If you handle government information on your company's computers, cybersecurity is part of your contract. For Department of Defense work, the Cybersecurity Maturity Model Certification (CMMC) program adds a verification step: you must show that required protections are in place, sometimes through an outside assessment. This guide gives a high-level overview. It is not a compliance checklist; always follow the requirements in your solicitation and the official sources linked here.
Two kinds of information
Federal contract information (FCI)
Information provided by or generated for the government under a contract that is not intended for public release. Most companies with federal contracts handle at least some FCI. FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems, sets basic safeguarding requirements for systems that process, store or transmit it.
Controlled unclassified information (CUI)
Information the government creates or possesses (or that a contractor creates or possesses for the government) that requires safeguarding or dissemination controls under law, regulation or policy. Defense contracts that involve CUI typically include DFARS 252.204-7012, which requires safeguarding covered defense information using the security requirements in NIST Special Publication 800-171 and reporting cyber incidents.
What CMMC is
CMMC is DoD's program to verify that contractors have implemented required security protections. The program rule is 32 CFR part 170, and the contract clause is DFARS 252.204-7021. Under 32 CFR 170.14, the CMMC model incorporates security requirements from:
- FAR 52.204-21 (basic safeguarding)
- NIST SP 800-171 Revision 2 (protecting CUI in nonfederal systems)
- Selected requirements from NIST SP 800-172 (enhanced protections for CUI)
The rule applies to DoD contractors and subcontractors that will process, store or transmit FCI or CUI on contractor information systems in performance of a DoD contract, with limited exceptions such as contracts exclusively for commercially available off-the-shelf (COTS) items. Requirements are being phased into contracts over time, so the CMMC level required — if any — will be stated in each solicitation.
The three levels at a glance
Level 1 (Self)
For FCI. You must meet all the Level 1 security requirements (drawn from FAR 52.204-21), conduct a self-assessment, and submit results in DoD's Supplier Performance Risk System (SPRS). Under 32 CFR 170.15, no plans of action are permitted for Level 1, and the self-assessment must be repeated annually.
Level 2 (Self) or Level 2 (C3PAO)
For CUI, based on NIST SP 800-171. Depending on the contract, Level 2 is met either through a self-assessment (32 CFR 170.16) or through a certification assessment by an authorized third-party assessment organization, known as a C3PAO (32 CFR 170.17). Level 2 assessments are repeated on a three-year cycle.
Level 3 (DIBCAC)
For certain CUI requiring enhanced protection. A Level 3 assessment is performed by DoD's Defense Contract Management Agency Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), and requires a final Level 2 (C3PAO) status first (32 CFR 170.18).
Annual affirmations
A senior official of the company must submit affirmations of continuing compliance in SPRS, including annually after the assessment (32 CFR 170.22).
Where small businesses usually start
- Figure out what information you handle. Do you only receive FCI (for example, contract documents and schedules), or will you handle CUI (for example, marked technical drawings or controlled data)? The answer drives everything else.
- Implement the basic safeguards. FAR 52.204-21's requirements cover fundamentals such as limiting system access to authorized users, identifying and authenticating users, limiting physical access, protecting against malicious code and correcting system flaws in a timely manner.
- Scope your environment. Keep government information in a defined set of systems. A smaller scope is easier to protect and assess.
- Document what you do. Assessments look for evidence — policies, configurations, records — not just good intentions.
- Read every solicitation's cyber clauses. The required CMMC level, if any, will be stated. Primes will also flow requirements down to subcontractors.
Free and official resources
- DoD's CMMC program pages (DoD CIO)
- The rule text at 32 CFR part 170
- NIST's publications for SP 800-171 and 800-172 at csrc.nist.gov
- SBA notes that DoD's Project Spectrum offers free cybersecurity tools and training for small businesses
- APEX Accelerators can point you to local help
Common misunderstandings
- "We're too small for this to apply." The rule applies based on the information you handle and the contract's requirements, not company size.
- "Our IT provider handles it." Providers can help a great deal, but the company remains responsible for its compliance and its affirmations.
- "We'll deal with it when we win." Required CMMC status is generally a condition of award for contracts that specify it, so plan ahead for any work that needs it.
- "Level 1 is only paperwork." Level 1 requires actually meeting every listed safeguarding requirement; plans of action are not permitted at that level.
Frequently asked questions
Does CMMC apply to non-DoD contracts?
CMMC is a DoD program. Other agencies' contracts can include their own cybersecurity requirements, and FAR 52.204-21 basic safeguarding applies broadly where covered contractor information systems are involved.
Do I need a third-party assessment?
Only if your contract requires CMMC Level 2 (C3PAO) or Level 3. Level 1 and Level 2 (Self) use self-assessments. The solicitation will state the required level.
Does CMMC apply to subcontractors?
Yes. The rule applies to subcontractors that process, store or transmit FCI or CUI, and primes flow the requirements down.
What is SPRS?
The Supplier Performance Risk System, where DoD contractors submit self-assessment results and affirmations.
This guide is general information, not legal advice. Rules change — always check the solicitation and the official sources linked here.