Guide to CMMC
Insights into the Cybersecurity Framework, resources, and general information.
Overview
If you’re a government contractor (GovCon), you can’t underestimate your need to establish solid cybersecurity principles. Beyond the general importance of safeguarding your data, people, and systems, there are also strict government mandates designed to ensure GovCons are maintaining proper cybersecurity protocols.
While these mandates help keep GovCons honest in terms of maintaining a satisfactory cybersecurity posture, achieving compliance can be a tough ask in practice. The U.S. Department of Defense (DOD)’s Cybersecurity Maturity Model Certification (CMMC) is a perfect example of regulatory guidance that can be challenging for GovCons supporting DOD. These requirements will likely be leveraged by other government agencies in the future as well.
CMMC is a complicated topic to discuss, but this guide will prepare your GovCon to achieve compliance AND become more secure as an organization.
UPDATE: With the Final Rule 48 published and the official start to CMMC set for November 10th, 2025, this document has been updated to reflect the final timeline. UPDATE — September 2026: CMMC Phase 1 self-assessment requirements took effect on November 10, 2025. On July 13, 2026, the Department of War suspended the transition to Phase 2 and placed future implementation milestones on hold pending program review. Phase 1 requirements and existing obligations to safeguard covered defense information under DFARS 252.204-7012 remain in effect. This guide reflects the current status at the time of publication; contractors should verify contract-specific requirements and official government guidance for changes.
Unanet’s Position
Unanet has achieved FedRAMP Moderate Equivalency for GovCon ERP, including AIM. This offering meets the NIST SP 800-53 Moderate security control baseline and supports customers pursuing CMMC Level 2 and Level 3 requirements for handling Controlled Unclassified Information (CUI).
FedRAMP Moderate Equivalency supports the cloud service provider portion of a contractor’s compliance responsibilities. It does not replace the contractor’s own CMMC, DFARS, data-classification, access-control, documentation, or assessment obligations. Only products identified in the customer’s order form operate within the Unanet FedRAMP Moderate Equivalent boundary.
Read the Unanet Trust Center FAQ on CMMC and FedRAMP
Learn more about how other customers have passed CMMC Level 2 below.
Covered in this Guide
-
What CMMC is and why it exists
-
Timeline and phased rollout
-
The implications for GovCons
CMMC is one of the toughest frameworks out there. It’s technical, policy-heavy, costly, and time-consuming. We’re proud to be among the few to earn Level 2 certification within the first quarter of its rollout, and even prouder to help our clients reach the same goal.
Alluvionic
Alluvionic is an SBA 8(a) certified, woman-owned small business providing government, commercial, and technology solutions. The company uses Unanet to manage time and expense tracking, automate project accounting, and support financial operations. Alluvionic recently achieved CMMC Level 2 certification, reinforcing its position as a leader in cybersecurity compliance and helping the company grow its DoD work. As one of the earliest Cyber AB Registered Practitioner Organizations (RPOs), Alluvionic has guided more than 140 clients on their cybersecurity journeys.
Offset Strategic Services
Offset Strategic Services (OSS) delivers innovative, mission-focused engineering and technical solutions to DoD and federal clients. Combining technical, tactical, and cybersecurity expertise with deep operational insight to support high-security programs globally. A Service Disabled Veteran Owned Small Business, OSS is committed to service and to protecting those who protect us. They take security and compliance very seriously by maintaining AS9100D, ISO9001:2015, NIST 800.171, and CMMC Level 2 (C3PAO) certifications, all while using Unanet across their resource management, planning, and accounting departments.
The origins of CMMC
Over the past decade, DOD has become increasingly concerned about cybersecurity. This has led to the department prioritizing the protection of government institutions and the DOD supply chain from cyberattacks. The agency believes the traditional measures of GovCon performance — cost, schedule, and quality — are only effective and applicable in a secure environment. Through the CMMC framework, the DOD tells defense contractors they must meet certain cybersecurity standards to work for the DOD in the future.
The first attempt to address cybersecurity issues was an informal request by the government that all GovCons comply with National Institute of Standards and Technology (NIST) Special Publication 800- 171 requirements. After that, the first Cybersecurity Maturity Model Certification – CMMC 1.0 – was unveiled by the DOD in 2019. This proposed guidance provided a new cybersecurity compliance framework for DOD contracts and the data associated with them. It introduced a DOD certification process that measured a company’s ability to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
CMMC combines various cybersecurity standards and maps these best practices and processes to three security levels. CMMC 1.0 would have required a third-party assessment for all contractors at all levels. The total number was estimated at more than 300,000, including both prime contractors and subcontractors. After much debate, CMMC 1.0 was rejected because it would be too expensive and burdensome for contractors and government agencies.
In November 2021, DOD released CMMC 2.0. The model described there was similar to management maturity models used by other entities inside and outside the government. CMMC 2.0 contains progressive levels that describe a GovCon’s cybersecurity practices and processes from basic cyber hygiene to highly advanced practices.
