If your business does any work for the Department of Defense, or hopes to, understanding what is CMMC has become essential. CMMC is the cybersecurity certification framework that increasingly determines whether a company can win and keep defense contracts. For the tens of thousands of contractors and subcontractors in the defense supply chain, especially across the DMV region, it is fast becoming a condition of doing business. Yet the rules are complex, they changed significantly in 2025 and 2026, and many businesses are unsure whether CMMC even applies to them.
The stakes are real. Once a CMMC requirement appears in a contract, the rule is simple: no certificate, no award. A business that handles government data without meeting the required level can lose eligibility for contracts it depends on. At the same time, the program’s rollout has seen important recent changes that every contractor needs to understand.
This guide explains what is CMMC in plain English. You will learn what CMMC actually is, the three levels, who needs which level, the current status of the rollout as of 2026, and how to tell whether your business needs to act. No acronym soup, just clarity on a framework that matters enormously if you touch defense work.
Quick Answer: CMMC, the Cybersecurity Maturity Model Certification, is a US Department of Defense program that requires defense contractors and subcontractors to prove they protect government information to a defined cybersecurity standard. It has three levels: Level 1 for basic protection of Federal Contract Information, Level 2 built on the 110 controls of NIST SP 800-171 for Controlled Unclassified Information, and Level 3 for the most sensitive work. It applies to any business in the defense supply chain that handles this data. Important 2026 note: the phased rollout beyond Level 1 self-assessment was suspended in July 2026 pending a program review, but the underlying obligation to protect defense data remains fully in effect.
Table of Contents
ToggleWhat Is CMMC, Really?
At its core, CMMC is the Department of Defense’s way of verifying that its contractors actually protect sensitive government information. The name stands for Cybersecurity Maturity Model Certification, and it exists to solve a specific problem.
Before CMMC, defense contractors simply self-attested that they met cybersecurity requirements, often inaccurately. Many overstated their compliance while cyberattacks on the defense supply chain kept rising (source: DoD, CMMC program background). Sensitive military information was leaking through under-secured contractors. CMMC replaces that honor system with defined levels and, for higher levels, independent verification.
The framework rests on two regulations. The CMMC Program Rule, 32 CFR Part 170, effective December 2024, built the program itself: the levels, the assessments, and the scoring. The companion DFARS rule, effective November 2025, created the contract mechanism that makes CMMC a condition of award (source: 32 CFR Part 170; DFARS 252.204-7021). Understanding what is CMMC starts with seeing it as both a security standard and a contracting requirement rolled into one. It sits within the broader landscape of compliance and risk that regulated businesses must navigate.
The Three CMMC Levels Explained
CMMC 2.0 streamlined an earlier five-level model down to three. Each level reflects the sensitivity of the information a contractor handles, and each carries different CMMC requirements. Here is what they mean.
CMMC Level 1: Foundational. This is the entry level, covering basic protection of Federal Contract Information, or FCI, which is non-public information provided or generated under a contract. Level 1 involves 17 basic safeguards and is met through an annual self-assessment. Any business handling FCI needs at least CMMC Level 1.
CMMC Level 2: Advanced. This level protects Controlled Unclassified Information, or CUI, the more sensitive category. It is anchored directly to the 110 security controls of NIST SP 800-171. Depending on the contract, Level 2 is met either through self-assessment or through certification by an independent Certified Third-Party Assessment Organization, known as a C3PAO.
CMMC Level 3: Expert. This is the highest level, reserved for the most sensitive programs. It builds on Level 2 and adds further requirements, with assessment led by the government’s own Defense Industrial Base Cybersecurity Assessment Center. Relatively few contractors need Level 3.
Understanding these CMMC requirements is the first step to knowing where your business fits. Most small contractors fall into Level 1 or Level 2, which is where our work on network and endpoint security most often applies.
CMMC Level 1: The Starting Point for Most Small Contractors
Because so many small businesses fall into it, CMMC Level 1 deserves a closer look. It is the most common requirement and the most achievable for a small contractor.
CMMC Level 1 applies to any business that handles Federal Contract Information but not the more sensitive CUI. FCI includes things like statements of work, delivery schedules, and non-public correspondence generated under a contract. If you have a defense contract but do not handle CUI, Level 1 is very likely your requirement.
