What is CMMC 2.0?
CMMC 2.0 levels explained
CMMC 2.0 timeline and implementation
The 14 NIST SP 800-171 control families
How Cyber Defense Agent maps to CMMC requirements
Key Takeaways
TL;DR
CMMC 2.0 has three levels: Level 1 (self-assessment, 17 practices), Level 2 (third-party assessment, 110 NIST SP 800-171 requirements), and Level 3 (government assessment, NIST SP 800-172).
CMMC certification is being phased into DoD contracts starting in 2025, with full enforcement expected by 2026.
Level 2 — required for contractors handling CUI — demands implementation of all 110 NIST SP 800-171 security requirements across 14 control families.
Cyber Defense Agent addresses externally verifiable controls across multiple CMMC control families including Access Control, Risk Assessment, and System and Communications Protection.
Start preparing now — C3PAO assessment capacity is limited and contractors that begin early will have a competitive advantage.
FAQ
Frequently asked questions
Do I need CMMC if I am a subcontractor?
Yes. CMMC requirements flow down to subcontractors at all tiers if they handle FCI or CUI. Prime contractors are required to ensure their subcontractors meet the appropriate CMMC level. The specific level depends on the type of information (FCI vs CUI) the subcontractor handles, not its position in the supply chain.
How much does CMMC Level 2 assessment cost?
C3PAO assessment costs vary based on the size and complexity of your organization. For small to mid-size contractors, expect assessment costs ranging from $30,000 to $100,000 for a Level 2 certification. This does not include the cost of implementing controls and remediating gaps, which can range from $50,000 to $500,000+ depending on your current maturity. Many contractors find that the cost of non-compliance — losing eligibility for DoD contracts — far exceeds the investment in certification.
Can I use a Plan of Action and Milestones (POA&M) to pass my assessment?
CMMC 2.0 allows limited POA&Ms for some requirements that are not fully implemented at the time of assessment. However, certain critical controls (including encryption, MFA, and malicious code protection) cannot be on a POA&M — they must be fully implemented. POA&M items must be closed within 180 days of assessment, and your certification is conditional until they are resolved.
How long does it take to prepare for CMMC Level 2?
For most small to mid-size contractors starting from a limited cybersecurity baseline, expect 12-18 months of preparation. This includes conducting a gap assessment, implementing controls, developing policies and procedures, training personnel, and collecting evidence. Starting with a Cyber Defense Agent scan gives you immediate visibility into your external security gaps.
What happens if I fail my CMMC assessment?
If you fail a C3PAO assessment, you will not receive certification and will be ineligible for DoD contracts requiring that CMMC level. You can remediate the identified gaps and schedule a reassessment, but this takes time and costs additional assessment fees. The best approach is thorough preparation before engaging a C3PAO, including a pre-assessment readiness review.
Get your Cyber Defense Score™ in 60 seconds.
100 tools. No installation. No credit card. Real evidence.