Compliance Framework · Aerospace & Defense

CMMC

CMMC 2.0 Compliance (Level 2/3)

Cybersecurity Maturity Model Certification

Mandatory for DoD contractors handling CUI. Level 2 requires alignment with all 110 NIST 800-171 controls.

220K+

Companies in the defense industrial base that handle FCI or CUI (DoD, 89 FR 83092)

110

NIST 800-171 practices required for CMMC Level 2

C3PAO

Third-party assessment planned for most Level 2 contracts once Phase 2 resumes

Phase 1

CMMC in DoD contracts since Nov 10, 2025; Phase 2 suspended July 2026

"CMMC Level 2 Preparation for Defense Contractors"

220K+

Companies in the defense industrial base that handle FCI or CUI (DoD, 89 FR 83092)

110

NIST 800-171 practices required for CMMC Level 2

C3PAO

Third-party assessment planned for most Level 2 contracts once Phase 2 resumes

Phase 1

CMMC in DoD contracts since Nov 10, 2025; Phase 2 suspended July 2026

Sources: DoD CMMC 2.0 Final Rule (Oct 2024); NIST SP 800-171 Rev 2; DFARS CMMC Final Rule (Sept 2025, effective Nov 10, 2025); DoD CIO CMMC program page (Phase II suspension, July 13, 2026); CMMC Accreditation Body C3PAO directory

What CMMC requires

The core obligations at a glance.

Every CMMC program AdVran builds is sized against these requirements. Use this as a quick orientation before reading the deeper analysis below.

110

Practices across 14 NIST 800-171 control families

Required

Plan of Action and Milestones (POA&M) for any unmet controls

Required

System Security Plan (SSP) maintained as living document

3 years

C3PAO assessment validity period

How AdVran handles CMMC

From gap analysis to audit-ready, in 3 to 6 months.

01

Scope definition

We define your CUI environment, identify in-scope assets, and map data flows. Output is a documented scope boundary that focuses assessment effort and cost.

02

SSP and POA&M creation

Living System Security Plan written against all 110 practices. POA&M tracks remediation owners, target dates, and evidence sources. Both are required for assessment.

03

Control implementation

Technical controls deployed including FIPS 140-2 encryption, multi-factor authentication, audit logging, incident response, and configuration management.

04

C3PAO readiness and assessment

Pre-assessment runs identify gaps. AdVran coordinates with the C3PAO directly. Most clients pass on first attempt and avoid the costly reassessment cycle.

What Is CMMC?

CMMC 2.0 (Cybersecurity Maturity Model Certification) is the Department of Defense’s mandatory cybersecurity framework for contractors and subcontractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Level 2 requires alignment with all 110 NIST 800-171 practices, verified by either a self-assessment or a third-party C3PAO assessment, depending on the contract. CMMC Phase 1 has been in effect since November 10, 2025. Phase 2, which would have made C3PAO assessments the norm for Level 2 contracts, was suspended on July 13, 2026 while the Department reviews the program (DoD CIO).

CMMC Level 2: What It Requires

CMMC Level 2 applies to defense contractors and subcontractors that process, store, or transmit Controlled Unclassified Information (CUI) on their own systems. You have to implement all 110 security requirements in NIST SP 800-171 Revision 2 and prove it through an assessment (32 CFR 170.16). That assessment is either your own self-assessment or a certification assessment by an accredited third party (a C3PAO), and the contract tells you which (32 CFR 170.3). As of September 2026, CMMC is paused in Phase 1, so most solicitations ask for a Level 2 self-assessment. The underlying obligation to protect CUI under DFARS 252.204-7012 never went away.

Who needs Level 2

The CMMC rule covers every DoD contract and subcontract where FCI or CUI will live on contractor information systems, except contracts solely for commercial off-the-shelf items and purchases at or below the micro-purchase threshold (32 CFR 170.3). The DoD program manager picks the required level based on the information involved. FCI alone means Level 1. CUI means Level 2 at minimum. Primes must flow the requirement down to subcontractors that handle the same CUI (32 CFR 170.23). If you machine parts from controlled drawings, host engineering data, or support a defense program’s IT, plan for Level 2. Our aerospace and defense IT page covers the typical environments we see.

