CMMC Readiness: What Contractors Need to Know
A plain-language breakdown of CMMC levels, scope, and what a Certified Third-Party Assessment actually looks at.
The short version
- CMMC verifies that defense contractors have actually implemented NIST SP 800-171 safeguards, rather than self-attesting to them.
- Your required level depends on the data you handle: FCI points to Level 1, CUI generally points to Level 2.
- Scoping the CUI boundary is the highest-leverage decision, because everything inside it must meet the full control set.
- Most lost points trace back to documentation, especially incomplete System Security Plans and over-used POA&Ms.
What is CMMC and why does it exist?
The Cybersecurity Maturity Model Certification program verifies that contractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) have implemented the safeguards required by DFARS 252.204-7012 and NIST SP 800-171, rather than just attesting to them. Self-attestation was the prior model, and the gap between what contractors reported and what assessors found when they looked is the reason the program exists.
Which CMMC level do I need?
- Level 1, Foundational: basic safeguarding of FCI, annual self-assessment
- Level 2, Advanced: the full NIST SP 800-171 control set, typically requiring a Certified Third-Party Assessment (C3PAO)
- Level 3, Expert: adds a subset of NIST SP 800-172 controls, for the highest-priority programs
How do I know whether I handle CUI?
This is the question that determines your level, and contractors get it wrong in both directions. FCI is information provided by or generated for the government under a contract that is not intended for public release. CUI is a narrower category requiring safeguarding under a specific law, regulation, or government-wide policy, and it should be marked as such when the government provides it. If your contract includes DFARS 252.204-7012, that is a strong signal CUI is in play. When markings are ambiguous, ask your contracting officer in writing rather than deciding internally, because the answer sets your scope, your level, and your cost.
How do I scope the CUI boundary?
Everything inside your CUI boundary must meet the full control set, so the boundary is the single largest cost driver in a CMMC program. Contractors who let CUI spread across a general-purpose corporate network end up assessing the entire environment. Contractors who isolate CUI into a defined enclave assess that enclave. The enclave approach costs more up front in design work and usually costs far less across the assessment and every subsequent reassessment.
Where contractors typically lose points
- Incomplete or inconsistent System Security Plans (SSPs)
- Plans of Action and Milestones (POA&Ms) used to defer too much scope
- Unclear boundaries for CUI in cloud environments and with subcontractors
- Missing evidence for controls that are implemented but undocumented
- External service providers assumed to inherit compliance without a documented shared responsibility position
What does a C3PAO assessment actually look at?
An assessor works through the control set and, for each one, looks for three things: a documented statement of how the control is implemented, evidence that the implementation is real, and confirmation from the people who operate it that the described process matches what they actually do. Discrepancies between those three are where findings come from. A control described accurately in the SSP but performed differently in practice fails, and so does a control performed well but described vaguely.
Getting to assessment-ready
- Determine your required level and scope your CUI and FCI boundary
- Assess current controls against NIST SP 800-171
- Remediate gaps and build the required SSP and POA&M
- Collect operating evidence for controls that require it
- Run a readiness (mock) assessment before your C3PAO engagement
Need hands-on help with this?
See how our CMMC Readiness engagement works.
Ready to put this into practice?
Reading the guide is the easy part. If you want practitioners who have run these implementations to scope the work with you, start with a free consultation.