Chapter 01
What is CMMC
Practitioner Guidance
CMMC is a verification program. It adds no new security rules. It checks whether you have implemented the requirements your Department of Defense contracts already carry. It makes the result a condition of award.
What CMMC is
The Cybersecurity Maturity Model Certification is a Department of Defense (DoD) program. It verifies that a contractor has implemented the safeguarding requirements for Federal Contract Information and Controlled Unclassified Information. Federal Contract Information (FCI) is information the government provides, or you generate for the government, under a contract, and that is not intended for public release. Controlled Unclassified Information (CUI) is information the government creates, or you create for it, that a law, regulation, or government-wide policy requires or permits an agency to protect. The program rule is 32 CFR part 170. The contract clause that applies it to you is DFARS 252.204-7021. DFARS is the Defense Federal Acquisition Regulation Supplement, the set of contract clauses DoD adds to its contracts. When that clause is in your contract, you must hold a current CMMC status at the level the contracting officer names before award. You must keep that status for the life of the contract. You must also flow the correct level down to every subcontractor that will handle FCI or CUI.
The requirements themselves are older than the program. Level 1 uses the fifteen safeguards in FAR 52.204-21, a clause from the Federal Acquisition Regulation, the rulebook for all federal contracts. Level 2 uses the 110 security requirements in NIST SP 800-171 Revision 2, the government publication that lists the security requirements for protecting CUI. DFARS 252.204-7012 has required contractors to implement NIST SP 800-171, in whichever revision was current, since the end of 2017. CMMC adds a verification step. The program rule describes CMMC as a way of verifying that requirements which already apply have been implemented.
Why it exists
For years the only check on a contractor's implementation of NIST SP 800-171 was the contractor's own word. A company signed a contract carrying DFARS 252.204-7012 and agreed to implement the requirements. Nobody verified that it had. CMMC exists because the Department decided that a self-reported claim was not enough protection for the information it shares with its suppliers. Under the program, DoD verifies your implementation before it awards the contract. For contracts that handle the more sensitive information, it requires a third party to do the verifying.
How it relates to DFARS 252.204-7012
CMMC does not replace DFARS 252.204-7012, and it does not change it. The program rule states that CMMC does not alter any separately applicable requirement to protect FCI or CUI, and it names 252.204-7012 directly. That clause still requires you to implement NIST SP 800-171 and to report a cyber incident to DoD within 72 hours of discovering it. Its other obligations around cloud services and incident evidence still stand. DFARS 252.204-7019 and 252.204-7020 still require a NIST SP 800-171 DoD Assessment score in the Supplier Performance Risk System (SPRS), the DoD database that holds assessment results.
Read the two clauses as a pair. 252.204-7012 requires you to protect the information. 252.204-7021 requires you to prove that you have.
The phased rollout
The program rule brings CMMC into contracts over four phases. Each phase starts one year after the last, counted from the effective date of the acquisition rule that created the 252.204-7021 clause. Two abbreviations appear in the phase names. A C3PAO is a CMMC Third-Party Assessment Organization, a private company authorized to perform certification assessments. DIBCAC is the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center, the government's own assessment team.
- Phase 1: DoD includes Level 1 (Self) or Level 2 (Self) as a condition of award in applicable solicitations, and may require Level 2 (C3PAO) at its discretion.
- Phase 2: DoD includes Level 2 (C3PAO) as a condition of award in applicable solicitations, and may require Level 3 (DIBCAC).
- Phase 3: Level 2 (C3PAO) applies to all applicable solicitations and to option periods on contracts awarded after the effective date. Level 3 (DIBCAC) becomes a condition of award where it applies.
- Phase 4: full implementation, including option periods on contracts awarded before Phase 4 began.
That schedule is suspended. On July 13, 2026 the Department suspended the transition to Phase 2 and opened a review of the program. The suspension also covers pending and future CMMC implementation milestones in its solicitations and contracts. Phase 1 self-assessment requirements remain in place. DFARS 252.204-7012 still binds every contractor that handles covered defense information, the clause's term for the CUI a defense contract covers. The phases above remain the rule text, because 32 CFR part 170 has not changed. The program status page tracks the suspension and what the Department does next.
During the rollout the program manager or requiring activity decides which solicitations carry the clause. Do not read that discretion as a reason to wait. The rule allows a waiver only in advance of a solicitation. Once the requirement appears in a solicitation, there is no process to remove it. There is also not enough time left to earn the status it requires.
