Company
About Contact
Schedule Security Assessment
Compliance

CMMC 2.0 Explained

CMMC 2.0 is the Department of Defense cybersecurity assessment program for organizations that handle Federal Contract Information or Controlled Unclassified Information. Learn what the requirements mean and how to prepare.

Compliance June 2026 12 min read
Article Details

Author

Direct Business Technologies

Category

Compliance

Topics

CMMC, CMMC 2.0, NIST 800-171, Compliance, Defense Contractors, Controlled Unclassified Information, Cybersecurity Governance

CMMC 2.0 compliance framework overview

What Is CMMC 2.0?

Cybersecurity Maturity Model Certification, commonly referred to as CMMC, is the Department of Defense cybersecurity assessment program for defense contractors and subcontractors that handle Federal Contract Information, Controlled Unclassified Information, or both.

The program is designed to verify that organizations in the defense industrial base are implementing appropriate cybersecurity safeguards to protect sensitive but unclassified government information.

For many organizations, CMMC is not just a technical project. It is a business readiness, documentation, governance, and risk management initiative that requires coordination between leadership, IT, security, operations, legal, contracting, and external service providers.

Key Takeaways

  • CMMC applies to many organizations that support Department of Defense contracts.
  • The required CMMC level depends on the type of information handled and contract requirements.
  • CMMC Level 2 aligns closely with NIST SP 800-171 requirements.
  • Technical controls alone are not enough; documentation, evidence, and governance matter.
  • Organizations should prepare before a contract requires formal assessment.

Why CMMC Matters

Defense contractors often store, process, or transmit sensitive government information on their own systems. If those systems are not properly secured, attackers may gain access to information that can affect national security, supply chain integrity, intellectual property, and operational readiness.

CMMC creates a structured way to evaluate whether contractors are implementing the cybersecurity practices required to protect that information.

For contractors, CMMC can affect:

  • Eligibility for future DoD contracts
  • Subcontractor requirements
  • Security program maturity
  • Customer and prime contractor expectations
  • Cyber insurance and risk management conversations
  • Operational readiness for audits and assessments

Who Needs to Pay Attention to CMMC?

CMMC is especially relevant for organizations that do business with the Department of Defense or participate in the defense supply chain.

This may include:

  • Manufacturers
  • Engineering firms
  • Technology providers
  • Professional services firms
  • Managed service providers supporting defense contractors
  • Subcontractors to prime contractors
  • Organizations that handle CUI or FCI

Even organizations that do not directly contract with the DoD may be affected if CMMC requirements are flowed down through prime contractors, subcontract agreements, or customer security expectations.

Common Trigger Points

Organizations often begin CMMC readiness work after one of the following events:

  • A prime contractor asks for evidence of cybersecurity maturity.
  • A solicitation includes CMMC language.
  • A customer asks whether the organization handles CUI.
  • An internal review identifies gaps against NIST 800-171.
  • Leadership realizes cybersecurity readiness may affect future contract eligibility.

CMMC 2.0 Levels Explained

CMMC 2.0 uses maturity levels to align cybersecurity expectations with the sensitivity of information handled by the contractor.

CMMC 2.0 levels overview
CMMC levels align cybersecurity expectations with the type of information an organization handles.

Level 1: Foundational

Level 1 is generally associated with organizations that handle Federal Contract Information but not Controlled Unclassified Information. It focuses on basic safeguarding practices and is typically assessed through self-assessment.

Level 2: Advanced

Level 2 is the level most commonly associated with organizations that handle Controlled Unclassified Information. It aligns closely with NIST SP 800-171 and requires substantially more formalized security controls, documentation, and evidence.

Level 3: Expert

Level 3 is intended for higher-risk environments and organizations supporting the most sensitive missions. It builds on Level 2 and introduces more advanced security expectations.

CMMC Level Common Applicability Primary Focus Typical Assessment Type
Level 1 Federal Contract Information Basic safeguarding practices Self-assessment
Level 2 Controlled Unclassified Information NIST 800-171-aligned security controls Self-assessment or third-party assessment depending on contract
Level 3 Higher-risk DoD programs Advanced security protections Government-led assessment

FCI vs CUI: Why the Difference Matters

Understanding the difference between Federal Contract Information and Controlled Unclassified Information is one of the first steps in CMMC readiness.

