Mar 30, 2026

What is CMMC 2.0 and Who Needs to Comply

For thousands of businesses working with the U.S. Department of Defense, a new compliance reality has arrived — and ignoring it could mean losing federal contracts entirely. CMMC 2.0 is here, and understanding what it requires is no longer optional.

If your business operates anywhere in the defense supply chain — whether you’re a large prime contractor or a small subcontractor providing cloud hosting, engineering services, or logistics — you’ve likely heard the acronym CMMC floating around in contract conversations. Short for Cybersecurity Maturity Model Certification, CMMC is the Department of Defense’s answer to a growing and undeniable problem: the defense industrial base is under constant cyberattack, and too many contractors weren’t doing enough to protect sensitive government information.

The original CMMC framework, released in 2020, was ambitious but complex — and in 2021, the DoD announced a significant overhaul. What emerged is CMMC 2.0, a streamlined, more practical version of the program that maintains rigorous security standards while reducing unnecessary burden on small and mid-sized businesses. CMMC 2.0 became a regulatory requirement embedded in DoD contracts beginning in late 2024, making compliance an urgent priority for any business that wants to continue winning — or bidding on — federal defense work.

Understanding the CMMC 2.0 Framework: Three Levels of Cybersecurity

At its core, CMMC 2.0 is a tiered certification model. Rather than applying a one-size-fits-all approach, the framework organizes cybersecurity requirements into three distinct levels based on the sensitivity of the information a contractor handles and the risk their systems pose to national security.

CMMC 2.0 certification levels diagram showing Level 1 Foundational, Level 2 Advanced, and Level 3 Expert requirements for defense contractors

CMMC LEVEL 1 — FOUNDATIONAL
17 basic cybersecurity practices. Annual self-assessment. Covers contractors handling Federal Contract Information (FCI).

CMMC Level 1 is the entry point, covering the most fundamental cybersecurity hygiene practices — things like using antivirus software, controlling who has access to systems, and regularly updating passwords. Most contractors who only handle basic Federal Contract Information (FCI) will fall into this tier, and a company-conducted annual self-assessment is all that’s required.

CMMC LEVEL 2 — ADVANCED
110 practices aligned with NIST SP 800-171. Tri-annual third-party assessment for most. Covers contractors handling Controlled Unclassified Information (CUI).

CMMC Level 2 is where the majority of defense contractors land — and where compliance becomes significantly more demanding. Level 2 maps directly to the 110 security practices outlined in NIST Special Publication 800-171, which covers the protection of Controlled Unclassified Information (CUI). Depending on the criticality of the program, companies may be required to pass a third-party assessment conducted by a CMMC Third-Party Assessment Organization (C3PAO).

CMMC LEVEL 3 — EXPERT
180+ practices aligned with NIST SP 800-172. Government-led assessments. Covers contractors on the most critical DoD programs.

CMMC Level 3 is reserved for contractors supporting the most sensitive and high-priority DoD programs. This level requires more than 180 security practices, aligns with NIST SP 800-172, and involves government-led assessments directly administered by the Defense Contract Management Agency (DCMA).

IMPORTANT NOTE: CMMC certification is not retroactive. You must achieve the required level before a contract is awarded — not after. Starting your CMMC compliance journey early gives you the best chance of meeting deadlines without disrupting ongoing business.

Who Needs to Comply with CMMC 2.0?

This is one of the most common questions organizations ask — and the answer is broader than many expect. CMMC applies to all organizations that are part of the Defense Industrial Base (DIB), which the DoD defines as any company that provides products or services that support national defense. This includes not just the household names in defense contracting, but a vast ecosystem of smaller businesses that often don’t realize they fall under the umbrella.

You likely need to comply with CMMC if your organization:

  • Is a prime contractor or subcontractor on any DoD contract that involves FCI or CUI
  • Provides IT services, managed security, cloud hosting, or software to a prime contractor
  • Manufactures components, materials, or equipment used in defense systems
  • Conducts research and development funded in whole or part by the DoD
  • Provides professional services such as consulting, engineering, or logistics to DoD programs
  • Acts as a staffing firm placing workers on defense contracts that involve sensitive information

Who needs to comply with CMMC 2.0 — defense contractors and subcontractors handling CUI and FCI in the DoD supply chain

It’s worth noting that CMMC flows down through the supply chain. If a prime contractor is required to meet Level 2, they are obligated to ensure their subcontractors who handle CUI also meet that standard. This means even a small business that considers itself far removed from “defense work” may be subject to CMMC requirements based on a contract clause buried in a subcontract agreement.