The 110 requirements

Level 2 is the 110 requirements of NIST SP 800-171 Rev 2, spread across 14 families such as access control, audit and accountability, incident response, and system and communications protection (NIST SP 800-171 Rev 2). CMMC assesses against Revision 2, not the newer Revision 3 (DoD CIO). Assessors check each requirement against the objectives in NIST SP 800-171A, and the evidence has to be final. Drafts, working papers, and unapproved policies do not count (32 CFR 170.24). Our NIST 800-171 compliance page walks through the control families in more detail.

Self-assessment or C3PAO certification

There are two Level 2 statuses:

  • Level 2 (Self). You assess your own environment, enter the score in the Supplier Performance Risk System (SPRS), and a senior official affirms it. You repeat the assessment every three years (32 CFR 170.16).
  • Level 2 (C3PAO). An authorized or accredited CMMC Third-Party Assessment Organization runs the assessment and submits the results through the CMMC instance of eMASS, which feeds SPRS. A C3PAO status also satisfies Level 1 (Self) and Level 2 (Self) for the same scope (32 CFR 170.17).

You don’t get to choose. The solicitation states the required status. Even in Phase 1, DoD may require Level 2 (C3PAO) instead of Level 2 (Self) on a given contract (32 CFR 170.3(e)).

Scoring, POA&Ms, and the 88-point line

The maximum Level 2 score is 110. Each requirement you haven’t met subtracts 1, 3, or 5 points depending on its weight, and the total can go negative (32 CFR 170.24). A perfect score earns Final Level 2 status.

Fall short of 110 and you can still hold Conditional status with a Plan of Action and Milestones (POA&M), but only if all of these hold (32 CFR 170.21):

  • Your score is at least 80 percent of 110, which works out to 88 points.
  • Every item on the POA&M is worth 1 point. The one exception is CUI encryption (SC.L2-3.13.11), which can be deferred if you use encryption that isn’t FIPS-validated.
  • None of six specific requirements is open, including the System Security Plan (CA.L2-3.12.4), external connections, public information control, and three physical access controls.

The POA&M has to be closed by a closeout assessment within 180 days of the Conditional status date. Miss that window and the Conditional status expires. For a self-assessment you run the closeout yourself. For a C3PAO assessment, a C3PAO has to do it (32 CFR 170.21(b)).

Timeline and phase status (as of September 2026)

  • October 15, 2024: DoD published the CMMC Program rule, 32 CFR Part 170, effective December 16, 2024 (Federal Register).
  • November 10, 2025: The DFARS acquisition rule (48 CFR) took effect, which started Phase 1 (Federal Register). Phase 1 requires Level 1 (Self) or Level 2 (Self) as a condition of award, with C3PAO assessments at DoD’s discretion.
  • Phase 2 (planned for November 10, 2026): Level 2 (C3PAO) becomes a condition of award for applicable contracts.
  • Phase 3 (one year after Phase 2): Level 2 (C3PAO) applies to all applicable contracts and to option periods, and Level 3 requirements begin.
  • Phase 4 (one year after Phase 3): Full implementation, including option periods on contracts awarded before Phase 4 (32 CFR 170.3(e)).
  • July 13, 2026: The Department of War suspended Phase II and set up a CMMC reform task force. Phase 1 self-assessment requirements stay in place, and the Department says it will keep enforcing NIST 800-171 Rev 2 through self-assessments and select government-led assessments (DoD CIO).

The Phase 2 through 4 language is still in the published regulation (32 CFR 170.3). The pause could end with a new rule or a revised one. If a prime or a program office is already asking about third-party assessment, treat that as the signal to get ready.

How long Level 2 status lasts

Final Level 2 status is valid for three years from the status date, for both self and C3PAO assessments. On top of that, an Affirming Official, a senior person in your company, must affirm continuing compliance in SPRS after every assessment, after any POA&M closeout, and every year after that (32 CFR 170.22). Skip the annual affirmation and the status lapses (DoD CIO). For C3PAO assessments, you also keep hashed copies of your assessment evidence for six years (32 CFR 170.17).

What DoD estimates Level 2 will cost

The final rule’s cost analysis gives these figures for the assessment and affirmations alone (Federal Register, 89 FR 83092):

Level 2 pathSmall entity, first assessmentSmall entity, 3-year totalOther than small, first assessmentOther than small, 3-year total
Self-assessment$34,277$37,196$43,403$48,827
C3PAO certification$101,752$104,670$112,345$117,768

Read the fine print. DoD assumed you had already implemented the 800-171 requirements, so these numbers leave out remediation, new tools, and the staff time it takes to close gaps. If you are starting from a low SPRS score, budget for that work separately.

