GovCon Cybersecurity | | 24 min read

CMMC Compliance: The Complete Guide for Defense Contractors


Cybersecurity code and network infrastructure representing CMMC compliance for defense contractors
Photo by Markus Spiske on Unsplash

Key Takeaways

CMMC is a state you prove continuously, not a certificate you buy before a deadline.

01

Prove a Continuous State

Assessors check that controls have been running all along, so treat CMMC as an operating condition you can demonstrate on any given day, not a deadline sprint.

02

The Clock Already Started

The program rule took effect December 2024 and the contract clause went live November 2025. The requirement is in solicitations now, and assessor capacity is finite.

03

Sequence Work by Burden

The 110 Level 2 requirements are not evenly weighted. Access Control, System and Communications Protection, and Identification and Authentication carry the most load, so start there.

04

Budget the Full Cost of Ownership

The assessment fee is the small part. Control implementation and recurring evidence dominate the cost, and keeping that evidence current never ends.

CMMC compliance is not a certificate you buy before a deadline.

It is a state you can prove on any given day.

That distinction is where most defense contractors lose time and money. They treat the Cybersecurity Maturity Model Certification as a one time event, a hurdle to clear right before an award, a binder to assemble and then forget. So they wait, watch the deadline, and plan a sprint. Then the assessor asks for evidence that the controls have been running all along, and the sprint falls apart.

CMMC does not work that way.

It asks whether you protect the government's information the way the rules require, and whether you can show it. Not once. On the day someone asks, and on every day in between. The certificate is a snapshot of a state you are supposed to hold continuously.

This guide walks through what CMMC compliance actually requires, why the timeline is no longer theoretical, how the three levels differ, and where the real effort and cost fall. We also share original GS Consulting research on which requirement families carry the most weight, so you can plan the work instead of reacting to it.

Turn CMMC from a deadline into a plan.

GS Consulting helps defense contractors scope their environment, close control gaps, and build the evidence an assessor will actually accept.

Request a CMMC Readiness Review

What CMMC Compliance Actually Is

CMMC is the Department of Defense program that verifies whether a contractor meets the cybersecurity requirements already written into federal rules. It does not invent new controls. It takes requirements that have existed for years, mostly in NIST SP 800-171, and adds a verification step so the government can trust that the requirements are actually met rather than merely promised.

The program protects two kinds of information. Federal Contract Information is the routine, non public information generated or received under a contract. Controlled Unclassified Information is more sensitive: technical data, specifications, and other material the government has marked for protection. The kind of information in your contract decides which level applies to you.

There is a useful way to think about the whole program. The certificate is small. The state behind it is large. Getting certified means implementing the controls, documenting how each one is met, and keeping the evidence current so that the state is real and not staged. That is why a contractor who treats CMMC as a project with an end date struggles, while one who treats it as an operating condition succeeds.

CMMC compliance timeline showing the program rule effective December 16 2024, the acquisition rule live November 10 2025, and the four phase rollout from 2025 through 2028
CMMC is now a contract condition. The rules are final, the clause is live, and the rollout runs through 2028.

Why the Clock Already Started

For years CMMC was a moving target, and waiting was a defensible strategy. That window is closed. The CMMC Program rule, published as 32 CFR Part 170, took effect on December 16, 2024. The acquisition rule that actually inserts the requirement into contracts, the DFARS rule adding clause 252.204-7021, became effective on November 10, 2025.

The requirement phases in over roughly three years so the assessment ecosystem can keep up. Phase 1 began in November 2025 with Level 1 and Level 2 self assessment requirements appearing in new contracts. Phase 2, in November 2026, makes third party Level 2 assessment the standard where a contract calls for it. Phase 3, in November 2027, brings Level 3 into applicable solicitations. Phase 4, in November 2028, completes the rollout, at which point the applicable CMMC level is a normal condition of award.

Here is the nuance that matters. The phased schedule does not mean you have until 2028. It means the requirement is already appearing in solicitations today, and the pool of assessors is finite. A contractor who waits for the last phase is competing for scarce assessment slots against everyone else who waited, while contracts they want are already carrying the clause. The safe read is simple: the requirement is live, and readiness is now a scheduling problem rather than a someday problem.

The Three Levels in Plain Terms

CMMC has three levels, and the level is set by the sensitivity of the information you handle, not by the size of your company. A two person shop handling CUI can face the same Level 2 requirements as a large integrator.

Level 1 protects Federal Contract Information. It covers the 15 basic safeguarding requirements in FAR 52.204-21, and it is met through an annual self assessment and an affirmation by a company official. This is the entry tier, and for many suppliers who never touch CUI, it is the whole story.

Level 2 protects Controlled Unclassified Information. It covers all 110 requirements in NIST SP 800-171 Rev 2, organized across 14 requirement families. Depending on the contract, Level 2 is met either through a self assessment or through a third party assessment performed by a certified assessor organization, with a certification that lasts three years and an annual affirmation in between. This is where most defense contractors who handle CUI will live.

