CMMC
Who needs it
Defense contractors and subcontractors in the Defense Industrial Base that handle Federal Contract Information or Controlled Unclassified Information as part of a DoD contract.
Key requirements
Implementation of the 110 security controls from NIST SP 800-171 for Level 2, a System Security Plan and Plan of Action & Milestones documenting current status, and assessment (self, C3PAO-led, or government-led) matched to your required level.
Cyber/privacy implications
Controlled Unclassified Information flowing through your environment needs to be identified and scoped precisely, since the control burden and assessment type both depend on exactly where CUI lives and moves.
Assessment methodology
CUI data-flow scoping, gap assessment against the applicable NIST SP 800-171 or 800-172 control set, System Security Plan development, and readiness support for self-assessment or C3PAO engagement.
Implementation phases
Scope
Identify FCI/CUI data flows and determine your required CMMC level.
Remediate
Close control gaps against NIST SP 800-171 (Level 2) or 800-172 (Level 3).
Assess
Complete self-assessment or support a C3PAO/government-led assessment.
Evidence & documentation requirements
System Security Plan, Plan of Action & Milestones, CUI data-flow diagrams, and control implementation evidence mapped to each applicable NIST SP 800-171 requirement.
Common mistakes
Under-scoping the CUI boundary to minimize apparent assessment burden, which creates contract compliance risk; waiting until a contract requires a specific level before starting remediation, when the underlying control implementation takes months.
Related standards
Expert review
FAQ
Request a Gap Assessment
Scope your CUI boundary and see where your controls stand against NIST SP 800-171.
Request a Gap Assessment →