA&M can hold

Start with the rule that has no exceptions. At Level 1, a POA&M is not permitted at any time. 32 CFR 170.21(a)(1) says so in one sentence, and 32 CFR 170.24(c)(1) repeats it. Every one of the fifteen safeguards must be MET, in its entirety, before you can report a Level 1 status. If chapter 2 put you at Level 1, your gap list must reach zero before you self-assess.

At Level 2, 32 CFR 170.21(a)(2) permits a Conditional status only when all three of its conditions hold.

  1. Your assessment score divided by 110 is at least 0.8. That is a score of 88. The scoring methodology in 32 CFR 170.24 subtracts one, three, or five points for every requirement NOT MET. A few of them can take the score below 88.
  2. No requirement on the POA&M has a point value greater than one. The single exception is SC.L2-3.13.11, encryption of CUI, Controlled Unclassified Information. It may sit on the plan at three points when you encrypt but the encryption is not FIPS-validated, meaning not validated under the government's Federal Information Processing Standards program for cryptographic modules. Encryption that is absent entirely is a five-point finding and cannot be planned around.
  3. None of six named requirements appears on the plan at any point value: AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, and PE.L2-3.10.5. The one with the widest effect is CA.L2-3.12.4, the system security plan, or SSP, the document that describes how your system meets each requirement. 32 CFR 170.24 states that without an up-to-date SSP at the time of assessment, the assessment cannot be completed at all.

Now put the second condition together with a rule from the scoring methodology: 32 CFR 170.24(c)(2)(i)(6) requires a POA&M for each NOT MET requirement. Every open gap lands on the plan, and the plan may not hold anything worth more than one point. So a single three-point or five-point requirement scored NOT MET, other than the encryption case, makes the Conditional status unavailable whatever your score. AU.L2-3.3.1, PS.L2-3.9.2, AT.L2-3.2.1, and AT.L2-3.2.2 are all five-point requirements. Fail any one of them and no Conditional status is available. AT.L2-3.2.3 and AU.L2-3.3.4 are one-point requirements and may sit on a plan.

The arithmetic also limits how many items the plan can hold. The 88 floor leaves at most 22 points of open findings, so a POA&M holds at most 22 one-point items, or 19 plus the encryption exception at three. A plan that full means you assessed too early.

Conditional and Final status

A Level 2 assessment ends in one of two statuses. If the assessment results in a passing score under 32 CFR 170.24, which means every requirement is MET, you hold Final Level 2. The status is Self or C3PAO according to your assessment type: a self-assessment, or a certification assessment by a C3PAO, a CMMC Third-Party Assessment Organization. If instead the assessment ends with a POA&M that satisfies every condition above, you hold Conditional Level 2 under 32 CFR 170.16(a)(1)(ii) or 170.17(a)(1)(ii).

A Conditional status is a real status. Under 32 CFR 170.16(b) and 170.17(b), either a Conditional or a Final status, together with your affirmation in SPRS, the Supplier Performance Risk System, makes you eligible for award. That is what the mechanism is for. A near-complete implementation should not cost you a contract while you finish the last few one-point items.

A Conditional status also sets your three-year clock. 32 CFR 170.4 defines the CMMC Status Date as the date the results are submitted to SPRS or eMASS, the government system that receives certification assessment results. It states that the Conditional date remains the CMMC Status Date after a successful closeout. No new date is set for the Final. Your three-year assessment cycle runs from the day you went Conditional. Closing the POA&M does not reset it.

The 180-day deadline

32 CFR 170.21(b) gives one deadline: the POA&M must be closed and confirmed by a POA&M closeout assessment within 180 days of the Conditional CMMC Status Date. The closeout assessment examines only the requirements that sat on the plan. For a Level 2 self-assessment you perform the closeout yourself, in the same manner as the initial self-assessment, and post the result to SPRS. For a Level 2 certification assessment, an authorized or accredited C3PAO must perform the closeout and post the result to eMASS. Budget for that second engagement the moment you accept a Conditional status, because your status is not final without it.

If the plan is not closed out in time, the Conditional status expires. 32 CFR 170.16 and 170.17 spell out what expiry within the period of performance of a contract means. Standard contractual remedies apply. You also become ineligible for further awards requiring that status or higher, for that information system, until you achieve a new CMMC status. A new status means a new assessment from the beginning. The closeout window does not reopen, and work you finish on day 190 does not count until you are assessed again.

