By IT Brew Staff
less than 3 min read
Definition:
The Department of Defense needs to verify that contractors are taking proper steps to protect sensitive government data; it extends to subcontractors carrying out parts of those contracts. The program embraces a tiered model, with stringent standards around the safeguarding of federal contract information (FCI) and controlled unclassified information (CUI).
Level 1 of CMMC demands contractors conduct an annual self-assessment, then affirm that they comply with 15 security requirements in FAR clause 52.204-21.
Level 2 requires either a self-assessment or an independent assessment every three years, depending on the type of data handled by the contractor, along with an annual affirmation of compliance with the 110 security requirements in NIST SP 800-171 Revision 2.
Level 3 includes an assessment every three years by the Defense Contract Management Agency’s (DCMA) Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), along with an annual affirmation of compliance with the 24 identified requirements from NIST SP 800-172.
As of 2025, new Department of Defense contracts must adhere to the CMMC. The first phase of CMMC implementation began in November 2025, with solicitations for new contracts requiring a Level 1 or 2 self-assessment; in November 2026, the second phase will kick off, with solicitations requiring a Level 2 assessment where applicable. Phase three will debut in November 2027 with applicable solicitations requiring Level 3 certification, and phase 4, with all solicitations and contracts requiring an applicable CMMC level, will finish off the rollout in November 2028.
Costs of compliance can potentially cost tens of thousands of dollars, and drift up into the six figures for enterprises that work with the Pentagon. But for companies that rely on defense contracts, CMMC will also become one of the fixed costs of doing business.