What is CMMC? Levels, Requirements & Timelines Explained

A plain-language guide to CMMC 2.0: the three levels, which one you need, NIST SP 800-171, C3PAO assessments, timelines, and how IT Solutions Consulting helps defense contractors get ready.

CMMC compliance is a U.S. Department of Defense (DoD) requirement that verifies contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) before they can win or keep defense contracts. IT Solutions Consulting helps organizations in the Defense Industrial Base reach CMMC 2.0 Level 1 and Level 2 through readiness assessments, gap remediation, and vCISO advisory support.

What is CMMC compliance?

CMMC compliance means meeting the Cybersecurity Maturity Model Certification (CMMC) standard the U.S. Department of Defense uses to confirm that contractors safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Compliance is mandatory for defense contractors and their subcontractors, and the required level appears in contract language.

For small and medium-sized businesses in the U.S. Defense Industrial Base (DIB), reaching compliance can be difficult with limited budget and in-house security expertise. This is where a managed service provider (MSP) with cybersecurity and compliance capabilities often supports the work, guiding contractors through readiness assessments and remediation for CMMC Level 1 and Level 2.

What are the CMMC levels?

CMMC 2.0 uses three levels that scale with the sensitivity of the information you handle, from Level 1 (Foundational) to Level 3 (Expert). Each level defines the security practices you must implement and how your compliance is assessed.

 

Level Focus Protects Standard Assessment Cadence
Level 1 (Foundational) Basic cyber hygiene FCI 17 practices from FAR 52.204-21 Self-assessment Annual
Level 2 (Advanced) Safeguarding CUI CUI 110 controls from NIST SP 800-171 Self-assessment; C3PAO certification paused as of July 2026 Every 3 years, plus an annual affirmation in SPRS
Level 3 (Expert) Highest-risk programs, defense against advanced persistent threats (APTs) CUI NIST SP 800-171 plus selected enhanced controls from NIST SP 800-172 Government assessment by DIBCAC Every 3 years

Level 1 protects FCI, meaning information generated for the government under a contract that is not intended for public release. Level 2 protects CUI, unclassified information that requires safeguarding under 32 CFR Part 2002 and the NARA CUI Registry. Level 3 applies to the DoD’s most critical programs and pulls in enhanced protections for contractors facing advanced persistent threats.

Which CMMC level do I need?

The level you need is set by the type of information you handle, and it is specified in the solicitation. If you only handle FCI, you are generally looking at Level 1 with an annual self-assessment. If you handle CUI, you need Level 2. The most sensitive work falls under Level 3.

How Level 2 and Level 3 are assessed has changed for now. Under the program’s design, Level 2 can require either a self-assessment or a third-party (C3PAO) certification, and Level 3 is assessed by the government (DIBCAC). But with Phase 2 suspended as of July 2026, contracting officers may currently designate only Level 1 (self) or Level 2 (self); C3PAO and DIBCAC certification are not being required while the program is under review. Always check the solicitation and any flow-down requirements from a prime, since those set your required level, and confirm the current assessment type in writing, because a certification clause already written into an existing contract still applies until that contract is modified.

How does CMMC relate to NIST SP 800-171?

NIST SP 800-171 is the control set behind CMMC Level 2, and the current baseline is Revision 2. To meet Level 2, an organization implements the 110 requirements in NIST SP 800-171 Revision 2 and demonstrates them using the NIST SP 800-171A assessment procedures. Level 3 then adds selected enhanced protections from NIST SP 800-172 for programs at higher risk from advanced persistent threats.

NIST published Revision 3 in May 2024, but it is not yet the CMMC requirement. The Department of Defense continues to assess CMMC Level 2 against Revision 2 and has said it will adopt Revision 3 only through future rulemaking, with advance notice expected before any transition. The practical guidance is to build and document your program to Revision 2 today, while tracking Revision 3 so a future transition is a managed project rather than a scramble.

Do I need a third-party (C3PAO) assessment?

Not right now, in most cases. On July 13, 2026, the Department of Defense suspended CMMC Phase 2, so third-party (C3PAO) Level 2 certification and government (DIBCAC) Level 3 assessment are not currently being designated in new solicitations, and existing certification requirements are being removed from contracts at the next modification. During the suspension, the required posture is self-assessment: Level 1 (self) or Level 2 (self).

Two things still hold. First, if a C3PAO or DIBCAC requirement is already written into one of your active contracts, it remains in force until that contract is formally modified, so confirm your specific awards in writing rather than assuming the requirement is gone. Second, self-assessment is not a lighter standard: you still implement NIST SP 800-171 Revision 2, post your score in SPRS, and provide an annual senior-official affirmation, so keep your evidence organized. When the reform review concludes, some form of third-party assessment may return, so staying ready is the safe posture.

