The single most useful thing to understand about CMMC is that it did not create the security requirements. If a contract flows down DFARS 252.204-7012, the obligation to implement NIST SP 800-171 has been in force for years. What CMMC adds is a verification mechanism: a defined level, a defined assessment type, and a defined consequence for not having one.
That reframing matters commercially. A supplier who reads CMMC as a new burden tends to treat it as a project with an end date. A supplier who reads it as verification of an existing obligation tends to ask the more useful question, which is what their environment would actually score if someone looked at it today.
The levels
The model is tiered by the sensitivity of the information a contract involves. The lowest tier covers Federal Contract Information and a small set of basic safeguards. The middle tier is the one most defense suppliers land in: it is built on the NIST SP 800-171 requirements and is where the majority of CUI-handling work sits. The highest tier adds enhanced requirements aimed at advanced persistent threats and applies to a narrow set of programs.
Assessment type varies with the tier as well — some are self-assessed and attested to, others require an independent assessment by an accredited third party, and the highest involves the government directly. Which type applies to a given contract is a question about that contract, not about the company, and it is set out in the program rule rather than negotiated.
Scoping is the decision that costs the most money
Before any control is implemented, someone has to decide which systems are in scope. That decision drives everything downstream: the number of endpoints to be hardened, the volume of evidence to be maintained, and the size of the assessment. Two companies of identical size can differ by an order of magnitude in cost purely on how their boundary was drawn.
The lever is reducing what touches CUI in the first place. An enclave that isolates CUI handling to a defined set of systems is usually cheaper to secure and far cheaper to assess than an environment where CUI has spread across general-purpose file shares, personal drives and email. Scoping work done before remediation is the highest-return hour in the engagement.
What to do first
- Read the contract. Establish which clauses flow down and whether the information involved is actually CUI.
- Map where that information goes — systems, people, subcontractors, cloud services, backups.
- Draw the smallest defensible boundary around it, and confirm the map matches reality rather than the org chart.
- Only then assess against the requirements, so the assessment covers the environment you intend to keep.
The program rule is published and readable. Where a specific level definition, assessment type or timeline matters to a decision you are making, the sources below are authoritative and current — this page is orientation, not a substitute for them.
Primary sources
- 32 CFR Part 170 — the CMMC Program rule
- CMMC Program final rule, with DoD responses to public comment
- DFARS 252.204-7021 — CMMC requirements clause
- CMMC Model Overview, Version 2.13 (September 2024)
- CMMC Assessment Guide — Level 2, Version 2.13 (September 2024)
- CMMC Scoping Guide — Level 2, Version 2.13 (September 2024)
Reference material, not legal advice. Where a specific number, deadline or level determination affects a decision, work from the source document and your own contract language.