DKDavid Koran& Associates
Home The CMMC Guide Part I · Foundations
The CMMC Guide · Part I

Foundations

What CMMC is, the three levels, the rules that bind it, the phase-in schedule, and how a contract turns a requirement into an obligation.

1What CMMC Is

The Cybersecurity Maturity Model Certification is the Department of Defense program that verifies whether the companies in its supply chain actually protect the sensitive information the government entrusts to them. It does not invent new security requirements. It takes standards that already existed and adds the one thing they lacked: a way to check.

Two kinds of information are at stake, and the whole program turns on the distinction. Federal contract information, or FCI, is information provided by or generated for the government under a contract to deliver a product or service, and not intended for public release. Controlled unclassified information, or CUI, is information the government creates or possesses, or that a contractor creates or possesses on the government's behalf, that a law, regulation, or governmentwide policy requires to be safeguarded. FCI is the broader, lower-sensitivity category; CUI is the narrower, more sensitive one, and it carries the heavier obligations.

For years the government's approach to protecting this information rested on self-attestation. A contractor implemented the applicable security requirements, scored its own compliance, and represented that it had done so. The safeguarding obligations were real and long-standing, but the verification was a signature. CMMC is the shift from that signature to a check: at the lower level a self-assessment made under the program's rules and affirmed by a senior official, and at the higher levels an assessment conducted by an independent third party or by the government itself. The requirements are largely the same ones that were already owed. What changes is that a contractor now has to demonstrate them, and at most levels prove them to someone else, before it can hold the work.

2CMMC and Its Look-Alikes

Several other regimes sit close enough to CMMC in a contractor's mind that they are routinely confused with it. Some share the maturity-model name, some govern the same data, and some are simply the other certificate on the wall in an aerospace shop. None of them is CMMC, and holding one does not satisfy it. Four come up most often.

C2M2, the Cybersecurity Capability Maturity Model. A voluntary self-evaluation tool published by the U.S. Department of Energy, used mainly by energy and critical-infrastructure organizations to gauge and improve their cybersecurity across defined domains. It shares the maturity-model lineage and much of the vocabulary, which is the source of the confusion, but it is self-administered, certified by no one, and attached to no DoD contract. A strong C2M2 result says nothing about CMMC compliance.

ITAR, the International Traffic in Arms Regulations. Administered by the State Department's Directorate of Defense Trade Controls under the Arms Export Control Act, ITAR governs the export and transfer of defense articles, services, and technical data on the United States Munitions List, including which persons, by nationality, may access that data. It is an export-control regime, not a cybersecurity assessment. The overlap is genuine, because ITAR-controlled technical data is frequently also CUI, so a manufacturer may owe both: ITAR to control who may see and export the data, and CMMC to secure it. Meeting one does not meet the other, because they answer different questions about the same drawing.

AS9100, the aerospace quality standard. Maintained by the International Aerospace Quality Group and built on ISO 9001 with aerospace additions, AS9100 is a quality management system certified by accredited registrars. It governs how a shop controls quality, not how it protects information. Many of the aerospace and defense manufacturers that need CMMC already hold AS9100, which is why the two are mentioned together, but the certificate speaks to product quality and traceability, not to the protection of CUI, and there is no crosswalk from one to the other.

ISO/IEC 27001, the information security standard. Sometimes written simply as ISO 27001, this is the international standard for an information security management system, certifiable by accredited bodies. Of the four it is the closest to CMMC in subject, because it is genuinely about information security. The differences are structural. ISO 27001 is risk-based: the organization defines its own scope and its Statement of Applicability, and the certificate attests that a management system exists and functions. CMMC Level 2 is prescriptive: it requires a fixed set of 110 controls from NIST SP 800-171 Rev 2, assessed against defined objectives, and it is imposed by DoD contracts. A company can hold ISO 27001 and still fall short of CMMC Level 2, because the control sets, the scoping, and the assessment all differ. ISO 27001 can be useful groundwork, but it is not a substitute.