Count the days before you accept a plan. The clock starts when the results are submitted, not when you begin the work. If an item depends on procurement, a vendor's roadmap, or a migration, you are assuming that delivery, deployment, and evidence will all fit inside six months. If you cannot prove an item closed within 180 days, it does not belong on a POA&M. It belongs on your internal gap list, before the assessment.

A POA&M is temporary

A POA&M changes your status, not your findings. 32 CFR 170.24 is explicit that a POA&M addressing NOT MET requirements is not a substitute for a completed requirement. The requirement stays NOT MET, on a plan or off it, until you implement it. The rule created the POA&M for a narrow case, which is an assessment that nearly passed and a Final status a few weeks later. Every condition on it points the same way. Only the lowest-value requirements qualify, six requirements never qualify, the score floor caps how many items fit, the deadline is fixed, and missing it costs you the status and eligibility.

So never plan an assessment around the POA&M. Accept a plan only when the assessment finds more open items than you expected. Do not plan to use one. Deferring a requirement to the POA&M does not defer the work. It compresses the work into 180 days and adds a second assessment you have to pay for. Your contract eligibility then depends on that schedule holding.

Close gaps before the assessment

Work your internal gap list until every requirement is MET, then assess. Score each open gap with the values in 32 CFR 170.24 and sort. Three-point and five-point gaps come first, because any one of them scored NOT MET ends the possibility of a Conditional status. One-point gaps come next, and you close those too, because closing a one-point gap now costs less than tracking it through a closeout assessment. The right target for the assessment is a Final status on the first pass. The gap list is how you know you are ready before the assessment starts.

Certification assessments give you one narrow recovery window. Under 32 CFR 170.17(c)(2), a requirement scored NOT MET may be re-evaluated during the assessment and for ten business days after the active assessment period. Three conditions apply. Additional evidence must show the requirement is MET. The change cannot limit the effectiveness of other requirements already scored MET. And the findings report must not have been delivered yet. That window exists for evidence you already have and did not show. You cannot implement anything in that window. It only helps if your evidence was already organized.

Exceptions and deficiencies are not POA&M items

32 CFR 170.24(b)(1) names two situations that score MET even though something is imperfect, and neither belongs on a POA&M.

An enduring exception, defined in 32 CFR 170.4, is a special circumstance where remediation and full compliance are not feasible. The rule's examples are systems that must replicate fielded configurations, medical devices, test equipment, operational technology, and IoT. You document the exception and its mitigations in your SSP, and the requirement is assessed MET. No operational plan of action is required, because there is nothing to remediate on any date.

A temporary deficiency, also defined in 32 CFR 170.4, is a fault where remediation is feasible and a known fix is available or in process. It arises after you implemented the requirement. The definition excludes an in-progress initial implementation, allowing only a narrow case where roll-out uncovers issues in a very limited subset of equipment. The rule's example is FIPS-validated cryptography where a required patch moves you off the validated version. You track it in an operational plan of action, the artifact CA.L2-3.12.2 requires, and the requirement is assessed MET.

The operational plan of action is a third document, and 32 CFR 170.4 defines how it differs. It carries no remediation timeline, and it is not the same as a POA&M, which is tied to an assessment and to the 180-day closeout. Classify each gap honestly. A requirement you never implemented is not a temporary deficiency. Writing it into an operational plan of action does not make it MET. It makes your SSP contradict your evidence in front of an assessor. Each document answers a different question. Your gap list records what you have not built. Your operational plan of action records what broke after you built it. Your POA&M records what an assessment found and what you will finish in 180 days.

How to write a gap entry you can close

Whether an entry lives on your internal list or on a regulatory POA&M, write it so that a stranger could verify closure. Four elements make an entry real.

  1. The objective, not the topic. Assessments are scored against the assessment objectives of NIST SP 800-171A, so name the requirement and the objective that failed. An entry that says fix audit logging never closes, because nothing tells you when it is done. An entry that says AU.L2-3.3.3 objective [a], no process defines when logged events are reviewed, closes the day the process exists in an approved document.
  2. The fix, stated as an end state. Write what will be true when the entry closes and what evidence will show it, because a closeout assessment examines evidence in final form. Drafts and working papers do not score under 32 CFR 170.24.
  3. One owner, by name. A gap assigned to the IT team is assigned to nobody in particular. The owner is the person who will produce the evidence.
  4. A date that fits the deadline. On a regulatory POA&M every date must land inside the 180 days with room for the closeout assessment itself. Milestones and scheduled completion dates are what 32 CFR 170.4 says a POA&M is made of. An entry without them cannot be closed or verified.

