Scope
Who it applies to.
CMMC applies to Department of Defense contractors and subcontractors whose contracts include DFARS § 252.204-7021, at every tier that will process, store, or transmit covered information. Companies handling only Federal Contract Information (FCI) fall at Level 1. Those handling Controlled Unclassified Information (CUI) fall at Level 2. A small number of the most critical programs are designated Level 3. Commercially available off-the-shelf items are excluded, and a prime must confirm a subcontractor’s status before award.
- Level 1 — annual self-assessment
- Level 1 covers Federal Contract Information and consists of the fifteen basic safeguarding requirements at FAR § 52.204-21(b)(1)(i) through (xv). It is met by self-assessment only, repeated annually, with results entered in the Supplier Performance Risk System (SPRS). Evidence supporting the assessment must be retained for six years from the CMMC Status Date.
- Level 2 — self-assessment or C3PAO certification
- Level 2 covers Controlled Unclassified Information and adopts the 110 security requirements of NIST SP 800-171 Revision 2, assessed against NIST SP 800-171A. Depending on what the solicitation specifies, it is met either by a self-assessment (Level 2 Self) or by a certification assessment from an accredited CMMC Third-Party Assessment Organization (Level 2 C3PAO). Either status runs on a three-year cycle.
- Level 3 — government-led DIBCAC assessment
- Level 3 applies to the highest-priority programs. It requires a Final Level 2 (C3PAO) status first, plus 24 additional security requirements selected from NIST SP 800-172. The assessment is performed by the government — the Defense Contract Management Agency’s DIB Cybersecurity Assessment Center (DIBCAC) — and repeated every three years for systems in the Level 3 scope.
- The DFARS clauses that carry the requirement
- Four clauses do the contractual work. DFARS § 252.204-7012 requires NIST SP 800-171 implementation and rapid reporting of a cyber incident to DoD within 72 hours of discovery. § 252.204-7019 and § 252.204-7020 govern posting a NIST SP 800-171 DoD Assessment score and granting the government access for Medium or High assessments. § 252.204-7021 makes CMMC status a condition of award.
- SPRS score and the annual affirmation
- Under § 252.204-7019 an offeror must have a summary level score posted in SPRS that is not more than three years old. Separately, CMMC status requires an Affirming Official — a senior representative with authority to affirm continuing compliance — to submit an affirmation in SPRS on achieving status and annually thereafter.
- Phased rollout under 32 CFR § 170.3
- The CMMC acquisition rule took effect on November 10, 2025, starting a four-phase, three-year rollout. Phase 1 requires Level 1 or Level 2 self-assessment. Phase 2, beginning one calendar year after Phase 1, adds Level 2 (C3PAO) certification as a condition of award. Phase 3 adds Level 3 (DIBCAC), and Phase 4 is full implementation across applicable solicitations, contracts, and option periods.
The vendor & sub-processor obligation
What it puts on you.
The requirements flow down the supply chain: prime contractors must ensure subcontractors that touch CUI meet the same bar, and using an external cloud means inheriting and continuously maintaining that provider’s authorization for the relevant controls.
How self-hosting addresses it
Remove the third party, remove the burden.
Processing CUI on hardware you physically control keeps it inside a boundary you define and assess directly — rather than depending on, and evidencing, a chain of cloud providers and subcontractors.
How FileFerret applies
CMMC scope follows the data. Keeping CUI on an appliance inside your own network avoids handing it to an external service provider or cloud service provider whose own security posture can then be pulled into your assessment boundary. A self-hosted appliance narrows what an assessor has to review — it does not, by itself, confer any CMMC status. See how it’s built →
Building your System Security Plan?
See the FileFerret shared-responsibility matrix & clean control answers →
Full, current text is maintained at the official source: DoD CMMC; NIST SP 800-171.
Enforcement
Who enforces it, and how.
Enforcement is contractual first: without the required status in SPRS you are ineligible for award or for the option periods and subcontracts a prime must verify before it can flow work down. Misrepresenting a score also carries False Claims Act exposure: LOGZONE Inc. agreed to pay $507,144 to resolve allegations that it knowingly failed to comply with the cybersecurity requirements of its Department of the Navy contracts.
Common questions
Questions firms ask.
Can I self-assess for Level 2, or do I need a C3PAO?
That depends on the solicitation. 32 CFR part 170 provides for both a Level 2 (Self) and a Level 2 (C3PAO) status, and the contracting officer specifies which one applies. During Phase 1 of the rollout the baseline expectation is self-assessment, but the Department retains discretion to require third-party certification earlier. Both statuses run on a three-year cycle.
How long does a CMMC status last, and what keeps it current?
Level 1 (Self) must be redone annually. Level 2 — whether self-assessed or C3PAO-certified — and Level 3 (DIBCAC) run on a three-year cycle. In every case an Affirming Official must submit an affirmation of continuing compliance in SPRS when the status is achieved and every year afterwards, so a valid assessment on its own does not keep you eligible.
What is the difference between Conditional and Final CMMC status?
If an assessment leaves some requirements unmet but still meets the passing score defined in 32 CFR § 170.24, the organization can receive a Conditional status backed by a plan of action and milestones. Closing that plan out through a closeout assessment converts it to Final status. Under DFARS § 252.204-7021 a Conditional status must be closed out successfully.