compliance
Cybersecurity Maturity Model Certification 2.0 (CMMC)

What Contractors Need to Know About CMMC 2.0

Starting in early 2025, the Department of Defense (DoD) will include new contracting requirements for contractors to comply with the Cybersecurity Maturity Model Certification 2.0 (CMMC), with all contracts including those requirements by October of 2026. This phased rollout will impact Managed Service Providers (MSPs), data centers, and any organization engaged in the DoD’s supply chain. With the DoD rolling out these new requirements, contractors must prepare to meet these heightened security standards if they wish to continue doing business with the DoD.

What Contractors Need to Know

CMMC 2.0 retains most of the original controls from CMMC 1.0 but introduces some streamlined updates. Initially, CMMC 1.0 contained five levels of certification, but the updated version consolidates this into three levels, designed to secure Controlled Unclassified Information (CUI) from sophisticated cyber threats. The CMMC 2.0 model is closely aligned with the National Institute of Standards and Technology (NIST) Special Publication 800-171, which has been the cornerstone of defense contractor cybersecurity compliance since 2017. While CMMC expands on the existing NIST framework, the overarching goal remains the same: to protect the confidentiality, integrity, and availability of CUI. Contractors, both large and small, will need to show their capacity to safeguard sensitive government data at various levels of protection.

The three CMMC levels are:

  • Level 1 (Self-Certification): Required for contractors working with Federal Contract Information (FCI). Based on 17 cybersecurity controls from FAR 52.204-21, this level focuses on basic cybersecurity practices aimed at protecting FCI.
  • Level 2: Required for those handling Controlled Unclassified Information (CUI). It is built around 110 controls from NIST SP 800-171 and requires an assessment from a CMMC Third Party Assessor Organization. This level aims to defend CUI from more sophisticated cyber threats, ensuring its integrity and availability.
  • Level 3: Aimed at contractors exposed to Advanced Persistent Threats (APTs) while managing CUI, includes 110 controls from NIST 800-171 and an additional 35 controls from NIST SP 800-172. This level also requires a triennial third-party assessment and provides the highest level of protection against APTs.
CMMC requirements have technically been in place in most DoD contracts since 2017, since current DFARS requirements were included in most contracts. However, there was no audit mechanism in place to actually enforce or confirm compliance. CMMC v2.0 addresses this issue through self-certification and 3rd party audits, ensuring that contractors aren’t just claiming compliance but are genuinely meeting the rigorous cybersecurity standards set forth by the DoD.

Lack of Preparedness: Contractors Face Uphill Battle

Despite the fact that CMMC requirements have been in place for years, many contractors in the Defense Industrial Base (DIB) remain alarmingly unprepared for mandatory compliance with CMMC 2.0.  A  recent study conducted by CyberSheath and Merril Research uncovered just how vast the gap in readiness is among companies subject to the new requirements. The study, which focused on companies ranging in size from 40 to 1,000 employees, paints a stark picture. Only 4% of companies believe they are truly prepared for CMMC certification. The rest struggle due to a lack of qualified personnel, inadequate cybersecurity processes, and outdated technologies. For many organizations, this shortfall stems from the absence of a clear understanding of CMMC requirements and how to implement them. This gap in readiness highlights the need for contractors to prioritize investing in the right people, processes, and technologies to prepare for the full rollout of CMMC 2.0. Failing to do so will not only limit their ability to secure contracts but also place sensitive government information at risk. Companies must begin assessing their current cybersecurity posture, close gaps in compliance, and work towards CMMC certification to remain competitive. However, the path to compliance doesn’t have to be a lonely one. ProCern’s team of certified CMMC professionals have the knowledge and experience to support you, wherever you might be in your compliance journey. The clock is ticking. For DoD contractors, the time to act is now—before the 2025 deadline arrives.