What is CMMC 2.0? A Plain-English Guide
Quick answer
CMMC 2.0 applies to any company in the DoD supply chain that handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) — primes and subcontractors alike. It uses three maturity levels: Level 1 (FCI, 17 practices, annual self-assessment), Level 2 (CUI, all 110 NIST SP 800-171 controls, third-party C3PAO assessment for prioritized CUI), and Level 3 (highest-priority CUI, NIST SP 800-172, government-led assessment).
You’ve probably heard the acronym "CMMC" (Cybersecurity Maturity Model Certification) if you work with the Department of Defense (DoD). In short, CMMC is a set of cybersecurity standards that all DoD contractors and subcontractors must meet to prove they can protect sensitive government information.
It's the DoD's way of locking its digital doors and ensuring its entire supply chain—from prime contractors building jets down to small machine shops making a single part—is secure. CMMC 2.0 is the streamlined, updated version that is now being rolled out.
Who Does CMMC Affect? (Hint: Probably You)
This is the most critical question. CMMC applies to all businesses in the Defense Industrial Base (DIB), regardless of size. If your company holds or creates any of the following information, CMMC applies to you:
- Federal Contract Information (FCI): This is information not intended for public release. It’s the basic info related to a DoD contract. If you only handle FCI, you'll likely fall under CMMC Level 1.
- Controlled Unclassified Information (CUI): This is the big one. CUI is information that requires safeguarding, but is not classified. Think of technical drawings, engineering data, project specifications, R&D data, and more. If your contract involves CUI, you will be required to meet at least CMMC Level 2.
It doesn't matter if you're a prime contractor or a subcontractor three tiers down. If you touch CUI, you must comply.
The Three Levels of CMMC 2.0
CMMC 2.0 simplified the old five-level model into three "Maturity Levels":
| Level | Requirement | Assessment |
|---|---|---|
| Level 1: Foundational | 17 foundational practices for handling FCI (based on NIST SP 800-171) | Annual self-assessment |
| Level 2: Advanced | All 110 controls from NIST SP 800-171 Rev 2 for handling CUI | Third-party C3PAO assessment every three years for prioritized CUI (some self-assessment) |
| Level 3: Expert | All 110 Level 2 controls plus a subset of NIST SP 800-172 enhanced controls | Government-led assessment by the DoD |
Level 1: Foundational
- Who it's for: Companies that only handle FCI.
- What's required: 17 basic "Foundational" cybersecurity practices (based on NIST SP 800-171). These are things like using antivirus, requiring passwords, and controlling access to your facility.
- Assessment: You can perform an annual Self-Assessment and submit your score to the DoD.
Level 2: Advanced
- Who it's for: Companies that handle CUI. This will be the most common level for DIB contractors.
- What's required: All 110 security controls from NIST SP 800-171. This is a significant undertaking, covering everything from access control and incident response to physical security and system integrity.
- Assessment: This is split. Some companies may be allowed to self-assess, but those handling "critical CUI" will require a Third-Party Assessment by an accredited CMMC Third-Party Assessment Organization (C3PAO) every three years. You must assume you'll need the third-party assessment.
Level 3: Expert
- Who it's for: Companies handling CUI for the DoD's most critical, high-priority programs.
- What's required: All 110 controls from Level 2, plus a subset of advanced controls from NIST SP 800-172.
- Assessment: This will be a rigorous Government-Led Assessment by the DoD itself.
What Should You Do Next?
CMMC is no longer a "when" but a "now." It is already appearing in new contracts. If you are a DoD contractor, your first steps should be:
- Identify your data: Do you handle FCI only, or do you have CUI? Look at your contracts and data—this determines your CMMC level.
- Read your contracts: Look for clauses like DFARS 252.204-7012, -7019, or -7020. These are your current legal obligations.
- Get a Gap Analysis: This is the most important step. You need a professional assessment to see how your current security practices stack up against the 110 controls of Level 2.
Don't wait until you're at risk of losing a contract. Start your CMMC journey today.
Ready to Put This Into Practice?
Book a free 30-minute AI Workflow Audit. We'll identify your highest-ROI automation opportunity and show you the exact build plan.
Book Free AI Audit →