The Cybersecurity Maturity Model Certification (CMMC) 2.0 is the Department of Defense's framework for ensuring that defense contractors adequately protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). If you hold or plan to hold DoD contracts, here's what you need to understand.
What Changed From CMMC 1.0 to 2.0
CMMC 1.0 had five maturity levels and introduced unique practices beyond NIST SP 800-171. CMMC 2.0 streamlined this to three levels, eliminated the unique practices, and aligned directly with existing NIST standards. Critically, CMMC 2.0 allows Level 2 contractors to self-attest in some cases — though DoD can still require third-party assessment for contracts involving critical programs or technologies.
The Three CMMC 2.0 Levels
Level 1 (Foundational) covers 17 basic safeguarding practices from FAR 52.204-21. It applies to contractors handling FCI only, and requires annual self-assessment. Level 2 (Advanced) covers all 110 practices from NIST SP 800-171. It applies to contractors handling CUI, and requires either annual self-assessment or triennial third-party assessment depending on contract criticality. Level 3 (Expert) covers 110+ practices including select NIST SP 800-172 requirements. It applies to contractors on the most critical DoD programs and requires triennial government-led assessments.
What Is CUI and Why It Matters
Controlled Unclassified Information is information the government creates or possesses that requires safeguarding per law, regulation, or policy — but is not classified. Examples include technical data, engineering drawings, export-controlled information, and personally identifiable information related to DoD programs. If your contract involves CUI, you are subject to CMMC Level 2 requirements at minimum.
The System Security Plan (SSP)
Every CMMC Level 2 contractor must maintain a System Security Plan that documents how each of the 110 NIST SP 800-171 practices is implemented across their environment. The SSP is not a one-time document — it must be kept current as your environment and controls evolve. It is the primary artifact reviewed during both self-assessments and third-party assessments.
The Plan of Action & Milestones (POA&M)
If you have practices that are not yet fully implemented, you document them in a POA&M — a structured plan showing what gaps exist, what remediation actions are planned, and when they will be completed. Under CMMC 2.0, a POA&M is acceptable at the time of assessment for practices that are partially implemented, but high-priority practices must be closed within 180 days of contract award.
Assessment Timeline and What to Expect
Third-party assessments are conducted by CMMC Third Party Assessment Organizations (C3PAOs) accredited by the Cyber AB. The assessment process includes a document review phase, an interview phase with key personnel, and a technical testing phase. Assessors verify that each practice is implemented, documented, and consistently followed. Findings result in a CMMC certification that is valid for three years.
When Does CMMC Apply to Your Contracts?
CMMC requirements are being phased into DoD contracts through the DFARS rulemaking process. As of 2025, CMMC requirements are appearing in new solicitations. Contractors should assume that any contract involving CUI will require CMMC Level 2 compliance within the next 1–2 contract cycles. Starting your readiness effort now — rather than waiting for a contract requirement — is strongly advisable.
Is Your Organization CMMC Ready?
DesignNMind provides end-to-end CMMC Level 2 readiness support — gap assessments, SSP development, POA&M management, and assessment preparation. Schedule a consultation to find out where you stand.
Schedule a CMMC ConsultationView CMMC ServicesCMMC 2.0 Quick Reference
- Level 1: 17 practices, FCI only
- Level 2: 110 practices, CUI required
- Level 3: 110+ practices, critical programs