How to prepare for CMMC Level 2

  1. Confirm you handle CUI. Look for DFARS 252.204-7012 in your contracts and CUI markings on the drawings and data you receive. Ask your prime which CMMC status they will flow down.
  2. Draw the assessment boundary. List every system, person, and facility that touches CUI, plus the security tools and service providers that protect them. Cloud services that hold CUI need FedRAMP Moderate authorization or an equivalent (32 CFR 170.17).
  3. Write the System Security Plan first. It is one of the requirements that can never go on a POA&M.
  4. Score yourself honestly. Use the 1, 3, and 5 point values from the rule, not a friendly estimate.
  5. Fix the 3 and 5 point gaps before anything else. They can’t be deferred, and a few of them can drop you below 88 on their own.
  6. Collect evidence in final form. Signed policies, configuration exports, logs, and training records. No drafts.
  7. Post your score in SPRS and affirm. Put a calendar reminder on the annual affirmation.
  8. Line up a C3PAO early if your contracts point that way. Assessor calendars fill up once requirements tighten.

AdVran is not a C3PAO. We handle the preparation: gap assessment, SSP and POA&M writing, control implementation, and coordination with the independent assessor you choose. See our compliance and risk management services, or request a CMMC Level 2 readiness assessment to find out where your score stands today.

Why Choose AdVran for CMMC?

When a contract calls for a C3PAO assessment, self-attestation won’t satisfy it. Your managed service provider counts as a Security Protection Asset inside your audit boundary, so the assessor looks at their security as part of yours. If your MSP’s controls are weak, the C3PAO can write that up as a finding before reviewing any of your own documents.

1. Audit-Ready Evidence

Logs alone don’t pass an assessment. We run a centralized GRC platform that automates evidence collection for all 110 NIST 800-171 controls, so when a C3PAO auditor shows up, your System Security Plans (SSP) and Plans of Action and Milestones (POA&M) are already timestamped and organized.

2. We Hold Ourselves to Level 2

Under CMMC 2.0, an MSP that touches your CUI environment is in scope for your audit. We keep our own security aligned to Level 2 standards so our internal tools and remote access protocols don’t turn into findings against you.

3. Sovereignty and Data Residency

We work within ITAR and DFARS requirements. Our support teams are US-based, and our cloud architectures use FedRAMP Moderate/High environments like Azure Government and AWS GovCloud. Your data stays on US soil and out of reach of unauthorized foreign nationals.

4. Proactive Threat Hunting

An assessment shows where your controls stood on the day of the review, and threats keep coming after that. Our MSSP division offers Managed Detection and Response (MDR) tuned specifically for the Defense Industrial Base, including a documented incident response capability that satisfies NIST 800-171 IR control family requirements. Our analysts hunt for the advanced persistent threats that go after defense contractors, along with the commodity malware that shows up in generic threat feeds.

5. A Clear Shared Responsibility Matrix

We give you a written Shared Responsibility Matrix that shows which of the 110 controls we manage, which you own, and which we share, so nobody is guessing at assessment time.

Frequently Asked Questions About CMMC Compliance

What is CMMC 2.0 and who does it apply to?

CMMC 2.0 applies to all DoD prime contractors and subcontractors who handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). DoD puts the defense industrial base at over 220,000 companies that process, store, or transmit CUI or FCI, and estimates that 8,350 medium and large entities will require a Level 2 certification assessment (89 FR 83092). Southern California holds a significant share of that base, near the major defense primes in Long Beach, El Segundo, Anaheim, and Pasadena. CMMC requirements flow down through the supply chain. If a prime requires CMMC, their subcontractors handling CUI must also comply.

What is the difference between CMMC Level 1, 2, and 3?

CMMC Level 1 covers 15 basic security requirements from FAR 52.204-21 for contractors handling FCI and requires annual self-assessment. Level 2 covers 110 practices aligned to NIST 800-171 for contractors handling CUI; most contracts require triennial third-party assessment by a C3PAO. Level 3 adds 24 enhanced requirements from NIST SP 800-172 for the most sensitive DoD programs and requires a government-led assessment by DCMA DIBCAC. Most Southern California defense contractors need Level 2.

What is a C3PAO and is a third-party assessment required?

