CMMC Compliance: Requirements, Levels, Assessment & Readiness Guide 2026
CMMC compliance requires applicable Department of Defence contractors and subcontractors to meet defined cybersecurity requirements for protecting Federal Contract Information and Controlled Unclassified Information. Learn about CMMC Levels 1–3, NIST SP 800-171, assessment scope, SSP, evidence, scoring, POA&M, cloud services, external service providers, and practical CMMC readiness in 2026.

CMMC Compliance in 2026: What Defence Contractors Need to Know
The Cybersecurity Maturity Model Certification (CMMC) is the U.S. Department of Defence framework for assessing whether applicable defence contractors and subcontractors have implemented required cybersecurity protections for information handled under qualifying DoD contracts.
CMMC is closely connected with:
• Federal Contract Information (FCI)
• Controlled Unclassified Information (CUI)
• FAR
• DFARS
• NIST SP 800-171
• NIST SP 800-172
• Security requirements
• Assessment scope
• System Security Plans (SSPs)
• Security evidence
• Continuous compliance
CMMC readiness is not simply about purchasing cybersecurity products or writing security policies.
An organization needs to understand:
• What information it handles
• Where that information exists
• Which systems process, store, or transmit it
• Which systems provide security protection
• Which CMMC requirements apply
• How those requirements are implemented
• How implementation can be demonstrated during an assessment
CMMC Status Update - September 2026
On July 13, 2026, the Department of War announced the immediate suspension of the CMMC Phase II requirements, which had originally been scheduled to begin on November 10, 2026.
The Department stated that Phase I self-assessment requirements remain in place while it conducts a broader review of the CMMC program.
During this period, the Department states that cybersecurity compliance will continue to be enforced through NIST SP 800-171 Revision 2 self-assessments and select government-led assessments.
The Phase II suspension does not mean that contractors can stop protecting FCI or CUI. Applicable contractual requirements, including relevant DFARS obligations, continue to matter.
Organizations should therefore verify:
1. The CMMC requirement specified in the contract or solicitation
2. The applicable DFARS clauses
3. The information being handled
4. The systems processing, storing, or transmitting that information
5. The applicable assessment and affirmation obligations
2026 takeaway: Do not rely on an old CMMC implementation timeline. CMMC requirements are contract-driven, and organizations should verify the current requirements applicable to each contract and environment.
What Is CMMC Compliance and Who Needs It?
CMMC compliance means meeting the cybersecurity requirements applicable to an organization's DoD contract and maintaining the required CMMC status for the contractor information systems covered by that requirement.
The CMMC framework contains three levels:
CMMC Level 1
Level 1 contains 15 requirements associated with the basic safeguarding of Federal Contract Information (FCI).
CMMC Level 2
Level 2 contains 110 security requirements based on NIST SP 800-171 Revision 2 under the current CMMC framework.
Level 2 is generally associated with the protection of Controlled Unclassified Information (CUI).
CMMC Level 3
Level 3 contains the 110 Level 2 requirements plus 24 additional requirements derived from NIST SP 800-172, resulting in 134 requirements.
The existence of three levels should not be confused with the current Phase I implementation status. The Department's July 2026 announcement suspended Phase II while keeping Phase I self assessment requirements in place. CMMC obligations are contract-driven.
Under DFARS 252.204-7021, applicable contractors must maintain the CMMC status specified in the contract, or a higher level, for information systems used to perform the contract that process, store, or transmit FCI or CUI. The clause also contains flow down requirements for applicable subcontractors and suppliers.
Business takeaway: CMMC requirements should be determined from the applicable contract, information, and systems - not simply from company size or industry classification.
FCI vs. CUI: The Starting Point for CMMC Scope
Before evaluating cybersecurity controls, an organization needs to understand the information it is required to protect.
Federal Contract Information (FCI)
FCI generally refers to information that is not intended for public release and is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, subject to the applicable exclusions.
CMMC Level 1 uses requirements associated with the basic safeguarding of FCI.
Controlled Unclassified Information (CUI)
CUI is information the Government creates or possesses, or information an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls.