The good news is that CMMC Level 1 is the most attainable level. It consists of 17 basic security practices, many of which overlap with fundamental cybersecurity hygiene like access control, and it is satisfied through an annual self-assessment rather than a costly third-party audit. For many small businesses, reaching CMMC Level 1 mainly means formalizing and documenting security basics they should already have, which is exactly where a managed IT partner adds value.
Does CMMC Apply to Your Business?
This is the question that matters most. The answer depends entirely on whether you handle defense information, directly or indirectly. Here is how to tell.
CMMC likely applies to you if:
You hold contracts with the Department of Defense, directly or as a subcontractor. You handle Federal Contract Information or Controlled Unclassified Information. You are part of the defense industrial base supply chain, even a few tiers down. You provide products or services that support defense work. Notably, subcontractors are covered too, and primes must flow the requirement down to them.
CMMC probably does not apply if:
You do no work connected to the Department of Defense. You do not handle any government-provided or government-generated non-public information. Your business operates entirely outside the federal supply chain.
One important point for defense contractor cybersecurity: the requirement follows the data, not the company size. A three-person machine shop handling CUI faces the same underlying Level 2 obligation as a large integrator. If you are anywhere in the defense supply chain, you need to determine your data type and your required level. A free risk assessment is a practical way to start that determination.
The Current Status: What Changed in 2026
Here is where you need current information, because the CMMC rollout changed significantly in 2026, and outdated guides will mislead you.
CMMC was rolling out in four phases from November 2025 through 2028, gradually widening which contracts carried a requirement. Phase 1, which began in November 2025, put Level 1 and Level 2 self-assessment requirements into select solicitations. However, as of July 13, 2026, the Department of War suspended Phases 2, 3, and 4 pending a 60-day program review (source: DoD/DoW, July 2026). This paused the expansion of mandatory third-party certification.
Two things are critical to understand about this pause. First, it is a suspension pending review, not a repeal. The underlying CMMC Program Rule and the DFARS clauses remain unchanged, and Phase 1 self-assessment requirements, DFARS 252.204-7012, and annual SPRS affirmations all remain fully in effect (source: DoD/DoW, 2026). Second, the obligation to protect defense data has not changed at all. NIST SP 800-171 has been contractually required for CUI since 2017, entirely independent of CMMC’s rollout timeline.
The practical takeaway is clear. Contractors already working toward compliance should keep going, because a reformed requirement and a resumed timeline are widely expected once the review concludes. This is defense contractor cybersecurity that you cannot afford to pause on, even while the assessment schedule is in flux.
Why You Should Not Wait
Even with the phase suspension, delaying your CMMC preparation is a mistake for several concrete reasons.
The underlying security obligation is already contractual. If you handle CUI, you are already required to meet NIST SP 800-171 under existing DFARS clauses, regardless of the CMMC assessment timeline. The pause does not relieve that.
Certification capacity is severely limited. There are fewer than 100 authorized assessor organizations serving an estimated 80,000 or more defense contractors (source: CMMC ecosystem analysis, 2026). When the assessment requirement resumes, that bottleneck means contractors who waited could face long delays that cost them contract eligibility.
Preparation takes time. Reaching Level 2 compliance involves implementing 110 controls, documenting them, and often remediating gaps, which can take many months. Starting now means being ready when requirements resume. This is exactly the kind of long-horizon security work our managed IT services are built to support.
Note Worthy Info
- CMMC has three levels. Level 1 for FCI, Level 2 for CUI (110 NIST controls), Level 3 for the most sensitive work.
- The requirement follows the data, not company size. A tiny shop handling CUI faces the same Level 2 obligation.
- Subcontractors are covered too. Primes must flow the requirement down the supply chain.
- Phases 2 to 4 were suspended in July 2026 pending review, but this is a pause, not a repeal.
- Phase 1 and the underlying obligations remain in effect. NIST SP 800-171 has been required since 2017.
- Certification capacity is a bottleneck. Under 100 assessors for 80,000+ contractors.
- A false compliance affirmation carries serious liability. It can trigger False Claims Act exposure.