A C3PAO (CMMC Third-Party Assessment Organization) is an accredited firm authorized by the Cyber AB to conduct official CMMC Level 2 assessments. The contract decides whether Level 2 is a self-assessment or a C3PAO assessment. During Phase 1 most Level 2 requirements are self-assessments, and Phase 2, which would have made C3PAO assessments standard, was suspended in July 2026. DoD can still require a C3PAO on any contract. AdVran prepares clients for C3PAO assessments by documenting all 110 controls, maintaining a System Security Plan, and closing gaps found during pre-assessment reviews.

How does having AdVran as my MSP affect my CMMC audit scope?

Under CMMC 2.0, any external service provider that processes, stores, or transmits CUI on your behalf is potentially in scope for your assessment. AdVran operates as a Security Protection Asset within your audit boundary, so our security affects your certification outcome. We keep our own environment aligned to CMMC Level 2 standards so that having us in scope doesn’t add findings to your assessment.

How long does CMMC Level 2 preparation take?

Most organizations need 6-18 months to reach CMMC Level 2 certification from a cold start, depending on their current posture and the gap between existing practices and all 110 NIST 800-171 controls. Organizations with an existing NIST 800-171 self-assessment score above 100 points can typically wrap up preparation in 3-6 months. AdVran starts with a gap assessment that produces a realistic timeline and remediation roadmap before any investment commitment.

What is CMMC Level 2?

CMMC Level 2 is the middle tier of the DoD’s Cybersecurity Maturity Model Certification, required for contractors that handle Controlled Unclassified Information. It requires all 110 security requirements in NIST SP 800-171 Rev 2, verified by a self-assessment or a C3PAO certification assessment, whichever the contract specifies (32 CFR 170.16, 32 CFR 170.17).

Can we self-assess for CMMC Level 2?

Yes, if the contract calls for Level 2 (Self). During Phase 1, which began November 10, 2025, most Level 2 requirements are self-assessments, though DoD can require a C3PAO on any contract. Phase 2 would have made C3PAO assessments standard, but it was suspended on July 13, 2026 (DoD CIO). You enter the score in SPRS and a senior official affirms it.

What score do we need for CMMC Level 2?

A perfect 110 earns Final status. A score of 88 or higher (80 percent of 110) can earn Conditional status with a POA&M, as long as the open items are 1-point requirements and none are on the rule’s excluded list. All POA&M items must be closed within 180 days or the Conditional status expires (32 CFR 170.21).

How long is CMMC Level 2 status valid?

Three years from the status date. You also need an annual affirmation in SPRS from a senior official, and the status lapses if you miss one (32 CFR 170.22).

How AdVran helps: AdVran’s managed CMMC compliance services handle gap assessment, SSP and POA&M authoring, control implementation, and C3PAO coordination, so your team isn’t running the project on top of its day jobs.

AdVran’s vulnerability management service runs scheduled scans across your environment, prioritizes findings by exploitability, and tracks remediation to closure, meeting CMMC CA.L2-3.11.2, which requires periodic scanning of organizational systems and real-time scanning of files from external sources.

Defense contractors pursuing CMMC certification often operate under additional frameworks. CJIS Security Policy requirements apply to defense and law enforcement contractors handling criminal justice information. FedRAMP applies to cloud service providers supporting DoD or federal agency systems within CMMC scope. FIPS 140-2 cryptographic validation is explicitly required by CMMC Level 2 and above for protecting CUI at rest and in transit. API Cybersecurity Standards govern oil, gas, and pipeline operators in the defense industrial supply chain.

Self-assessment

CMMC Level 2 and NIST 800-171 readiness snapshot

This is a self-check you complete yourself against the 110 security requirements in NIST SP 800-171 Revision 2 and the related obligations in DFARS 252.204-7012. It is not a C3PAO or government assessment, and a high score here is not a certification, an SPRS score, or a legal opinion that you are compliant.

  1. 1. Do you have a written, current inventory of every system, device, cloud service, and physical location that stores, processes, or transmits CUI? higher weight

    Standard requirement: NIST SP 800-171 Rev 2, 3.4.1

  2. 2. Is there a written System Security Plan that describes your system boundary, your operating environment, and how each NIST 800-171 requirement is implemented, and has it been updated since your last significant system change? higher weight

    Standard requirement: NIST SP 800-171 Rev 2, 3.12.4

  3. 3. For every requirement you have not fully met, is there a written plan of action that names the fix, the person responsible, and a target date?

