Contracting officers cannot award a covered Department of Defense (DoD) contract without a current Cybersecurity Maturity Model Certification (CMMC) status. That status must be posted in the Supplier Performance Risk System (SPRS), and the requirement has applied since November 10, 2025.
The rule tightens further on November 10, 2026. Third-party certification becomes the standard path for most contracts involving Controlled Unclassified Information (CUI). For a small or mid-size business (SMB) in the defense supply chain, CMMC certification is now a condition of doing business with the DoD.
This roadmap lays out the certification levels and the regulations behind them. It also covers the System Security Plan requirement and how to scope the effort for a smaller organization.
Three Levels, One Regulation
The DoD finalized the CMMC program rule at 32 Code of Federal Regulations (CFR) Part 170. The rule took effect December 16, 2024, and it sorts contractors into three levels based on the sensitivity of the information they handle.
Level 1 covers companies that handle only Federal Contract Information (FCI). It requires 15 basic safeguarding practices drawn from 48 CFR 52.204-21 and an annual self-assessment. Level 2 covers companies that handle CUI and carries 110 security requirements.
Depending on the contract, Level 2 permits either self-assessment or a certification assessment. A CMMC Third-Party Assessment Organization (C3PAO) performs that assessment, and Phase 2 of the rollout makes the C3PAO path the default for new CUI contracts.
Level 3 applies to the most sensitive programs and adds 24 enhanced requirements. Assessment authority at Level 3 sits with the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).
An SMB rarely needs to guess its level. The DoD solicitation states the required CMMC status, and that status determines which path applies.
Why DFARS and NIST 800-171 Matter Before CMMC Even Enters the Picture
CMMC did not create the underlying security requirements for Level 2. Instead of adding new security controls, it verifies obligations that have been part of defense contracts for years. The Defense Federal Acquisition Regulation Supplement (DFARS) is where those obligations originate.
DFARS 252.204-7012 requires adequate security on covered contractor information systems. It also requires rapid reporting of any cyber incident within 72 hours of discovery. The clause points to NIST Special Publication 800-171, often shortened to NIST SP 800-171, as the definition of adequate security.
Two related clauses, DFARS 252.204-7019 and 252.204-7020, require contractors to score their implementation and post it to SPRS. The CMMC acquisition rule took effect on November 10, 2025. It added DFARS 252.204-7021 to keep certification current throughout contract performance, and DFARS 252.204-7025 to state the required status in each solicitation.
The 110 Level 2 requirements are identical to the NIST SP 800-171 requirements a contractor already accepted under DFARS 252.204-7012. A company that genuinely implemented that standard has already done most of the work toward CMMC certification. A company that only claims to implement it now faces a verification process built to find the gap.
The System Security Plan Sets the Foundation
NIST SP 800-171 requires a System Security Plan (SSP) under security requirement 3.12.4. The SSP describes the system boundary and operating environment. It also documents how the organization meets each of the 110 requirements.
The SSP is not optional paperwork. Under 32 CFR 170.24, an assessor cannot complete an assessment without a current SSP on hand. The SSP also anchors the Plan of Action and Milestones (POA&M), the score entered in SPRS, and the boundaries of the assessment itself.
A POA&M tracks requirements not yet met and still support a conditional CMMC status. It never substitutes for actual implementation. Contractors get 180 days to close out eligible POA&M items, and only select requirements qualify for that window.
Implementation teams should review NIST SP 800-171 controls against existing infrastructure before drafting the SSP. They should record gaps rather than glossing over them. An SSP built on an accurate gap analysis typically holds up under assessment, while an SSP written to look complete does not.
Scoping the Effort Without Overspending
Assessment scope drives compliance cost more than any other decision an SMB makes. Under 32 CFR 170.19, the scope covers every asset that touches CUI in any way: processing it, storing it, or transmitting it. It also covers the security tools and services protecting those assets.
Segmentation is the most common cost lever for a small DoD contractor. A dedicated CUI enclave, a boundary where all CUI lives and nowhere else, keeps the number of in-scope assets small. Every asset added to scope adds licensing, monitoring, and documentation work. A tight enclave pays off across the whole certification effort, not just at assessment time.
Cloud services deserve scrutiny early in the process. A cloud product that touches CUI needs Federal Risk and Authorization Management Program (FedRAMP) Moderate authorization or an equivalent security baseline. External providers, including managed service providers, often belong in the assessment scope and need documentation in the SSP as well.
C3PAO capacity remains limited, and remediation for a first Level 2 effort rarely moves fast. Scoping decisions made early protect both the budget and the timeline.
Starting Early Is the Real Advantage
CMMC certification favors contractors who scope tightly, document honestly, and start before a solicitation forces the issue. A single regulation defines the three levels, and the Level 2 requirements mirror NIST SP 800-171 line for line. The SSP holds the entire effort together.
SMBs that treat certification as a structured project, rather than a compliance scramble, protect their standing to bid on DoD work. Organizations still mapping out where to begin benefit most from an experienced compliance partner who can run the gap analysis and set the scope before any spending on tools or assessors.
Frequently Asked Questions
How long does it take to get CMMC certified? Timelines depend heavily on scope and existing security maturity. Organizations with substantial gaps often need many months of remediation before an assessment. Limited C3PAO availability adds further scheduling time, though early scoping and a current System Security Plan shorten the path.
Is CMMC certification required for all DoD contractors? It applies to contractors and subcontractors that handle Federal Contract Information or Controlled Unclassified Information on their own systems. The DoD introduced the requirement through a phased rollout that began on November 10, 2025. Contracts limited to commercially available off-the-shelf items fall outside the rule.
What is the difference between CMMC Level 1 and Level 2? Level 1 applies to companies handling only Federal Contract Information and requires 15 basic safeguards verified through annual self-assessment. Level 2 applies to companies handling Controlled Unclassified Information and requires all 110 NIST SP 800-171 requirements. Third-party assessment becomes the norm at Level 2 as the rollout advances.
Can a company still pass a CMMC assessment with unmet requirements? Yes, through a Plan of Action and Milestones covering select unmet requirements. That plan supports a conditional CMMC status, and the contractor then has 180 days to close those items and reach final status.
Does CMMC certification replace NIST 800-171 compliance? No. CMMC Level 2 verifies implementation of the same NIST SP 800-171 requirements that DFARS 252.204-7012 already requires. The certification changes how the DoD checks compliance. It does not change what compliance actually means.