For CMMC readiness, an organization should identify:
• What CUI it handles
• Which CUI categories apply
• Who can access it
• Where it is stored
• Which applications process it
• How it is transmitted
• Which systems protect it
• Which external providers support the environment
Why FCI and CUI Matter
FCI and CUI are not interchangeable.
The information being handled affects the applicable security requirements, assessment scope, architecture, documentation, evidence, and assessment approach.
Technical principle: You cannot create a defensible CMMC scope until you understand the information that the scope is intended to protect
CMMC Levels 1, 2 and 3 Explained
Level 1 - Basic Safeguarding of FCI
CMMC Level 1 contains 15 requirements associated with FAR 52.204-21.
These requirements cover foundational security practices including areas such as:
• Access control
• External system connections
• Identification and authentication
• Communications protection
• Physical protection
• Flaw remediation
• Malicious-code protection
• System and file scanning
Under the current Phase I implementation, Level 1 uses an annual self-assessment and annual affirmation model. POA&Ms are not permitted for Level 1
Level 2 - Protection of CUI
CMMC Level 2 contains 110 requirements based on NIST SP 800-171 Revision 2.
The requirements address areas such as:
• Access control
• Awareness and training
• Audit and accountability
• Configuration management
• Identification and authentication
• Incident response
• Maintenance
• Media protection
• Personnel security
• Physical protection
• Risk assessment
• Security assessment
• System and communications protection
• System and information integrity
Depending on the applicable contractual requirement, Level 2 can involve self-assessment or a C3PAO assessment pathway.
Organizations should determine the required pathway from the actual contract or solicitation.
Level 3 - Enhanced Protection
CMMC Level 3 builds on Level 2 by adding 24 requirements derived from NIST SP 800-172.
That results in:
110 Level 2 requirements + 24 additional requirements = 134 requirements.
Level 3 is intended for environments requiring enhanced protection against advanced threats and includes a government-led DIBCAC assessment pathway under the broader CMMC framework.
Because CMMC implementation timelines can change, organizations should verify the current contractual requirements before planning a Level 3 assessment.
CMMC Level 2 Requirements: The Technical Core
CMMC Level 2 is built around the 110 security requirements from NIST SP 800-171 Revision 2.
These requirements span 14 security families:
1. Access Control
2. Awareness and Training
3. Audit and Accountability
4. Configuration Management
5. Identification and Authentication
6. Incident Response
7. Maintenance
8. Media Protection
9. Personnel Security
10. Physical Protection
11. Risk Assessment
12. Security Assessment
13. System and Communications Protection
14. System and Information Integrity
A Level 2 environment may require coordinated capabilities across:
• Identity and access management
• Multi-factor authentication
• Privileged access management
• Endpoint protection
• Network security
• Configuration management
• Vulnerability management
• Audit logging
• Incident response
• Media protection
• Security awareness
• Physical protection
• Risk management
• Security assessment
The important question is not:
"Do we own a security product for this requirement?"
The better question is:
"Is the applicable requirement implemented correctly in the assessed environment, and can that implementation be demonstrated?"
A cybersecurity tool can support a requirement, but the tool itself does not automatically establish compliance.
NIST SP 800-171 Revision 2 vs. Revision 3
One of the most important technical considerations for CMMC planning is the difference between NIST SP 800-171 Revision 2 and Revision 3.
NIST withdrew Revision 2 on May 14, 2024, and Revision 3 is now the current NIST publication.
However, the current CMMC framework and DoD guidance for the Phase I environment continue to reference NIST SP 800-171 Revision 2 for the applicable CMMC requirements.
This creates an important distinction.
An organization may decide to implement security improvements based on Revision 3 while its current CMMC obligation remains tied to the Revision 2 baseline.
Therefore, organizations should determine:
• Which NIST revision applies to the CMMC requirement
• Which Revision 2 requirements are satisfied
• Where the current implementation differs
• Which assessment objectives require evidence
• Whether the SSP accurately describes the assessed environment
• Whether the organization has introduced controls that are outside or beyond the current CMMC baseline
Technical takeaway: Implementing a newer NIST revision can strengthen an organization's security program, but it should not automatically be treated as proof that the applicable CMMC requirements have been satisfied.