What to do first

Open your current gap list, or start one now from your most recent self-assessment. Write the 32 CFR 170.24 point value next to every open item. Any three-point or five-point item goes to the top, because each one is, by itself, the difference between a Conditional status and no status. Then rewrite each entry until it names the objective, the end state, the owner, and the date. Read chapter 1 again for how scoring and assessment fit the wider program. Browse the published requirement pages to see the exact objectives your entries must cite. When the list is short, low-value, and honestly dated, and only then, schedule the assessment.

Next chapter 10 What assessors ask for

Chapter 10

What assessors ask for

Practitioner Guidance

An assessor does not discover your compliance. You hand it over, item by item, against a request list that is already published. The Level 2 assessment guide for CMMC, the Cybersecurity Maturity Model Certification program, prints three lists for every requirement. They name the documents that can be examined, the people who can be interviewed, and the mechanisms that can be tested. Read those lists before the assessment and you spend the week retrieving evidence you already prepared. Read them after it starts and you spend the week searching for evidence you have not organized.

Evidence must be in final form

32 CFR 170.24 sets the standard of evidence. A requirement is MET only when every applicable objective is satisfied based on evidence, and all evidence must be in final form. The rule names what is unacceptable, without limiting the list: working papers, drafts, and unofficial or unapproved policies. A policy nobody approved is still a draft, whatever it is called. A procedure that lives in an administrator's head is not evidence at all. Before the assessment, every document you intend to present needs an approval, an approver, and a date. The version you present must be the version in force.

The rule also tells you what happens when evidence falls short. For each objective marked NOT MET, the assessor documents why the evidence does not conform. The finding arrives in writing, objective by objective, with reasons. You will not talk your way past it in the closing meeting, so spend the effort before the assessment, where it changes the outcome.

The request list is already published

Every per-requirement section of the assessment guide carries three headings drawn from NIST SP 800-171A, the document that breaks each requirement into assessment objectives: Examine, Interview, and Test. Under each heading sits a list that begins with the words SELECT FROM. Those lists are the shape of every request. The assessor selects from them, and you can read every one of them today, for every requirement in scope.

The lists are specific. The examine list for AC.L2-3.1.1 names the list of active system accounts, with the name of the individual associated with each account. It names notifications of recently transferred, separated, or terminated employees, and the list of recently disabled accounts. The examine list for AT.L2-3.2.1 names the training policy, the curriculum, the training materials, the system security plan, and the training records. The examine list for AU.L2-3.3.1 names the audit and accountability policy, the system audit logs and records, and the system's auditable events. When an assessor asks you to produce your account list with a named human being beside every account, that request was printed years before your assessment was scheduled. Nothing on it is a surprise.

Two things limit how far you can rely on the lists. Nothing obliges the assessor to use every method or every object, a point chapter 5 makes and this chapter builds on. Prepare for all three methods rather than betting on one. Every examine list ends with other relevant documents or records. Treat each list as the minimum you prepare, because the assessor is not limited to what it names. The objectives still bound what the evidence must show. The lists tell you the form the requests will take.

What each method means for you

Examine

The assessor pulls documents and records and reads them. You are asked for the policy, the procedure, the system security plan, the records that prove the procedure ran, and the configuration documentation that shows the setting. The assessor names an artifact and waits for it. If you produce it in two minutes, the assessor sees a program that runs. If it takes a day of searching, the assessor sees a program assembled for the assessment.

Interview

The assessor questions your people, and not only your IT staff. The interview lists name the people who live under the safeguards, not just the people who run them. The interview list for AT.L2-3.2.1 includes personnel composing the general system user community. So a machinist, an office manager, or a project engineer can be asked what they were taught and what they do when something looks wrong. The interview list for PS.L2-3.9.2 includes personnel with personnel security responsibilities, and the people who fit that description handle hiring and terminations, not servers. Brief every population the lists name, because the assessor can reach all of them.

Test

The safeguard runs while the assessor watches. Your administrator sits at the console, performs the action, and the system either does what the policy claims or it does not. The test list for PS.L2-3.9.2 names the mechanisms for disabling system access and revoking authenticators. Expect to disable a test account and show that its sessions and credentials die with it. The test list for AU.L2-3.3.1 names the mechanisms implementing system audit logging. Expect to perform an action and then find it in the log.