    Standard requirement: NIST SP 800-171 Rev 2, 3.12.2

  4. 4. Have you calculated a NIST SP 800-171 self-assessment score and posted it in the Supplier Performance Risk System, with a submission less than three years old as DFARS 252.204-7019(b) requires? higher weight

    Contract clause: DFARS 252.204-7019(b), which is where the three year window comes from. Class Deviation 2026-O0025 Revision 3 substitutes DFARS 252.240-7997, whose paragraph lettering has not been read, so treat the window as sourced from 7019(b) only

  5. 5. Does every administrator account, and every remote or network sign-in by a regular user, require a second authentication factor rather than a password alone? higher weight

    Standard requirement: NIST SP 800-171 Rev 2, 3.5.3

  6. 6. For every tool you use to encrypt CUI, can you produce the NIST Cryptographic Module Validation Program certificate number for the module, rather than only a vendor claim that the product is FIPS compliant? higher weight

    Standard requirement: NIST SP 800-171 Rev 2, 3.13.11

  7. 7. Do the systems that handle CUI create and retain audit logs, and does a named person review the logged events on a set schedule?

    Standard requirement: NIST SP 800-171 Rev 2, 3.3.1 and 3.3.3

  8. 8. If you discovered a cyber incident today, could you report it to DoD through DIBNet within 72 hours using a DoD-approved medium assurance certificate you already hold? higher weight

    Contract clause: DFARS 252.204-7012(a) and (c)

  9. 9. Before you dispose of, resell, return, or reassign any laptop, drive, phone, printer, or backup tape that held CUI, do you sanitize or destroy the storage media?

    Standard requirement: NIST SP 800-171 Rev 2, 3.8.3

  10. 10. Is physical access to the equipment, racks, and work areas used for CUI limited to individuals you have specifically authorized?

    Standard requirement: NIST SP 800-171 Rev 2, 3.10.1

  11. 11. Has everyone who handles CUI, including managers and system administrators, completed training for their assigned security duties, with dated records you could show an assessor?

    Standard requirement: NIST SP 800-171 Rev 2, 3.2.2

  12. 12. For each cloud service that stores, processes, or transmits CUI, do you hold written evidence that it meets the FedRAMP Moderate baseline, or requirements equivalent to it? higher weight

    Contract clause: DFARS 252.204-7012(b)(2)(ii)(D)

  13. 13. Is DFARS 252.204-7012 written into every subcontract whose performance involves covered defense information or operationally critical support?

    Contract clause: DFARS 252.204-7012(m)

  14. 14. Have you decided and written down which outside systems and personally owned devices are allowed to connect to your network or handle CUI, and is that limit enforced by configuration rather than policy alone? higher weight

    Standard requirement: NIST SP 800-171 Rev 2, 3.1.20

  15. 15. Do you scan your systems and applications for vulnerabilities on a set schedule, and again when a new vulnerability affecting them is announced?

    Standard requirement: NIST SP 800-171 Rev 2, 3.11.2

  16. 16. Is there a process that finds security flaws in the systems handling CUI and installs the fixes within a stated timeframe, with a current list of what is still outstanding?

    Standard requirement: NIST SP 800-171 Rev 2, 3.14.1

  17. 17. When someone leaves or changes role, do you follow a set procedure every time to disable their accounts and recover their devices, keys, badges, and credentials?

    Standard requirement: NIST SP 800-171 Rev 2, 3.9.2

Common questions

CMMC compliance.

Don't see yours? Call (714) 694-4573 or email contact@advran.com.

What is CMMC and who needs to comply? +

Mandatory for DoD contractors handling CUI. Level 2 requires alignment with all 110 NIST 800-171 controls.

How does AdVran help with CMMC compliance? +

AdVran provides end-to-end CMMC compliance management, including gap assessment, control implementation, continuous monitoring, evidence collection, and audit coordination. Our team handles the technical complexity so you can focus on your business.

How long does it take to achieve CMMC compliance? +

Timeline depends on your current security posture and the scope of required controls. Most organizations achieve initial compliance within 3-6 months with AdVran's guidance. We provide a detailed timeline during our initial assessment.

What happens if we fail a compliance audit? +

AdVran conducts pre-audit readiness assessments to identify and resolve gaps before the official audit. If issues are found during an audit, we provide immediate remediation support and work with auditors to address findings.