CMMC Scoping: What Systems and Assets Are in Scope?
CMMC readiness should begin with assessment scope.
A common mistake is to define scope simply as:
"The servers where CUI is stored."
CMMC scoping can be broader.
An organization should identify the different categories of assets relevant to its environment.
CUI Assets
Assets that process, store, or transmit CUI.
These assets form part of the CMMC Assessment Scope and are assessed against the applicable requirements.
Security Protection Assets
Assets that provide security functions or capabilities to the CMMC Assessment Scope.
For example, a security monitoring platform may not store CUI but can provide security protection for systems within the assessed environment.
Contractor Risk Managed Assets
Assets that may process, store, or transmit CUI but are managed according to the applicable risk management and policy requirements.
Specialized Assets
These may include:
• IoT
• IIoT
• Operational Technology
• Specialized equipment
• Other systems requiring special scoping considerations
Out-of-Scope Assets
An asset should not simply be declared "out of scope" because it does not directly store CUI.
The organization needs to demonstrate that the applicable separation, protection, and scoping conditions are satisfied.
CMMC Scoping Principle
A defensible assessment boundary should identify:
CUI → CUI Assets → Security Protection Assets → Supporting Systems → External Dependencies
CMMC Data Flow Mapping and System Security Plan
An asset inventory answers:
What systems do we have?
A CUI data-flow analysis answers:
How does CUI move through those systems?
A data-flow review should identify:
• Where CUI enters the environment
• Which users receive it
• Which applications process it
• Where it is stored
• How it is transmitted
• Where backups are maintained
• Which cloud services are involved
• Which external providers support the environment
• Which security systems protect the environment
For example, an engineering document containing CUI may be stored in a cloud application while authentication, endpoint management, networking, backups, monitoring, and administrative systems support the workflow.
Understanding this relationship is essential for accurate scoping.
System Security Plan (SSP)
The System Security Plan (SSP) documents how applicable security requirements are implemented within the system.
NIST SP 800-171 Requirement 3.12.4 addresses developing, documenting, and periodically updating the SSP.
NIST does not prescribe one mandatory SSP format. The important requirement is that the necessary information is conveyed accurately.
A useful SSP should remain aligned with:
• System architecture
• Assessment boundary
• Asset inventory
• Network diagrams
• Security controls
• Cloud infrastructure
• Identity systems
• External service providers
• Responsible personnel
• Security processes
Practical SSP Test
Ask:
"If an assessor reviewed our environment today, would our SSP accurately describe what actually exists?"
If the answer is no, the SSP should be updated before the assessment.
CMMC Assessment: Implementation Is Not the Same as Evidence
A security control may exist without an organization being ready to demonstrate it.
Consider MFA.
Technology
An MFA platform has been deployed.
Implementation
Applicable accounts and systems actually enforce MFA.
Documentation
The configuration, responsibilities, and procedures are documented.
Evidence
The organization can demonstrate that the implementation satisfies the applicable assessment objectives.
The same principle applies to logging.
Technology
A SIEM or centralized logging platform exists.
Implementation
Relevant events are actually collected and protected.
Operation
Logs are managed and reviewed according to the applicable requirements.
Evidence
The organization can demonstrate the implementation.
CMMC assessments therefore require preparation across:
• People
• Processes
• Technology
• Documentation
• Evidence
Assessment activities can involve methods such as:
Examine
Review documentation, configurations, records, policies, procedures, and other assessment objects.
Interview
Discuss implementation with personnel responsible for the applicable systems and processes.
Test
Evaluate technical or procedural implementation.
Technical principle:
A control should be implemented, operated, documented, and demonstrable.
CMMC Level 2 Scoring and POA&M
CMMC Level 2 uses a scoring methodology based on the 110 applicable security requirements.
The maximum score is:
110 points
Individual requirements can have different point values based on their importance in the CMMC scoring methodology.
A score of 88 or higher is associated with the threshold for Conditional Level 2 status when the other applicable conditions are satisfied.
Conditional status is not the same as final status.
Organizations using a POA&M must satisfy the applicable requirements for Conditional status and subsequently close the permitted remediation items within the applicable timeframe.
