Quick answer
If you do business with the Department of Defense, or plan to, there is one acronym you need to understand right now: CMMC.
The Cybersecurity Maturity Model Certification is the DoD's new framework for ensuring that every contractor in the defense supply chain meets specific cybersecurity standards. Starting in 2025 and reaching full enforcement by 2028, CMMC compliance will be a mandatory requirement in DoD solicitations. If you can't prove compliance, you can't bid.
This guide covers everything defense contractors need to know: what CMMC is, the three certification levels, how to prepare, what it costs, and how to avoid getting locked out of the defense market.
What Is CMMC?
CMMC stands for Cybersecurity Maturity Model Certification. It's a framework developed by the DoD to verify that defense contractors adequately protect two types of sensitive information:
- Federal Contract Information (FCI): information provided by or generated for the government under a contract that isn't intended for public release. This includes things like contract terms, deliverable specifications, and project schedules.
- Controlled Unclassified Information (CUI): information that requires safeguarding or dissemination controls under law, regulation, or government-wide policy, but isn't classified. Examples include technical drawings, engineering data, test results, vulnerability assessments, and export-controlled information.
The distinction matters because the level of information you handle determines which CMMC level you need.
Why CMMC Exists
Before CMMC, the DoD relied on DFARS clause 252.204-7012, which required contractors to self-assess their compliance with NIST SP 800-171. A 2019 DoD Inspector General report found widespread non-compliance, contractors were checking boxes while missing dozens of required controls. Meanwhile, adversaries were systematically targeting the defense supply chain to steal sensitive technical data. The DoD decided self-assessment wasn't working and developed CMMC to add verified, third-party assessment.
The Three CMMC Levels
CMMC 2.0 (the current version) has three levels, each building on the one below it.
Level 1: Foundational
Who needs it: Every DoD contractor that handles Federal Contract Information (FCI). This is the baseline, if you have any DoD contract at all, you almost certainly handle FCI.
What it requires: Implementation of 17 basic cybersecurity practices derived from FAR clause 52.204-21. These are fundamental controls that any business should already have in place:
- Use passwords and authentication on all systems
- Limit system access to authorized users
- Control who can access physical systems and facilities
- Identify and fix system vulnerabilities
- Monitor and protect your network boundaries
- Update antivirus and anti-malware software
- Keep systems and software patched and updated
Assessment method: Self-assessment. You evaluate your own compliance, document it, and affirm it annually. No third party reviews your work.
Cost to achieve: Minimal if you're already following basic IT security practices. Most small businesses can achieve Level 1 with existing staff and common security tools. Budget $5,000, $15,000 for a formal gap assessment and documentation if you want professional help.
Key point: Level 1 is the bare minimum. If your only DoD work involves FCI (not CUI), this is all you need. But most contractors who handle technical data, engineering specifications, or sensitive programmatic information are handling CUI, and that means Level 2.
Level 2: Advanced
Who needs it: Every DoD contractor that handles Controlled Unclassified Information (CUI). This is the big one. If your contract involves technical drawings, engineering data, test results, source code, vulnerability assessments, or any information marked as CUI, you need Level 2.
What it requires: Implementation of all 110 security controls from NIST SP 800-171 Revision 2. These controls span 14 families including Access Control, Identification and Authentication (multifactor authentication, password complexity), Audit and Accountability, Incident Response, System and Communications Protection (encryption, boundary monitoring), and Configuration Management, among others.
Assessment method: Third-party assessment by a CMMC Third-Party Assessment Organization (C3PAO) accredited by The Cyber AB (formerly the CMMC Accreditation Body). This is the critical change from the old self-assessment model. An independent assessor comes to your organization, reviews your documentation, examines your systems, interviews your staff, and determines whether you've actually implemented the controls.
Cost to achieve: This varies significantly based on your current cybersecurity posture and company size:
- Gap assessment: $15,000, $50,000 (hiring a consultant to evaluate where you stand)
- Remediation: $25,000, $150,000+ (implementing missing controls, this is the big variable)
- C3PAO assessment: $25,000, $75,000 (the formal third-party certification)
- Ongoing compliance: $20,000, $50,000/year (monitoring, maintenance, annual reviews)
Total for a mid-size company (50-200 employees): $50,000, $200,000 to achieve initial certification, plus ongoing annual costs.
Key point: Level 2 is where most defense contractors will need to be. If you're building weapons systems, developing software for DoD, providing engineering services, or handling any technical data, Level 2 applies to you.
Level 3: Expert
Who needs it: Contractors working on the most sensitive DoD programs, think advanced weapons systems, critical infrastructure, and programs that face the most sophisticated cyber threats (nation-state adversaries).
What it requires: All 110 NIST 800-171 controls plus a subset of controls from NIST SP 800-172, addressing advanced persistent threats including threat hunting, advanced incident response, and supply chain risk management.