Finally, in October of 2024, the CMMC rule was finalized and will be implemented in December of 2024. After this, a timeline starts where Level 2 Assessments must be in place for contracts starting in the middle of 2025 - pending any waivers or extensions that will be decided for individual contracts and awards. Full rollout of all 3 levels will continue until the end of 2028.
Why now?
CMMC requirements are now being incorporated into applicable DoD procurements, but the implementation schedule has changed. Phase 1 self-assessment requirements remain in effect.
On July 13, 2026, the Department of War suspended the transition to CMMC Phase 2 and placed future implementation milestones on hold pending a program review. During this interim period, the government will continue enforcing cybersecurity requirements through self-assessments and select government-led assessments.
So, what should GovCons do now? Continue protecting covered defense information, review the requirements in each applicable contract, and monitor official government guidance for changes to the implementation schedule.
-
Phase 1 self-assessment requirements remain in effect
Applicable procurements may require Level 1 or Level 2 self-assessment status as a condition of award.
-
Phase 2 transition is currently suspended
The planned expansion of Level 2 third-party assessment requirements is on hold pending government review. Do not present November 10, 2026 as a firm deadline.
-
Future implementation milestones are pending review
Later Level 3 and broader rollout requirements may change. Contractors should follow the requirements in their applicable solicitations and contracts.
CMMC and cybersecurity requirements may flow down to subcontractors based on the prime contract, the information handled, and the requirements identified in the applicable solicitation or subcontract. If you are a subcontractor, review the specific flow-down language and determine which systems will process, store, or transmit FCI or CUI.
The CMMC level and assessment path that apply to your organization depend on the information handled and the requirements in your contract. The next section explains the differences between the three CMMC levels and the requirements associated with each one.
A breakdown of CMMC levels
CMMC 2.0 uses three levels with requirements that correspond to the type and sensitivity of federal information a contractor handles. Level 1 addresses Federal Contract Information (FCI), Level 2 addresses Controlled Unclassified Information (CUI) using NIST SP 800-171 requirements, and Level 3 adds selected NIST SP 800-172 requirements for the most sensitive DoD programs.
The CMMC level and assessment path that apply to an organization depend on the information handled and the requirements in the applicable solicitation or contract. Assessment requirements and implementation milestones may change as the government reviews the program. The table below provides a high-level overview.
CMMC 2.0 Processes
CMMC Model 2.0
Level 3
Expert
Level 2 +
Selected requirements from NIST SP 800-172
Government-led DIBCAC assessment when required
Level 2
Advanced
110
requirements based on NIST SP 800-171
Self-assessment or C3PAO assessment, depending on the contract and current government requirements
Level 1
Fundamental
17
practices based on FAR 52.204-21
Annual self-assessment when required by the contract
-
Level 1
Foundational cybersecurity requirements
Level 1 applies to contractors handling Federal Contract Information (FCI) and is based on the applicable FAR 52.204-21 safeguarding requirements. Organizations complete an annual self-assessment when required by the contract. Level 1 does not require a C3PAO assessment.
-
Level 2
Advanced cybersecurity requirements
Level 2 applies to contractors handling Controlled Unclassified Information (CUI) and is based on 110 requirements from NIST SP 800-171. The assessment path depends on the applicable contract. Phase 1 self-assessment requirements remain in effect, while the transition to Phase 2 third-party C3PAO assessment requirements is currently suspended pending government review. Contractors should not rely on older estimates about affected organizations or assessor availability.
-
Level 3
Expert cybersecurity requirements
Level 3 applies to selected DoD programs involving the most sensitive CUI. It builds on Level 2 and adds selected requirements from NIST SP 800-172. A government-led DIBCAC assessment applies when required by the contract and current government guidance. Future Level 3 implementation milestones remain subject to change as the government reviews the program.
What CMMC means for Defense Contractors
CMMC applies to contractors and subcontractors based on the requirements in their applicable solicitations and contracts, the information they handle, and any requirements flowed down by a prime contractor. The program can affect eligibility, cybersecurity operations, documentation, assessments, and supply-chain relationships. The six areas below summarize the most important considerations.
-
Whether CMMC applies, and which CMMC level or status is required, depends on the applicable solicitation or contract, the information handled, and any requirements flowed down by a prime contractor.
During the current interim period, applicable procurements may require Level 1 or Level 2 self-assessment status. The transition to Phase 2 third-party Level 2 assessments and later implementation milestones is currently suspended pending government review. The CMMC level required will be specified for each procurement in its solicitation.
-
POA&M eligibility and conditional CMMC status are governed by current CMMC rules and applicable contract requirements.
Contractors should verify whether a POA&M is permitted for their specific CMMC status and contract. A POA&M does not replace the requirement to implement applicable security controls, and contractors should not rely on historical estimates about assessor capacity.
-
Prime contractors must flow down the appropriate CMMC requirement to the subcontractors they intend to use for a specific contract.
Verification of the subcontractors’ status will also be the Prime’s responsibility.
-
The DOD contracting officer will determine the appropriate CMMC level for the contracts they award and administer.
Not all contracts will require the highest level of security and the level required for a particular contract will be specified in the solicitation and in the resulting contract. The former CMMC Pilot Program approval language describes an earlier implementation period and should not be used as current guidance. Contractors should follow the requirements in the applicable solicitation, contract, and current government instructions.
