If your company does any work for the U.S. Department of Defense — now also referred to as the Department of War (DoD / DoW) — as a prime or a subcontractor, CMMC is no longer something coming down the road. It’s here. As of November 10, 2025, the Cybersecurity Maturity Model Certification (CMMC) program is enforceable, and the requirement is now showing up in DoD contracts. If you handle federal contract information or controlled unclassified information and you aren’t on a path to certification, you are at real risk of losing eligibility for that work.
This is a topic I care about, because I talk to a lot of companies in the defense supply chain that don’t yet have the security controls or the governance in place to meet it. Below is what CMMC is, where the program stands, and what you actually need to do.
What CMMC is
CMMC is the DoD / DoW program for verifying that companies in the Defense Industrial Base protect sensitive government information. It takes existing federal security standards — mainly from NIST — and requires you to prove you’ve implemented them, through a self-assessment or a third-party audit, before you can win or keep certain contracts.
Two types of information drive it:
- Federal Contract Information (FCI) — non-public information provided by or generated for the government under a contract.
- Controlled Unclassified Information (CUI) — more sensitive information that law or policy requires you to safeguard.
Which one you handle determines the level you need.
The three levels
CMMC has three levels, each tied to NIST guidance:
- Level 1 (FCI) — the 17 basic safeguarding practices that map to FAR 52.204-21. Met with an annual self-assessment.
- Level 2 (CUI) — all 110 security controls in NIST SP 800-171 Revision 2. Depending on the contract, this is either a self-assessment or a third-party assessment by a certified C3PAO. Note that the DoD / DoW has locked the requirement to Revision 2, even though NIST has since released Revision 3.
- Level 3 (high-priority CUI) — the Level 2 controls plus 24 enhanced requirements from NIST SP 800-172, assessed by the government. This applies to programs where a breach would create serious, widespread risk.
You can review the Level 2 control set — the heart of CMMC — directly from NIST here: https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final
Where the program stands: the phased rollout
The DoD / DoW is phasing CMMC in over four years:
- Phase 1 (November 10, 2025) — Level 1 and Level 2 self-assessments start appearing in contracts. The DoD / DoW can also require Level 2 third-party certification at its discretion.
- Phase 2 (November 10, 2026) — Level 2 third-party (C3PAO) certification becomes a standard contract requirement. This is the date most contractors are circling.
- Phase 3 (November 10, 2027) — Level 3 assessments begin.
- Phase 4 (November 10, 2028) — full implementation across all applicable contracts.
The phased timeline is not a reason to wait. A Level 2 certification — from gap assessment to audit-ready — commonly takes a year or more depending on where you’re starting. If you want to be eligible for Phase 2 contracts in November 2026, the work needs to start now.
The certification journey: what you need to do
Here’s the path most companies follow:
- Determine your level. Read your contracts and flowdown clauses. Do you handle FCI, CUI, or both? That sets your target level.
- Scope your environment. Identify exactly where CUI is stored, processed, and transmitted. Good scoping keeps the assessment focused and keeps your costs down.
- Run a gap assessment against NIST SP 800-171 Revision 2. This tells you where you stand against all 110 controls.
- Document your System Security Plan (SSP) and a Plan of Action & Milestones (POA&M). The SSP describes how you meet each control; the POA&M tracks what’s left to fix.
- Remediate the gaps. Put the missing controls in place — access control, multi-factor authentication, encryption, logging, incident response, and the rest.
- Score and report in SPRS. The DoD / DoW methodology scores you out of 110 points. You need at least 88 to be eligible, certain high-value controls cannot be deferred, and any POA&M items, where allowed, must be closed within 180 days.
- Self-assess or engage a C3PAO, depending on your required level and the contract.
- Affirm annually and flow requirements down to your subcontractors. CMMC doesn’t stop at the prime — it follows the data down the supply chain.
Where companies get into trouble
This is where I have the most concern. When I hear a company say “we don’t really have a network” or “we don’t have any governance,” that’s a company carrying serious risk — not just for CMMC, but for its business as a whole. A few patterns come up again and again:
- Starting late. The single biggest risk. A year-plus timeline means a 2026 deadline is a today problem.
- Bad scoping. Letting CUI spread across the whole environment turns a manageable assessment into an expensive one.
- Treating it as a checkbox. CMMC expects controls that are implemented and maintained, not documented once and forgotten.
- No one owns it. Without clear ownership of IT and security, controls drift and the score slips.
These companies need some level of governance and expertise to manage their environments. Without the controls in place, they’re putting themselves at risk.
How CloudHesive helps
This is the kind of work we do. As an Amazon Premier Partner and Amazon Managed Services Partner, we help DoD / DoW contractors build and maintain the security and governance CMMC requires — implementing the NIST SP 800-171 controls, standing up the right architecture on AWS, documenting your SSP and POA&M, and managing the environment so you stay ready between assessments. We don’t perform the certification audit itself — that’s the C3PAO’s role — but we get you to the point where you can pass it and stay there.
If you’re in the defense supply chain and you’re not sure where you stand, we can help you find out and build the plan to close the gaps. We should talk.
Frequently asked questions
What is CMMC?
CMMC (Cybersecurity Maturity Model Certification) is the U.S. Department of Defense / Department of War (DoD / DoW) program that requires companies in its supply chain to prove they protect federal contract information and controlled unclassified information before they can win or keep certain contracts.
Is CMMC mandatory now?
Yes. The program became enforceable on November 10, 2025, and CMMC requirements are now appearing in new DoD / DoW contracts on a phased schedule that runs through 2028.
What are the CMMC levels?
There are three. Level 1 covers federal contract information with 17 basic practices and a self-assessment. Level 2 covers controlled unclassified information with all 110 controls in NIST SP 800-171 Revision 2. Level 3 adds 24 enhanced requirements from NIST SP 800-172 for high-priority programs.
What is the CMMC security control set?
For Level 2, the control set is NIST SP 800-171 Revision 2, which contains 110 security controls. The official source is https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final.
How long does CMMC certification take?
It varies with your starting point, but a Level 2 certification commonly takes a year or more from gap assessment to audit-ready, which is why starting early matters.
Does CMMC apply to subcontractors?
Yes. Requirements flow down the supply chain, so subcontractors that handle FCI or CUI must meet the appropriate level too.