POA&M
A Plan of Action and Milestones (POA&M) identifies permitted remediation activities, responsible actions, milestones, and completion dates.
POA&M use is limited.
Level 1
POA&Ms are not permitted.
Level 2
Limited POA&M use is permitted under defined conditions.
Conditional CMMC status is generally subject to a 180-day validity period, and applicable POA&M requirements must be addressed within the permitted timeframe.
Organizations should not treat a POA&M as a substitute for implementing security requirements.
Business takeaway: A POA&M should be a controlled remediation mechanism-not the foundation of a compliance program.
CMMC and DFARS 252.204-7012
CMMC does not replace other cybersecurity obligations that may apply under DoD contracts.
DFARS 252.204-7012 addresses requirements related to safeguarding covered defence information and cyber incident reporting.
Depending on the contract, the clause includes requirements involving:
• Adequate security
• NIST SP 800-171
• Cyber incident reporting
• Malicious software
• Media preservation
• Forensic analysis
• Cyber incident damage assessment
Under DFARS 252.204-7012, cyber incidents must be rapidly reported, with "rapidly report" defined as reporting within 72 hours of discovery.
The clause also contains requirements concerning preservation and protection of relevant information and system data following a cyber incident.
Important distinction
CMMC assessment requirements and DFARS 252.204-7012 obligations should be managed together, but they are not the same requirement.
A contractor should review all applicable contract clauses rather than assuming that CMMC alone represents its entire cybersecurity obligation.
CMMC, Cloud Services and External Providers
Cloud and third-party services can significantly affect CMMC scope.
Cloud Service Providers
When a contractor uses an external cloud service provider to store, process, or transmit covered defence information, applicable DFARS requirements can impose security obligations on that cloud environment.
Organizations should identify:
• The exact cloud service being used
• Whether the service stores, processes, or transmits CUI
• Which controls are inherited
• Which controls remain the contractor's responsibility
• What security documentation is available
• What evidence the provider can provide
• Whether the service meets the applicable contractual requirements
Avoid evaluating a cloud provider solely by its company-wide compliance claims. The specific cloud service or offering matters.
External Service Providers, MSPs and MSSPs
Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), and other external providers can affect the CMMC environment.
For example, an MSSP may provide:
• Security monitoring
• Endpoint management
• Log management
• Vulnerability management
• Incident response
• Security administration
Even when such providers do not directly process CUI, their services may provide security protection for the assessed environment.
Organizations should document:
• What the provider does
• Which systems it can access
• What information it handles
• Which controls are inherited
• Which responsibilities remain with the contractor
• What evidence the provider can supply
CMMC and Subcontractors
CMMC requirements can flow down to applicable subcontractors and suppliers.
Organizations should therefore identify:
• Which subcontractors handle FCI
• Which subcontractors handle CUI
• Which information systems they use
• Which CMMC status is required
• Whether the appropriate requirement has been flowed down contractually
• Whether required affirmations or status information are current
Supply-chain security should be treated as part of the CMMC readiness process rather than as a separate activity.
SPRS, CMMC UID and Continuous Compliance
CMMC compliance is not simply an assessment-day activity.
Applicable organizations have ongoing obligations related to maintaining their CMMC status and annual affirmation of continuous compliance.
Under DFARS 252.204-7021, contractors must maintain the CMMC status required by the contract for applicable information systems processing, storing, or transmitting FCI or CUI.
The clause also requires applicable annual affirmations and reporting of CMMC Unique Identifiers (CMMC UIDs) through the required processes.
What Is a CMMC UID?
A CMMC Unique Identifier (CMMC UID) is a 10-character alphanumeric identifier associated with a CMMC assessment and reflected in SPRS for the applicable contractor information system.
Organizations should maintain accurate records of:
• CMMC assessment status
• CMMC UID
• Assessment date
• Required affirmation
• Applicable information system
• Contractual requirement
• Changes affecting the assessed environment Continuous
Compliance Principle
Do not think:
"We completed the assessment, so the project is finished."
Instead think:
"We need to maintain the security posture represented by our CMMC status."