Level 3 protects CUI on the highest risk programs. It builds on Level 2 by adding 24 selected requirements drawn from NIST SP 800-172, for a total of 134, and the assessment is led by the government rather than a commercial assessor. A contractor must achieve Level 2 first before Level 3 is even on the table.

If you want the level by level breakdown, including exactly what separates a self assessment from a third party assessment, read our companion guide on CMMC 2.0 levels explained. For the purposes of this guide, the point is that Level 2 and its 110 requirements are the center of gravity for the defense industrial base.

Original Research: Where the Burden Falls

The 110 requirements are not evenly weighted in practice. Some families involve a handful of controls that are easy to prove. Others involve many controls that demand deep engineering work and generate evidence you have to maintain forever. Knowing the difference is the difference between a plan and a scramble.

To make that concrete, GS Consulting built a Control Family Burden Index. We took the control count for each of the 14 NIST SP 800-171 families as a factual anchor, then added two weighting factors from our assessment practice: how much implementation effort a family typically demands, and how intensive its ongoing evidence is. The index weights control count at 50 percent, implementation effort at 25 percent, and evidence intensity at 25 percent, scaled from 0 to 100.

GS CMMC Control Family Burden Index ranking the 14 NIST 800-171 families, with Access Control, System and Communications Protection, and Identification and Authentication carrying the most load
Access Control, System and Communications Protection, and Identification and Authentication carry the heaviest combined implementation and evidence load.

The pattern is clear and it holds up against what assessors see. Access Control sits at the top with 22 requirements, followed by System and Communications Protection and Identification and Authentication. These three families define how people and systems get access, how data moves across boundaries, and how identity is proven, and they are exactly where scoping decisions and evidence gathering get hardest. Families like Personnel Security and Awareness and Training sit far lower, not because they do not matter, but because they involve fewer controls and simpler proof.

The practical takeaway: do not work the 110 requirements in numerical order. Start where the burden concentrates. A team that gets Access Control, boundary protection, and identity right early has done most of the heavy lifting, and the lighter families fall into place with far less friction.

Where the Real Effort and Cost Go

Ask a contractor what CMMC costs and many will name the assessment fee. That is the wrong anchor. The assessment is the visible line item, but it is rarely the largest one.

We modeled where effort and cost actually concentrate across the compliance lifecycle. The result is not subtle. Control implementation and remediation, recurring evidence and monitoring, and system security plan documentation carry the most weight. The third party assessment itself sits well down the list.

Chart of where CMMC effort concentrates, with control implementation, recurring evidence, and documentation ranking far above the third party assessment itself
The certificate is the small part. Implementation, evidence, and staying ready are the real load.

This matters for how you budget and staff. If you treat the assessment as the finish line, you underfund the two things that actually decide the outcome: getting the controls in place, and keeping the evidence alive. Cloud, managed service provider, and software as a service boundary work deserves special attention, because a large share of a modern contractor's CUI lives in services someone else operates. Sorting out which controls you own and which your providers own is a whole workstream on its own.

Subcontractor flow down is another underestimated line. If you pass CUI to a subcontractor, the requirement flows with it, and you carry responsibility for confirming they can protect it. That is a management burden, not a one time contract clause.

The Readiness Decision Path

When the burden is clear, the sequence becomes obvious. The mistake we see most is teams starting with a tool or a binder. They buy a platform, or they start filling in a template, before they know what they are actually protecting. That gets it backward.

Readiness starts with the data and works outward. Find the data first: does the contract involve Federal Contract Information, Controlled Unclassified Information, or neither? The answer sets the level. Then set the scope by mapping every asset, cloud service, and provider that stores, processes, or transmits that data. Then assess against the requirements and calculate an honest SPRS score. Only then do you remediate gaps and stand up the evidence that proves the state.

CMMC readiness decision path with five steps: find the data, set the level, define the scope, assess and score, then close and affirm
Start with the data, then work outward to scope, score, and evidence. Tools come last, not first.

Scoping deserves the most care, because it is the single biggest lever on cost. A CUI data flow map that draws a tight, defensible boundary can cut the number of in scope systems dramatically, which cuts both the implementation load and the evidence burden. A sloppy scope drags your entire environment into the assessment. We wrote a full walkthrough on building a CUI data flow map for CMMC, and it is worth reading before you touch a single control.

For the detailed, control by control preparation sequence, our guide on the CMMC readiness checklist for government contractors lays out the tasks in order. And if AI systems are part of your environment, preparing AI systems for a CMMC assessment covers the extra scoping questions those tools raise.

What Compliance Costs to Own

Cost of ownership is the honest frame. There is the cost to reach compliance, and the cost to hold it, and the second one never ends.