Why interviews are hard to prepare for

The examine method fails companies with weak paperwork. The interview method fails companies with strong paperwork, because they treat the documents as the finish line and never tell anyone where the documents live. An assessor who has read a flawless acceptable use policy will then ask a user whether it exists, what it covers, and where to find it. If the user cannot answer, the assessor records a finding no matter how good the policy is. Objectives that require people to be made aware are satisfied by what people know, not by what you filed.

The person does not need to recite the policy. The person needs to know the policy exists, where it lives, who the security contact is, and what to do when something looks wrong. The first three are the standard the published guidance on AT.L2-3.2.1 sets for awareness evidence, and the fourth is this chapter's addition. Together they are the standard an interview applies to everyone in the room. Do not give people scripts to recite. A script fails as soon as the assessor asks a follow-up question. Make the policies short, put them in one place everyone can name, and have every person acknowledge them in writing. Then ask a user yourself, before the assessment does: where do our security policies live, and who do you call about a suspicious email. If the answer takes more than ten seconds, you have found a gap you can still fix before the assessment.

An interview can also contradict your documents. Your procedure says accounts are disabled the day a person leaves. Your administrator says it happens when someone gets to it. The assessor now has two pieces of evidence for the same finding, and the requirement is NOT MET. Fix the practice or fix the document until they say the same thing.

Show the control working

Demonstrating a configuration and describing one produce different evidence, and they score differently. Narration is your administrator explaining that sessions lock after fifteen minutes. That is interview evidence about a technical objective, and it proves what the administrator believes. Demonstration is opening the console, showing the session lock policy applied to the machines that hold CUI, Controlled Unclassified Information, and letting a session actually lock. That is the test method, and it proves what the system does.

Answer requests at the strongest level of evidence you can. Show the assessor a live console and there is nothing left to verify. Hand over a screenshot and the assessor knows only that the setting existed on that machine on that day. Describe it and the assessor writes it down, then asks for the evidence anyway. Rehearse every demonstration before the assessment: who drives, which console, which path through the menus, which test account. If your administrator has to hunt through an unfamiliar admin center, the assessor concludes that nobody operates the safeguard, even when the setting is correct.

What the C3PAO does before it arrives

A C3PAO, a CMMC Third-Party Assessment Organization, plans your Level 2 certification assessment from your system security plan, the SSP. Under 32 CFR 170.24, the SSP must be in place at the time of assessment to describe each information system within the CMMC Assessment Scope. The absence of an up-to-date SSP results in a finding that an assessment could not be completed, due to incomplete information and noncompliance with 48 CFR 252.204-7012. Under 32 CFR 170.17, the C3PAO assesses against NIST SP 800-171A within the scope set by 32 CFR 170.19 and records a result for every assessment objective. It submits the results, including the name, date, and version of your SSP, into the CMMC instantiation of eMASS, the government system that receives certification assessment results. Before anyone arrives, the C3PAO reads your SSP, confirms your scope, and builds its assessment plan from what you wrote.

Every sentence of the SSP therefore tells the assessor what to ask you for. Name a tool and the assessor asks to see the tool doing the job you named. Claim a review happens quarterly and the assessor asks for four dated records per year. Describe an enclave and the assessor asks how anything outside it is kept out. Write the SSP so that each requirement's description names the evidence that proves it. The C3PAO then builds its assessment plan out of things you have already prepared.

The rule leaves you one narrow recovery. Under 32 CFR 170.17(c)(2), a requirement assessed as NOT MET may be re-evaluated during the assessment and for ten business days after the active assessment period. Three conditions apply: additional evidence is available, the fix does not limit other requirements already MET, and the findings report has not been delivered. Use that window for a document you had but did not produce in time. It does not help with a requirement you never implemented. Chapter 9 covers the same window from the remediation side.

Build the evidence library first

Organize the evidence before the assessment, per requirement and per objective, or spend the assessment week searching while the assessor waits. The structure is mechanical. One folder per requirement, named by identifier. Inside it, the artifacts that answer each assessment objective, named so the objective letter, the content, and the date are readable without opening the file. The 110 requirements break into 320 objectives. The objective letters are the index the assessor works from, so they are the index you should file by.

Run two checks over the finished library. First, final form: no drafts, no working copies, an approval and a date on everything, per 32 CFR 170.24. Second, retrieval: pick ten objectives at random and produce the artifact for each in under five minutes.

