Jump to a page

32 pages.

All servicesAssessments, testing, and advisory work for security and compliance programs.
PCI DSS readinessScoping, readiness, and remediation for card-payment environments
Penetration testingAuthorized testing of apps, APIs, and networks
Compliance readinessSOC 2, ISO/IEC 27001, HIPAA, and CMMC readiness
Cloud & application securityArchitecture, configuration, and identity reviews
vCISO advisorySecurity leadership without a full-time hire
Incident readinessResponse plans and tabletop exercises
Risk assessmentsWhere you stand against NIST CSF 2.0 and CIS Controls
Policies, controls & evidenceA security program you can repeat and prove
Vendor riskThird-party reviews with clear priorities
Find the right service
SOC 2 readiness
ISO/IEC 27001 readiness
HIPAA Security Rule readiness
CMMC readiness
Assurance and trust centerHow to check credentials, how engagements run, how we stay independent, and how this website handles your data.
Credentials & authorizationsHow credentials and authorizations work, and how to check them
MethodologyHow engagements are scoped, run, and reported
IndependenceHow advisory work stays separate from formal assessment
Responsible disclosureHow to report a security issue in our website or systems
About
Team
Industries
Pricing
Contact
InsightsPlain-language articles on security and compliance topics
GlossarySecurity and compliance terms, defined in plain language
Search the siteServices, readiness guides, glossary terms, and articles
Privacy notice
Terms of use
Accessibility
Privacy choices

Compliance readiness

CMMC readiness: prepare for Level 1 and Level 2 assessments

Readiness for CMMC Level 1 and Level 2 against FAR 52.204-21 and NIST SP 800-171 Rev 2, with support for self-assessments and for a certification assessment by an authorized C3PAO if you need one.

Version as of

CMMC Program (32 CFR Part 170); Level 2 uses NIST SP 800-171 Rev 2

Program rule effective December 16, 2024; acquisition rule effective November 10, 2025

As of 2026-09-26, CMMC Level 2 is defined by NIST SP 800-171 Rev 2 (32 CFR 170.14(c)(3)), and DFARS 252.204-7012 applies NIST SP 800-171 to covered contractor information systems. For the program's current implementation, read the dated program update on this page.

Check the official CMMC source (external site)

Regulatory status changes — last checked September 26, 2026

CMMC program update — September 26, 2026: CMMC implementation remains paused in Phase 1 following the suspension of Phase II on July 13, 2026. Phase I self-assessment requirements remain in force. During the suspension, procurement requirements may designate CMMC Level 1 (Self) or Level 2 (Self), but not Level 2 (C3PAO) or Level 3 (DIBCAC).

Check the DoW CIO CMMC page and your contract language before relying on this page.

What is CMMC?

CMMC, the Cybersecurity Maturity Model Certification program, is a Department of Defense program that verifies how contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

Level 1 covers the 15 requirements in FAR 52.204-21 and is self-assessed every year. Level 2 covers the 110 requirements of NIST SP 800-171 Rev 2 and is either self-assessed or assessed by an authorized C3PAO, every three years. Level 3 adds 24 requirements from NIST SP 800-172 and is assessed by DCMA DIBCAC.

Results are entered in SPRS, and your organization's own senior Affirming Official makes the required affirmations.

Type
Federal program set out in regulation
Current version, as of
CMMC Program (32 CFR Part 170); Level 2 uses NIST SP 800-171 Rev 2. Program rule effective December 16, 2024; acquisition rule effective November 10, 2025. Version source for CMMC (external site)

Who needs CMMC?

  • Defense contractors and subcontractors whose contracts involve FCI (Level 1)
  • Contractors that handle CUI and must meet NIST SP 800-171 Rev 2 under DFARS 252.204-7012 (Level 2)
  • Contractors whose contracts or target solicitations name a CMMC level and want to confirm which assessment type applies
  • Suppliers asked by a customer for a voluntary Level 2 certification assessment

Which NIST SP 800-171 revision CMMC uses

CMMC Level 2 uses NIST SP 800-171 Revision 2. The program rule says the Level 2 security requirements “are identical to the requirements in NIST SP 800-171 R2” (32 CFR 170.14(c)(3)), and the DoW CIO describes Level 2 as the 110 security requirements in that revision.

NIST published Revision 3 in May 2024 and withdrew Revision 2 on May 14, 2024. Both facts hold at once: Revision 2 is withdrawn by NIST and is still the CMMC Level 2 baseline, because the CMMC rule incorporates Revision 2 by reference.

For CMMC planning, map your controls and evidence to Revision 2. If you also track Revision 3, keep the two mappings separate so an assessment against one isn't confused with the other, and check your contract language for the revision it names.