DoD's own analysis in the program rule estimated about $104,670 for a small entity Level 2 assessment, reporting, and affirmation. That figure covers the assessment activity, not the implementation and remediation that precede it. When you model the full picture, the initial implementation and remediation phase is the largest single block, documentation and readiness preparation is significant, and the recurring annual upkeep, keeping evidence current, monitoring controls, and staffing the effort, is a permanent line in your budget.

CMMC cost of ownership by activity showing initial implementation as the largest block, followed by recurring annual upkeep, documentation, and the third party assessment
The DoD cost model puts most of the burden before and after the assessment, not in the assessment itself.

The strategic implication is to invest early in the things that lower recurring cost. Automation that collects evidence continuously, a tightly scoped environment, and clean documentation all reduce the permanent upkeep line. A contractor who spends a little more up front to automate evidence collection pays far less over the three year certification cycle than one who reassembles a binder by hand every year.

The Evidence Packet That Proves Readiness

Readiness comes down to one question: on the day a customer or an assessor asks how you protect their information, what can you show? A confident answer is a small, well maintained set of artifacts. Everything in the program points back to these.

Minimum viable CMMC evidence packet listing ten artifacts including the CUI data flow map, assessment scope, system security plan, SPRS score, plan of action, and leadership affirmation
These ten artifacts are the practical answer when someone asks how you protect controlled information.

The system security plan is the spine. It describes how each requirement is met across the scoped environment, and every other artifact hangs off it. The SPRS score and its calculation worksheet show where you stand and what remains. The plan of action tracks open gaps, their owners, and their closure dates, within the limits of what the rules allow to remain open. The control evidence library, the configurations, screenshots, logs, and records that prove each control actually operates, is the part teams most often neglect and assessors most want to see.

Two artifacts deserve special mention for cloud heavy contractors. The shared responsibility matrix splits duties clearly between you, your cloud providers, and your managed service providers, so nothing falls through the cracks. And provider authorization evidence, including FedRAMP status for services that handle CUI, proves that the platforms you depend on are themselves cleared to hold the data. If you are working through cloud choices, our overview of the readiness checklist and the wider GovCon cybersecurity resources on our hub will help you connect the pieces.

Research Sources and Caveats

The GS CMMC Control Family Burden Index and the cost of ownership model are GS Consulting derived planning tools based on cited public sources and documented assumptions. They are not official legal, audit, compliance, NIST, CMMC, DoD, or C3PAO determinations. Requirement counts, dates, clauses, and the SPRS scoring mechanic are drawn from the regulations and standards below. The effort and evidence weights, and the relative rankings, are GS planning assumptions.

Your actual CMMC obligations depend on your contracts, the data you handle, your scope decisions, your environment, and the direction of your contracting officer and prime. Use these models to structure the work, not to replace legal, security, or assessment judgment.


Frequently Asked Questions About CMMC Compliance

What is CMMC compliance?

CMMC compliance means meeting the cybersecurity requirements of the Cybersecurity Maturity Model Certification program at the level your contract calls for, and being able to prove it. Level 1 covers 15 basic safeguarding requirements from FAR 52.204-21 for Federal Contract Information. Level 2 covers all 110 requirements in NIST SP 800-171 Rev 2 for Controlled Unclassified Information. Level 3 adds 24 selected requirements from NIST SP 800-172 for the highest risk programs. Compliance is a state you can demonstrate, not a document you file once.

Is CMMC actually required now, or is it still coming?

It is here. The CMMC Program rule (32 CFR Part 170) took effect December 16, 2024, and the acquisition rule that puts the requirement into contracts became effective November 10, 2025. The rollout is phased over three years, so not every solicitation carries a CMMC requirement yet, but the clause is live and appearing in new contracts. Treating it as a future problem is the most common and most expensive mistake.

How long does it take to become CMMC compliant?

For most contractors targeting Level 2, plan on a program measured in months, not weeks. The assessment itself is a small slice of the timeline. The real work is scoping the environment, implementing and remediating controls, writing the system security plan, and building the evidence that shows each control operates. A firm already close to NIST SP 800-171 may need a few months. A firm starting from a commercial baseline should plan for a year or more.

What does CMMC compliance cost?

The assessment is the visible cost and often the smallest one. DoD estimated about $104,670 for a small entity Level 2 assessment, reporting, and affirmation, which excludes implementation. Most of the real spend lands before and after the assessment: control implementation, tooling, documentation, and the recurring cost of keeping evidence current. Budget for the full cost of ownership, not just the certificate.

What is an SPRS score and why does it matter?

The Supplier Performance Risk System score reflects your implementation of NIST SP 800-171. You start at 110 and subtract weighted points of 1, 3, or 5 for each requirement that is not fully implemented, with no partial credit. The lowest possible score is -203. Contracting officers can see your posted score, so a handful of open high value requirements can put you at a real disadvantage before an assessment even happens.

Related Reading

© GS Consulting, LLC . All Rights Reserved | For more information, contact us at info@gsconsultingllc.com. Image credit: ©iStock.com/Vertigo3d. Privacy Policy | Terms of Use