CMMC produces more confident wrong answers than almost any other requirement in defense contracting, partly because it reaches so many companies at once, and partly because much of what is said about it was true of an earlier version and no longer is. This page collects the misconceptions and the questions that come up most often in readiness conversations and answers them plainly, with links to the fuller treatment elsewhere in the guide.
1Common Myths
"CMMC keeps getting delayed, so there is no need to act yet."
Both rules that make CMMC binding are now in force. The program rule at 32 CFR Part 170 took effect in December 2024, and the acquisition rule that places CMMC into contracts took effect on November 10, 2025, which started the phased rollout. Phase 1 is live now, and Phase 2, which requires a third-party Level 2 certification for most contracts involving CUI, begins on November 10, 2026. Because readiness commonly takes a year or more, the interval between today and the next relevant solicitation is the thing to plan around, as Foundations sets out in detail.
"We only handle FCI, so CMMC does not apply to us."
Handling FCI places a contractor at Level 1, with fifteen basic safeguarding requirements and an annual self-assessment, so CMMC does apply, at the lower level. The moment any CUI enters the environment, the requirement rises to Level 2 and its 110 requirements. The question is never whether CMMC applies but at what level, and the level is set by the information a given contract involves rather than by the company.
"We can become compliant after we win the contract."
The rule closed that door. A CMMC status has to be current at the time of award, including at the award of an option, and there is no post-award period in which to finish the work. A contractor that treats the solicitation, or the option notice, as the moment to begin readiness has already missed the window, a point CMMC and Existing Contracts works through in full.
"We were told a company could certify us in thirty days."
A promise like that is worth reading closely, because it usually means something narrower than it sounds. A software platform can stand up documentation and a scoring dashboard quickly, and a gap review can be scheduled fast, but building the 110 requirements into a working environment, maturing the evidence behind them, and passing a third-party assessment is not a thirty-day exercise for an organization starting from a standing start. Readiness commonly runs twelve to eighteen months, and a certified assessor books months ahead. When a vendor compresses all of that into thirty days, what they are describing is almost always the setup rather than the certification.
"We can certify our own company."
CMMC is precisely the move away from that. The program replaced the older habit of self-attestation with verification, and a Level 2 certification is a determination made by a certified third-party assessor rather than something a company grants itself. A self-assessment does still exist for Level 1 and for the Level 2 contracts that permit one, but even then it is a formal, scored assessment under the DoD methodology, affirmed by a senior official and posted to SPRS, and it carries False Claims Act exposure if the affirmation is wrong. The word certified belongs to the third-party path, and the self path is a rigorous assessment rather than a checkbox, as The Assessment describes.
"A plan of action lets us defer whatever we have not finished."
A plan of action is far narrower than that reputation suggests. It can carry only requirements worth a single point, the assessment score has to reach at least 88 of 110 to qualify for a conditional status at all, six named one-point requirements are excluded from it, and every deferred item has to be closed within 180 days. The requirements that carry the most weight, the three-point and five-point ones, cannot be deferred, as Core Concepts explains.
"We hold ISO 27001, AS9100, or SOC 2, so we are essentially compliant."
None of those establishes CMMC compliance. ISO 27001 is the closest in subject, but it is risk-based and self-scoped rather than prescriptive, so a certificate does not map onto the fixed set of 110 requirements. AS9100 governs quality rather than information security, and a SOC 2 report attests to a different set of criteria for a different audience. Each can be useful groundwork, and none of them is a substitute, a distinction drawn out in Foundations.
"CMMC is only for prime contractors and large companies."
The requirement flows down. A prime that holds a CMMC obligation must flow it to the subcontractors that handle FCI or CUI, at the level appropriate to what each handles, so the smallest shop deep in the supply chain can carry the same Level 2 obligation as the prime above it. The defense industrial base is counted in the hundreds of thousands of companies, most of them small, and the program was designed to reach the information wherever it lives.
"We can get certified through a GRC software tool."
