Compliance glossary
What is CMMC 2.0?
CMMC 2.0 (Cybersecurity Maturity Model Certification version 2.0) is the United States Department of Defense's contractor cybersecurity certification program. It requires Defense Industrial Base contractors that handle Federal Contract Information or Controlled Unclassified Information to prove their security posture at one of three levels.
In one line: CMMC 2.0 is the DoD's certification program that verifies a contractor's cybersecurity before it can win or keep contracts involving sensitive federal information.
Definition
The original CMMC featured five maturity levels. The updated version collapses to three levels and aligns those levels directly to existing NIST publications. Level 1 corresponds to basic safeguarding in FAR clause 48 CFR 52.204-21. Level 2 aligns with the 110 controls from NIST Special Publication 800-171. Level 3 incorporates NIST SP 800-172 enhanced security requirements.
Assessment methods vary by level. Level 1 is an annual self-assessment with executive affirmation. Level 2 is a third-party assessment conducted every three years by a CMMC Third-Party Assessor Organisation (C3PAO), supplemented by annual self-affirmation. Level 3 is a government-led assessment conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).
Core components
- Federal Contract Information (FCI)
- Information provided by or generated for the Government under a contract and not intended for public release. Triggers the Level 1 requirement.
- Controlled Unclassified Information (CUI)
- Government-created or owned unclassified information that requires safeguarding under law, regulation, or government-wide policy. Triggers the Level 2 requirement.
- Level 1
- 17 basic safeguarding practices from FAR 52.204-21. Annual self-assessment with executive affirmation. Required for handling FCI.
- Level 2
- 110 security controls from NIST SP 800-171. Third-party assessment by a C3PAO every three years, with annual self-affirmation between assessments. Required for handling CUI.
- Level 3
- The 110 NIST SP 800-171 controls plus a subset of NIST SP 800-172 enhanced controls. Government-led assessment by DIBCAC. Required for the most sensitive CUI.
- C3PAO
- CMMC Third-Party Assessor Organisation, accredited to perform Level 2 certification assessments.
- System Security Plan (SSP)
- A document describing the system boundary, the implemented controls, and the implementation methodology. Required for Level 2.
- Plan of Action and Milestones (POA&M)
- A document tracking known control gaps, planned remediation, and milestone dates. A limited POA&M is permitted under specific conditions.
Why it matters
The program functions as an active procurement gate for DoD contractors and subcontractors. Contracts that previously required only self-attestation increasingly demand Level 1 self-assessment with affirmation, Level 2 C3PAO certification, or Level 3 DIBCAC assessment. Contractors that fail to meet the required level lose eligibility for the affected awards.
For MSPs serving DoD-contractor clients, the framework affects two dimensions. First, the MSP as a service provider must maintain a control posture compatible with the client's required level, because the MSP is part of the client's system boundary. Second, the MSP often delivers compliance support as a billable service.
The Canadian Program for Cyber Security Certification (CPCSC) is being designed in alignment with CMMC 2.0 using the same NIST SP 800-171 control base, so a single evidence base can serve both programs.
How Lavawall® helps with CMMC 2.0
Lavawall® treats CMMC 2.0 as a first-class framework. It maps the 110 NIST SP 800-171 controls to evidence the platform already collects: patching state, configuration posture, MFA enforcement, audit logging, privileged-access controls, incident response artifacts, and supply-chain risk indicators.
The multi-tenant delivery model lets standard Level 1 and Level 2 control profiles be applied to new tenants quickly, with co-branded SSP and POA&M generation supporting client-ready deliverables.
Frequently asked
- When is CMMC 2.0 enforceable?
- The DoD has been phasing CMMC 2.0 into solicitations under DFARS 252.204-7021. Through 2025 and 2026 an increasing number of contracts include CMMC 2.0 requirements, and by the end of the rollout all relevant DoD contracts will. Treat it as enforceable for any contract that names it.
- Does Level 2 require a C3PAO every year?
- No. The C3PAO assessment happens every three years. Annual self-affirmation occurs in the intervening years, though the evidence base must be maintained continuously.
- Can a POA&M cover failing controls during assessment?
- CMMC 2.0 permits limited POA&M items, primarily for higher-scoring controls and with closure deadlines. A POA&M is a structured acknowledgment of known gaps with remediation commitments, not a blanket exemption.
- Is CMMC 2.0 the same as NIST SP 800-171?
- CMMC 2.0 Level 2 is built on the 110 controls of NIST SP 800-171. The update adds assessment infrastructure (C3PAO, scoring, affirmation) on top of the NIST control set. Full NIST SP 800-171 implementation achieves functional Level 2 control coverage, and CMMC 2.0 then introduces the certification process.