A plain-language guide to CMMC 2.0: the three levels, which one you need, NIST SP 800-171, C3PAO assessments, timelines, and how IT Solutions Consulting helps defense contractors get ready.
CMMC compliance is a U.S. Department of Defense (DoD) requirement that verifies contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) before they can win or keep defense contracts. IT Solutions Consulting helps organizations in the Defense Industrial Base reach CMMC 2.0 Level 1 and Level 2 through readiness assessments, gap remediation, and vCISO advisory support.
What is CMMC compliance?
CMMC compliance means meeting the Cybersecurity Maturity Model Certification (CMMC) standard the U.S. Department of Defense uses to confirm that contractors safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Compliance is mandatory for defense contractors and their subcontractors, and the required level appears in contract language.
For small and medium-sized businesses in the U.S. Defense Industrial Base (DIB), reaching compliance can be difficult with limited budget and in-house security expertise. This is where a managed service provider (MSP) with cybersecurity and compliance capabilities often supports the work, guiding contractors through readiness assessments and remediation for CMMC Level 1 and Level 2.
What are the CMMC levels?
CMMC 2.0 uses three levels that scale with the sensitivity of the information you handle, from Level 1 (Foundational) to Level 3 (Expert). Each level defines the security practices you must implement and how your compliance is assessed.
| Level | Focus | Protects | Standard | Assessment | Cadence |
|---|---|---|---|---|---|
| Level 1 (Foundational) | Basic cyber hygiene | FCI | 17 practices from FAR 52.204-21 | Self-assessment | Annual |
| Level 2 (Advanced) | Safeguarding CUI | CUI | 110 controls from NIST SP 800-171 | Self-assessment; C3PAO certification paused as of July 2026 | Every 3 years, plus an annual affirmation in SPRS |
| Level 3 (Expert) | Highest-risk programs, defense against advanced persistent threats (APTs) | CUI | NIST SP 800-171 plus selected enhanced controls from NIST SP 800-172 | Government assessment by DIBCAC | Every 3 years |
Level 1 protects FCI, meaning information generated for the government under a contract that is not intended for public release. Level 2 protects CUI, unclassified information that requires safeguarding under 32 CFR Part 2002 and the NARA CUI Registry. Level 3 applies to the DoD’s most critical programs and pulls in enhanced protections for contractors facing advanced persistent threats.
Which CMMC level do I need?
The level you need is set by the type of information you handle, and it is specified in the solicitation. If you only handle FCI, you are generally looking at Level 1 with an annual self-assessment. If you handle CUI, you need Level 2. The most sensitive work falls under Level 3.
How Level 2 and Level 3 are assessed has changed for now. Under the program’s design, Level 2 can require either a self-assessment or a third-party (C3PAO) certification, and Level 3 is assessed by the government (DIBCAC). But with Phase 2 suspended as of July 2026, contracting officers may currently designate only Level 1 (self) or Level 2 (self); C3PAO and DIBCAC certification are not being required while the program is under review. Always check the solicitation and any flow-down requirements from a prime, since those set your required level, and confirm the current assessment type in writing, because a certification clause already written into an existing contract still applies until that contract is modified.
How does CMMC relate to NIST SP 800-171?
NIST SP 800-171 is the control set behind CMMC Level 2, and the current baseline is Revision 2. To meet Level 2, an organization implements the 110 requirements in NIST SP 800-171 Revision 2 and demonstrates them using the NIST SP 800-171A assessment procedures. Level 3 then adds selected enhanced protections from NIST SP 800-172 for programs at higher risk from advanced persistent threats.
NIST published Revision 3 in May 2024, but it is not yet the CMMC requirement. The Department of Defense continues to assess CMMC Level 2 against Revision 2 and has said it will adopt Revision 3 only through future rulemaking, with advance notice expected before any transition. The practical guidance is to build and document your program to Revision 2 today, while tracking Revision 3 so a future transition is a managed project rather than a scramble.
Do I need a third-party (C3PAO) assessment?
Not right now, in most cases. On July 13, 2026, the Department of Defense suspended CMMC Phase 2, so third-party (C3PAO) Level 2 certification and government (DIBCAC) Level 3 assessment are not currently being designated in new solicitations, and existing certification requirements are being removed from contracts at the next modification. During the suspension, the required posture is self-assessment: Level 1 (self) or Level 2 (self).
Two things still hold. First, if a C3PAO or DIBCAC requirement is already written into one of your active contracts, it remains in force until that contract is formally modified, so confirm your specific awards in writing rather than assuming the requirement is gone. Second, self-assessment is not a lighter standard: you still implement NIST SP 800-171 Revision 2, post your score in SPRS, and provide an annual senior-official affirmation, so keep your evidence organized. When the reform review concludes, some form of third-party assessment may return, so staying ready is the safe posture.
What are the CMMC compliance timelines?
CMMC requirements were being phased into defense contracts over a multi-year rollout, but the schedule changed significantly in 2026. Here is where things stand as of August 2026:
- Phase 1 is active. The acquisition rule took effect on November 10, 2025, and Phase 1 introduced CMMC Level 1 and Level 2 self-assessment requirements into applicable solicitations. A current NIST SP 800-171 self-assessment posted in SPRS, with an annual senior-official affirmation, remains a condition of eligibility.
- Phase 2 is suspended. On July 13, 2026, the Department of Defense suspended CMMC Phase 2, which had been scheduled for November 10, 2026 and would have made third-party (C3PAO) Level 2 certification a condition of award. Pending and future milestones, including Level 3 (DIBCAC) assessments, are paused with it.
