What Is CMMC 2.0?
CMMC (Cybersecurity Maturity Model Certification) is the U.S. Department of Defense framework that requires companies in the defense supply chain to prove they protect sensitive government information. It's a DoD-specific cybersecurity program, administered through the Cyber AB accreditation body, not an ISO management-system standard, so the certification path looks different from ISO 27001 or SOC 2. If you hold, or want, DoD contracts, CMMC is how you demonstrate your cybersecurity is up to standard, and a CMMC certification consultant is how most contractors get there without burning a year of internal engineering time.
CMMC 2.0 streamlined the original five-level model into three levels, aligned the technical requirements to existing NIST standards, and reintroduced annual self-assessments for the lowest tier. It protects two types of data: Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
Who needs CMMC? Every organization in the Defense Industrial Base (DIB), prime contractors and subcontractors alike. If CUI or FCI flows through your systems, your contract will require a specific CMMC level. Avantcert helps DoD suppliers reach the right level efficiently and stay compliant.
CMMC 2.0 Levels: 1, 2 and 3
CMMC 2.0 has three levels. The level your contract requires depends on the sensitivity of the information you handle.
| Level | Name | Protects | Requirements & Assessment |
|---|---|---|---|
| Level 1 | Foundational | FCI | 17 basic practices · annual self-assessment |
| Level 2 | Advanced | CUI | 110 practices (NIST SP 800-171) · C3PAO third-party assessment every 3 years |
| Level 3 | Expert | CUI (high-priority) | 110+ practices plus NIST SP 800-172 · government-led assessment |
Most contractors handling CUI need Level 2. Contracts the DoD flags as "prioritized" require an independent assessment by a Certified Third-Party Assessment Organization (C3PAO) accredited through the Cyber AB; a smaller set of "non-prioritized" Level 2 contracts still allow an annual self-assessment. Avantcert prepares you for whichever path your contract requires, so the assessment is a formality, not a gamble.
2026 update: In July 2026 the DoD paused the rollout of CMMC Phase 2, the expansion of mandatory C3PAO assessments, for a 60-day review of cost impact and assessor capacity. Phase 1 obligations already written into contracts, including Level 1 self-assessment and initial Level 2 requirements, remain fully in force. If your contract already specifies a level, keep moving, don't wait on the review to conclude.
CMMC Requirements: NIST SP 800-171
At the core of CMMC Level 2 are the 110 security controls of NIST SP 800-171, organized into 14 families, access control, audit and accountability, configuration management, identification and authentication, incident response, and more.
To meet the requirements you'll need a documented System Security Plan (SSP), a Plan of Action & Milestones (POA&M) for any gaps, and evidence that each control is implemented and operating. Avantcert builds this evidence package with you and maps every control to your environment so nothing is missed before the C3PAO arrives.
These requirements don't stop at your own walls. Under DFARS 252.204-7021, they flow down to every subcontractor and supplier who touches that FCI or CUI, at whatever level their piece of the work requires, and your Supplier Performance Risk System (SPRS) score reflects how well you can prove it. If you're a prime, that means verifying your supply chain actually meets its flowed-down level, not just naming the clause in the subcontract.
CUI vs FCI: What's the Difference?
CMMC exists to protect two information types, and they decide your level:
| Data type | What it is | CMMC level |
|---|---|---|
| FCI | Federal Contract Information, not intended for public release, generated for/under a contract | Level 1 |
| CUI | Controlled Unclassified Information, sensitive government data requiring safeguarding | Level 2 (or 3) |
Identifying exactly where FCI and CUI live in your systems is the first practical step of any CMMC project, and it's where Avantcert's gap analysis starts.
CMMC vs CMMI: They're Not the Same
These two are frequently confused because the acronyms look alike, but they solve different problems.
| CMMC | CMMI | |
|---|---|---|
| Focus | Cybersecurity for DoD contractors | Process & capability maturity |
| Owner | U.S. Department of Defense | ISACA / CMMI Institute |
| Result | Certification (C3PAO) | Appraisal rating (SCAMPI, Levels 1-5) |
In short: CMMC proves your cybersecurity meets DoD requirements; CMMI rates how mature your processes are. Avantcert delivers both, see our CMMI certification & appraisal services, so we can advise which (or both) your goals require.
The CMMC Certification Process
Avantcert follows a proven four-stage path to certification:
1. Gap Analysis, scope where FCI/CUI lives and assess your current state against the required level. 2. Implementation, close gaps, write the SSP, and stand up the 110 NIST 800-171 controls. 3. Internal Audit & Pre-Assessment, validate readiness and remediate findings. 4. C3PAO Assessment & Certification, the accredited third-party assessment, followed by ongoing surveillance and your next renewal.
CMMC Cost, Timeline & How to Get Certified
How long does CMMC take? For most contractors, Level 2 readiness takes 6 to 12 months, depending on your starting maturity, the size of your CUI environment, and C3PAO scheduling.