Federal Contract Information

Federal Contract Information, or FCI, generally refers to information provided by or generated for the government under a contract that is not intended for public release.

Controlled Unclassified Information

Controlled Unclassified Information, or CUI, is more sensitive and requires stronger safeguarding. Organizations that process, store, or transmit CUI typically face more rigorous cybersecurity requirements.

Misunderstanding whether your organization handles CUI can lead to underestimating the required level of security, documentation, and assessment readiness.

Practical Question

Before starting a CMMC project, organizations should ask:

  • Do we handle FCI?
  • Do we handle CUI?
  • Where does that information live?
  • Who can access it?
  • Which systems process, store, or transmit it?
  • Are subcontractors or service providers involved?

These answers help define scope, which is one of the most important parts of CMMC readiness.

CMMC and NIST 800-171

For many organizations, CMMC Level 2 readiness is closely tied to implementation of NIST SP 800-171. NIST 800-171 provides security requirements for protecting Controlled Unclassified Information in nonfederal systems and organizations.

This means that CMMC readiness usually requires more than buying a tool or enabling a single security control. Organizations need a programmatic approach across access control, authentication, configuration management, incident response, logging, vulnerability management, risk assessment, security awareness, and documentation.

Common CMMC Readiness Gaps

Organizations often discover that their technical environment is only part of the challenge. Many CMMC gaps are related to documentation, ownership, consistency, and evidence.

  • Unclear CUI scope: The organization has not clearly identified where sensitive information lives.
  • Incomplete asset inventory: Systems, users, applications, and service providers are not fully documented.
  • Weak MFA coverage: Multi-factor authentication does not consistently protect required users and systems.
  • Limited logging: Security logs are not collected, retained, or reviewed consistently.
  • Missing policies: Required policies and procedures are informal, outdated, or incomplete.
  • Insufficient evidence: Controls may exist, but the organization cannot prove they are operating.
  • Unmanaged vulnerabilities: Scanning, remediation, and tracking processes are inconsistent.
  • Unclear shared responsibility: MSP, MSSP, cloud, and internal responsibilities are not clearly documented.
Common CMMC readiness gaps
CMMC readiness usually requires technical controls, documentation, evidence, and governance.

What a CMMC Readiness Program Should Include

A practical CMMC readiness program should start with scope and then move through control assessment, remediation planning, implementation, evidence collection, and ongoing governance.

  • Scope definition: Identify users, systems, applications, locations, and service providers that handle FCI or CUI.
  • Gap assessment: Compare current-state controls against applicable CMMC and NIST 800-171 requirements.
  • System Security Plan: Document the environment, boundaries, controls, and implementation details.
  • POA and M development: Track remediation tasks, owners, dates, and risk decisions.
  • Technical remediation: Implement missing or incomplete security controls.
  • Evidence collection: Build repeatable proof that controls are implemented and operating.
  • Ongoing governance: Maintain compliance through recurring reviews, updates, and monitoring.

CMMC Is Not a One-Time Project

Many organizations treat compliance as a point-in-time event. CMMC readiness is more sustainable when treated as an operating model.

  • Policies need owners.
  • Controls need evidence.
  • Risks need tracking.
  • Vulnerabilities need remediation.
  • Users need training.
  • Systems need monitoring.

The goal is not just passing an assessment. The goal is building a security program that can be maintained.

Recommended CMMC Readiness Roadmap

Most organizations make better progress when they approach CMMC readiness in phases instead of trying to address every control at once.

CMMC readiness roadmap
A phased readiness roadmap helps organizations move from uncertainty to sustainable compliance operations.
  • Phase 1 – Confirm Applicability: Determine whether CMMC requirements apply based on contracts, customer obligations, and the handling of FCI or CUI.
  • Phase 2 – Define Scope: Identify systems, users, applications, data flows, cloud services, and third parties in scope.
  • Phase 3 – Assess Current State: Evaluate existing controls against applicable CMMC and NIST 800-171 requirements.
  • Phase 4 – Build the Remediation Plan: Prioritize gaps, assign owners, estimate effort, and document risk decisions.
  • Phase 5 – Implement Controls: Strengthen identity, endpoint, logging, vulnerability, access control, backup, and incident response capabilities.
  • Phase 6 – Prepare Evidence: Collect documentation, screenshots, reports, tickets, policies, procedures, and operational proof.
  • Phase 7 – Maintain Readiness: Establish recurring governance so compliance does not decay after initial preparation.

