The Department of Defense released version 1.0 of the Cybersecurity Maturity Model Certification (CMMC) on January 31, 2020. It changes how defense contractors prove their cybersecurity. Instead of attesting to your own compliance, you'll need a certification from an accredited third-party assessor at one of five levels.

If you handle only Federal Contract Information (FCI), expect to need Level 1. If you handle Controlled Unclassified Information (CUI), expect Level 3, which includes all 110 NIST SP 800-171 requirements. DoD plans to start small in 2020 and phase CMMC into new contracts over several years. The best preparation right now is to fully implement NIST SP 800-171.

What is CMMC and why did DoD create it?

Since the end of 2017, contractors handling covered defense information have been required under DFARS 252.204-7012 to implement NIST SP 800-171. That clause required implementation "as soon as practical, but not later than December 31, 2017." It relied on contractors to assess and represent their own compliance.

CMMC adds verification. An independent assessor will check a contractor's cybersecurity practices, and contracts that include CMMC will require a certification at a specified level.

CMMC doesn't replace DFARS 252.204-7012. The existing obligations to safeguard covered defense information and to report cyber incidents to DoD within 72 hours of discovery remain in place.

How is CMMC 1.0 structured?

The model is organized into 17 domains, 43 capabilities, 171 practices and 5 processes. Practices are the technical and operational activities, such as enforcing multifactor authentication. Processes measure how well those practices are institutionalized through policies, plans and reviews.

Fourteen of the domains line up with the 14 requirement families in NIST SP 800-171. CMMC adds three more: Asset Management, Recovery and Situational Awareness.

The levels are cumulative. Each one includes everything in the levels below it.

Level Practices (cumulative) Processes What it's for
1 17 None assessed Basic safeguarding of FCI
2 72 2 A transitional step toward protecting CUI
3 130 3 Protecting CUI: all 110 NIST SP 800-171 requirements plus 20 more
4 156 4 Protecting CUI against more sophisticated, persistent adversaries
5 171 5 The most advanced practices for the most sensitive programs

The process maturity at each level is described as Performed (Level 1), Documented (Level 2), Managed (Level 3), Reviewed (Level 4) and Optimizing (Level 5). In practical terms, Level 2 asks you to establish policies and document your practices for each domain. Level 3 adds a plan that is maintained and resourced. Level 4 adds reviews of effectiveness, and Level 5 adds standardization across the organization.

Level 1's 17 practices correspond to the 15 basic safeguarding requirements in FAR 52.204-21, which has applied to contractor systems that process, store or transmit FCI since 2016.

FCI vs. CUI: Which CMMC level do you need?

Your required level depends on the information you handle, so this distinction matters more than any other.

Federal Contract Information is defined in FAR 52.204-21 as "information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public websites) or simple transactional information, such as necessary to process payments."

Controlled Unclassified Information is information that law, regulation or government-wide policy requires to be safeguarded or have its dissemination controlled, but that isn't classified. The National Archives maintains the CUI Registry, which lists the categories. In defense work, CUI often includes technical drawings, specifications and other controlled technical information.

Based on DoD's guidance so far:

  • Contractors and subcontractors that handle only FCI should plan for Level 1.
  • Contractors and subcontractors that handle CUI should plan for at least Level 3.
  • Levels 4 and 5 are intended for a smaller set of contracts involving the most sensitive programs.

Contracts that include CMMC will specify the level required. Subcontractors will need the level appropriate to the information they receive or create, so primes will be asking their supply chains about CMMC readiness.

Who performs CMMC assessments?

There is no self-certification under CMMC. Assessments will be performed by Certified Third-Party Assessment Organizations (C3PAOs) and their trained assessors.

The CMMC Accreditation Body (CMMC-AB) is an independent nonprofit organization with a board drawn from industry, the cybersecurity community and academia. It will accredit C3PAOs, oversee the training and certification of individual assessors, and manage the quality of assessments.

The CMMC-AB is still building its training and accreditation programs, so no assessments are taking place yet. DoD officials have said that a certification will be valid for three years.

When will CMMC appear in DoD contracts?