You also keep the library after the assessment. Under 32 CFR 170.17 you must hash the artifact files with a NIST-approved algorithm. A hash is a computed fingerprint that changes if the file changes, so it proves the file stayed as submitted. You give the C3PAO the list of artifact names, the hash values, and the algorithm used, for upload into eMASS. You retain the hashed artifacts for six years from the CMMC Status Date. The file names you choose become part of the permanent assessment record. The hash records each file exactly as you submitted it, which is one more reason to keep drafts out of the library.

What to do first

  1. Pull the Examine, Interview, and Test lists for every requirement in your scope from the assessment guide, and turn them into a checklist per objective. The published pages at /requirements/ give you the objectives to index by.
  2. Build the evidence library, one folder per requirement, artifacts named by objective letter, and remove or finalize anything marked draft.
  3. Read your SSP one requirement at a time and confirm that every named tool, interval, and process has a matching artifact in the library.
  4. Rehearse the interviews. Ask a general user, a manager, and an administrator where the policies live and who the security contact is, and fix whatever takes longer than ten seconds.
  5. Rehearse the demonstrations. For each technical safeguard, decide who drives, which console proves it, and which test account you will use, and run each one once.

Interviews and demonstrations are the two methods no document can perform for you. Prepare the people and the consoles with the same discipline you give the paperwork. The assessment then becomes a week in which you retrieve things you already had.

Next chapter 11 Staying compliant

Chapter 11

Staying compliant

Practitioner Guidance

An assessment measures your systems on one day. The obligations it creates run continuously after that. Your status under CMMC, the Cybersecurity Maturity Model Certification program, takes effect the day it posts. From that day, 32 CFR 170.22 requires a named person in your company to affirm every year that you implement and maintain every applicable requirement. DFARS 252.204-7021 makes your eligibility depend on that affirmation staying current. DFARS is the Defense Federal Acquisition Regulation Supplement, the source of the cybersecurity clauses in DoD contracts. Keeping a status means doing scheduled work every year.

The annual affirmation is how the program is enforced

32 CFR 170.22 requires your Affirming Official to affirm continuing compliance in the Supplier Performance Risk System, SPRS. The affirmation is due after every assessment, including the closeout of a POA&M, the Plan of Action and Milestones that holds gaps an assessment left open, and annually thereafter. The Affirming Official is the senior official in your company who is responsible for CMMC compliance and has the authority to affirm it. The affirmation names that person. Its statement attests that you have implemented, and will maintain implementation of, all applicable security requirements for every system in the assessment scope. The official signs it once a year.

The affirmation is also what keeps your status usable. DFARS 252.204-7021 defines a current CMMC status to include an affirmation not older than one year. It requires you to complete one annually for each CMMC unique identifier, and it requires your prime to confirm the same of you before subcontract award. A Final Level 2 status with a fifteen-month-old affirmation is not current, and a status that is not current does not satisfy the clause. The Department states in its CMMC FAQ that the Affirming Official bears the legal and contractual risk of continued compliance. Choose someone senior enough to own that risk and close enough to operations to know whether the work behind the signature actually happened.

The three-year period and when it starts

A Level 2 status lasts three years. For Level 2 (Self), 32 CFR 170.16 requires you to conduct a new self-assessment every three years and submit the results in SPRS. Level 2 (C3PAO) is the status earned through a certification assessment by a C3PAO, a CMMC Third-Party Assessment Organization. For that status, 32 CFR 170.17 requires the next certification assessment to be completed within three years of your CMMC Status Date.

Know where your clock starts. The CMMC Status Date is the date your results were submitted, and 32 CFR 170.4 states that when a Conditional status is closed out, the Conditional date remains the CMMC Status Date. If you passed with a POA&M and closed it at day 170, your three years run from the original assessment, not from the closeout. Put the expiry date in writing on the day your status posts, then schedule the next assessment well inside the window. If you book a C3PAO at month 34, you are depending on that company having an open date. You do not control their schedule. Where a contract requires a certification assessment, an expired status makes you ineligible for award until a new one is achieved. On July 13, 2026 the Department suspended Phase 2 and began amending third-party assessment requirements out of active solicitations while its review runs. 32 CFR part 170 has not changed. Self-assessments and annual affirmations remain conditions of award where the clause names them. Ask your primes in writing what they will expect of you while the review runs. The program status page tracks what the Department announces next.

What breaks compliance between assessments

Companies fall out of compliance without deciding to. Four things cause it, and you will not notice any of them until an assessor or an incident finds them.

