What Contractors Need to Know About CMMC 2.0
Starting in early 2025, the Department of Defense (DoD) will include new contracting requirements for contractors to comply with the Cybersecurity Maturity Model Certification 2.0 (CMMC), with all contracts including those requirements by October of 2026. This phased rollout will impact Managed Service Providers (MSPs), data centers, and any organization engaged in the DoD’s supply chain. With the DoD rolling out these new requirements, contractors must prepare to meet these heightened security standards if they wish to continue doing business with the DoD.
What Contractors Need to Know
CMMC 2.0 retains most of the original controls from CMMC 1.0 but introduces some streamlined updates. Initially, CMMC 1.0 contained five levels of certification, but the updated version consolidates this into three levels, designed to secure Controlled Unclassified Information (CUI) from sophisticated cyber threats. The CMMC 2.0 model is closely aligned with the National Institute of Standards and Technology (NIST) Special Publication 800-171, which has been the cornerstone of defense contractor cybersecurity compliance since 2017. While CMMC expands on the existing NIST framework, the overarching goal remains the same: to protect the confidentiality, integrity, and availability of CUI. Contractors, both large and small, will need to show their capacity to safeguard sensitive government data at various levels of protection.The three CMMC levels are:
- Level 1 (Self-Certification): Required for contractors working with Federal Contract Information (FCI). Based on 17 cybersecurity controls from FAR 52.204-21, this level focuses on basic cybersecurity practices aimed at protecting FCI.
- Level 2: Required for those handling Controlled Unclassified Information (CUI). It is built around 110 controls from NIST SP 800-171 and requires an assessment from a CMMC Third Party Assessor Organization. This level aims to defend CUI from more sophisticated cyber threats, ensuring its integrity and availability.
- Level 3: Aimed at contractors exposed to Advanced Persistent Threats (APTs) while managing CUI, includes 110 controls from NIST 800-171 and an additional 35 controls from NIST SP 800-172. This level also requires a triennial third-party assessment and provides the highest level of protection against APTs.