Sources: eCFR: 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program; DoW CIO: About CMMC; NIST SP 800-171 Rev. 2 (withdrawn by NIST on May 14, 2024; still the CMMC Level 2 baseline); NIST SP 800-171 Rev. 3 (May 2024)

Knowing which information you handle

Federal Contract Information (FCI) is information, not intended for public release, that is provided by or generated for the government under a contract to develop or deliver a product or service. It excludes information the government makes public and simple transactional information, such as what's needed to process payments (FAR 52.204-21).

FAR 52.204-21 sets 15 basic safeguarding requirements for contractor information systems that process, store, or transmit FCI, and CMMC Level 1 consists of exactly those 15 requirements (32 CFR 170.14(c)(2)).

Controlled Unclassified Information (CUI) is unclassified information that requires safeguarding or dissemination controls under law, federal regulation, or government-wide policy. The National Archives administers the CUI program, which Executive Order 13556 established. For covered contractor information systems that aren't operated on the government's behalf, DFARS 252.204-7012 applies the security requirements of NIST SP 800-171, which is where CMMC Level 2 comes in.

Sources: FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems; eCFR: 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program; National Archives: Controlled Unclassified Information (CUI) program; DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting

The documents an assessment starts from

A system security plan (SSP) describes a system's boundaries, its environments of operation, how each security requirement is implemented, and its relationships with or connections to other systems. NIST SP 800-171 Revision 2 requires contractors to develop, document, and periodically update one (requirement 3.12.4). A DFARS Basic Assessment is based on the contractor's review of its system security plans (DFARS 252.204-7020).

A plan of action and milestones (POA&M) describes how unimplemented security requirements will be met and how planned mitigations will be carried out (requirement 3.12.2).

The CMMC rule limits POA&Ms (32 CFR 170.21). A Level 1 self-assessment never permits one. At Level 2, a POA&M can support only a conditional status, only for requirements worth one point in the CMMC scoring method (with one narrow exception for encryption), and never for the system security plan requirement itself. It must be closed out within 180 days of the conditional status date, or the conditional status expires.

Sources: NIST SP 800-171 Rev. 2 (withdrawn by NIST on May 14, 2024; still the CMMC Level 2 baseline); DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements; eCFR: 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program

Where results are reported, and which clauses require it

The Supplier Performance Risk System (SPRS) is where NIST SP 800-171 assessment scores are posted and where CMMC affirmations are entered. Under the CMMC rule, an Affirming Official from each organization, prime or subcontractor, affirms continuing compliance after every assessment, including a POA&M closeout, and annually after that (32 CFR 170.22).

Four DFARS clauses tie NIST SP 800-171 and CMMC to defense contracts:

  • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, requires adequate security on covered contractor information systems, including the NIST SP 800-171 requirements for systems not operated on the government's behalf.
  • DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements: to be considered for award, an offeror required to implement NIST SP 800-171 needs a current assessment, not more than 3 years old unless the solicitation specifies less, with summary level scores posted in the Supplier Performance Risk System (SPRS).
  • DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements, defines a Basic Assessment as the contractor's own self-assessment, with a Low confidence level in the resulting score, and Medium and High Assessments as assessments conducted by the government.
  • DFARS 252.204-7021, Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements, is the clause for CMMC level requirements in contracts.

Sources: DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting; DFARS 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements; DFARS 252.204-7020, NIST SP 800-171 DoD Assessment Requirements; SPRS: NIST SP 800-171 assessments; eCFR: 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program

Formal assessment: who performs it, and on whose authority

Readiness work prepares you. The formal outcome below comes only from the organization the program authorizes.

Formal outcome
Level 1 (Self) or Level 2 (Self) results posted in SPRS, a Certificate of CMMC Status after a Level 2 (C3PAO) certification assessment, or a Level 3 (DIBCAC) assessment
Who performs it
Self-assessments are performed by your own organization and affirmed by your own senior official. Level 2 certification assessments are performed by a C3PAO authorized by the Cyber AB, using assessors certified by the CAICO (ISACA since December 2025). Level 3 assessments are performed by DCMA DIBCAC.

Outside our services

Security Inspect isn't a managed SOC, an MDR provider, or a round-the-clock emergency-response provider. We don't offer ASV scanning, PCI forensic investigations, or P2PE, SSF, PIN, or 3DS assessments, and we don't perform CMMC certification assessments or HITRUST assessments.

What we do and don’t do

CMMC Level 1 and Level 2 readiness — preparation for self-assessment or a certification assessment by an authorized C3PAO.