-
The cost of preparing for a CMMC audit and becoming certified will be an “allowable cost” to government contracts.
While DCAA has not issued specific guidance yet, it is the opinion of many experts in GovCon accounting and compliance that the cost will almost certainly be an indirect cost – most likely as a general and administrative (G&A) expense.
-
When a contract requires a third-party CMMC assessment, the assessment is performed by an accredited C3PAO. Level 3 assessments are government-led by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) when required.
Because the transition to CMMC Phase 2 and later implementation milestones is currently suspended, third-party assessment requirements should not be presented as universal current requirements. Contractors should verify the applicable assessment path and current assessor information against official government guidance and The Cyber AB.
Definition and treatment of CUI
A key part of CMMC is Controlled Unclassified Information (CUI), sensitive government information that requires safeguarding or dissemination controls. In DoD contracting, related terms such as Covered Defense Information (CDI) may appear in contract language; CUI and CDI should not be treated as exact synonyms.
-
CUI Definition
Controlled Unclassified Information is unclassified information the United States Government creates or possesses that requires safeguarding or dissemination controls limiting its distribution to those with a “lawful government purpose.” CUI may not be released to the public without further review. There are different types of CUI and different distribution levels. Defined CUI markings alert recipients that special handling may be required to comply with law, regulation, or Governmentwide policy. Federal agencies are responsible for marking or identifying CUI shared with or generated by contractors. Questions about whether information is CUI should be directed to the responsible contracting agency. Contractors and government officials must undergo annual CUI training.
Contractors are responsible for handling CUI in accordance with applicable contract requirements. CUI is a key factor in determining whether a contract requires CMMC Level 2, but the applicable solicitation or contract determines the required level and status.
-
CUI, CSP, and FedRAMP Moderate Equivalency
Cloud Service Providers (CSP) or External Service Providers that handle CUI must be authorized or provide evidence of Equivalency – which essentially means demonstrating they can fully fulfill the requirements of FedRAMP Moderate Authorization. It is the contractor’s duty to verify any cloud software they use meets these requirements.
-
CMMC Cost, Scope, and Timing Considerations
Historical estimates of CMMC cost, preparation time, contractor volume, and C3PAO capacity should not be treated as current universal figures. Actual effort varies by CMMC level, system boundary, data environment, existing controls, documentation, remediation needs, and assessment path.
The July 2026 suspension of the Phase 2 transition changes the timing of future third-party assessment requirements, but it does not eliminate the underlying obligations to protect covered defense information. Contractors should verify current requirements against their contracts and official government guidance.
The CMMC milestone timeline
To understand your CMMC obligations, review the current requirements in your contracts and solicitations and monitor official government guidance. The timeline below distinguishes the active Phase 1 requirements from later implementation milestones that are currently subject to review.
Historical estimates of contractor volume, C3PAO availability, assessment capacity, cost, and preparation time should not be treated as current universal figures. Actual requirements and effort vary by contract, CMMC level, system boundary, data environment, existing controls, and assessment path.
Contractors should not wait for a future milestone to begin protecting covered defense information. Phase 1 self-assessment requirements remain in effect, and the transition to Phase 2 and later implementation milestones is currently suspended pending government review.
Self-assessment
Applicable Level 1 and Level 2 self-assessments may be required as a condition of award
Requirements depend on the contract
Phase 2 transition suspended
Planned Level 2 C3PAO assessment requirements are on hold pending government review.
No replacement implementation date has been announced.
Future milestone pending review
The original Level 3 implementation milestone is suspended and may change as the government reviews the program.
No current effective date
Full rollout pending review
The original full-rollout milestone is not currently operative. Future requirements and timing remain subject to government guidance.
No current effective date
Support for GovCons with CMMC compliance needs
Individual GovCons are responsible for understanding and meeting the cybersecurity and CMMC requirements that apply to their contracts. Phase 1 self-assessment requirements remain in effect, while the transition to Phase 2 third-party assessments and later implementation milestones is currently suspended pending government review. Maintaining awareness is only the first step. Contractors should implement and document the controls required by their contracts and use software that supports secure, auditable operations.
Unanet’s purpose-built business software can support CMMC readiness when configured and used within the appropriate environment. Unanet GovCon ERP, including AIM, has achieved FedRAMP Moderate Equivalency. The FedRAMP Moderate Equivalent offering supports the cloud service provider portion of a contractor’s compliance responsibilities; it does not replace the contractor’s own CMMC, DFARS, data-classification, access-control, documentation, or assessment obligations. Where applicable to the product and environment, Unanet’s platform supports relevant technical requirements including multifactor authentication, identification and access controls, and data encryption.
The Unanet Cloud Operations team has been diligent about staying aligned with new DOD policies and has taken the necessary steps to ensure that its processes and procedures are also aligned with CMMC, FedRAMP and NIST 800-171 standards.
Find out more
For information on how Unanet can support and simplify your organization’s CMMC readiness, including the role of a FedRAMP Moderate Equivalent cloud environment, request a demo today.