Technical Controls That Commonly Matter

Every environment is different, but CMMC readiness frequently involves strengthening several core security areas.

  • Multi-factor authentication
  • Privileged access management
  • Endpoint detection and response
  • Vulnerability scanning and remediation
  • Patch management
  • Secure configuration baselines
  • Centralized logging and monitoring
  • Incident response planning
  • Backup and recovery
  • Security awareness training
  • Access reviews
  • Vendor and service provider management

Documentation and Evidence Matter

One of the most common surprises in CMMC readiness is that organizations may have security controls in place but lack documentation showing how those controls are implemented, maintained, reviewed, and evidenced.

Examples of useful evidence may include:

  • Policies and procedures
  • System Security Plan documentation
  • Asset inventories
  • Access review records
  • MFA configuration exports
  • Vulnerability scan reports
  • Patch management reports
  • Security alert review records
  • Incident response exercises
  • Training completion reports
  • Ticketing records showing remediation activity

Assessment Readiness Tip

Do not wait until an assessment is scheduled to begin collecting evidence.

Evidence collection should become part of normal security operations so the organization can show that controls are not only configured, but also reviewed and maintained over time.

How Managed IT and Managed Security Providers Fit In

Many organizations rely on external IT, security, cloud, or compliance partners to help operate parts of their environment. This can be valuable, but responsibilities must be clearly defined.

A service provider may help with:

  • Endpoint security
  • Patch management
  • Vulnerability management
  • Centralized logging
  • Managed SIEM
  • Incident response support
  • Microsoft 365 security configuration
  • Policy and procedure development
  • Readiness assessments
  • Remediation planning

However, outsourcing a tool or service does not automatically outsource accountability. Organizations still need clear ownership, documented responsibilities, and evidence that required controls are operating.

When Should Organizations Start Preparing?

Organizations should begin preparing before CMMC requirements appear in a contract. Waiting until a customer, prime contractor, or solicitation requires evidence can create unnecessary pressure and limit remediation options.

Early preparation allows organizations to:

  • Understand whether CMMC applies
  • Clarify CUI scope
  • Reduce remediation surprises
  • Budget for technical improvements
  • Develop required documentation
  • Improve cybersecurity maturity over time
  • Respond more confidently to customer security questions

How CMMC Supports Broader Cybersecurity Maturity

CMMC readiness should not be viewed only as a contractual requirement. Many of the same practices that support CMMC also reduce real-world cyber risk.

For example, organizations that improve MFA coverage, vulnerability management, endpoint protection, logging, incident response, and access control are also better prepared to prevent, detect, and respond to ransomware, credential theft, insider risk, and supply chain attacks.

When implemented thoughtfully, CMMC readiness can become a catalyst for building a more mature and measurable security program.

Final Thoughts

CMMC 2.0 is a major cybersecurity and business readiness consideration for organizations in the defense industrial base. For many contractors, the challenge is not simply understanding the framework; it is turning requirements into practical, sustainable security operations.

The strongest approach begins with clear scoping, realistic gap assessment, prioritized remediation, documentation, and ongoing governance.

Organizations that start early will be better positioned to meet customer expectations, reduce assessment pressure, and build a stronger cybersecurity foundation.

Next Step

Need help preparing for CMMC requirements?

DBT helps organizations assess cybersecurity gaps, align controls to CMMC and NIST 800-171, document remediation plans, and build sustainable compliance programs.

Security Readiness Assessment

Start with a clear view of your risk, readiness, and next steps.

DBT’s Security Readiness Assessment helps identify gaps across cybersecurity operations, identity, compliance, infrastructure, monitoring, and resilience so your team can prioritize practical improvements.