What are the CMMC compliance timelines?

CMMC requirements were being phased into defense contracts over a multi-year rollout, but the schedule changed significantly in 2026. Here is where things stand as of August 2026:

  • Phase 1 is active. The acquisition rule took effect on November 10, 2025, and Phase 1 introduced CMMC Level 1 and Level 2 self-assessment requirements into applicable solicitations. A current NIST SP 800-171 self-assessment posted in SPRS, with an annual senior-official affirmation, remains a condition of eligibility.
  • Phase 2 is suspended. On July 13, 2026, the Department of Defense suspended CMMC Phase 2, which had been scheduled for November 10, 2026 and would have made third-party (C3PAO) Level 2 certification a condition of award. Pending and future milestones, including Level 3 (DIBCAC) assessments, are paused with it.
  • A reform review is underway. A CMMC Reform Task Force is reviewing the program, prompted by concerns over compliance costs and a shortage of assessors. During the suspension, contracting officers may designate only Level 1 (self) or Level 2 (self); Level 2 (C3PAO) and Level 3 (DIBCAC) are not being required, and existing certification requirements are being removed from solicitations and, at the next modification, from active contracts.

The underlying obligation has not gone away. NIST SP 800-171 remains required through DFARS 252.204-7012 independently of CMMC, so the standard still applies. For most Level 2 teams, closing gaps against NIST SP 800-171 Revision 2 still takes months rather than weeks, especially for identity, logging, incident response, and vulnerability management, so the pause is time to get ready, not time to stop.

How do you get ready for CMMC?

Getting ready follows a repeatable path. IT Solutions recommends these seven steps:

  1. Scope your environment. Identify whether you handle FCI, CUI, or both, and draw a hard boundary for in-scope systems. Consider a CUI enclave to minimize disruption to the rest of the business.
  2. Conduct a gap assessment. Compare current practices to NIST SP 800-171, document results in your System Security Plan (SSP) and POA&M using 800-171A methods, and produce a prioritized remediation roadmap.
  3. Prioritize the big rocks. MFA everywhere it belongs, solid logging and monitoring, an incident response plan you can actually execute, strong access control, and an ongoing vulnerability management rhythm.
  4. Post and maintain your SPRS score. Use PIEE to record your 800-171 self-assessment score. Contracting officers check it.
  5. Schedule the assessment if required. For Level 2 solicitations that mandate certification, line up a C3PAO and prepare objective evidence. Level 3 is DIBCAC territory.
  6. Close POA&Ms fast. They are allowed in limited fashion and on a clock. Track owners and due dates.
  7. Sustain compliance. Plan on three-year certification cycles where applicable, plus annual affirmations, and keep your evidence artifacts current.

What are the consequences of CMMC non-compliance?

Failing to achieve or maintain CMMC compliance carries real consequences for organizations in the Defense Industrial Base:

  • Loss of contract eligibility. Non-compliant organizations can be disqualified from bidding on, winning, or retaining contracts. CMMC status is a requirement for award under DFARS.
  • Contract termination or suspension. Failing to maintain compliance or to close POA&Ms within required timeframes can lead to loss of Conditional status and termination for default.
  • False Claims Act exposure. False or misleading attestations in SPRS or annual affirmations can trigger investigations and penalties under the False Claims Act, with financial and reputational damage.
  • Reputational and business impact. Security incidents or non-compliance disclosures can erode trust with primes, subcontractors, and government partners.
  • Legal liability. Organizations may face legal action for negligence in protecting FCI or CUI.

How does IT Solutions Consulting support CMMC compliance?

IT Solutions Consulting is a managed IT and cybersecurity provider, founded in 1994, that helps defense contractors and manufacturers in the U.S. Defense Industrial Base prepare for CMMC 2.0 Level 1 and Level 2 compliance. ITS focuses on Level 1 and Level 2 and combines gap assessments with vCISO-led advisory support to move organizations toward certification.

ITS CMMC readiness and advisory services include:

  • CMMC readiness assessments. ITS performs comprehensive gap analyses aligned with the CMMC 2.0 framework to identify where your environment, policies, and documentation fall short of required controls, including technical safeguards, administrative policies, and the evidence needed for a successful assessment. Scoping often separates a CUI enclave to reduce the effort.
  • Remediation and implementation support. Through the ITS vCISO Cybersecure Regulatory Program, the team addresses identified gaps with policy guidance, structured workshops, and advisory support aligned with CMMC 2.0 and NIST SP 800-171.
  • Continuous compliance and advisory. The ITS vCISO team provides ongoing governance and oversight, monitors evolving DoD requirements, manages POA&Ms, and supports audit-readiness for future C3PAO or DIBCAC reviews.

