Plain answers,
cited to the source.
Reference material on CMMC 2.0, NIST SP 800-171, and SPRS scoring. Nothing here sits behind a form. The nine working documents in the Resource Library ask for a name, company, work email and industry, and that is the only place on this site that does.
Start here.
Five questions that come before any of the technical work. If a supplier can answer these, the rest of the programme is a plan rather than a panic.
- What is CMMC?
- Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense program that verifies a contractor has implemented the safeguards its contracts already required. The obligation is not new. If a contract flows down Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, the duty to implement National Institute of Standards and Technology (NIST) SP 800-171 has been in force for years. What CMMC adds is verification: a defined level, a defined assessment type, and a defined consequence for not holding one. There are three levels. Level 1 covers the fifteen basic safeguards in Federal Acquisition Regulation 52.204-21 for Federal Contract Information. Level 2 covers all 110 NIST SP 800-171 requirements and is where most Controlled Unclassified Information work sits. Level 3 adds twenty-four enhanced requirements for a narrow set of programs. Which level applies is set by the contract and the program rule, not by a vendor, and not by the company.Read the full reference →Source: 32 CFR Part 170 — the CMMC Program rule ↗
- What is Controlled Unclassified Information?
- Unclassified information that the government still requires you to safeguard, under a government-wide policy rather than a classification marking. In practice it arrives as drawings, specifications, test data or program information attached to a contract. The safest working assumption is the one an assessor will make: if a contract flows down DFARS 252.204-7012, treat Controlled Unclassified Information as in scope until you have established otherwise in writing.Read the full reference →
- Who needs CMMC?
- Any contractor or subcontractor whose own systems process, store or transmit Federal Contract Information or Controlled Unclassified Information for the Department of Defense. It flows down: a prime is obliged to pass the requirement to suppliers who handle the information on their systems, and commercial off-the-shelf suppliers are excluded. Being a subcontractor is not an exemption, and neither is being small.
- Do I need Level 1 or Level 2?
- It follows the information, not the company. Federal Contract Information alone puts a contract at Level 1, which is the fifteen safeguards in Federal Acquisition Regulation 52.204-21. Controlled Unclassified Information puts it at Level 2, which is all 110 NIST SP 800-171 requirements. One company can hold contracts at both levels at once. The determination is in the contract language and the program rule, so anyone who tells you your level without reading your contracts and mapping where the information goes is guessing.Read the full reference →
- What is NIST SP 800-171?
- The publication that lists the 110 requirements for protecting Controlled Unclassified Information on a non-federal system, grouped into fourteen families such as access control, audit and accountability, and incident response. CMMC Level 2 does not invent its own controls — it is these 110, assessed. The scoring methodology weights them at 5, 3 or 1 points, which is why remediation is worth sequencing by points recovered rather than by whichever gap is easiest to close.Read the full reference →
What it costs, how long it takes, and where it goes wrong.
The three questions every supplier asks before committing budget. Answered with the Department of Defense’s own figures where they exist, and named as estimates where they are estimates.
- How long does CMMC take?
- Longer than the assessment, and the assessment is the short part. The first pass is a question-and-answer gap identification against the requirements, which is fast. What follows is not: standing up the tooling that produces evidence typically runs two to four weeks, and remediating the gaps behind a Plan of Action and Milestones runs weeks to months depending on how complex the environment is and how much has already been done. Most suppliers arriving at this for the first time have no documentation that shows the forensic record an assessor needs. The honest answer for a given company comes from looking at its environment, not from a page.
- What does it typically cost?
- The Department of Defense published its own estimates with the program rule. It models a Level 2 self-assessment at $34,277 for a small entity, and a Level 2 certification assessment by a Certified Third-Party Assessment Organization at $101,752 for a small entity and $112,345 for a larger one — of which the assessor’s own fee is $31,234 and $52,056 respectively, on an assumed three-person, 120-hour team at a blended $260.28 an hour. Level 1 self-assessment is modelled at $5,977 a year. Two cautions. These are modelled costs, and the rule says plainly that they "do not include actual prices of C3PAO services available in the marketplace." And they exclude the remediation, which for most suppliers is the largest line by a distance.Source: CMMC Program final rule, cost analysis at 89 FR 83185 ↗
- What are the common mistakes?
- Four, in the order they cost money. Securing before scoping, which pays to harden systems that never needed to be in the boundary. Treating the System Security Plan as paperwork produced at the end — a missing or out-of-date plan is the finding that stops an assessment rather than reducing a score. Remediating the easiest findings rather than the heaviest, which spends the budget and moves the number very little. And reading a Plan of Action and Milestones as a pass: only certain requirements can go on one at all, and the closeout window is 180 days from the status date, after which a conditional status expires.Read the full reference →
Seven steps, in this order.
Grouped under the four stages of the Method, because they are the same work described at two levels of detail. Out of order, each step makes the next one more expensive.
- Scope
Step 1: Discovery
Read the contracts, find where the information actually goes, and draw the smallest boundary that honestly contains it.
- Assess
Step 2: Gap assessment
Every in-scope requirement tested against the live environment, each finding carrying the points it costs.
Step 3: Remediation
Close the gaps in order of points recovered per dollar, not in order of what is easiest.
- Document
Step 4: Documentation
The System Security Plan, the Plan of Action and Milestones, and the scoring package, written from evidence.
Step 5: Internal review
Reconcile the score before it is submitted, and confirm the evidence supports every point claimed.
Step 6: Assessment
The self-assessment and affirmation, or the certifying assessment by an accredited third party where a contract requires one.
- Guidance
Step 7: Continuous compliance
Monitoring, evidence refresh, and score defence between assessments, because the affirmation comes due every year.
The same facts, by the decision you own.
Four readers, four different calls to make. Every figure in them is the Department of Defense’s own, cited on the page.
CMMC for chief executives
What is yours to decide, and what is yours to sign
Read →CMMC for finance leaders
What the government models it at, and what that model leaves out
Read →CMMC for program managers
Flow-down, scoping, and the evidence cadence
Read →CMMC for small businesses
The level that applies, and the lever that makes it affordable
Read →Asked by almost every supplier.
- What is a Supplier Performance Risk System (SPRS) score?
- A self-assessment score against the 110 National Institute of Standards and Technology (NIST) SP 800-171 requirements, submitted to the Supplier Performance Risk System. It starts at 110 and each unimplemented control subtracts its weight (5, 3, or 1 points).
- What score do I need to win work?
- There is no universal minimum. Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7019 requires a current score on file to be eligible for award, and individual contracting officers may set their own bar. A score below 110 must be paired with a Plan of Action and Milestones (POA&M).
- What is Controlled Unclassified Information (CUI)?
- Unclassified information that requires safeguarding under a government-wide policy. If a contract flows down DFARS 252.204-7012, assume CUI is in scope until proven otherwise.
- Is CMMCg a Certified Third-Party Assessment Organization (C3PAO)?
- No. We prepare you for assessment and maintain your posture afterward. The certifying assessment itself is performed by an accredited C3PAO — a separation that exists for good reason.
- How long does readiness take?
- It depends entirely on the starting score and the size of the CUI boundary. The readiness call exists to answer this for your environment specifically rather than in the abstract.
Question not answered here?
The readiness call is the fastest way to get a specific answer about your environment rather than a general one.
- Your CUI boundary sketched on the call
- The requirements costing you the most points, named
- A written summary afterward, yours to keep
NDA signed before anything technical. No cost, no obligation.