FrameworkWhat it governsAdministered byRelationship to CMMC
C2M2Cybersecurity maturity, by self-evaluationU.S. Department of EnergyVoluntary and uncertified; shares the maturity-model name but is not a DoD contract condition
ITARExport of defense articles and technical dataU.S. Department of State (DDTC)Mandatory where it applies; governs who may access and export data that is often also CUI, a different question than how CMMC secures it
AS9100Aerospace quality managementAccredited registrars (IAQG standard)Common among CMMC-bound manufacturers, but a quality certificate unrelated to CUI protection
ISO/IEC 27001Information security management systemAccredited certification bodiesClosest in subject, but risk-based and self-scoped rather than prescriptive; certification does not establish CMMC compliance

3The Three Levels

CMMC is organized into three levels, each matched to the sensitivity of the information involved. A company does not choose its level. The information it handles under a given contract determines the level that contract will require.

LevelInformation protectedRequirementsHow it is assessed
Level 1FCI15 requirements, from the basic safeguarding rule (FAR 52.204-21, renumbered FAR 52.240-93 in 2026)Annual self-assessment and affirmation
Level 2CUI110 requirements, from NIST SP 800-171 Rev 2Self-assessment or C3PAO certification every three years, plus annual affirmation
Level 3CUI of the highest sensitivity134 requirements: the 110 from NIST SP 800-171 Rev 2 plus 24 enhanced requirements from NIST SP 800-172Government (DIBCAC) certification every three years, plus annual affirmation

Level 1 is the floor, covering any contractor that handles FCI, assessed by the contractor itself each year. Level 2 is where most of the defense industrial base concerned with CUI will live, and it is the level this guide treats control by control across its Part III. Whether a Level 2 requirement is met by self-assessment or by a certified third-party assessment organization, the C3PAO, depends on the contract and the phase of the rollout. Level 3 adds a subset of the enhanced requirements from NIST SP 800-172 for the most sensitive programs and is assessed by the government's own Defense Industrial Base Cybersecurity Assessment Center. At every level, a senior official must affirm continued compliance each year, which turns compliance from a one-time event into a standing obligation.

A level attaches to the contract and the environment, not to a person or a department

A reasonable question follows from this, and it comes up often on the shop floor: if some staff, say a billing group, only ever handle FCI and never see CUI, do they need only Level 1? CMMC levels do not attach to people or to departments. They attach to contracts and to the information systems that carry a contract's information. A billing clerk does not hold a personal CMMC level, and a company does not run one department at Level 1 and another at Level 2. The required level for a contract is set by the most sensitive information that contract involves, so a contract that includes CUI requires Level 2 of the contractor.

What the billing example actually raises is a scoping question rather than a level question. If the billing systems genuinely never process, store, or transmit CUI, and they are separated from the environment that does, those systems can sit outside the Level 2 assessment scope. That is sound practice, because it narrows both the assessment and the attack surface. It depends on real separation rather than an assertion, because if CUI can reach the billing system through an invoice, an ERP record, or a contract document, then that system handles CUI and falls inside the scope.

Placing a function outside the Level 2 assessment does not make it obligation-free, because FCI must be safeguarded wherever it lives. A billing system that handles FCI still owes the basic safeguarding requirements that Level 1 codifies, even while it sits outside the Level 2 boundary. The practical result is therefore not that billing runs at Level 1 while engineering runs at Level 2, but that the CUI environment is assessed against the 110 requirements while the separated FCI systems continue to meet the 15. The detailed scoping model, including the asset categories that decide what falls in and out, is the subject of Part II.

The short version
A contract that involves CUI requires Level 2 of the contractor, and staff who handle only FCI do not create a Level 1 department inside that obligation. Their systems can be scoped out of the Level 2 assessment when they are truly separated from CUI, and those systems still owe the basic FCI safeguards either way.

4The Regulatory Stack

CMMC can look like a single thing, but it is assembled from several layers of authority, each doing a different job. Understanding which layer does what is the fastest way to make sense of the program, because a question that seems unanswerable at one layer is usually settled cleanly at another.

The technical standard. At the base sit the requirements themselves. For CUI and Level 2 that is NIST SP 800-171 Rev 2, which states 110 security requirements, together with NIST SP 800-171A, which decomposes each requirement into the assessment objectives an assessor actually checks. For FCI and Level 1 it is the basic safeguarding rule, with its 15 requirements. For Level 3 it is a subset of NIST SP 800-172. CMMC remains pinned to Revision 2 of 800-171 even though NIST has since published Revision 3, so the standard the program enforces is a fixed target, not a moving one.