Important: IT Solutions Consulting is not a certifying body. Official CMMC Level 2 certifications can only be performed by an accredited Certified Third-Party Assessment Organization (C3PAO). The ITS role is to help your organization identify and close CMMC compliance gaps before the formal certification assessment.

To pressure-test your scope, SPRS score, and schedule, book a CMMC readiness consult with IT Solutions.

Frequently asked questions

Is CMMC compliance mandatory? Yes. CMMC compliance is mandatory for U.S. Department of Defense contractors and their subcontractors, and the required CMMC status is a condition of contract award under DFARS. The specific level you must meet is set by the information you handle and appears in the solicitation.

What is the difference between FCI and CUI? FCI (Federal Contract Information) is information generated or provided for the government under a contract that is not intended for public release, safeguarded under FAR 52.204-21. CUI (Controlled Unclassified Information) is unclassified information requiring safeguarding under 32 CFR Part 2002 and the NARA CUI Registry. Which one you handle determines your CMMC level.

Can an MSP certify my business for CMMC? No. An MSP, including IT Solutions Consulting, is not a certifying body. Official Level 2 certification is performed only by an accredited C3PAO, and Level 3 is assessed by DIBCAC. An MSP helps you identify and close gaps and prepare evidence before the formal assessment.

What is SPRS? SPRS (Supplier Performance Risk System) is where your NIST SP 800-171 score and, when applicable, your CMMC status are recorded. Contracting officers check it, and you post your self-assessment score through PIEE. Without a current score or affirmation when the clause applies, expect problems at award time.

What is a POA&M in CMMC? A POA&M (Plan of Action and Milestones) documents the gaps you have not yet closed and the timeline to remediate them. CMMC permits POA&Ms only in a limited, time-boxed way, so they must be closed quickly, with clear owners and due dates.

Preparing for a CMMC Assessment: Steps & Timelines for Manufacturers & Builders

If you’re a mid-market manufacturer or construction firm, you’ve probably felt the change coming. The Department of Defense (DoD) is finalizing the Cybersecurity Maturity Model Certification (CMMC), and it’s raising the bar for everyone in the defense supply chain. Instead of simply saying you protect Controlled Unclassified Information (CUI), you now have to prove it clearly and consistently.

For many teams, that’s easier said than done. CUI shows up in more places than people realize: CAD models, build sheets, cloud-based plan rooms, email exchanges with subcontractors, and even jobsite devices that come and go. Wherever it flows, CMMC follows.

So if you’re trying to figure out what this means for your upcoming bids or how fast you need to move, you’re in the right place.

 Book a CMMC Readiness Consult with IT Solutions.

Why This Matters for Manufacturers & Builders

CMMC requirements now flow down through the supply chain via Defense Federal Acquisition Regulation Supplement (DFARS) clauses, meaning many midsize contractors qualify simply by touching CUI, whether directly or through subcontracted work.

For manufacturers, CUI often moves across CAD platforms, PLM systems, and shop-floor technologies. Many plants also blend traditional IT with industrial control systems (ICS/OT), where segmentation and logging aren’t as mature.

For construction firms, the challenge is different: mobile crews, shared plans hosted in cloud environments, varied subcontractor devices, and jobsite networks that don’t always meet enterprise standards.

Failing a CMMC assessment or failing to post required information to the Supplier Performance Risk System (SPRS) can disqualify you from award consideration.

What to Expect in a CMMC Assessment

A CMMC assessment reviews how well your security controls match the level required in your contract and whether you can prove those controls are in place. Depending on the solicitation, Level 2 may allow self-assessment or require a C3PAO, while Level 3 is performed by a DoD assessment team.

What you can expect:

  • Three levels: Level 1, Level 2, Level 3
  • Objective evidence is required for every assessed control
  • Self- or third-party attestation posted in SPRS
  • Annual affirmation through the Procurement Integrated Enterprise Environment (PIEE)

The DoD’s program rule (32 CFR Part 170, Federal Register, Oct. 15, 2024) outlines the model structure, while the CMMC Assessment Process (CAP v2.0) from Cyber AB explains how C3PAO-led reviews are executed.

How to Conduct a CMMC Assessment

A CMMC assessment follows a predictable flow: determine scope, assemble documentation, perform the review, and post results to SPRS. Any gaps may be placed on a POA&M if allowed and later closed out.

