In 2025, a 60-person precision machining firm in Ohio won a subcontract from a defense prime. Two weeks after the award, the prime asked for the firm’s CMMC status in SPRS. The owner had never heard of SPRS, and the IT manager had never seen the term CUI on a purchase order. The team spent the next month learning that the drawings it received every week counted as Controlled Unclassified Information, that its email and file sharing sat outside any defined boundary, and that a contract clause now tied future awards to proof of security. Many small and mid-size defense suppliers face the same surprise.
This guide explains what CMMC is, how the 2.0 levels differ, which requirements apply and where the program stands today.
What Is CMMC?
CMMC stands for Cybersecurity Maturity Model Certification. It is the US Department of War program, still widely called the Department of Defense program, that verifies whether defense contractors protect Federal Contract Information and Controlled Unclassified Information. The program turns the self-attested security promises of earlier contracts into assessed and documented results. CMMC 2.0 reduced the original five maturity levels to three, and the rule that governs it sits in 32 CFR Part 170.
Why Did The Department Of War Create CMMC?
The Department created CMMC because contractor self-attestation under DFARS 252.204-7012 left no reliable way to confirm that suppliers had implemented required controls. Sensitive design, logistics and technical data moves through long supply chains, and a single weak subcontractor can expose information that adversaries want. CMMC adds verification to the existing NIST requirements so that contracting officers can see a supplier’s real status before they award work. The program also gives primes and the Department a common, checkable standard instead of hundreds of contract-specific questionnaires.
What Are The CMMC 2.0 Levels?
CMMC 2.0 defines three levels, and each level matches the sensitivity of the information a contractor handles:
- Level 1 (Foundational): 15 basic safeguarding requirements from FAR 52.204-21 for Federal Contract Information, verified by an annual self-assessment and affirmation.
- Level 2 (Advanced): 110 requirements from NIST SP 800-171 Rev 2 for Controlled Unclassified Information, verified by self-assessment or by a C3PAO, depending on the contract.
- Level 3 (Expert): the Level 2 requirements plus 24 selected requirements from NIST SP 800-172, verified by a government-led DIBCAC assessment.

Which CMMC Level Does Your Organization Need?
The level depends on the data you handle and on the level your solicitation names. A contractor that handles only Federal Contract Information needs Level 1. A contractor that stores, processes or transmits CUI needs Level 2, and the few contractors that support the most critical programs may need Level 3. Contracts specify the required level through DFARS clause 252.204-7021, so read the solicitation and any amendments before you assume a level.
Who Must Comply With CMMC?
Every contractor and subcontractor in the Defense Industrial Base that handles FCI or CUI falls under the program when a contract includes the clause. Primes must flow the requirement down to subcontractors at the level that matches the information each one receives. Suppliers that do not touch FCI or CUI, such as a vendor selling commercial off-the-shelf products, fall outside the requirement. A subcontractor that receives CUI from a prime need the level the prime’s contract names, and outsourced IT and cloud providers that handle CUI can fall inside the assessment scope.
When Does CMMC Apply And What Is The Status Of Phase 2?
The DFARS rule took effect on November 10, 2025, which started Phase 1. Phase 1 puts Level 1 and Level 2 self-assessment requirements into applicable solicitations. The original schedule would have started Phase 2 on November 10, 2026, with mandatory C3PAO assessments for many Level 2 contracts.
On July 13, 2026, the Department of War suspended Phase 2 and launched a CMMC Reform Task Force review. A class deviation issued on September 3, 2026 directed contracting officers to follow the suspension. As of early October 2026, the Department had not published the review results or a replacement date. Phase 1 self-assessments, DFARS 252.204-7012 and NIST SP 800-171 Rev 2 remain in force, and contractors should read each solicitation for the requirement that applies.

How Does The CMMC Assessment Process Work?
The process moves through five stages. The contractor first defines the scope by identifying where CUI lives and which systems touch it. It then runs a gap assessment against the applicable requirements and remediates the findings. Next it completes a self-assessment or a C3PAO assessment, depending on the contract, and posts the result in SPRS. A senior official then affirms compliance each year. Level 2 certification from a C3PAO lasts three years.
Where Should Contractors Start Their CMMC Preparation?
Start with scoping, because every later cost and control depends on the CUI boundary. A smaller boundary reduces the number of systems to secure and the cost to prove it. Many firms move CUI into a dedicated enclave or a compliant cloud environment instead of securing the entire network. Build the System Security Plan next, then close gaps in the order of risk and score impact, and run a mock assessment so that evidence, interviews and documentation hold up under review.
Ampcus Cyber’s CMMC services cover readiness and compliance guidance, keeps evidence and control status in one place. Teams that run GRC automation usually find that an audit request becomes a report instead of a scramble.
| Talk to Ampcus Cyber’s CMMC experts to scope your CUI boundary, close Level 2 gaps and stay ready for any assessment model. |
People Also Ask
What does CMMC stand for?
CMMC stands for Cybersecurity Maturity Model Certification, the Department of War program that verifies how defense contractors protect FCI and CUI.
How many levels does CMMC 2.0 have?
Three: Level 1 (Foundational), Level 2 (Advanced) and Level 3 (Expert).
Is CMMC mandatory right now?
Phase 1 self-assessment requirements apply where solicitations include them. Phase 2 third-party requirements are suspended, so check each solicitation.
Is CMMC Phase 2 still starting on November 10, 2026?
No. The Department of War suspended Phase 2 on July 13, 2026, and no replacement date had been announced as of early October 2026.
Is NIST SP 800-171 the same as CMMC?
No. NIST SP 800-171 sets the requirements, and CMMC verifies them through assessment.
Do subcontractors need CMMC?
Yes, when they handle FCI or CUI and the contract flows the requirement down at the level that matches their data.
Enjoyed reading this blog? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn.
No related posts found.




