CMMC 2.0NIST SP 800-171DFARS Compliance

The Complete CMMC 2.0 Compliance Guide for Defense Contractors (2026)

Glenn Ballard

Glenn Ballard

Founder & CEO, Dragonfli Group · CMMC Registered Practitioner · June 7, 2026 · 12 min read

The DoW's Cybersecurity Maturity Model Certification program is no longer a future requirement — since the acquisition rule took effect November 10, 2025, it is actively appearing in solicitations across all DoW services. Defense contractors who delay are losing bids to competitors who are already compliant. This guide covers everything you need to understand about CMMC 2.0: what it requires, who it applies to, how the certification process works, and what it costs.

I have spent 26 years building and auditing cybersecurity programs for federal agencies and defense contractors. This guide is based on that experience, current DoW guidance, and the hundreds of assessment engagements our team at Dragonfli Group has conducted.

In this guide:

  1. What is CMMC 2.0?
  2. Who needs CMMC certification?
  3. The three CMMC levels explained
  4. The 14 CMMC domains and 110 requirements
  5. Understanding your SPRS score
  6. C3PAO assessments: what to expect
  7. What CMMC compliance costs
  8. How long compliance takes
  9. How to prepare: your first steps

What is CMMC 2.0?

CMMC (Cybersecurity Maturity Model Certification) is the US Department of War's mandatory cybersecurity framework for its supply chain. The original CMMC 1.0 was released in January 2020 with five maturity levels. CMMC 2.0 was announced in November 2021, streamlining the model to three levels and aligning it more closely with existing NIST standards. The CMMC Program rule (32 CFR Part 170) became effective in December 2024, and the acquisition rule (48 CFR) that puts CMMC clauses into contracts took effect November 10, 2025 — beginning a four-phase rollout that requires Level 2 C3PAO certification from November 10, 2026 and reaches full implementation on November 10, 2028.

CMMC is not a voluntary framework. It is enforced through the Defense Federal Acquisition Regulation Supplement (DFARS), specifically clause 252.204-7021, which contractors must flow down to all subcontractors handling covered information. Misrepresenting your CMMC status can trigger False Claims Act liability with treble damages.

Key distinction: CMMC vs. NIST SP 800-171

NIST SP 800-171 is the technical standard (110 security requirements). CMMC is the certification program that enforces it. You can be self-certified under NIST 800-171 today, but CMMC adds third-party verification for many contracts.

Who needs CMMC certification?

If your company holds or bids on DoW contracts and handles any of the following, CMMC applies to you:

  • Federal Contract Information (FCI) — Any information provided by or generated for the government under a contract that is not intended for public release. Requires CMMC Level 1.
  • Controlled Unclassified Information (CUI) — Technical data, engineering drawings, export-controlled information, procurement-sensitive information, or other information the government designates as CUI. Requires CMMC Level 2 (or Level 3 for the most sensitive programs).

This applies to prime contractors and all subcontractors at every tier. If you are a sub to a prime handling CUI, you must comply. Small businesses are not exempt — though the DoW has indicated it will prioritize enforcement on higher-risk contracts first.

How to know if you handle CUI

Your prime contractor's contract will reference CUI requirements if you handle it. Look for DFARS clause 252.204-7012 in your contract. If it's there, you must comply with NIST SP 800-171 and likely need CMMC Level 2.

The three CMMC levels explained

CMMC Level 1 — Foundational (17 practices)

Level 1 covers the 17 basic cybersecurity practices from FAR 52.204-21. These are the absolute fundamentals: limit system access to authorized users, control physical access, use antivirus, implement multi-factor authentication for privileged accounts, and similar baseline controls. Level 1 contractors may self-attest annually via a senior company official and do not need a third-party assessor.

CMMC Level 2 — Advanced (110 practices)

Level 2 is where most defense contractors focus. It covers all 110 security requirements from NIST SP 800-171 Rev 2 across 14 practice domains. For contracts the DoW designates as "critical," third-party certification by a C3PAO is required every three years. For non-critical programs, self-assessment may be permitted — but this distinction is made by the contracting officer in each solicitation.

CMMC Level 3 — Expert (110+ practices)

Level 3 is reserved for contractors on the most sensitive DoW programs, particularly those involving Advanced Persistent Threat (APT) risk. It is based on a subset of NIST SP 800-172 requirements and requires a government-led assessment by the Defense Contract Management Agency (DCMA). Very few contractors will need Level 3.

The 14 CMMC domains and 110 security requirements

CMMC Level 2 assesses all 14 practice families from NIST SP 800-171. Here is what each domain covers:

ACAccess Control

22 requirements covering who can access what systems and data

ATAwareness & Training

3 requirements covering security awareness programs

AUAudit & Accountability

9 requirements covering logging and audit trails

CMConfiguration Management

9 requirements covering system baselines and change control

IAIdentification & Authentication

11 requirements covering MFA, passwords, and identity management

IRIncident Response

3 requirements covering incident detection, reporting, and recovery

MAMaintenance

6 requirements covering system maintenance procedures

MPMedia Protection

9 requirements covering CUI on portable media

PEPhysical Protection

6 requirements covering physical access to systems

PSPersonnel Security

2 requirements covering personnel screening and termination

RARisk Assessment

3 requirements covering vulnerability scanning and risk analysis

CASecurity Assessment

4 requirements covering system assessment and monitoring

SCSystem & Communications Protection

16 requirements covering network architecture and encryption

SISystem & Information Integrity

7 requirements covering malware protection and security alerts

No single domain can be ignored. A gap in any domain impacts your overall SPRS score, your certification eligibility, and your exposure if an assessment identifies unaddressed weaknesses.

