CMMC 2.0 Compliance Guide
Everything defense contractors need to know about the Cybersecurity Maturity Model Certification - the three levels, the 110 practices, common gaps, and your path to certification.
CMMC 2.0 (Cybersecurity Maturity Model Certification) is the Department of Defense's framework for verifying that defense contractors and subcontractors adequately protect sensitive federal information. If your organization handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) as part of a DoD contract, CMMC certification is a contractual requirement - not optional.
The CMMC 2.0 rule became effective December 16, 2024. DoD is phasing it into contracts throughout 2025–2026. If you're a defense industrial base (DIB) company that has been operating on an honor-system self-attestation, that window is closing.
DFARS 252.204-7021 Clause
When a contract includes this clause, you must achieve and maintain the required CMMC level as a condition of award. Misrepresenting your compliance status is a False Claims Act violation - with significant personal and corporate liability. Self-attestation is only available for Level 1 and some Level 2 programs; critical programs require third-party assessment.
The Three Levels of CMMC 2.0
CMMC 2.0 reduced the original five levels to three. Most defense contractors fall under Level 2.
Foundational
DIB companies handling Federal Contract Information (FCI) only
Covers the basic safeguarding requirements from FAR 52.204-21. Practices map to basic cyber hygiene - access control, media protection, physical protection, and system/communications protection.
Assessment: Annual self-assessment
Advanced
DIB companies handling Controlled Unclassified Information (CUI)
Full alignment with NIST SP 800-171 Rev 2. The most common certification target for defense contractors. Covers 14 domains across access control, incident response, risk assessment, configuration management, and more.
Assessment: Triennial third-party assessment (C3PAO) for critical programs; annual self-assessment for others
Expert
Companies on DoD's highest-priority programs handling CUI
Adds selected requirements from NIST SP 800-172 on top of Level 2. Government-led assessments conducted by the Defense Industrial Base Cybersecurity Assessment Center. Reserved for the most sensitive programs.
Assessment: Government-led assessment (DIBCAC)
Level 2: The 14 Practice Domains
CMMC Level 2 maps directly to NIST SP 800-171 Rev 2 - 110 practices across 14 domains. If your contract involves CUI, these are the requirements you need to meet.
Access Control
22 practicesLimit system access to authorized users, processes, and devices. Control the flow of CUI through systems.
Awareness & Training
3 practicesEnsure personnel understand security risks and can recognize and report threats.
Audit & Accountability
9 practicesCreate, protect, retain, and review audit records to monitor activity and enable investigations.
Configuration Management
9 practicesEstablish baselines, control changes, and restrict software installation on organizational systems.
Identification & Authentication
11 practicesIdentify users, processes, and devices; authenticate before allowing access to systems.
Incident Response
3 practicesEstablish capabilities to detect, report, and respond to cybersecurity incidents.
Maintenance
6 practicesPerform maintenance on organizational systems, controlling tools and personnel with access.
Media Protection
9 practicesProtect system media, limit access to CUI on media, and sanitize before disposal.
Personnel Security
2 practicesScreen individuals before authorizing access; protect systems during and after personnel actions.
Physical Protection
6 practicesLimit physical access to systems and the facilities in which they reside.
Risk Assessment
3 practicesPeriodically assess risk to operations, assets, and individuals from system operation.
Security Assessment
4 practicesAssess security controls, develop plans of action, monitor controls on an ongoing basis.
System & Communications Protection
16 practicesMonitor, control, and protect communications at system boundaries.
System & Information Integrity
7 practicesIdentify and correct flaws, protect from malicious code, monitor system security alerts.
Common Gaps We Find in CMMC Assessments
Based on our gap assessments across defense contractor clients, these are the most common Level 2 deficiencies - and the ones most likely to generate POA&Ms.
No documented System Security Plan (SSP)
CMMC Level 2 requires a complete SSP describing how each of the 110 practices is implemented. Most small contractors have never written one.
Missing multi-factor authentication
Practice IA.3.083 requires MFA for all non-local access and privileged accounts. Many organizations still rely on passwords alone.
No formal incident response plan
IR.2.092 requires a documented IR capability. "We'll call our IT guy" doesn't satisfy this.
CUI not inventoried or labeled
You can't protect what you haven't identified. Many organizations don't have a complete inventory of where CUI lives - email, file shares, OneDrive, endpoints.
No audit log retention policy
AU.2.042 requires audit records to support after-the-fact investigation. Most organizations have audit logging but no defined retention period or review cadence.
Unconfigured or default configurations
CM.2.061 requires baseline configurations for all systems. Defaults are rarely secure baselines.
No vulnerability management program
RA.2.141 requires periodic scanning for vulnerabilities. Scanning is only the first step - there must be a documented remediation process.
The Path to CMMC Level 2 Certification
Gap Assessment
Evaluate your current security posture against all 110 NIST SP 800-171 practices. Identify which requirements are fully met, partially met, and not met. This produces your starting score and a prioritized list of deficiencies.
System Security Plan (SSP)
Document how each of the 110 practices is implemented in your environment. The SSP is the primary artifact for CMMC assessment. It describes your systems, boundaries, CUI flows, and the specific controls in place for each requirement.
Plan of Action & Milestones (POA&M)
For any practices not yet fully implemented, create a POA&M documenting the gap, the planned remediation, the responsible party, and the target completion date. CMMC allows limited POA&Ms at assessment time.
Remediation
Execute the POA&M. Common remediation projects include implementing MFA, deploying endpoint detection, establishing vulnerability management, creating and training to an IR plan, and hardening system configurations.
C3PAO Assessment (if required)
If your contract requires third-party assessment, engage a CMMC Third-Party Assessment Organization (C3PAO). They will assess your implementation against the 110 practices and submit results to the CMMC eMASS system.
Ongoing Compliance
CMMC is not a one-time project. Annual affirmations are required even for third-party assessed organizations. Continuous monitoring, vulnerability management, and security awareness training must be maintained.
How SOClogix Supports CMMC Compliance
CMMC Gap Assessment
We evaluate your environment against all 110 Level 2 practices and produce a scored gap report with remediation priority.
System Security Plan Development
We author or co-develop your SSP - the primary document assessed by C3PAOs.
24/7 SOC Monitoring (AU, IR domains)
Our managed SOC satisfies audit logging, monitoring, and incident response practice requirements with documented evidence.
Vulnerability Management (RA domain)
Our named-vulnerability reporting satisfies RA.2.141 and provides POA&M input for configuration findings.
Endpoint & Identity Protection (AC, IA domains)
MFA deployment, privileged access management, and endpoint detection across your CUI-handling systems.
Detection-as-Code (SI, AU domains)
Versioned, peer-reviewed detection rules that satisfy ongoing monitoring requirements with auditable evidence.
We'll score your current posture and give you a prioritized remediation roadmap - no commitment required.
Don't Wait for a Contract Clause
CMMC requirements are rolling into new DoD contracts now. A gap assessment today gives you time to remediate before it becomes a contract condition.