CMMC 2.0 Framework and Certification Levels
NIST SP 800-171 Implementation and DFARS Compliance
CUI Protection and Assessment Readiness
Key Takeaways
TL;DR
CMMC 2.0 is now required in DoD contracts — contractors who cannot certify at the required level are ineligible for award.
Level 2 requires implementation of all 110 NIST SP 800-171 controls and, for most contractors, a third-party C3PAO assessment.
CUI scoping and boundary definition are the most critical (and often overlooked) steps in the compliance process.
DFARS 252.204-7012 has required NIST 800-171 compliance since 2017; CMMC adds independent verification.
Prime contractors are responsible for subcontractor CMMC compliance, creating supply-chain-wide security requirements.
FAQ
Frequently asked questions
Do I need CMMC certification if I only handle FCI, not CUI?
If you only handle Federal Contract Information (FCI) and not CUI, you need CMMC Level 1, which requires implementation of 17 basic practices from FAR 52.204-21 and annual self-assessment. You do not need a C3PAO assessment. However, carefully evaluate whether any of the information you handle qualifies as CUI — many contractors underestimate their CUI exposure. If you handle any CUI, you need Level 2.
Can I use a POA&M to pass a CMMC assessment?
CMMC 2.0 allows limited use of Plans of Action and Milestones. You may have a POA&M for a subset of controls, but certain critical controls must be fully implemented at the time of assessment — there is no POA&M allowance for these. The DoD has published a list of controls that cannot be on a POA&M. Even for allowable POA&M items, remediation must be completed within 180 days of the assessment.
How long does it take to prepare for a CMMC Level 2 assessment?
For a typical small-to-mid-sized contractor starting with moderate existing controls, plan for 12 to 18 months of preparation. This includes CUI scoping (2-3 months), control implementation (6-12 months), documentation and evidence collection (ongoing), and a readiness assessment before the formal C3PAO engagement. Organizations with minimal existing controls should plan for 18 to 24 months.
Get your Cyber Defense Score™ in 60 seconds.
100 tools. No installation. No credit card. Real evidence.