A governance and compliance platform is genuinely useful for organizing policies, tracking evidence, drafting a system security plan, and watching a SPRS score move, but a tool does not confer a CMMC status. Certification comes from an assessment, conducted by a certified third-party assessor for Level 2 and by the government for Level 3, or from a self-assessment where the contract permits one. The software helps a contractor prepare and stay organized, while the assessment is a separate event conducted by people, against evidence, within a defined scope, so buying the platform is the beginning of the work rather than the end of it.
"Our IT provider handles CMMC for us."
A managed provider can implement and operate controls, but the compliance obligation stays with the contractor. An external or cloud provider whose services touch the CUI environment is itself within the assessment scope, its responsibilities have to be documented in a customer responsibility matrix, and the contractor remains the party that affirms compliance and bears the consequence if that affirmation turns out to be wrong. Outsourcing the work does not outsource the accountability.
"We are required to use Microsoft GCC High."
GCC High is a common and often sensible environment for handling CUI, but it is not mandated. What the rules require is that a cloud service handling CUI meet the FedRAMP Moderate baseline, or a documented equivalency, and more than one offering can satisfy that. A compliant platform is also a foundation rather than a finish line, because the 110 requirements still have to be implemented across the people and processes that use it. The right environment depends on the CUI involved and the contract, not on a single product.
2Frequently Asked Questions
Who actually needs CMMC?
Any organization in the defense industrial base that processes, stores, or transmits FCI or CUI under a Department of Defense contract, including subcontractors and suppliers, at the level the contract requires. Handling only FCI means Level 1; handling CUI means Level 2 or, for the most sensitive programs, Level 3.
Self-assessment or a third-party assessment?
It depends on the contract and the phase of the rollout. Level 1 is always a self-assessment. Some Level 2 contracts permit a self-assessment, but most work involving CUI will require a certified third-party assessment as Phase 2 takes effect, and the contract states which applies. The Assessment describes how a certification assessment is conducted.
How long does readiness take?
For an organization starting without a mature NIST SP 800-171 program, twelve to eighteen months is common, and third-party assessment scheduling adds further time. The practical consequence is that readiness has to begin well before the contract that will require it, because the interval between a solicitation and an award is far too short to build and assess an environment inside it.
Can the firm that prepares us also assess us?
No. A provider that helped prepare an organization, and the assessors that provider employs, cannot take part in that organization's certification assessment, with the separation measured in years. Readiness and assessment are structurally separate functions, for the same reason an auditor does not audit their own work, as Reference and Glossary explains.
What happens if we score below the threshold?
A score below 88 of 110, or remaining gaps that are not eligible for a plan of action, produces neither a final nor a conditional status, and no award follows for a contract that requires the level. The path forward is to remediate the gaps and reassess, which is why an honest internal score well before the assessment is worth more than an optimistic one.
Do we follow NIST SP 800-171 Rev 2 or Rev 3?
CMMC Level 2 is pinned to Revision 2, even though NIST has since issued Revision 3. The standard the program enforces is Revision 2 until the government moves it, so a readiness effort should be built against Rev 2 and its assessment objectives.
Does CMMC apply to a contract we already hold?
This comes up often enough to have its own page. In short, a contract awarded before CMMC existed does not automatically acquire the requirement in the middle of performance, but options, new orders, and modifications are all entry points, and if the work involves CUI the underlying NIST SP 800-171 obligation is very likely already owed. CMMC and Existing Contracts works through the mechanism.
When a myth turns into a real question
Clearing up what CMMC does and does not require is the easy part. Applying it to a specific environment, with its own scope, evidence, and gaps, is onsite readiness work, from the first scoping walk through the pre-assessment review. That is the practice behind this guide.
Start CMMC Readiness or call 802-335-26623Sources
- 32 CFR Part 170, CMMC Program, including the levels, the scoring and plan of action rules, and the phase-in schedule. ecfr.gov
- 48 CFR CMMC Acquisition Rule and DFARS 252.204-7021 and 252.204-7025, which place the requirement into contracts and require a current status at award. acquisition.gov
- NIST SP 800-171 Rev 2 and NIST SP 800-171A, the 110 requirements and assessment objectives to which CMMC Level 2 is pinned. csrc.nist.gov
- The Cyber AB and ISACA, for the ecosystem roles and the independence separation between readiness and assessment. cyberab.org