CMMC has been a source of considerable anxiety in the defense industrial base, much of it stemming from a misunderstanding about what it actually changed.
It did not create new security requirements. Contractors handling controlled unclassified information have been contractually required to implement NIST SP 800-171 since DFARS 252.204-7012 took effect in 2017. What CMMC introduced is verification.
That distinction explains why many contractors find themselves behind: the obligation existed for years under self-attestation, and self-attestation is a weak forcing function.
The Levels
Level 1 applies to contractors handling federal contract information only. It covers 15 basic safeguarding requirements from FAR 52.204-21, and permits annual self-assessment with executive affirmation.
Level 2 applies to contractors handling controlled unclassified information, and is where most of the defense industrial base sits. It aligns with the 110 controls of NIST SP 800-171 Revision 2. Most Level 2 contracts require certification assessment by a C3PAO every three years, with annual affirmation between assessments. A subset permits self-assessment, determined by the contract.
Level 3 applies to a smaller set of contractors supporting the highest-priority programs, adding selected controls from NIST SP 800-172 and requiring government-led assessment.
Determining which level applies to you comes from your contracts, specifically whether you receive or generate CUI. Contractors regularly discover during scoping that they handle CUI in more places than they thought, which is itself a useful finding.
Scoping Is the First Real Decision
The most consequential early decision is what falls inside the assessment boundary, because it determines both the cost and the difficulty of everything that follows.
The boundary covers systems that process, store or transmit CUI, plus systems providing security protection for those, plus systems that could affect their security. That last category is broader than contractors expect and catches shared infrastructure, identity systems and management tooling.
The strategy that works for most mid-sized contractors is an enclave: a defined, separated environment where CUI is handled, keeping the wider corporate network outside the boundary. This substantially reduces the systems requiring 110 controls, and it requires the separation to be real, which means it must be tested rather than asserted.
An enclave that leaks is worse than no enclave, because the assessment scope silently expands to everything the separation was supposed to exclude.
The System Security Plan
The SSP is the central artifact and the most common point of failure.
It documents how each of the 110 controls is implemented in your specific environment. Assessors work from it, and a plan that restates control text rather than describing implementation gives them nothing to assess against. So does one that describes an intended implementation rather than the current one.
Alongside it sits the Plan of Action and Milestones, recording controls not yet fully implemented with dates and owners. POA&Ms are permitted for a limited set of controls and cannot cover the highest-weighted ones, so a POA&M-heavy submission is a signal that assessment is premature.
Keep the SSP current. An SSP describing an environment that changed six months ago will produce findings for controls you actually implemented correctly, which is an avoidable way to fail.
Where Contractors Fall Short
Patterns recur across assessments.
Multifactor authentication, incompletely applied. Deployed for most users and absent for service accounts, legacy applications or administrative access paths, which are the accounts that matter most.
Boundary protection not verified. The enclave exists in the architecture diagram and permits paths the diagram does not show.
Media protection and marking. CUI marking, handling and sanitization requirements are frequently the least-implemented family, because they involve process and people rather than technology.
Audit and accountability. Logging enabled, retained, and reviewed by nobody. The controls require review, not merely collection.
Configuration management. Baselines undocumented, and the deployed configuration having drifted from whatever was originally established.
Incident response untested. A written plan that has never been exercised, which the controls expect.
Testing Before Assessment
CMMC does not require penetration testing by name, and several 800-171 controls require assessment of control effectiveness and vulnerability management, which assessors ask about.
The stronger reason to test is practical. The failure mode in these assessments is a gap between what the SSP claims and what the environment does, and that gap is invisible from the inside. Technical assessment against the enclave boundary, the identity controls and the systems holding CUI is the most reliable way to find it while there is still time to fix it.
Testing the enclave separation specifically is worth prioritizing, for the reason above: it is the control whose failure has the largest consequence.
Timing
Begin earlier than feels necessary. C3PAO capacity is limited relative to the number of contractors requiring assessment, remediation of the gaps found during preparation typically takes quarters rather than weeks, and the requirement arrives through contract flow-down, which means a prime can impose a deadline you did not choose.
Contractors who treated 800-171 seriously before CMMC existed are finding this straightforward. Those who attested and moved on are finding it is a program rather than a project.
To discuss assessing your CUI environment before a certification assessment, get in touch.
Frequently asked questions
What is CMMC?
The Cybersecurity Maturity Model Certification is the Department of Defense mechanism for verifying that contractors protect sensitive information. Level 1 covers federal contract information with basic safeguarding. Level 2 covers controlled unclassified information and aligns with the 110 controls of NIST SP 800-171. Level 3 adds requirements for the highest-priority programs.
Does CMMC introduce new security requirements?
Largely no, and this is the point most often missed. Contractors handling CUI have been contractually obliged to implement NIST SP 800-171 since DFARS clause 252.204-7012 took effect in 2017. What CMMC changed is verification: self-attestation is replaced by third-party assessment for most Level 2 contracts. The requirements were always there.
What is a C3PAO?
A CMMC Third-Party Assessment Organization, authorized to conduct certification assessments. For most Level 2 contracts, certification requires an assessment by a C3PAO rather than self-assessment. Availability is limited relative to the number of contractors requiring assessment, which is a practical reason to begin early rather than when a contract requires it.
What is a System Security Plan and why does it matter so much?
The SSP documents how each of the 110 controls is implemented in your environment. It is the primary artifact an assessor works from, and an inadequate SSP is among the most common reasons assessments go poorly. It must describe your actual implementation specifically, not restate the control text, and it must be current.
Does CMMC require penetration testing?
Not as a named requirement. Several 800-171 controls require assessment of control effectiveness and vulnerability management, and assessors ask how you satisfied them. More practically, testing before an assessment is how contractors find the gaps between what the SSP claims and what the environment does, which is where assessments usually go wrong.