  • Configuration drift. A requirement scored MET because a setting was true on assessment day. Session timeouts get lengthened for convenience, log forwarding stops working and nobody notices, a firewall rule added for a troubleshooting session never gets removed. The requirement is now failing in an environment whose system security plan, the SSP, still says it passes.
  • New systems entering the boundary. A new server, a new SaaS subscription, a new laptop model enters the scope you drew and carries none of the hardening your assessed systems carry. Nothing about it has ever been assessed, which is exactly the condition the Department names as the trigger for reassessment.
  • Turnover hitting role-based duties. Requirements are met by named people doing recurring work. When the person who reviewed logs, ran the account review, or delivered training leaves, nobody performs the duty unless you reassign it the same week. The departure itself is also a requirement: PS.L2-3.9.2 requires system access and credentials to be terminated coincident with the personnel action, meaning at the same time as it.
  • Lapsed periodic activities. Several requirements say periodically, and 32 CFR 170.4 defines periodically as an interval you choose that may not exceed one year. RA.L2-3.11.1 risk assessments, RA.L2-3.11.2 vulnerability scans, CA.L2-3.12.1 periodic assessments, and CA.L2-3.12.4 system security plan updates carry the word in their statements. SI.L2-3.14.5's periodic malware scans run on the same definition. Your SSP states the interval you chose, and an activity that misses its own interval is a requirement no longer met. Skipping a year is not an option the rule leaves open.

The compliance calendar for a small contractor

Turn the recurring obligations into a calendar, and give every entry an owner and a deputy. Below is an example of what that calendar could look like for a small defense contractor.

  • Weekly: review the logs and the alerts. AU.L2-3.3.5 requires your review, analysis, and reporting processes to work together so that findings become investigations. SI.L2-3.14.6 requires you to monitor traffic for attacks and unauthorized connections, and a weekly look at those alerts is the smallest habit that satisfies it. Keep a dated log of each review and what it found, even when it found nothing. An assessor cannot credit a review you did not record.
  • Monthly: scan, patch, and reconcile accounts. Run the vulnerability scan RA.L2-3.11.2 requires, and remediate what it finds in risk order under RA.L2-3.11.3. Patch operating systems and applications the same month. SI.L2-3.14.1 requires flaws to be corrected within the time frame you defined. Then compare every account that exists against the list of who is authorized under AC.L2-3.1.1, and disable what nobody can justify. Check service accounts and vendor accounts closely. They are the accounts people forget to review.
  • Monthly: read the records that prove control. Review the physical access logs PE.L2-3.10.4 requires you to keep. Review your gap list and any POA&M dates under CA.L2-3.12.2. If nobody reads the plan, you will miss the dates on it.
  • Quarterly: prune software and public content. Review what is installed against the essential-only rule in CM.L2-3.4.7 and remove what nothing needs. Check everything your organization publishes for CUI and FCI under AC.L2-3.1.22, so a bad upload cannot sit exposed for a year.
  • On every hire and role change: train before access. AT.L2-3.2.1 requires managers, administrators, and users to be made aware of security risks and of your policies and procedures. A person hired after your last session has never been made aware, so awareness training belongs in onboarding, not just in the annual cycle.
  • As it happens: the event-driven entries. Run the CM.L2-3.4.4 security impact analysis before a change ships, not after. Scan removable media from outside before it touches the system under MA.L2-3.7.4. Sanitize media before disposal or reuse under MP.L2-3.8.3. Screen a person under PS.L2-3.9.1 before their CUI access begins.
  • Annually: review, assess, then affirm. Reconfirm the system inventory and hardening baselines under CM.L2-3.4.1 and CM.L2-3.4.2, and re-read the logged event list AU.L2-3.3.3 requires you to keep current. Review the incident response plan and run the exercise IR.L2-3.6.3 requires. Reconfirm who may enter your facility under PE.L2-3.10.1. Run the awareness refresher for everyone under AT.L2-3.2.1, including the insider threat indicators AT.L2-3.2.3 requires people to recognize and report. Run the RA.L2-3.11.1 risk assessment, the CA.L2-3.12.1 self-assessment, and the CA.L2-3.12.4 review of the SSP, and fix or track what they find. Then, with that evidence in hand, the Affirming Official signs the annual affirmation in SPRS.
  • Same day as any departure: offboard completely. PS.L2-3.9.2 requires a policy for terminating access coincident with personnel actions and evidence that it happened. Disable the accounts, collect badges and keys, and change any code or shared credential the person knew. A dated offboarding checklist per departure is the evidence.
  • Every three years: confirm your cloud provider still qualifies. DFARS 252.204-7012 requires a cloud service holding CUI to meet the FedRAMP Moderate baseline or its equivalent, and an authorization can lapse. FedRAMP is the federal cloud authorization program. Check the provider's status when you schedule your own reassessment.