The safeguarding clause. Above the standard sits DFARS 252.204-7012, the safeguarding and cyber incident reporting clause that has obligated defense contractors to implement NIST SP 800-171 for years, together with the provisions that required a self-assessment score to be posted in the Supplier Performance Risk System, the SPRS. This layer is why the substance of Level 2 is not new to most contractors: they already owed these controls. What this layer never included was independent verification.

The program rule. 32 CFR Part 170, effective December 16, 2024, is the CMMC Program rule. It defines the program itself: the three levels, the assessment types, the roles of the accreditation body and the C3PAOs and DIBCAC, the scoring methodology, the rules for plans of action and milestones, the annual affirmations, and the phase-in schedule at 32 CFR 170.3(e). It is the rulebook for how CMMC works. What it does not do, on its own, is put CMMC into a contract.

The acquisition rule. That last step is the job of the 48 CFR CMMC acquisition rule, the amendment to the Defense Federal Acquisition Regulation Supplement that was published in the Federal Register on September 10, 2025 and took effect on November 10, 2025. It amends 48 CFR Parts 204, 212, 217, and 252, and it authorizes contracting officers to place the CMMC requirement into solicitations and contracts and to make it a condition of award. Before this rule, 32 CFR Part 170 was a fully built framework with no contractual hook. After it, CMMC has teeth.

The shape of it
Four layers, four jobs. The standard says what to do. The safeguarding clause has long required it. The program rule defines how compliance is assessed and certified. The acquisition rule puts it into contracts. A contractor feels all four at once, as a single requirement in a solicitation, but the answers to most CMMC questions live at one specific layer.

5The Clauses

In practice a contractor encounters CMMC as a set of clauses in a solicitation or contract. Three matter most, and a 2026 renumbering has changed some of the citations without changing the obligations.

DFARS 252.204-7012 remains the safeguarding and incident reporting clause. DFARS 252.204-7021 is the CMMC clause proper: it requires the contractor to hold, and to maintain for the life of the contract, a current CMMC status at the level the contract requires. The solicitation provision, DFARS 252.204-7025, requires the solicitation itself to state the required CMMC level, so that a bidder knows the bar before it bids.

On February 1, 2026, a set of class deviations tied to the Revolutionary FAR Overhaul, the acquisition-regulation restructuring that began with Executive Order 14275 in April 2025, renumbered several of the cybersecurity citations. The basic safeguarding rule moved, the older self-assessment provision was retired, and one clause was relocated, while the CMMC clauses and the safeguarding clause kept their numbers. The changes are citations, not substance: the obligations are the same, and these are interim class deviations with formal rulemaking still to follow.

What it coversBefore February 1, 2026From February 1, 2026
Basic safeguarding of FCI (Level 1)FAR 52.204-21FAR 52.240-93
Safeguarding CUI and incident reportingDFARS 252.204-7012Unchanged
NIST SP 800-171 self-assessment in SPRSDFARS 252.204-7019Eliminated
Subcontractor SPRS requirementDFARS 252.204-7020DFARS 252.240-7997
CMMC compliance, maintain required statusDFARS 252.204-7021Unchanged
Required CMMC level stated in the solicitationDFARS 252.204-7025Unchanged

The practical consequence is small but real: a solicitation issued after February 1, 2026 uses the new citations, while older contracts and much of the guidance written before then use the old ones. A reader who knows both will not be thrown when the same obligation appears under two different numbers.

6The Phase-In Schedule

CMMC did not arrive all at once when the acquisition rule took effect. 32 CFR 170.3(e) sets out a phased rollout over three years, in four phases, each beginning one year after the one before it, reaching full implementation 36 months after the rule's effective date. The design lets the assessment ecosystem, the C3PAOs and the assessors, scale up as the requirement widens.