System changes, new applications, cloud migrations, new users, third-party changes, and architectural changes can all affect the security environment.
CMMC Readiness Assessment: A Practical Approach
A structured readiness program can follow eight stages.
01 — Discover
Identify:
• Contracts
• FCI
• CUI
• Users
• Systems
• Applications
• Cloud services
• External providers
• Subcontractors
02 — Classify
Determine:
• What is FCI
• What is CUI
• Which CUI categories apply
• How the information is handled
03 — Scope
Identify:
• CUI Assets
• Security Protection Assets
• Contractor Risk Managed Assets
• Specialized Assets
• Out-of-Scope Assets
04 — Assess
Evaluate the applicable CMMC requirements against the actual environment.
The assessment should identify both technical and procedural gaps.
05 — Document
Align:
• SSP
• Asset inventory
• Network diagrams
• Policies
• Procedures
• Roles and responsibilities
• Evidence
06 — Remediate
Address:
• Technical gaps
• Configuration gaps
• Process gaps
• Documentation gaps
• Evidence gaps
07 — Validate
Retest remediation.
Confirm:
• Controls work
• Configurations are correct
• Evidence exists
• Documentation is accurate
• Scope remains correct
08 — Maintain
Establish processes for:
• System changes
• New cloud services
• New users
• New applications
• Third-party changes
• Security evidence
• Annual affirmations
• Continuous compliance
CMMC Readiness Checklist
Use the following checklist as a starting point for CMMC preparation:
☐ Identify applicable DoD contracts
☐ Identify FCI
☐ Identify CUI
☐ Identify applicable CUI categories
☐ Map CUI data flows
☐ Build an asset inventory
☐ Identify CUI Assets
☐ Identify Security Protection Assets
☐ Identify specialized assets
☐ Identify applicable external service providers
☐ Define the assessment boundary
☐ Create or update the network diagram
☐ Review applicable CMMC requirements
☐ Assess technical controls
☐ Review identity and access management
☐ Review MFA
☐ Review privileged access
☐ Review endpoint security
☐ Review vulnerability management
☐ Review logging and monitoring
☐ Review incident response
☐ Review configuration management
☐ Review cloud security responsibilities
☐ Review third-party dependencies
☐ Update the SSP
☐ Collect assessment evidence
☐ Identify gaps
☐ Remediate gaps
☐ Validate remediation
☐ Prepare assessment documentation
☐ Establish continuous compliance processes
☐ Track annual affirmation requirements
Common CMMC Readiness Gaps
Organizations preparing for CMMC should pay particular attention to:
1. Unclear CUI boundaries
The organization cannot clearly identify where CUI enters, moves, and resides.
2. Incomplete asset inventory
Systems supporting the CUI environment are missing from the inventory.
3. SSP and environment mismatch
The SSP describes an architecture that no longer matches the production environment.
4. Insufficient evidence
Controls exist, but the organization cannot demonstrate their implementation.
5. Weak privileged-access governance
Administrative accounts are not appropriately controlled, monitored, or documented.
6. Incomplete logging
Relevant security events are not collected, protected, or sufficiently managed.
7. Unclear cloud responsibilities
The organization assumes the cloud provider handles controls that remain its responsibility.
8. Third-party dependencies
MSPs, MSSPs, cloud providers, or subcontractors are not properly included in the compliance analysis.
9. Unvalidated remediation
The organization fixes a finding but does not retest the implementation.
10. Lack of continuous compliance
The organization prepares for an assessment but does not establish processes to maintain the assessed security posture.
Frequently Asked Questions About CMMC Compliance
What is CMMC compliance?
CMMC compliance means meeting the CMMC requirements applicable to an organization's DoD contract and maintaining the required status for the relevant contractor information systems.
How many requirements are in CMMC Level 1?
CMMC Level 1 contains 15 requirements associated with FAR 52.204-21.
How many requirements are in CMMC Level 2?
CMMC Level 2 contains 110 requirements based on NIST SP 800-171 Revision 2 under the current CMMC framework.
How many requirements are in CMMC Level 3?
CMMC Level 3 contains 134 requirements in total: the 110 Level 2 requirements plus 24 additional requirements derived from NIST SP 800-172.