Assessment method: Government-led assessment by DCSA directly.
Cost to achieve: Well above $500,000. Most Level 3 contractors are large defense primes with dedicated cybersecurity teams. If you're not sure whether you need Level 3, you probably don't, your contracting officer will tell you explicitly.
The CMMC Rollout Timeline
CMMC is being implemented in phases. Understanding the timeline is critical for planning:
Phase 1 (Starting 2025)
- CMMC Level 1 self-assessments begin appearing in solicitations
- CMMC Level 2 self-assessments (for select programs) begin appearing
- The DFARS clause 252.204-7021 starts being included in new solicitations
Phase 2 (2026)
- CMMC Level 2 C3PAO assessments begin being required in solicitations
- More solicitations include CMMC requirements as mandatory evaluation criteria
Phase 3 (2027)
- CMMC Level 3 government-led assessments begin
- CMMC requirements become standard in most DoD solicitations
Phase 4 (2028)
- Full enforcement across all DoD solicitations
- All new contracts and contract renewals include applicable CMMC requirements
- Non-certified contractors are effectively excluded from the DoD market
The practical implication: If you're planning to bid on DoD contracts in 2026 or 2027, you need to be working on CMMC compliance now. Getting to Level 2 takes 6-18 months for most organizations, you can't start the month before a solicitation drops and expect to be certified in time.
What CMMC Means for Your Business
It's a Gate, Not a Preference
This is the most important thing to understand: CMMC is not a "nice to have" or an evaluation preference. It's a pass/fail requirement. Solicitations will state the required CMMC level, and if you don't hold that certification at the time specified, your proposal is non-responsive.
This is different from how cybersecurity requirements worked in the past. Under the old DFARS 7012 regime, contractors self-attested to compliance, and the government rarely verified. Under CMMC, you need an actual certification from an accredited assessor.
The Competitive Impact
CMMC will reshape the competitive landscape. Companies that can't afford compliance will exit the defense market, reducing competition for certified contractors. Early movers who achieve certification before competitors will have access to solicitations others can't bid on. During the transition period (2025-2028), holding CMMC certification signals to the government that you take cybersecurity seriously.
Subcontractor Flow-Down
Primes must ensure their subcontractors are also CMMC compliant. If you're a prime with a Level 2 requirement, every subcontractor who handles CUI must also hold Level 2 certification, regardless of tier. This means primes need to verify sub CMMC status, and subs who aren't certified may lose teaming opportunities. Your teaming agreements should include CMMC compliance requirements.
How to Prepare for CMMC Certification
Whether you're starting from scratch or building on existing cybersecurity practices, here's a step-by-step approach:
Step 1: Determine Your Required Level
Review your current and target DoD contracts. What type of information do you handle?
- FCI only → Level 1
- CUI → Level 2
- CUI on highest-sensitivity programs → Level 3
If you're not sure, look at your contracts for DFARS clauses 252.204-7012 (safeguarding CUI) and 252.204-7020 (NIST 800-171 assessment). If either clause is present, you're handling CUI and need Level 2.
Step 2: Scope Your CUI Environment
Identify exactly where CUI lives in your organization. The smaller your CUI boundary, the fewer systems you need to secure and the lower your costs. Many organizations create a dedicated CUI enclave rather than applying all 110 controls enterprise-wide.
Step 3: Conduct a Gap Assessment
Compare your current security posture against NIST 800-171 controls. For each of the 110 controls, determine whether it's fully implemented, partially implemented, not implemented, or not applicable. You can do this internally or hire a consultant, many MSSPs and CMMC consultants offer gap assessments as a standalone service.
Step 4: Create a System Security Plan (SSP) and POA&M
The System Security Plan documents how you implement each control, it's the primary document assessors review. The Plan of Action and Milestones (POA&M) documents controls not yet fully implemented, with actions and target dates. Under CMMC, you can have limited POA&M items at assessment time, but critical controls like multifactor authentication must be fully implemented.
Step 5: Implement Missing Controls
This is the heavy lifting. Common gaps include: multifactor authentication (required for all remote and privileged access), encryption of CUI in transit and at rest, comprehensive audit logging, a documented incident response plan (including 72-hour DoD reporting), security awareness training, endpoint detection and response (basic antivirus isn't sufficient), and regular vulnerability scanning with timely remediation.
Step 6: Engage a C3PAO for Assessment
Once you're ready, engage a C3PAO from The Cyber AB marketplace to schedule your Level 2 assessment. The assessment involves documentation review, technical testing of your systems, staff interviews, and a findings report with a certification determination. Expect 1-2 weeks of on-site work for a mid-size organization.
