CMMC is the Department of Defense's way of saying "prove your cybersecurity is real before we trust you with our data." The rollout began in contracts on November 10, 2025, so for defense contractors and their subcontractors it is no longer a future problem.
If you've heard "CMMC" in a meeting or received an email from a prime contractor asking about your "CMMC level," this entry explains what it is, who needs it, how the levels work and what getting ready actually involves.
What does CMMC stand for?
Cybersecurity Maturity Model Certification.
- Cybersecurity: protecting data, systems and networks from attack.
- Maturity model: a framework that measures how developed and consistent your security practices are, not just whether you own a few tools.
- Certification: a verifiable result from an assessment, rather than a self-declared badge (though some levels allow self-assessment, as explained below).
The simple way to think about it
CMMC works like a tiered driver's license for handling DoD information. You don't need the same license to drive a sedan as you do to haul hazardous materials. The more sensitive the information you handle, the higher the level you need and the more rigorous the check:
- Handling basic Federal Contract Information (FCI)? Level 1.
- Handling Controlled Unclassified Information (CUI)? Level 2.
- Handling high-value CUI tied to critical defense programs? Level 3.
A short history: CMMC 1.0 to CMMC 2.0
The original CMMC, announced in 2019, had five levels and drew heavy criticism for cost and complexity, especially for small contractors. The DoD revised it in late 2021 as CMMC 2.0, with three levels and self-assessment allowed in some cases. The legal pieces then took several years:
- 32 CFR Part 170 (the program rule): published in October 2024 and effective December 16, 2024. It defines the levels and the assessment process.
- 48 CFR (the DFARS acquisition rule): effective November 10, 2025. It lets contracting officers put CMMC requirements into actual contracts.
The rollout is phased. In Phase 1, which began November 10, 2025, new contracts can require Level 1 or Level 2 self-assessments. Phase 2 begins November 10, 2026 and adds Level 2 certification by a third-party assessor for applicable contracts. Later phases extend Level 3 and full implementation across applicable contracts over the following years.
The three levels of CMMC 2.0
Level 1: Foundational
- Who: contractors that handle FCI, meaning information created for or provided under a federal contract that isn't meant for public release.
- Requirements: the 15 basic safeguarding requirements in FAR 52.204-21 (things like limiting access to authorized users, keeping malware protection current and controlling physical access).
- Assessment: annual self-assessment with an affirmation by a senior company official.
Level 2: Advanced
- Who: contractors that handle CUI, such as technical drawings, specifications or certain personnel data.
- Requirements: the 110 requirements of NIST SP 800-171 Rev 2, the same standard many contractors have been expected to meet for years under DFARS 252.204-7012.
- Assessment: every three years. Depending on the contract, either a self-assessment or a certification assessment by a Certified Third-Party Assessment Organization (C3PAO). Phase 2 is when C3PAO certification starts appearing as a requirement in applicable contracts; some contracts may still permit self-assessment.
Level 3: Expert
- Who: contractors working with high-value CUI on critical programs.
- Requirements: Level 2 plus selected requirements from NIST SP 800-172 aimed at advanced persistent threats.
- Assessment: conducted by the government's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), after a Level 2 certification.
Who actually needs CMMC?
If you are in the DoD supply chain, even several layers down, CMMC may apply to you. This is what catches small businesses off guard. You may not hold a DoD contract yourself, but if you supply parts, services, software or support to a company that does, the requirement can flow down to you for the information you handle.
- Handle FCI? Level 1 at minimum.
- Handle CUI? Level 2 at minimum.
- Work on designated high-priority programs? Level 3 may apply.
Machine shops, fabricators, engineering firms and specialty contractors are common examples. We support manufacturers and construction firms in Southwest Florida that sit in or near these supply chains. If you aren't sure what category your data falls into, start there, because the level you need shapes everything else about your IT environment.
Why CMMC matters even if you're not a defense contractor
- Federal frameworks spread. NIST SP 800-171 now shows up in other federal and state contracts, cyber insurance applications and large-company vendor questionnaires.
- Requirements flow downhill. If your largest customer is in defense, aerospace or critical infrastructure, expect similar questions to reach you.
- The groundwork overlaps. CMMC sits on the broader NIST library. If you're already aligning with the NIST Cybersecurity Framework, much of the foundational work carries over.
What the assessment process looks like
For Level 2, where most contractors handling CUI will land, the path usually goes like this:
- Scope your environment. Find where CUI lives, who touches it and which systems process it. This is where many contractors discover their environment is bigger and messier than they thought.
- Write your System Security Plan (SSP). A document describing how you meet each of the 110 requirements.
- Run a gap assessment. Compare what you actually do with what NIST SP 800-171 requires and document each gap.
- Remediate. Close the gaps with technology, policies, procedures and training. Gaps you can't close yet go into a plan of action with milestones, within the limits the rule allows.
- Assess. Either submit a self-assessment score to the DoD's Supplier Performance Risk System (SPRS) or schedule a C3PAO assessment, depending on the contract.
- Maintain. CMMC is ongoing. You affirm continued compliance for the life of the contract.
Preparation for a third-party assessment commonly takes many months, so starting early is the cheaper option.
How NerdSquad helps
NerdSquad is not a C3PAO, and we don't perform the formal assessment. As a Managed Service Provider (MSP), we do the work that prepares you for one and helps you keep the controls running afterward.
That includes scoping your CUI environment, building and maintaining the System Security Plan, deploying the controls NIST SP 800-171 calls for (access management, audit logging, encryption, endpoint detection and response, secure backup), training your team and producing the documentation an assessor will ask to see. The assessment result is up to the assessor, but you'll walk in organized.
If you're a small or midsize contractor facing a CMMC requirement and not sure where to start, it's worth a conversation before Phase 2 arrives. Related reading: CISA explained and what a compliance risk assessment is.
NerdSquad is not a law firm; confirm your obligations with your compliance counsel and your contracting officer.
Talk to NerdSquad
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.
Related: Cybersecurity services for businesses