Back to Learning CenterBeginner Guide

What Is CMMC? A Complete Guide for Defense Contractors

The Cybersecurity Maturity Model Certification is the DoD's framework for ensuring defense contractors can protect sensitive information. Here's everything you need to know.

What Is CMMC?

CMMC stands for Cybersecurity Maturity Model Certification. It's a Department of Defense (DoD) program that requires defense contractors to meet specific cybersecurity standards before they can bid on or perform DoD contracts.

CMMC was created because unverified self-attestation wasn't working — studies found that the vast majority of contractors claiming compliance weren't actually meeting the requirements. The program's answer was independent assessments by C3PAOs (Certified Third Party Assessment Organizations). In July 2026, the Department of War (formerly DoD) suspended that third-party mandate (Phase 2) pending a top-to-bottom program review — which means verification currently runs on documented self-assessments affirmed in SPRS, with the legal responsibility for accuracy resting squarely on the contractor. Read our full breakdown of what the suspension actually changes.

Who Needs CMMC Certification?

If your organization handles DoD contracts or is part of the Defense Industrial Base (DIB) supply chain, you are likely subject to CMMC requirements. This includes:

  • Prime contractors — Companies that contract directly with the DoD
  • Subcontractors — Companies that supply goods or services to prime contractors
  • Supply chain vendors — Any organization that processes, stores, or transmits CUI or FCI

Approximately 220,000 defense contractors are subject to CMMC requirements. During the Phase 2 suspension, contracts require current Level 1 or Level 2 self-assessments— if your SPRS score and affirmation aren't current when a contract requires them, you won't be eligible to bid.

The Three CMMC Levels

CMMC 2.0 simplified the original five-level model into three levels, each building on the previous:

L1

Level 1 — Foundational

For organizations handling Federal Contract Information (FCI) only.

  • 15 basic cybersecurity practices from FAR 52.204-21
  • Annual self-assessment (no third-party audit)
  • Covers basic cyber hygiene: passwords, antivirus, access control
L2

Level 2 — Advanced Most Common

For organizations handling Controlled Unclassified Information (CUI).

  • All 110 NIST SP 800-171 Revision 2 security practices
  • C3PAO third-party assessment (mandate suspended July 2026 — self-assessment currently applies)
  • Triennial certification with annual affirmations
  • Covers 14 security domains: Access Control, Audit, Incident Response, and more
L3

Level 3 — Expert

For organizations handling the most sensitive CUI (high-value assets, advanced persistent threats).

  • All Level 2 requirements plus select NIST SP 800-172 practices
  • Government-led assessments (DCMA DIBCAC)
  • Designed for programs with nation-state threat exposure

Key Terms You Need to Know

CUI (Controlled Unclassified Information)

Information the government creates or possesses that requires safeguarding — technical drawings, specifications, test results, etc.

FCI (Federal Contract Information)

Information provided by or generated for the government under contract, not intended for public release.

C3PAO

Certified Third Party Assessment Organization — the independent assessors authorized to conduct CMMC Level 2 assessments.

SSP (System Security Plan)

A document describing your security controls, how they're implemented, and the boundaries of your information system. Bedrock CMMC generates your SSP directly from your control implementations.

POA&M (Plan of Action & Milestones)

A document tracking security weaknesses and your remediation plan with target completion dates. Bedrock CMMC includes a built-in POA&M tracker with status workflows and deadline monitoring.

SPRS Score

Your Supplier Performance Risk System score (-203 to 110) reflecting NIST 800-171 implementation status. Required for DoD contracts.

How to Get Started with CMMC

1

Determine your required CMMC level

Check your contracts for DFARS clauses. If you handle CUI, you'll likely need Level 2. FCI only? Level 1 may suffice.

2

Conduct a gap assessment

Evaluate your current cybersecurity posture against the required practices. Identify which controls you've implemented and which have gaps. Bedrock CMMC shows your MET/NOT MET status across all 14 domains and calculates your SPRS score automatically.

3

Remediate gaps and document controls

Implement missing controls, collect evidence, and build your SSP and POA&M. This is where compliance software like Bedrock CMMC accelerates the process.

4

Consider a voluntary C3PAO assessment

The third-party mandate is suspended, but voluntary Level 2 assessments remain available — many primes value them, and a certification is the strongest evidence behind your affirmation. The Bedrock C3PAO Marketplace connects you directly with available assessors.

5

Get certified and maintain compliance

After passing your assessment, you receive your CMMC certification. Level 2 certification is valid for 3 years with annual affirmations required.

Frequently Asked Questions

What is CMMC?

CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense's framework for verifying that defense contractors have adequate cybersecurity practices to protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). As of the July 2026 suspension of Phase 2, verification runs on documented self-assessments affirmed in SPRS while a Department of War task force reviews the third-party assessment model.

Who needs CMMC certification?

Any company that handles DoD contracts or is part of the Defense Industrial Base (DIB) supply chain is subject to CMMC requirements — during the July 2026 Phase 2 suspension, that means current Level 1 or Level 2 self-assessments with SPRS affirmations. This includes prime contractors, subcontractors, and any organization that processes, stores, or transmits CUI or FCI. Approximately 220,000 defense contractors are affected.

What are the CMMC levels?

CMMC has three levels: Level 1 (Foundational) requires 15 basic cybersecurity practices with annual self-assessment. Level 2 (Advanced) requires all 110 NIST SP 800-171r2 practices — verified by C3PAO third-party assessment under the Phase 2 mandate suspended in July 2026, and by self-assessment during the suspension. Level 3 (Expert) adds NIST SP 800-172 requirements with government-led assessments.

How long does CMMC certification take?

Timeline varies based on your current cybersecurity posture. Organizations starting from scratch typically need 12-18 months to implement all controls and prepare for assessment. Those with existing NIST 800-171 compliance may need 3-6 months for gap remediation and assessment preparation.

What is the difference between CMMC and NIST 800-171?

NIST SP 800-171 defines the 110 security requirements. CMMC is the certification framework that verifies you've actually implemented those requirements — through structured self-assessments affirmed in SPRS today, and through certified C3PAO assessments if the suspended third-party mandate returns. Implementing NIST 800-171 remains a binding contract condition under DFARS 252.204-7012 either way.

What happens if I don't get CMMC certified?

Compliance is still a condition of doing business with the DoD. During the Phase 2 suspension, contracts require current Level 1 or Level 2 self-assessments with SPRS affirmations — without them you are not eligible to bid. Inaccurate affirmations carry False Claims Act exposure, and many primes continue to prefer or contractually require third-party certification from their subcontractors.

Continue Learning

CMMC Level 2 Requirements

Detailed breakdown of all 110 NIST 800-171r2 practices organized by security domain.

Read Guide

The CMMC Assessment Process

From self-assessment to certification — evidence, SPRS scoring, and readiness.

Read Guide

C3PAO Assessment Guide

How to prepare for your assessment, choose a C3PAO, and what to expect.

Read Guide

Continuous Monitoring

How to maintain compliance after certification with ongoing monitoring.

Read Guide

Start Managing Your CMMC Compliance

Bedrock CMMC tracks all 110 controls, manages your evidence, generates your SSP, and connects you with C3PAO assessors — all in one platform.