Keep the SSP current as change happens

CA.L2-3.12.4 requires the SSP to be updated periodically. In practice, update it when the system changes, as part of the same piece of work that changes the system. If you wait and rewrite the SSP the month before reassessment, you have to research your own environment from scratch. If you update it change by change, it already matches what you run.

The Department's FAQ lays out the sequence for any change that touches Federal Contract Information, FCI, Controlled Unclassified Information, CUI, security requirements, or your scope. Before the change, perform the CM.L2-3.4.4 security impact analysis. Check the effect on CUI flow under AC.L2-3.1.3. Run the change through your CM.L2-3.4.3 change management process, and review it with the Affirming Official. During the change, track it in your CA.L2-3.12.2 operational plan of action. After the change, update the SSP and review the result with the Affirming Official before the next annual affirmation. Your next three-year assessment will test whether changes were managed the way your SSP said they would be. Failure to demonstrate adherence to the previous SSP can fail that assessment.

Which changes need a new assessment

The Affirming Official decides whether a change is significant enough to require reassessment, and the Department's FAQ gives the test. A reassessment is required when the resulting environment includes systems, configurations, or security tools that have never been assessed. It states the clear case directly. If a requirement or objective was not applicable at your assessment and a change makes it applicable, reassessment is required, because that requirement has never been assessed. Adding WiFi to an environment assessed without it puts AC.L2-3.1.16 and AC.L2-3.1.17 in front of an assessor for the first time. That forces a new assessment, whether your assessment treated them as not applicable or as met through a prohibition.

Routine maintenance is the clear case in the other direction. Patching, and replacing a security tool with a like solution of the same or better capability, are the expected changes your change management requirements exist to handle. They are not significant. The hard cases fall in between. They are major new functionality, a new security approach that the assessed SSP does not describe, and a change that removes support for a requirement. Evaluate those with the Affirming Official before implementation, not after. Once the change is in place, you either pay for a new assessment or ask the Affirming Official to sign something they know is untrue.

Incident obligations do not pause between assessments

DFARS 252.204-7012's obligations continue for the life of the contract. Chapter 1 describes what the clause requires. Discover a cyber incident and you must rapidly report it to DoD at dibnet.dod.mil. Rapidly means within 72 hours of discovery. You must also preserve images of affected systems and relevant monitoring data for at least 90 days from the report. Reporting requires a DoD-approved medium assurance certificate. Obtaining one takes time you will not have during an incident, so acquire it now and record where it lives.

An incident also lands in your compliance rhythm. The response changes configurations and systems under pressure. Route those changes through the same sequence as any other change, update the SSP, and put the incident's lessons into the next log review and risk assessment. The 72-hour report is a DFARS 252.204-7012 obligation and does not by itself alter your CMMC status. What the incident reveals about unmet requirements is exactly what the Affirming Official must weigh before signing again.

What to do first

Name your Affirming Official in writing, with the definition from 32 CFR 170.4 attached, and make sure the person accepting the title understands the annual signature it carries. Then build the calendar: every periodic activity your SSP names, with its interval, its owner, its deputy, and where its evidence lands. Add three dates to it: the affirmation anniversary, the day your reassessment window should open, and the day your status expires.

Then use change management to keep all of it current. Every change ticket answers one question before it closes. Does the SSP still describe reality? If you have not yet drawn your boundary or written that SSP, this chapter is ahead of you. Start at chapter 1, work out what information you hold and which level applies, and learn to read the requirements objective by objective.

Next chapter 12 What it costs

Chapter 12

What it costs

Practitioner Guidance

Nobody can tell you what CMMC will cost you until you have drawn your boundary. The price depends on how many systems the work covers, how much of the requirement set you already meet, and which assessment type your contract names. What you can know before you ask anyone for a quote is what you are buying, and which of your own decisions moves the number.

Why a single price does not exist

Every quote you receive is priced against a scope. Drawing your boundary explains how to decide which systems are inside that scope. That decision also sets your price.

Controlled Unclassified Information (CUI) is information the government creates, or you create for it, that a law, regulation, or government-wide policy requires or permits an agency to protect. Two companies of the same size can pay very different amounts. One put its CUI work in a small enclave. The other left it spread across the whole network.