Is CMMC the same as NIST SP 800-171?
No.
NIST SP 800-171 establishes security requirements for protecting CUI in applicable nonfederal systems and organizations.
CMMC provides the DoD assessment framework used to verify applicable cybersecurity requirements under DoD contracts.
Does CMMC Level 2 use NIST Revision 2 or Revision 3?
The current CMMC framework uses NIST SP 800-171 Revision 2 for the applicable Level 2 requirements, even though NIST withdrew Revision 2 in 2024 and superseded it with Revision 3.
Organizations should therefore distinguish between the current NIST publication and the revision incorporated into the applicable CMMC requirement.
Does CMMC require an SSP?
For applicable Level 2 environments, the security requirements include CA.L2-3.12.4 System Security Plan.
The SSP should accurately describe the assessed environment, security implementation, and applicable boundary.
Are POA&Ms allowed?
Level 1 does not permit POA&Ms.
Limited POA&M use is permitted for Level 2 under defined conditions, including the applicable remediation timeframe for Conditional status.
What is a C3PAO?
A CMMC Third-Party Assessment Organization (C3PAO) is an authorized organization within the CMMC ecosystem that performs applicable third-party CMMC assessments.
What is CMMC scoping?
CMMC scoping is the process of identifying and documenting the systems and assets that fall within the applicable CMMC Assessment Scope.
Does CMMC apply to subcontractors?
CMMC requirements can flow down to applicable subcontractors and suppliers when contractual requirements require them to process, store, or transmit FCI or CUI.
Does a cloud provider need FedRAMP?
The applicable contractual requirements determine the security obligations for cloud services handling covered defence information.
Where DFARS requirements apply, an external cloud service provider handling covered defence information must satisfy the applicable security requirements, including requirements associated with the FedRAMP Moderate baseline. Organizations should evaluate the specific cloud service offering, not simply the provider's general compliance status.
What is the maximum Level 2 score?
The maximum Level 2 score is 110 points.
A score of 88 or higher can support Conditional Level 2 status when the other applicable requirements and conditions are satisfied.
Is CMMC compliance a one-time activity?
No.
Applicable CMMC obligations include maintaining current status and completing required annual affirmations of continuous compliance.
What is the current CMMC status in 2026?
As of September 2026, the Department has suspended the implementation of CMMC Phase II, originally scheduled to begin November 10, 2026.
The Department states that Phase I self-assessment requirements remain in place while the broader CMMC program undergoes review.
Organizations should continue to verify their specific contractual requirements and applicable DFARS clauses.
How NuageSEC Can Help With CMMC Readiness
CMMC readiness requires more than checking whether a cybersecurity product has been deployed.
Organizations need visibility into:
• What is in scope
• What requirements apply
• What is implemented
• What is documented
• What can be demonstrated
• What gaps remain
• What needs remediation
• What needs validation
NuageSEC can support organizations through a structured CMMC Readiness & Gap Assessment focused on understanding the current environment and identifying technical, documentation, scope, and evidence gaps.
Our assessment approach can help evaluate:
• CMMC applicability
• FCI and CUI handling
• Assessment scope
• Asset inventory
• CUI data flows
• Security requirement implementation
• Technical control gaps
• Documentation gaps
• Evidence gaps
• SSP alignment
• Cloud and third-party dependencies
• Remediation requirements
• Validation requirements
• Continuous compliance processes
Our CMMC Readiness Approach
Contract → Information → Scope → Controls → Documentation → Evidence → Assessment → Remediation → Validation → Continuous Compliance
This approach helps organizations understand not only whether a requirement is implemented, but also whether the implementation can be demonstrated and maintained
https://www.nuagesec.com/compliance/federal/cmmc
Know Your CMMC Readiness Before the Assessment
Identify the gaps. Prioritize remediation. Validate your security posture.
Talk to NuageSEC about a CMMC Readiness & Gap Assessment.
https://www.nuagesec.com/compliance/federal/cmmc
Prepare your environment. Understand your scope. Build defensible evidence
https://www.nuagesec.com/contact







