Skip to content
CMMC Guidance
← Knowledge Base

Levels, scoping, and what actually changed.

CMMC is the Department of Defense program that verifies a contractor has implemented the safeguards its contracts already required. The obligation is not new. The verification is.

The single most useful thing to understand about CMMC is that it did not create the security requirements. If a contract flows down DFARS 252.204-7012, the obligation to implement NIST SP 800-171 has been in force for years. What CMMC adds is a verification mechanism: a defined level, a defined assessment type, and a defined consequence for not having one.

That reframing matters commercially. A supplier who reads CMMC as a new burden tends to treat it as a project with an end date. A supplier who reads it as verification of an existing obligation tends to ask the more useful question, which is what their environment would actually score if someone looked at it today.

The levels

The model is tiered by the sensitivity of the information a contract involves. The lowest tier covers Federal Contract Information and a small set of basic safeguards. The middle tier is the one most defense suppliers land in: it is built on the NIST SP 800-171 requirements and is where the majority of CUI-handling work sits. The highest tier adds enhanced requirements aimed at advanced persistent threats and applies to a narrow set of programs.

Assessment type varies with the tier as well — some are self-assessed and attested to, others require an independent assessment by an accredited third party, and the highest involves the government directly. Which type applies to a given contract is a question about that contract, not about the company, and it is set out in the program rule rather than negotiated.

Scoping is the decision that costs the most money

Before any control is implemented, someone has to decide which systems are in scope. That decision drives everything downstream: the number of endpoints to be hardened, the volume of evidence to be maintained, and the size of the assessment. Two companies of identical size can differ by an order of magnitude in cost purely on how their boundary was drawn.

The lever is reducing what touches CUI in the first place. An enclave that isolates CUI handling to a defined set of systems is usually cheaper to secure and far cheaper to assess than an environment where CUI has spread across general-purpose file shares, personal drives and email. Scoping work done before remediation is the highest-return hour in the engagement.

What to do first

  • Read the contract. Establish which clauses flow down and whether the information involved is actually CUI.
  • Map where that information goes — systems, people, subcontractors, cloud services, backups.
  • Draw the smallest defensible boundary around it, and confirm the map matches reality rather than the org chart.
  • Only then assess against the requirements, so the assessment covers the environment you intend to keep.

The program rule is published and readable. Where a specific level definition, assessment type or timeline matters to a decision you are making, the sources below are authoritative and current — this page is orientation, not a substitute for them.

Primary sources

Reference material, not legal advice. Where a specific number, deadline or level determination affects a decision, work from the source document and your own contract language.

Need this answered for your environment?

These pages are general. The readiness call is where it gets specific to your boundary, your contracts and your actual score.

  • Your CUI boundary sketched on the call
  • The requirements costing you the most points, named
  • A written summary afterward, yours to keep
Book the readiness call

NDA signed before anything technical. No cost, no obligation.