The level sets which requirements apply. The boundary sets how many systems each requirement applies to. Ask for a quote before you have a boundary and you are asking a vendor to guess, and the guess protects the vendor.

What you are actually paying for

Costs fall into five groups. A vendor quoting an assessment fee is quoting one of them.

  • Work to close the gaps. Configuration changes, new or replaced software, and the labor to do both. This is usually the largest amount, and it is the one that varies most between companies.
  • Documents. Your System Security Plan, your policies, and your procedures. Policy and your SSP covers what these must contain. Writing them takes time whether you do it yourself or pay someone.
  • Evidence preparation. What assessors ask for explains that an assessment consumes evidence in final form. Collecting and finishing that evidence is work, and it happens before anyone arrives.
  • The assessment. For Level 2 (C3PAO) this is a fee paid to a CMMC Third-Party Assessment Organization, a private company authorized to perform certification assessments. For a self-assessment there is no fee, but the time is still yours.
  • Keeping the status. Covered below. This is the group people leave out.

What the assessment type changes, and what it does not

Level 2 (Self) and Level 2 (C3PAO) require exactly the same work. Which level applies makes this point about the requirements, and it holds for the money too. You implement all 110 requirements either way.

The assessment type changes who verifies your work. A self-assessment costs you the time to run it. A certification assessment adds the assessor's fee, and it adds the cost of being ready for someone else to check. Evidence that satisfies you may not satisfy an assessor who has never seen your systems.

Do not treat Level 2 (Self) as the cheap option and plan to upgrade later. The implementation cost is the same, and you will pay it now or pay it under time pressure when a solicitation names Level 2 (C3PAO).

What you pay every year after that

A CMMC status is maintained, not achieved. Staying compliant sets out the obligations, and each one has a cost.

You affirm continuing compliance in SPRS, the Supplier Performance Risk System, every year. That affirmation is a statement by a senior official, so someone has to check that it is still true before signing it. You reassess every three years, and for Level 2 (C3PAO) that means engaging a C3PAO again. The requirements themselves name periodic activities, so log review, vulnerability scanning, and training continue for as long as you hold the status.

Budget these as running costs from the start. A company that budgets only for certification finds the recurring bill in its third year and has not planned for it.

A conditional status means paying for two assessments

If you finish your assessment with open items on a Plan of Action and Milestones, you hold a conditional status. Gaps and your POA&M sets out the narrow conditions. 32 CFR 170.21(b) gives you 180 days to close the plan and pass a closeout assessment.

That closeout is a second engagement. For Level 2 (C3PAO), an authorized or accredited C3PAO must perform it. You are paying an assessor twice for one certification, and the second visit is on a deadline you cannot move.

Closing your gaps before the assessment is cheaper than planning around them.

Where to find the Department's own estimates

The Department of Defense published cost estimates alongside the CMMC program rule, broken out by level and by assessment type, and separately for small entities. Those figures are public and you can read them yourself.

Treat them as what they are. They are an average across a whole industry, calculated for a rulemaking, and your own number depends on the boundary you draw and the requirements you already meet. Use them to check whether a quote is in a sensible range, not to predict your own bill.

What people leave out of the budget

Four costs are commonly missed.

  • The second assessment, if you accept a conditional status.
  • The recurring cost, from the fourth year onward.
  • Evidence work, which is separate from the work of meeting the requirement.
  • Scope growth. A boundary drawn for today's contracts grows if your CUI work grows. Changes to the boundary can require a new assessment, so a boundary drawn too tightly for the contracts you expect to win costs you later.

What to do first

  1. Draw your boundary before you ask anyone for a price. Without it, no quote you receive means anything.
  2. Run a self-assessment against NIST SP 800-171A and score it under 32 CFR 170.24. Assessing yourself explains how. Your score tells you how much of the gap work is left, which is the largest and most variable cost.
  3. Write down all five cost groups above for your own situation, including the recurring ones. Do this before you talk to a vendor, so you can tell what a quote does and does not include.
  4. Ask any assessor or consultant in writing what their price excludes, and whether a closeout assessment is priced separately.

Read Drawing your boundary again before you commit to anything. Every number in this chapter moves when that line moves. The requirements you have not yet met are where the rest of the money goes.

CMMCpedia is independently maintained and is not affiliated with the U.S. Department of Defense. The content is educational. It is not legal advice, and it does not guarantee certification.