The Bottom Line
Understanding what is CMMC comes down to this: it is the Department of Defense’s framework for verifying that its contractors protect government information, structured in three levels based on data sensitivity, and enforced as a condition of winning contracts. It applies to any business in the defense supply chain that handles Federal Contract Information or Controlled Unclassified Information, including subcontractors several tiers down.
While the phased rollout beyond Level 1 was suspended in mid-2026 pending review, the underlying obligation to protect defense data remains fully in force, and preparation should continue. Given the limited certification capacity and the months of work involved, the contractors who stay ready will be the ones who keep winning contracts. If you want to understand what is CMMC for your specific business and where you stand today, request a free risk assessment and we will help you determine your data type, your required level, and a clear path forward, whatever the timeline turns out to be.
Frequently Asked Questions
1. What is CMMC in simple terms?
CMMC, the Cybersecurity Maturity Model Certification, is a US Department of Defense program that requires its contractors and subcontractors to prove they protect sensitive government information to a defined cybersecurity standard. It replaced an older honor system where contractors simply self-attested compliance, often inaccurately. CMMC establishes three levels of requirements based on the sensitivity of the data a contractor handles, and for higher levels, it requires independent verification rather than self-reporting. Meeting the required level becomes a condition of winning defense contracts.
2. What are the three CMMC levels?
CMMC 2.0 has three levels. Level 1 (Foundational) covers basic protection of Federal Contract Information through 17 safeguards and an annual self-assessment. Level 2 (Advanced) protects Controlled Unclassified Information and is anchored to the 110 controls of NIST SP 800-171, met through either self-assessment or third-party certification depending on the contract. Level 3 (Expert) is for the most sensitive programs, builds on Level 2, and is assessed by the government directly. Your required level depends on the type of defense information you handle.
3. Does CMMC apply to my small business?
CMMC applies if your business handles defense information, directly or as a subcontractor. If you hold Department of Defense contracts, handle Federal Contract Information or Controlled Unclassified Information, or sit anywhere in the defense industrial base supply chain, CMMC likely applies to you. Importantly, the requirement follows the data, not the company size, so even a very small business handling CUI faces the same underlying obligation as a large contractor. If you do no defense-related work, CMMC generally does not apply.
4. What is CMMC Level 1?
CMMC Level 1 is the foundational, entry-level tier. It applies to businesses that handle Federal Contract Information, which is non-public information provided or generated under a contract, such as statements of work and delivery schedules, but not the more sensitive Controlled Unclassified Information. Level 1 consists of 17 basic security practices and is satisfied through an annual self-assessment rather than a third-party audit. For many small contractors, it mainly means formalizing and documenting fundamental cybersecurity practices they should already have in place.
5. Was CMMC suspended in 2026?
Partially. As of July 13, 2026, the Department of War suspended Phases 2, 3, and 4 of the CMMC rollout pending a 60-day program review, which paused the expansion of mandatory third-party certification. However, this is a suspension pending review, not a repeal. Phase 1 self-assessment requirements, the DFARS 252.204-7012 clause, and annual SPRS affirmations all remain fully in effect. Critically, the underlying obligation to protect defense data under NIST SP 800-171 has been contractual since 2017 and did not change.
6. Should I stop preparing for CMMC because of the suspension?
No. Delaying preparation would be a mistake for several reasons. The underlying security obligation is already contractual for anyone handling Controlled Unclassified Information, independent of the CMMC timeline. Certification capacity is severely limited, with fewer than 100 authorized assessors for over 80,000 contractors, so waiting risks long delays when requirements resume. And reaching compliance can take many months of implementing and documenting controls. Contractors who continue preparing will be positioned to win contracts when the timeline resumes.
7. What is the difference between CMMC and NIST SP 800-171?
NIST SP 800-171 is the underlying set of 110 security controls for protecting Controlled Unclassified Information, and it has been contractually required for defense contractors since 2017. CMMC is the certification program that verifies contractors actually meet those controls. In other words, CMMC Level 2 is built directly on NIST SP 800-171, adding an assessment and certification mechanism on top of the existing requirements. CMMC does not create new security requirements so much as it enforces and verifies compliance with standards that already applied.