How much does CMMC cost? Three things drive the number: gap remediation, closing the space between where you are and the 110 NIST 800-171 controls, which is usually the largest line item; the C3PAO assessment fee for Level 2, paid directly to the assessor and separate from preparation work; and ongoing costs like continuous monitoring and annual affirmations. Environment size is the biggest lever, a tightly scoped CUI enclave costs far less to certify than putting your whole network in scope. Rather than a generic figure, Avantcert gives you a tailored estimate after a short scoping call. Request a free CMMC quote to get your number and a readiness roadmap.
New to the process? Read our guide on how to choose a CMMC consultant, the 7 criteria, questions to ask, and red flags to avoid.
CMMC Certification FAQs
What is CMMC?
CMMC (Cybersecurity Maturity Model Certification) is the U.S. Department of Defense framework that requires defense contractors to demonstrate they protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). CMMC 2.0 has three levels.
What are the CMMC 2.0 levels?
Level 1 Foundational (17 practices, self-assessment, FCI), Level 2 Advanced (110 NIST SP 800-171 practices, C3PAO assessment, CUI), and Level 3 Expert (adds NIST SP 800-172, government-led assessment).
What are the CMMC requirements?
CMMC Level 2 requires the 110 security controls of NIST SP 800-171 across 14 families, plus a System Security Plan (SSP) and a Plan of Action & Milestones (POA&M).
What is the difference between CMMC and CMMI?
CMMC is a DoD cybersecurity certification; CMMI is a process-maturity appraisal owned by ISACA. CMMC proves your security; CMMI rates how mature your processes are. They are unrelated frameworks.
Who needs CMMC certification?
Every organization in the DoD supply chain (the Defense Industrial Base), prime contractors and subcontractors, that handles FCI or CUI. Your contract specifies the required level.
How do you get CMMC certified, and how much does it cost?
Through gap analysis, implementation of NIST 800-171 controls, internal audit, and a C3PAO assessment (Level 2). Timelines run 6-12 months; cost depends on environment complexity. Request a free quote for a tailored estimate.
Do CMMC requirements flow down to subcontractors?
Yes. Under DFARS 252.204-7021, prime contractors must flow CMMC requirements down to subcontractors at every tier that processes, stores, or transmits FCI or CUI. The level required for a subcontractor is set by the data the prime shares with them, not by the prime's own CMMC level, so a Level 2 prime can still have Level 1 subcontractors who never touch CUI. Primes are responsible for verifying that compliance, not just naming the clause.
What is a POA&M, and can I use one to pass my C3PAO assessment?
A Plan of Action & Milestones (POA&M) documents any NIST SP 800-171 controls you haven't fully implemented yet, and how and when you'll close each gap, typically within 180 days. A limited number of lower-weighted controls can stay open on a POA&M at assessment time, but high-weighted controls, most notably multi-factor authentication, generally can't, and missing them can fail the assessment outright.
Is CMMC still moving forward after the 2026 Phase 2 pause?
Yes. In July 2026 the DoD paused the rollout of CMMC Phase 2, the expansion of mandatory third-party C3PAO assessments, for a 60-day review of cost impact on small contractors and C3PAO assessor capacity. Phase 1 requirements already written into contracts, including Level 1 self-assessment and initial Level 2 obligations, remain in force. If your contract already requires a level, keep building toward it, the review doesn't pause your own deadline.
About Avantcert
Avantcert is an accredited ISO and compliance certification consultancy that helps organizations achieve CMMC 2.0 certification through gap analysis, implementation, and accredited audit support. Avantcert has supported 3,000+ organizations across 40+ markets, following a proven four-stage methodology, Gap Analysis, Implementation, Internal Audit, and Certification. To begin your CMMC 2.0 certification, request a free quote or talk to an Avantcert expert.
CMMC with Avantcert vs Sprinto & Drata
Compliance-automation tools like Sprinto and Drata focus on SOC 2 and ISO 27001, most don't cover CMMC's NIST SP 800-171 controls or the C3PAO assessment at all. Avantcert takes DoD contractors from gap analysis to C3PAO-ready across Levels 1-3, done for you.
| Sprinto / Drata | Avantcert | |
|---|---|---|
| Model | DIY compliance software | Done-for-you experts |
| Who does the work | Your team | Avantcert's consultants |
| Evidence collection | You upload it | We gather & organize it |
| Audit preparation | Self-guided | Audit-ready, with you on the day |
| CMMC / NIST 800-171 | Limited or not covered | Full coverage, Levels 1-3 |
Compare approaches in our Sprinto alternative and Vanta alternative guides, or get a free CMMC quote.
Free CMMC checklist
Download our free CMMC pre-audit checklist, 68 audit-ready items with the exact evidence your auditor will ask for, as a print-friendly PDF and an editable CSV tracker. No cost.
Related certifications
Avantcert also helps organizations achieve these related standards, often alongside CMMC 2.0 as part of one programme: ISO 27001, SOC 2, SOC 1, NIST CSF, HITRUST, PCI DSS. Not sure which you need? Use the free estimator or talk to an expert.
Official reference: U.S. DoD, CMMC.
Ready to start your CMMC journey?
Get expert guidance from gap analysis to C3PAO-ready across CMMC Levels 1-3.