What Is CMMC 2.0? A Guide to CMMC Compliance Requirements for Defense Contractors

Learn what CMMC 2.0 is, its compliance levels, requirements, changes from CMMC 1.0, and how defense contractors can achieve cybersecurity compliance.
Many organizations assume CMMC 2.0 is simply another cybersecurity certification, but in reality, it represents something much larger. The framework marks a broader shift in how the Department of Defense (DoD) evaluates operational trust across its contractor ecosystem. Cybersecurity is becoming part of how defense readiness itself is assessed.
This is an important distinction because many contractors already believe they are secure. They may have firewalls, endpoint protection, access controls, and written policies in place. Yet during audit assessments, organizations often discover missing documentation, undefined system boundaries, unmanaged vendors, or incomplete evidence that can create significant compliance gaps.
CMMC 2.0 was designed specifically to close that gap between assumed security and demonstrable security. As a result, CMMC compliance is becoming a critical requirement for organizations that want to participate in the defense supply chain, with the Cybersecurity Maturity Model Certification framework providing a structured method for validating cybersecurity practices.
What Is CMMC 2.0?
CMMC 2.0, short for Cybersecurity Maturity Model Certification 2.0, is the cybersecurity compliance framework developed by the U.S. DoD to improve the protection of sensitive government information shared with defense contractors and suppliers.
The framework applies to organizations operating within the Defense Industrial Base (DIB), including prime contractors, subcontractors, manufacturers, engineering firms, technology providers, and third-party vendors that process, store, or transmit defense-related information.
The primary objective of CMMC 2.0 is to ensure that contractors handling sensitive data integrate appropriate cybersecurity controls based on the type of information they access. The framework focuses heavily on protecting:
-
· Federal Contract Information (FCI)
-
· Controlled Unclassified Information (CUI)
FCI generally refers to non-public information provided under government contracts, while CUI includes more sensitive data that requires safeguarding but is not formally classified.
What Are the Main Changes from CMMC 1.0 to CMMC 2.0?
One of the primary goals behind the introduction of CMMC 2.0 was to simplify the original framework while making cybersecurity requirements more practical and easier to implement across the DIB.
When CMMC 1.0 was introduced, many organizations found it overly complex. In response to industry feedback, the DoD revised the framework to reduce unnecessary complexity while still maintaining strong cybersecurity expectations for organizations handling sensitive government information.
As a result, CMMC 2.0 introduces several important structural and operational changes. These revisions were intended to make the Cybersecurity Maturity Model Certification framework more streamlined while preserving the security expectations required across the defense industrial base.
1.Reduction From Five Levels to Three
One of the most noticeable changes is the reduction of the framework from five maturity levels to three compliance levels. Under CMMC 1.0, organizations had to navigate multiple maturity levels, often creating confusion about applicable controls and compliance requirements.
CMMC 2.0 simplifies this structure into:
-
Level 1 (Foundational)
-
Level 2 (Advanced)
-
Level 3 (Expert)
This revised model creates a clearer relationship between the type of information handled and the cybersecurity controls required. It also makes the framework easier for contractors to understand, scope, and integrate. For many contractors pursuing CMMC certification, the simplified structure makes it easier to identify the appropriate compliance level and associated security obligations.
2. Stronger Alignment with Existing NIST Standards
Another major change is the stronger alignment between CMMC 2.0 and established federal cybersecurity standards. Instead of introducing large numbers of additional practices unique to CMMC, the revised framework relies more heavily on existing standards such as:
-
NIST SP 800-171
-
FAR 52.204-21
-
NIST SP 800-172
By aligning with NIST requirements, CMMC 2.0 reduces compliance overlap, streamlines security efforts, and improves consistency across the defense supply chain
3.More Flexible Assessment Requirements
CMMC 1.0 required third-party certification assessments for nearly all contractors, regardless of the sensitivity of the information they handled. Under CMMC 2.0, the DoD introduced more flexibility by allowing some organizations to complete annual self-assessments instead of mandatory third-party audits.
For example:
-
Level 1 organizations generally perform self-assessments annually.
-
Certain Level 2 contractors may also qualify for self-assessments depending on contract requirements.
-
Higher-risk Level 2 and Level 3 environments still require third-party or government-led assessments.
4. Simplified Compliance Expectations
CMMC 1.0 included additional “maturity processes” that evaluated not only whether security controls existed, but also how formally organizations managed and optimized those processes over time.