Understanding your SPRS score

The Supplier Performance Risk System (SPRS) score is a numeric representation of your NIST SP 800-171 compliance posture. It ranges from -203 to +110. A score of 110 means you have fully implemented all 110 requirements. Each unimplemented requirement carries a weighted penalty (1–5 points depending on criticality). Partial implementation earns partial credit.

Contractors must self-report their SPRS score in the PIEE (Procurement Integrated Enterprise Environment) portal and update it when controls are remediated. Your SPRS score is visible to DoW contracting officers and is increasingly used as a qualification factor in source selection. A negative SPRS score is a significant red flag.

SPRS score vs. CMMC readiness score

Your SPRS score (-203 to 110) and your CMMC readiness percentage (0–100%) measure related but different things. SPRS uses a weighted deduction model; readiness percentage is a simpler proportion of requirements met. Our assessment estimates both.

C3PAO assessments: what to expect

A C3PAO (Certified Third-Party Assessment Organization) is an accredited firm authorized by the CyberAB to conduct official CMMC Level 2 certification assessments. The assessment process typically involves:

  1. Scoping: Define the assessment boundary — which systems, locations, and personnel are in scope for CUI handling.
  2. Evidence submission: Provide documentation proving control implementation: policies, procedures, configuration screenshots, audit logs, training records.
  3. Assessment activities: C3PAO assessors interview personnel, review documentation, and test controls. This typically takes 1–4 weeks on-site or hybrid.
  4. POA&M review: Gaps identified during the assessment are documented in a Plan of Action & Milestones. The assessor evaluates whether gaps are remediable within 180 days and whether they are blocking.
  5. Certification decision: The C3PAO uploads findings to the CyberAB's eMASS instance. If requirements are met, your organization receives CMMC Level 2 certification valid for three years.

Working with an RPO (Registered Practitioner Organization) like Dragonfli Group before your C3PAO assessment dramatically improves your first-time pass rate and reduces total cost by ensuring your documentation and evidence packages are complete.

What CMMC compliance costs

Total CMMC compliance costs vary enormously by organization size, current security posture, and the complexity of your IT environment. Here are realistic estimates based on our engagement experience:

Readiness assessment$3,500

Dragonfli Group Full Report Package — includes SSP draft, POA&M, gap analysis, remediation roadmap

Documentation & policy development$5,000–$15,000

SSP, POA&M, 18 required policy templates, SPRS score calculation — T1 Scout engagement

Technical remediation$10,000–$100,000+

Depends on number of gaps; can include MFA rollout, network segmentation, endpoint security, SIEM deployment

C3PAO certification assessment$50,000–$200,000+

Charged by the C3PAO; varies by scope, number of sites, and assessor

Annual maintenance$5,000–$20,000/yr

Ongoing compliance monitoring, policy updates, employee training, evidence collection

The cost of non-compliance is higher

A missed DoW contract due to CMMC non-compliance typically far exceeds the cost of getting compliant. For most defense contractors, CMMC compliance is a net-positive ROI when measured against contract revenue protected.

How long CMMC compliance takes

The timeline to CMMC Level 2 compliance depends heavily on your starting point. Here is a realistic breakdown:

You are largely compliant with solid IT practices30–90 days

Primarily documentation work: SSP, POA&M, policy templates, evidence collection. Minimal technical remediation.

You have significant gaps but basic security hygiene6–12 months

Technical remediation required (MFA, endpoint protection, network controls) plus documentation. C3PAO assessment can follow.

You are starting from near-zero security posture12–24 months

Infrastructure rebuild may be required. Consider a CMMC-compliant managed security service (MSP) as a faster path.

How to prepare: your first steps

The best first step is always a gap assessment. You cannot build a remediation plan without knowing where you stand. Here is the sequence we recommend for every defense contractor:

  1. 1
    Run a readiness assessment
    Get your current CMMC score across all 14 domains. Understand your SPRS estimate. This is the foundation of everything that follows. Our Full Report ($3,500) does this in 15 minutes.
  2. 2
    Build your SSP and POA&M
    Your System Security Plan (SSP) documents how you meet each requirement. Your Plan of Action & Milestones (POA&M) documents how you will close gaps. These are required for C3PAO assessment.
  3. 3
    Calculate and submit your SPRS score
    Even if you have gaps, you must report your current SPRS score in the PIEE portal. A submitted score — even a low one — is better than no score.
  4. 4
    Remediate gaps by priority
    Focus on Critical and High priority gaps first (score < 65%). Use your POA&M as the project plan. Your Dragonfli consultant will help sequence this efficiently.
  5. 5
    Engage a C3PAO when ready
    When your POA&M shows 180-day closure for remaining gaps and your documentation is complete, schedule your C3PAO assessment. Do not engage a C3PAO before your RPO says you are ready.

Start with a Free Pulse Check

Find out where you stand in 10 minutes — across the 5 highest-risk CMMC domains. No credit card, no signup required.

Glenn Ballard

Glenn Ballard

Founder and CEO, Dragonfli Group LLC

26+ years of federal cybersecurity delivery experience across US government agencies, Fortune 500 financial institutions, and defense contractors. CMMC Registered Practitioner (RP), certified by the Cyber Accreditation Body (CyberAB). Founded Dragonfli Group in 2008.