PhaseBeginsWhat it introduces
Phase 1November 10, 2025Level 1 and Level 2 self-assessment requirements in applicable new solicitations and contracts; Level 2 C3PAO certification at the Department's discretion for select contracts
Phase 2November 10, 2026Level 2 C3PAO certification required for most contracts involving CUI
Phase 3November 10, 2027Broader Level 2 C3PAO certification, and Level 3 DIBCAC certification where applicable
Phase 4November 10, 2028Full implementation across all applicable solicitations and contracts

As this part is written, Phase 1 is in effect and Phase 2 begins on November 10, 2026. The distinction between the phases is largely the distinction between self-assessment and third-party certification: Phase 1 leans on the contractor's own assessment, and the later phases push the more sensitive work toward the C3PAO and, for Level 3, toward the government. A contractor's exposure therefore depends not only on the information it handles but on when the contracts it wants fall within the widening scope.

7How a Contract Triggers a Requirement

CMMC does not apply to a company in the abstract. It applies through a contract, and the mechanism is worth following step by step, because it explains why timing varies so widely from one contractor to the next.

The requiring activity or program office determines the CMMC level an acquisition needs, based on the information the work involves. The solicitation states that required level. The resulting contract carries DFARS 252.204-7021, which obligates the contractor to hold and maintain the required CMMC status throughout performance. Before award, the contracting officer checks the contractor's status in the SPRS, and cannot award to an offeror that lacks the current required status. The requirement then flows down: subcontractors that handle FCI or CUI must meet the level appropriate to what they handle. What began as a decision inside a program office ends as an eligibility condition running through the whole supply chain for that work.

The reading this guide takes, consistent across its author's published work, is that the defining feature of this design is that it is not a single national deadline. The obligation crystallizes for a given company at the moment a clause lands in a contract it wants or already holds, which means two similar companies can face very different timing depending only on their contract calendars. The weight of CMMC therefore lands gradually and unevenly, concentrating as Phase 2 and Phase 3 widen third-party certification through 2026 and 2027, and it is felt first through prime contractors flowing requirements down to their suppliers ahead of the formal phases.

That has a practical implication the calendar makes unavoidable. The interval between a solicitation and an award is short, while the work of scoping an environment, remediating the gaps, assembling the evidence, and passing an assessment is long, often a year or more, so readiness that begins when the solicitation appears begins too late. The requirement arrives quietly, through the ordinary administration of contracts, which is precisely why it is easy to underestimate until it is already binding.

A question that follows directly from this mechanism, what happens to a contract already in performance that was awarded before the requirement existed, is common enough to warrant its own treatment, and it is examined in depth in CMMC and Existing Contracts.

From the foundations to a specific environment

This part explains how CMMC is built and how it reaches a contractor. Turning that into a scoped environment, remediated gaps, and evidence an assessor will accept is onsite readiness work, from the first scoping walk through the pre-assessment review. That is the practice behind this guide.

Start CMMC Readiness or call 802-335-2662

8Sources

  1. 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program, effective December 16, 2024, including the phase-in schedule at 32 CFR 170.3(e). ecfr.gov
  2. 48 CFR CMMC Acquisition Rule (DFARS Case 2019-D041), amending 48 CFR Parts 204, 212, 217, and 252, published in the Federal Register September 10, 2025 and effective November 10, 2025; DFARS subpart 204.75. ecfr.gov
  3. DFARS 252.204-7021, Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirements, and the related solicitation provision DFARS 252.204-7025. acquisition.gov
  4. DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. acquisition.gov
  5. NIST Special Publication 800-171 Rev 2 and NIST SP 800-171A for the Level 2 requirements and assessment objectives, and NIST SP 800-172 for the Level 3 enhanced requirements. csrc.nist.gov
  6. FAR 52.204-21 (basic safeguarding, renumbered FAR 52.240-93) and DoD class deviation 2026-O0025, the Revolutionary FAR Overhaul renumbering of the cybersecurity clauses effective February 1, 2026, which began with Executive Order 14275 (April 2025).
← The CMMC Guide
Return to the guide index
Part III →
The 110 Level 2 Controls
About the Author
David W. Koran is a CyberAB Registered Practitioner Advanced and the author of The CMMC Decision, now in its second edition. He works onsite with defense contractors and their counsel, from the first leadership briefing through the pre-assessment review. Reach him at 802-335-2662 or dkoran@davidkoran.com.
Part I: Foundations · Edition 2026.1 · Last reviewed July 12, 2026