Skip to main content

CMMC 2.0 Compliance Guide

Everything defense contractors need to know about the Cybersecurity Maturity Model Certification - the three levels, the 110 practices, common gaps, and your path to certification.

CMMC 2.0 (Cybersecurity Maturity Model Certification) is the Department of Defense's framework for verifying that defense contractors and subcontractors adequately protect sensitive federal information. If your organization handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) as part of a DoD contract, CMMC certification is a contractual requirement - not optional.

The CMMC 2.0 rule became effective December 16, 2024. DoD is phasing it into contracts throughout 2025–2026. If you're a defense industrial base (DIB) company that has been operating on an honor-system self-attestation, that window is closing.

DFARS 252.204-7021 Clause

When a contract includes this clause, you must achieve and maintain the required CMMC level as a condition of award. Misrepresenting your compliance status is a False Claims Act violation - with significant personal and corporate liability. Self-attestation is only available for Level 1 and some Level 2 programs; critical programs require third-party assessment.

The Three Levels of CMMC 2.0

CMMC 2.0 reduced the original five levels to three. Most defense contractors fall under Level 2.

Level 1

Foundational

DIB companies handling Federal Contract Information (FCI) only

17
practices

Covers the basic safeguarding requirements from FAR 52.204-21. Practices map to basic cyber hygiene - access control, media protection, physical protection, and system/communications protection.

Assessment: Annual self-assessment

Level 2

Advanced

DIB companies handling Controlled Unclassified Information (CUI)

110
practices

Full alignment with NIST SP 800-171 Rev 2. The most common certification target for defense contractors. Covers 14 domains across access control, incident response, risk assessment, configuration management, and more.

Assessment: Triennial third-party assessment (C3PAO) for critical programs; annual self-assessment for others

Level 3

Expert

Companies on DoD's highest-priority programs handling CUI

110+
practices

Adds selected requirements from NIST SP 800-172 on top of Level 2. Government-led assessments conducted by the Defense Industrial Base Cybersecurity Assessment Center. Reserved for the most sensitive programs.

Assessment: Government-led assessment (DIBCAC)

Level 2: The 14 Practice Domains

CMMC Level 2 maps directly to NIST SP 800-171 Rev 2 - 110 practices across 14 domains. If your contract involves CUI, these are the requirements you need to meet.

AC

Access Control

22 practices

Limit system access to authorized users, processes, and devices. Control the flow of CUI through systems.

AT

Awareness & Training

3 practices

Ensure personnel understand security risks and can recognize and report threats.

AU

Audit & Accountability

9 practices

Create, protect, retain, and review audit records to monitor activity and enable investigations.

CM

Configuration Management

9 practices

Establish baselines, control changes, and restrict software installation on organizational systems.

IA

Identification & Authentication

11 practices

Identify users, processes, and devices; authenticate before allowing access to systems.

IR

Incident Response

3 practices

Establish capabilities to detect, report, and respond to cybersecurity incidents.

MA

Maintenance

6 practices

Perform maintenance on organizational systems, controlling tools and personnel with access.

MP

Media Protection

9 practices

Protect system media, limit access to CUI on media, and sanitize before disposal.

PE

Personnel Security

2 practices

Screen individuals before authorizing access; protect systems during and after personnel actions.

PS

Physical Protection

6 practices

Limit physical access to systems and the facilities in which they reside.

RA

Risk Assessment

3 practices

Periodically assess risk to operations, assets, and individuals from system operation.

CA

Security Assessment

4 practices

Assess security controls, develop plans of action, monitor controls on an ongoing basis.

SC

System & Communications Protection

16 practices

Monitor, control, and protect communications at system boundaries.

SI

System & Information Integrity

7 practices

Identify and correct flaws, protect from malicious code, monitor system security alerts.

Common Gaps We Find in CMMC Assessments

Based on our gap assessments across defense contractor clients, these are the most common Level 2 deficiencies - and the ones most likely to generate POA&Ms.

No documented System Security Plan (SSP)

CMMC Level 2 requires a complete SSP describing how each of the 110 practices is implemented. Most small contractors have never written one.

Missing multi-factor authentication

Practice IA.3.083 requires MFA for all non-local access and privileged accounts. Many organizations still rely on passwords alone.

No formal incident response plan

IR.2.092 requires a documented IR capability. "We'll call our IT guy" doesn't satisfy this.

CUI not inventoried or labeled

You can't protect what you haven't identified. Many organizations don't have a complete inventory of where CUI lives - email, file shares, OneDrive, endpoints.

No audit log retention policy

AU.2.042 requires audit records to support after-the-fact investigation. Most organizations have audit logging but no defined retention period or review cadence.

Unconfigured or default configurations

CM.2.061 requires baseline configurations for all systems. Defaults are rarely secure baselines.

No vulnerability management program

RA.2.141 requires periodic scanning for vulnerabilities. Scanning is only the first step - there must be a documented remediation process.

The Path to CMMC Level 2 Certification

01

Gap Assessment

Evaluate your current security posture against all 110 NIST SP 800-171 practices. Identify which requirements are fully met, partially met, and not met. This produces your starting score and a prioritized list of deficiencies.

02

System Security Plan (SSP)

Document how each of the 110 practices is implemented in your environment. The SSP is the primary artifact for CMMC assessment. It describes your systems, boundaries, CUI flows, and the specific controls in place for each requirement.

03

Plan of Action & Milestones (POA&M)

For any practices not yet fully implemented, create a POA&M documenting the gap, the planned remediation, the responsible party, and the target completion date. CMMC allows limited POA&Ms at assessment time.

04

Remediation

Execute the POA&M. Common remediation projects include implementing MFA, deploying endpoint detection, establishing vulnerability management, creating and training to an IR plan, and hardening system configurations.

05

C3PAO Assessment (if required)

If your contract requires third-party assessment, engage a CMMC Third-Party Assessment Organization (C3PAO). They will assess your implementation against the 110 practices and submit results to the CMMC eMASS system.

06

Ongoing Compliance

CMMC is not a one-time project. Annual affirmations are required even for third-party assessed organizations. Continuous monitoring, vulnerability management, and security awareness training must be maintained.

How SOClogix Supports CMMC Compliance

CMMC Gap Assessment

We evaluate your environment against all 110 Level 2 practices and produce a scored gap report with remediation priority.

System Security Plan Development

We author or co-develop your SSP - the primary document assessed by C3PAOs.

24/7 SOC Monitoring (AU, IR domains)

Our managed SOC satisfies audit logging, monitoring, and incident response practice requirements with documented evidence.

Vulnerability Management (RA domain)

Our named-vulnerability reporting satisfies RA.2.141 and provides POA&M input for configuration findings.

Endpoint & Identity Protection (AC, IA domains)

MFA deployment, privileged access management, and endpoint detection across your CUI-handling systems.

Detection-as-Code (SI, AU domains)

Versioned, peer-reviewed detection rules that satisfy ongoing monitoring requirements with auditable evidence.

Request a CMMC Gap Assessment

We'll score your current posture and give you a prioritized remediation roadmap - no commitment required.

Don't Wait for a Contract Clause

CMMC requirements are rolling into new DoD contracts now. A gap assessment today gives you time to remediate before it becomes a contract condition.