The three levels
Level 1 applies when you handle FCI and no CUI. Level 1 is the fifteen safeguards in FAR 52.204-21, assessed against the NIST SP 800-171A objectives that map to them. NIST SP 800-171A is the assessment companion to NIST SP 800-171. It breaks each requirement into the objectives an assessor checks. You assess yourself every year, enter the result in SPRS, and a senior person in your company affirms it. Every safeguard must be met. No plan of action is permitted at Level 1.
Level 2 applies when you handle CUI. It is the 110 requirements of NIST SP 800-171 Revision 2, exactly as written. The contract decides which kind of assessment you need. Level 2 (Self) is a self-assessment you enter in SPRS. Level 2 (C3PAO) is a certification assessment performed by an authorized third-party assessment organization, which uploads the result to DoD. Either way, the status lasts three years, and you affirm continuing compliance every year in between. If you are a subcontractor that will handle CUI and the prime contract requires Level 2 (C3PAO), then Level 2 (C3PAO) is your minimum too. This reference covers Level 2.
Level 3 adds selected requirements from NIST SP 800-172, a companion catalog of enhanced security requirements, on top of a Final Level 2 (C3PAO) status. DIBCAC performs the assessment. Level 3 is reserved for the Department's most critical programs and is beyond this reference.
Nobody can waive it for you
A contracting officer cannot waive CMMC for you, and neither can your prime. The rule reserves the waiver decision to a Service or Component Acquisition Executive, in very limited circumstances. A waiver applies to the solicitation as a whole, before it is issued. Even then the rule states that contractors remain obligated to comply with every applicable cybersecurity requirement. A waiver removes the verification. You still have to do the work.
Your prime is also bound the other way. Under 252.204-7021 the prime must confirm that you hold a current CMMC status at the correct level before it awards you the subcontract. A prime that tells you the requirement does not apply to you is either wrong or has already decided you will not be handling FCI or CUI. Get that decision in writing.
How the requirements are assessed
The requirements are assessed with NIST SP 800-171A, which breaks the 110 requirements into 320 assessment objectives. A requirement is scored MET only when every applicable objective is satisfied on evidence that is in final form. If one objective is not satisfied, the whole requirement is NOT MET. Drafts, working papers, and unapproved policies do not count as evidence. Two situations still score as MET. The first is an enduring exception that you describe, along with its mitigations, in your system security plan (SSP), the document that describes how your system meets each requirement. The second is a temporary deficiency that you track in an operational plan of action with progress toward the fix.
Only the requirement statement and its assessment objectives can fail you. The discussion text in NIST SP 800-171 and the further discussion in the CMMC Assessment Guide are explanatory. They exist to help you understand a requirement, not to extend it, and an assessor cannot base a finding on them. Every requirement page on this site quotes the requirement and its objectives verbatim, so you can see exactly what you are being measured against. AT.L2-3.2.1 is a good first example.
Scoring starts at 110 and subtracts one, three, or five points for each requirement NOT MET. Partial credit is available for two requirements, multifactor authentication and CUI encryption. A Plan of Action and Milestones (POA&M) is a tracked list of open items with deadlines. The rule allows one only in narrow circumstances. You may hold a Conditional Level 2 status with open items only if your score is at least 88 and every requirement on the plan is worth one point. The single exception is CUI encryption, SC.L2-3.13.11. It may sit on the plan at three points when you encrypt but the encryption is not FIPS validated, meaning the cryptographic module does not hold a government validation certificate. Six requirements can never be on the plan: AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, and PE.L2-3.10.5. You then have 180 days to close the plan and pass a closeout assessment, or the status expires. A POA&M does not make a requirement MET. It stays NOT MET until you fix it.
What to do first
Read the contract before you do anything else. Find DFARS 252.204-7012, 7019, 7020, and 7021 in it, or in the flow-down from your prime, and note the CMMC level named in 7021. That level tells you how many requirements you have to implement. No vendor or consultant can tell you what it is without reading the same clause.
Then work through the next three chapters in order. Chapter 2, CUI or FCI, tells you how to work out which kind of information you actually hold. Chapter 3, Which level applies, turns that answer into the level your contract will require. Chapter 4, Drawing your boundary, shows you how to limit where that information lives so the rest of the work stays small. Do not buy anything until you have finished chapter 4.
Next chapter 02 CUI or FCI