- A reform review is underway. A CMMC Reform Task Force is reviewing the program, prompted by concerns over compliance costs and a shortage of assessors. During the suspension, contracting officers may designate only Level 1 (self) or Level 2 (self); Level 2 (C3PAO) and Level 3 (DIBCAC) are not being required, and existing certification requirements are being removed from solicitations and, at the next modification, from active contracts.
The underlying obligation has not gone away. NIST SP 800-171 remains required through DFARS 252.204-7012 independently of CMMC, so the standard still applies. For most Level 2 teams, closing gaps against NIST SP 800-171 Revision 2 still takes months rather than weeks, especially for identity, logging, incident response, and vulnerability management, so the pause is time to get ready, not time to stop.
How do you get ready for CMMC?
Getting ready follows a repeatable path. IT Solutions recommends these seven steps:
- Scope your environment. Identify whether you handle FCI, CUI, or both, and draw a hard boundary for in-scope systems. Consider a CUI enclave to minimize disruption to the rest of the business.
- Conduct a gap assessment. Compare current practices to NIST SP 800-171, document results in your System Security Plan (SSP) and POA&M using 800-171A methods, and produce a prioritized remediation roadmap.
- Prioritize the big rocks. MFA everywhere it belongs, solid logging and monitoring, an incident response plan you can actually execute, strong access control, and an ongoing vulnerability management rhythm.
- Post and maintain your SPRS score. Use PIEE to record your 800-171 self-assessment score. Contracting officers check it.
- Schedule the assessment if required. For Level 2 solicitations that mandate certification, line up a C3PAO and prepare objective evidence. Level 3 is DIBCAC territory.
- Close POA&Ms fast. They are allowed in limited fashion and on a clock. Track owners and due dates.
- Sustain compliance. Plan on three-year certification cycles where applicable, plus annual affirmations, and keep your evidence artifacts current.
What are the consequences of CMMC non-compliance?
Failing to achieve or maintain CMMC compliance carries real consequences for organizations in the Defense Industrial Base:
- Loss of contract eligibility. Non-compliant organizations can be disqualified from bidding on, winning, or retaining contracts. CMMC status is a requirement for award under DFARS.
- Contract termination or suspension. Failing to maintain compliance or to close POA&Ms within required timeframes can lead to loss of Conditional status and termination for default.
- False Claims Act exposure. False or misleading attestations in SPRS or annual affirmations can trigger investigations and penalties under the False Claims Act, with financial and reputational damage.
- Reputational and business impact. Security incidents or non-compliance disclosures can erode trust with primes, subcontractors, and government partners.
- Legal liability. Organizations may face legal action for negligence in protecting FCI or CUI.
How does IT Solutions Consulting support CMMC compliance?
IT Solutions Consulting is a managed IT and cybersecurity provider, founded in 1994, that helps defense contractors and manufacturers in the U.S. Defense Industrial Base prepare for CMMC 2.0 Level 1 and Level 2 compliance. ITS focuses on Level 1 and Level 2 and combines gap assessments with vCISO-led advisory support to move organizations toward certification.
ITS CMMC readiness and advisory services include:
- CMMC readiness assessments. ITS performs comprehensive gap analyses aligned with the CMMC 2.0 framework to identify where your environment, policies, and documentation fall short of required controls, including technical safeguards, administrative policies, and the evidence needed for a successful assessment. Scoping often separates a CUI enclave to reduce the effort.
- Remediation and implementation support. Through the ITS vCISO Cybersecure Regulatory Program, the team addresses identified gaps with policy guidance, structured workshops, and advisory support aligned with CMMC 2.0 and NIST SP 800-171.
- Continuous compliance and advisory. The ITS vCISO team provides ongoing governance and oversight, monitors evolving DoD requirements, manages POA&Ms, and supports audit-readiness for future C3PAO or DIBCAC reviews.
Important: IT Solutions Consulting is not a certifying body. Official CMMC Level 2 certifications can only be performed by an accredited Certified Third-Party Assessment Organization (C3PAO). The ITS role is to help your organization identify and close CMMC compliance gaps before the formal certification assessment.
To pressure-test your scope, SPRS score, and schedule, book a CMMC readiness consult with IT Solutions.
Frequently asked questions
Is CMMC compliance mandatory? Yes. CMMC compliance is mandatory for U.S. Department of Defense contractors and their subcontractors, and the required CMMC status is a condition of contract award under DFARS. The specific level you must meet is set by the information you handle and appears in the solicitation.
What is the difference between FCI and CUI? FCI (Federal Contract Information) is information generated or provided for the government under a contract that is not intended for public release, safeguarded under FAR 52.204-21. CUI (Controlled Unclassified Information) is unclassified information requiring safeguarding under 32 CFR Part 2002 and the NARA CUI Registry. Which one you handle determines your CMMC level.
Can an MSP certify my business for CMMC? No. An MSP, including IT Solutions Consulting, is not a certifying body. Official Level 2 certification is performed only by an accredited C3PAO, and Level 3 is assessed by DIBCAC. An MSP helps you identify and close gaps and prepare evidence before the formal assessment.
What is SPRS? SPRS (Supplier Performance Risk System) is where your NIST SP 800-171 score and, when applicable, your CMMC status are recorded. Contracting officers check it, and you post your self-assessment score through PIEE. Without a current score or affirmation when the clause applies, expect problems at award time.
What is a POA&M in CMMC? A POA&M (Plan of Action and Milestones) documents the gaps you have not yet closed and the timeline to remediate them. CMMC permits POA&Ms only in a limited, time-boxed way, so they must be closed quickly, with clear owners and due dates.