DoD has described a gradual rollout rather than an overnight switch. Based on what DoD officials said at and after the January 31 release:

Timeframe What DoD has said to expect
2020 A DFARS rule to implement CMMC, with DoD officials pointing to spring or early summer 2020
2020 CMMC requirements in a limited number of acquisitions, roughly ten requests for information around mid-year and about ten requests for proposals later in the year
Following years A growing share of new contracts include CMMC requirements
By fiscal year 2026 CMMC included in all new DoD contracts

These dates are DoD's stated plans, not regulation. The DFARS change hasn't been published yet, and the timeline may shift. Plan to be ready early rather than counting on a later date for your contracts.

How should defense contractors prepare for CMMC?

Most of the work for a Level 3 certification is the work you should already have done for DFARS 252.204-7012. If your NIST SP 800-171 implementation is incomplete, start there.

Confirm what information you handle

Review your contracts, statements of work and clauses such as DFARS 252.204-7012. Talk to your contracting officers and primes about whether you receive or generate CUI. If the answer isn't clear, get it clarified in writing, because it determines your target level.

Scope your CUI environment

Identify every system, person, facility and external service that stores, processes or transmits CUI. The smaller and better-defined that environment, the smaller your assessment scope. You may be able to isolate CUI in a separate enclave rather than bringing the whole network up to Level 3.

Write or update your SSP and POA&M

NIST SP 800-171 already requires a system security plan (requirement 3.12.4) and plans of action to correct deficiencies (requirement 3.12.2). Your SSP should describe the system boundary, the environment and how each requirement is met. Your plan of action and milestones (POA&M) should list each gap, the fix, an owner and a date.

Under CMMC, an assessor will check whether practices are actually in place. Treat the POA&M as a work plan to close, not a place to park gaps indefinitely.

Run a gap assessment against NIST SP 800-171

Assess each of the 110 requirements honestly and record evidence for the ones you meet. Revision 1 is the current final version, and CMMC 1.0 maps to it. NIST released a draft Revision 2 in June 2019 for public comment, and it doesn't change the 110 requirements themselves.

Address the practices that go beyond 800-171

Level 3 adds 20 practices beyond NIST SP 800-171, and some of them fall in the three domains 800-171 doesn't have: Asset Management, Recovery and Situational Awareness. It also requires the Level 2 and Level 3 processes, meaning documented policies and a maintained, resourced plan for each domain. Review the CMMC 1.0 model and appendices from DoD to see exactly what each practice expects.

Talk to your primes and subcontractors

If you're a subcontractor, ask your primes what level they expect you to hold. If you're a prime, start asking your own suppliers now. Your ability to win future work will depend partly on their readiness.

Frequently asked questions

Does CMMC replace DFARS 252.204-7012?

No. The DFARS clause still governs how you safeguard covered defense information and requires reporting cyber incidents within 72 hours of discovery. CMMC adds third-party verification on top of those obligations.

Can we self-certify for CMMC Level 1?

No. DoD has said every CMMC level, including Level 1, requires an assessment by an accredited third party.

Do subcontractors need CMMC certification?

Yes. Subcontractors will need certification at the level that matches the information they handle. A subcontractor that receives only FCI would need Level 1, even if the prime holds a higher level.

Is CMMC 1.0 final?

Version 1.0 is DoD's released model, but implementation details such as the DFARS rule, assessment procedures and assessor training are still being developed. Expect clarifications during 2020.

Key takeaways

This post reflects CMMC as of mid-February 2020 and isn't legal advice, so confirm contract-specific questions with counsel and your contracting officer.

  • CMMC 1.0 has five cumulative levels, from 17 practices at Level 1 to 171 at Level 5.
  • FCI-only contractors should plan for Level 1. CUI handlers should plan for Level 3, which means all 110 NIST SP 800-171 requirements plus 20 more practices and documented processes.
  • Certification comes from accredited third-party assessors, not self-attestation.
  • DoD expects a small number of contracts to include CMMC in 2020, with a phase-in to all new contracts by fiscal year 2026.
  • Start now: confirm what information you handle, scope your CUI environment, update your SSP and POA&M, and close your NIST SP 800-171 gaps.