What we do

  • Scoping support: identify where FCI and CUI live and which systems, people, and providers are in scope
  • Gap assessment against FAR 52.204-21 (Level 1) and NIST SP 800-171 Rev 2 (Level 2)
  • System security plan (SSP) and plan of action and milestones (POA&M) support
  • Preparation for your Level 1 or Level 2 self-assessment and SPRS entry
  • Evidence preparation for a Level 2 certification assessment by an authorized C3PAO, if a contract or customer asks for one

What we don’t do

  • Act as a C3PAO, perform certification assessments, or issue a Certificate of CMMC Status
  • Make your SPRS affirmation; your own senior Affirming Official does that
  • Take part in your Level 2 certification assessment
  • Claim Cyber AB status, or use Cyber AB or CAICO logos
  • Promise that you'll pass an assessment

Independence

Under 32 CFR 170.8(b)(17)(ii)(G), members of the CMMC ecosystem may not take part in the Level 2 certification assessment process for an organization they served as a consultant to prepare for any CMMC assessment within three years. The rule reaches C3PAOs, their assessors, and CMMC professionals.

When a program requires a formal assessment, audit, or certification, it's performed by an independent, authorized assessor. We keep advisory work and formal assessment apart: a practitioner never assesses controls they designed, developed, or implemented.

How advisory work and formal assessment stay separate

How readiness works

Every engagement begins with a written scope and proposal.

  1. Confirm the requirement

    Check which CMMC level and assessment type your solicitation or contract calls for, and read the dated program update on this page.

  2. Scope FCI and CUI

    Identify the systems, people, facilities, and providers that handle FCI or CUI.

  3. Assess gaps

    Compare your practices and evidence with FAR 52.204-21 or NIST SP 800-171 Rev 2.

  4. Document and plan

    Build or update your system security plan and POA&M, and agree on a remediation plan. Level 1 doesn't permit POA&Ms.

  5. Prepare to assess

    Get ready for your self-assessment and SPRS entry, or for a C3PAO certification assessment that you arrange directly.

Deliverables

  • Scoping summary for FCI and CUI
  • Gap assessment against FAR 52.204-21 or NIST SP 800-171 Rev 2
  • System security plan and POA&M review notes or drafts for your approval
  • Self-assessment preparation checklist
  • Prioritized remediation roadmap

What CMMC readiness costs

  • CMMC Level 1 Readiness

    From $6,000

    Typical scoped range: $6,000 to $12,000

    One-time project

  • CMMC Level 2 Self-Assessment Readiness

    From $15,000

    Typical scoped range: $15,000 to $40,000

    One-time project

Non-binding. Final pricing follows a written scope and proposal.

What affects the final price

Pricing depends on environment size, complexity, testing depth, locations, applications, accounts, user roles, compliance objectives, and delivery timeline. Every engagement begins with a written scope and proposal. Taxes, travel, remediation, third-party audit or certification fees, licensing, and emergency work are separate. Readiness services do not include independent certification, attestation, legal advice, or a guarantee of passing.

Compare published prices for every service

Guides

Frequently asked questions

Do we need a C3PAO certification assessment?

Only if your contract or solicitation calls for Level 2 (C3PAO), or a customer asks for one. Each CMMC requirement names a level and an assessment type: Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), or Level 3 (DIBCAC). Which of these the Department includes in solicitations has changed over time, so read the dated program update on this page, the DoW CIO CMMC page, and your contract language before you plan.

Do our NIST SP 800-171 obligations depend on CMMC?

No. Where DFARS 252.204-7012 is in your contract, it applies NIST SP 800-171 to covered contractor information systems whether or not the contract also names a CMMC level. DFARS 252.204-7019 separately calls for a current NIST SP 800-171 assessment, with summary level scores posted in SPRS. CMMC Level 2 is defined by NIST SP 800-171 Rev 2, not Rev 3, even though NIST has published Rev 3.

Can the firm that helped us prepare also assess us?

Not for a Level 2 certification assessment within three years. 32 CFR 170.8(b)(17)(ii)(G) bars CMMC ecosystem members from the Level 2 certification assessment process for an organization they served as a consultant to prepare for any CMMC assessment within the previous three years. It applies to C3PAOs, their assessors, and CMMC professionals.

Who certifies CMMC professionals and assessors?

The CMMC Assessor and Instructor Certification Organization (CAICO) certifies individuals such as CCPs and CCAs, and ISACA has held that role since December 17, 2025. C3PAOs certify organizations at Level 2; they don't certify people. The Cyber AB remains the Accreditation Body that authorizes C3PAOs.

Who submits our self-assessment results?

Your organization does. Results go into SPRS, and your own senior Affirming Official makes the affirmation. An outside adviser can help you prepare the assessment and its evidence, but can't make the affirmation on your behalf.

Educational information, not legal advice

Information on this website is general and educational. It isn't legal advice, and it doesn't create a client relationship.

Primary sources

Talk to a practitioner about CMMC readiness

Tell us what’s driving the work and who’s asking for it, and we’ll help you judge where you stand and whether readiness support makes sense.

What happens next

  1. Tell us about your environment and the formal outcome you're working toward.
  2. Talk through scope, timing, and options with a practitioner.
  3. Review the proposal and decide whether to go ahead.