The DoD has made clear that CMMC requirements will be included in all applicable solicitations and contracts, and that companies that fail to achieve — and maintain — the appropriate certification level will be ineligible to bid, win, or continue performing on those contracts. The message is unambiguous: CMMC compliance is not a competitive advantage; it is a baseline requirement for continued participation in the defense marketplace.

Getting Started: What CMMC Compliance Looks Like in Practice

For many organizations, the journey to CMMC certification begins with a gap assessment — a thorough review of your current cybersecurity posture compared against the practices required at your target CMMC level

. This process often reveals a mix of quick wins (practices you’re already meeting) and longer-term remediation items that require investment in new tools, processes, or personnel.

A few foundational steps every organization should take:

document, implement, engage flow within CMMC

Document your CUI environment.
Before you can protect Controlled Unclassified Information, you need to know exactly where it lives — which systems store it, which people access it, and how it flows in and out of your organization. This scoping exercise is the foundation of your System Security Plan (SSP), a core document required for CMMC Level 2 assessments.

Implement a Plan of Action & Milestones (POA&M)
If your gap assessment reveals security practices you haven’t yet implemented, a POA&M documents your plan to close those gaps, including timelines and responsible parties. For Level 2, limited POA&Ms may be acceptable at the time of assessment, but certain high-priority practices must be fully implemented — not just planned.

Engage a C3PAO early for Level 2
If your contracts require a third-party CMMC assessment, find a certified C3PAO well in advance. Assessment slots fill quickly, and the process takes time. Rushing into a third-party assessment without preparation is one of the most common — and costly — mistakes contractors make.

Conclusion

CMMC 2.0 represents the DoD’s most significant and enforceable push yet to raise the cybersecurity floor across the entire defense supply chain. Whether you’re a 10-person engineering firm or a multi-billion-dollar systems integrator, if your work touches federal defense programs, CMMC is your reality.

The good news is that CMMC 2.0 is more approachable than its predecessor — with clearer requirements, familiar frameworks like NIST 800-171, and tiered demands that scale with actual risk. The key is starting now: assess where you stand, build a roadmap, and treat CMMC not as a compliance checkbox but as an investment in the long-term security and competitiveness of your business.

Not Sure Where Your Organization Stands?

Our CMMC readiness experts can assess your current cybersecurity posture, identify gaps, and build a clear compliance roadmap — before your next contract is on the line.

No commitment required. Results delivered within 5 business days.

Frequently Asked Questions about CMMC 2.0

What is the difference between CMMC 1.0 and CMMC 2.0?
CMMC 1.0 had five maturity levels with program-specific practices. CMMC 2.0 streamlined this to three levels, replaced proprietary practices with established NIST standards, and reintroduced self-attestation options for some contractors — making it more accessible for small and mid-sized businesses without compromising security goals.

How long does it take to get certified?
It depends on your level and current security posture. Level 1 self-assessments can take just a few weeks. Level 2 with a third-party assessment typically requires 6–18 months of preparation, including gap remediation, SSP documentation, and scheduling with a C3PAO. Starting early is strongly advised.

Can small businesses use a self-assessment instead of hiring a third-party assessor?
For Level 1, yes — all companies may self-attest annually. For Level 2, it depends on the program: contractors on “prioritized” acquisitions must use a certified C3PAO, while others may self-attest. Level 3 always requires a government-led assessment. Company size alone does not determine eligibility for self-assessment.

What happens if my company fails a CMMC assessment?
You won’t be eligible for contract award until you reach the required level. If you fail during an active contract, you may be in breach. After a failed assessment, you can remediate and re-assess. Intentionally misrepresenting your compliance status can trigger False Claims Act liability with serious legal and financial consequences.

Does CMMC apply to foreign companies or non-U.S. contractors?
Yes. Any organization — domestic or foreign — that handles FCI or CUI under a DoD contract must meet CMMC requirements. Foreign contractors may face added complexity due to CUI access restrictions and should work with advisors experienced in international compliance early in the process.

Related Resources:

DoD CMMC Program Page — Official updates, policy docs, and FAQs.

NIST SP 800-171 — The security standard behind CMMC Level 2.

NIST SP 800-172 — The advanced standard behind CMMC Level 3.

DFARS Clause 252.204-7021 — The contract clause that enforces CMMC requirements.

Ready to start your CMMC compliance journey?

Our team is here to help — from initial gap assessments to full certification support.

Visit Us: https://vso-inc.com/cmmc/ | Phone: (888) 805-0510

About the Author Ethan Watts is the VP of Commercial and Channel Business at VSO, where he leads sales and delivery across dozens of successful contracts and engagements. He works closely with clients and partners to develop and achieve their IT goals.

Share This Story, Choose Your Platform!