Key steps:

  • Define scope (systems, users, apps, OT networks, jobsites)
  • Build or update the System Security Plan (SSP)
  • Map NIST SP 800-171 Rev. 3 controls and gather evidence
  • Run internal interviews and walkthroughs
  • Perform self-assessment or schedule with a C3PAO
  • Post SPRS score or certificate
  • Create POA&M items, close within allowed windows (eCFR §170.23 outlines 180-day limits)

 

How Long Does a CMMC Assessment Take?

Expect fieldwork to take anywhere from a few days to several weeks. The real timeline depends on evidence readiness, the complexity of your environment, and how quickly you can remediate gaps.

Time factors include:

  • C3PAO scheduling (sometimes months out)
  • Whether OT or jobsite visits are required
  • Completeness of your SSP and evidence
  • Remote vs. onsite interviews
  • Time needed to assemble logs, screenshots, configs, and training records

If your documentation is complete, a self-assessment moves quickly. If not, remediation often takes several months.

If You Don’t Pass: POA&Ms, Conditional Status & Closeout

Falling short doesn’t end your chances if the gap is eligible for a POA&M. Under 32 CFR Part 170, the DoD permits limited POA&M items but not for the highest-impact controls.

Key considerations:

  • Ineligible POA&M controls include several encryption, MFA, and logging requirements
  • Conditional status requires timely and documented remediation
  • Most POA&Ms must be closed within 180 days (per eCFR §170.23)
  • Failure to close on time can trigger loss of award eligibility

After remediation, an assessor (or C3PAO) reviews the updated evidence to validate closure.

Manufacturing & Construction Readiness Checklist

Start here:

  • Confirm your required CMMC level from the solicitation
  • Identify FCI (per FAR 52.204-21) and CUI (per 32 CFR 2002)
  • Build/update your SSP, calculate your NIST 800-171 score, and post to SPRS
  • Prioritize controls sensitive to your environment: ICS/OT segmentation, jobsite Wi-Fi, subcontractor access, MDM and MFA
  • Assemble evidence: policies, network diagrams, screen captures, config exports, ticket trails, onboarding/offboarding logs
  • Conduct a mock assessment (interviews, facility walk-throughs, sampling)
  • Pre-assign POA&M owners and establish remediation timing
  • If your solicitation mandates it, book a C3PAO early

→ Ready to verify your environment? Contact IT Solutions to start your readiness review.

 

Risks & Trade-offs to Recognize Early

CMMC isn’t purely a paperwork exercise. Decisions about scope, tooling, and timing all affect cost and compliance.

Watch for:

  • Over-scoping (bringing in systems that never touch CUI)
  • Under-scoping (missing contractor or cloud systems where CUI flows)
  • Documentation gaps or “tool-only” approaches
  • OT downtime and jobsite connectivity issues
  • Supplier and subcontractor dependencies

Good scoping and early evidence preparation often make the difference between passing and a long remediation slog.

 

When to Bring in Expert Help

You can manage a self-assessment alone, but certain situations call for experienced guidance:

  • A solicitation due within the next 6–12 months
  • First-time CMMC Level 2 organizations
  • Low or negative NIST 800-171 SPRS scores
  • Complex OT networks or multiple subcontractor pathways
  • Need for policy development, diagrams, or evidence structuring

Book a CMMC Readiness Consult

 

IT Solutions helps manufacturers and builders align systems, documentation, OT environments, and subcontractor workflows with CMMC requirements so you can pass on the first attempt or close gaps quickly.

FAQs

  • Do we need a C3PAO for Level 2?
    • It depends on the solicitation. Some Level-2 contracts allow self-assessment; others require a C3PAO-led certification on a three-year cycle with annual affirmations in PIEE.
  • What happens if we fail a CMMC assessment?
    • You may receive conditional status if your gaps qualify for a POA&M. All eligible items must be closed within the allowed window, which is usually 180 days, before you can achieve final status.
  • How should manufacturers secure OT/ICS environments?
    • Segment OT from IT, restrict external connections, log interfaces, and document procedures. NIST SP 800-171 requirements apply, and NIST SP 800-82 offers additional ICS/OT guidance.
  • What is SPRS?
    • The Supplier Performance Risk System is where DoD suppliers post required NIST 800-171 scores, affirmations, and ultimately CMMC results.
  • Which level do most mid-market firms need?
    • Organizations handling only FCI need Level 1. Those handling CUI often require Level 2. Level 3 applies to high-risk programs and requires a government-led assessment.