Step 7: Maintain Compliance
CMMC certification isn't a one-time event. You must maintain compliance continuously, undergo reassessment every three years, perform regular vulnerability scanning, conduct annual security awareness training, update your SSP when systems change, and submit annual affirmation of continued compliance.
Common CMMC Preparation Mistakes
- Starting too late. Level 2 compliance takes 6-18 months. If you wait until a solicitation drops with a CMMC requirement, you're already too late.
- Applying all controls everywhere. Scope your CUI environment tightly. Create a dedicated enclave for CUI processing rather than securing your entire enterprise network.
- Ignoring documentation. Assessors verify that policies and procedures are documented, not just technically implemented. Incomplete documentation fails assessments.
- Overlooking subcontractor requirements. If you're a prime, your subs' CMMC status is your problem. Start those conversations now.
- Choosing the wrong cloud provider. Cloud services processing CUI must be FedRAMP authorized. Microsoft GCC High, AWS GovCloud, and Google Cloud for Government are common compliant options.
How Bidovate Helps Contractors Navigate CMMC Requirements
As CMMC requirements roll out across DoD solicitations, knowing which opportunities require which certification level becomes essential for your bid/no-bid decisions.
Bidovate's opportunity discovery platform tracks which solicitations include CMMC requirements and at what level, helping contractors filter for opportunities they're certified to pursue. Instead of reading through every solicitation to find the CMMC clause buried in Section L, you can quickly identify:
- Opportunities that match your current certification level
- Upcoming recompetes where CMMC may be added as a new requirement
- Solicitations where competitors may be eliminated due to CMMC non-compliance, creating opportunities for certified contractors
For contractors still working toward certification, knowing the timeline of when CMMC requirements will appear in your target market helps you prioritize your compliance investment.
Frequently Asked Questions
How long does it take to get CMMC Level 2 certified?
From starting preparation to receiving certification, expect 6-18 months for most mid-size organizations. The timeline breaks down roughly as: gap assessment (2-4 weeks), remediation planning (2-4 weeks), implementing missing controls (3-12 months depending on your starting point), documentation (concurrent with implementation), and C3PAO assessment (4-8 weeks including scheduling lead time). The biggest variable is remediation, if you're starting with solid cybersecurity practices, you might need only 3-4 months of remediation. If you're starting with basic antivirus and passwords, plan for 12+ months.
Can I still bid on DoD contracts without CMMC certification?
During the phased rollout (2025-2027), many DoD solicitations will not yet include CMMC requirements. You can still bid on those. However, as the rollout progresses, an increasing number of solicitations will require certification. By 2028, all new DoD contracts are expected to include applicable CMMC requirements. If you plan to be in the defense market long-term, getting certified is not optional, it's a matter of when, not if.
What happens if I fail a CMMC assessment?
If the C3PAO assessment identifies deficiencies, you'll receive a report detailing what needs to be fixed. You can remediate the issues and request a reassessment. There is no formal penalty for failing, you simply don't receive certification until you pass. However, failing delays your ability to bid on CMMC-required solicitations, so it costs you in missed opportunities. The best way to avoid failing is to conduct a thorough self-assessment or hire a consultant for a pre-assessment readiness review before engaging a C3PAO.
Does CMMC apply to commercial-item contracts with DoD?
Yes. CMMC applies based on the type of information you handle, not the type of contract. If you sell commercial products or services to the DoD and handle CUI in the process, which includes receiving technical specifications, engineering data, or vulnerability information, you need the applicable CMMC level. The only exception is contracts that involve only publicly available information with no FCI or CUI.
How does CMMC relate to NIST 800-171?
CMMC Level 2 is directly based on NIST SP 800-171, the 110 controls in Level 2 are the same 110 controls from NIST 800-171. The difference is verification. Under the old DFARS 7012 requirement, you self-assessed your compliance with NIST 800-171. Under CMMC Level 2, a third-party C3PAO verifies your compliance with those same controls. Think of CMMC as NIST 800-171 with teeth, the same requirements, but with independent verification instead of self-attestation.
Start Preparing Now
CMMC is coming, and the contractors who prepare early will have a significant competitive advantage. Those who wait will find themselves locked out of solicitations they could have won.
The steps are clear: determine your required level, scope your CUI environment, conduct a gap assessment, implement missing controls, and get assessed. It's a significant investment, but it's an investment in your ability to remain in the defense market.
For contractors handling CUI, Level 2 certification isn't just about compliance. It's about survival in the DoD market. Every month you delay preparation is a month closer to solicitations dropping with CMMC requirements you can't meet.
Start with a gap assessment against NIST 800-171. Know where you stand. Then build a plan to close the gaps before the deadlines arrive.
Book a Demo to see how Bidovate helps defense contractors track CMMC requirements across DoD solicitations and find opportunities that match their certification level.
Ready to win more contracts?
Bidovate scans 1000+ procurement portals and matches opportunities to your company profile.