Many contractors viewed these maturity requirements as difficult to interpret and resource-intensive to implement. CMMC 2.0 removes several of these additional maturity process requirements and places greater emphasis on whether security controls are properly implemented and functioning effectively.
The 4 Pillars of the Revised CMMC 2.0 Framework
CMMC 2.0 framework is built around four key pillars designed to improve cybersecurity resilience across the Defense Industrial Base (DIB) while making compliance requirements more practical and scalable for contractors of different sizes and operational maturity levels.
These pillars reflect the DoD’s broader objective of improving cybersecurity accountability throughout the defense supply chain without creating unnecessary complexity for lower-risk organizations.
1.Tiered Cybersecurity Requirements
One of the core principles of CMMC 2.0 is its tiered approach to cybersecurity requirements. Instead of applying the same level of security obligations to every contractor, the framework scales requirements based on the sensitivity of the information an organization handles.
For example, contractors working only with Federal Contract Information (FCI) may be required to implement foundational cybersecurity practices such as basic access controls, password management, and device protection. In contrast, organizations handling Controlled Unclassified Information (CUI) must implement more advanced security controls aligned with NIST SP 800-171 requirements. Most organizations handling CUI fall within CMMC Level 2, which includes a broader set of security requirements designed to protect sensitive government information.
This risk-based approach tailors cybersecurity requirements to an organization's risk level, ensuring practical compliance while advancing protection for sensitive defense information.
2.Alignment With Existing Federal Standards
Another major pillar of CMMC 2.0 is its stronger alignment with established federal cybersecurity standards and regulatory requirements. Rather than introducing a completely separate cybersecurity framework, CMMC 2.0 relies heavily on recognized standards such as:
-
NIST SP 800-171
-
FAR 52.204-21
-
NIST SP 800-172
This alignment helps reduce duplication in compliance efforts and creates greater consistency across government cybersecurity expectations. Many defense contractors were already executing NIST-based controls before CMMC was introduced, so the revised framework allows organizations to build upon existing cybersecurity programs instead of starting from scratch.
3.Flexible Assessment Approaches
CMMC 2.0 introduces a more flexible and risk-based assessment structure compared to the original framework. Under this model, assessment requirements vary depending on the contractor’s required compliance level and the sensitivity of the information involved. Some organizations may complete annual self-assessments, while others require independent third-party certification assessments or government-led evaluations. The assessment pathway selected often determines the level of scrutiny required before an organization can achieve CMMC certification.
This tiered assessment approach helps reduce compliance burdens for lower-risk contractors while maintaining stronger verification requirements for organizations handling sensitive Controlled Unclassified Information or supporting critical national security programs.
4.Enhanced Accountability and Verification
One of the most significant shifts introduced under CMMC 2.0 is the increased focus on accountability and demonstrable implementation. Under previous compliance approaches, organizations often relied on self-attestation, where contractors claimed that required security controls were in place without formal validation. CMMC 2.0 moves beyond this model by requiring organizations to provide evidence that controls are properly implemented, maintained, and functioning effectively.
This includes demonstrating compliance through:
-
Policies and procedures
-
System Security Plans (SSPs)
-
Technical evidence and audit records
-
Executive affirmations
-
Ongoing governance and monitoring activities
A well-maintained System Security Plan (SSP) plays a critical role in documenting security controls, system boundaries, and compliance activities during assessments. The framework prioritizes operational cybersecurity maturity, requiring organizations to continuously manage and validate security controls.
What Are the New CMMC 2.0 Levels?
CMMC 2.0 is divided into three compliance levels designed to align cybersecurity requirements with the sensitivity of the information an organization handles. Instead of applying the same controls to every contractor, the framework follows a risk-based approach where security expectations increase based on the type of government information involved.
Level 1 — Foundational
Level 1 applies to organizations that handle Federal Contract Information (FCI). The focus at this stage is on basic cyber hygiene practices aligned with FAR 52.204-21 requirements. Organizations at this level are generally permitted to complete annual self-assessments instead of third-party certification audits.
Typical controls include:
-
Password management
-
Access restrictions
-
Basic endpoint protection
-
Secure system configurations
Although Level 1 requirements are considered foundational, organizations are still expected to demonstrate that required controls are actively implemented and maintained.
Level 2 — Advanced
Level 2 applies to organizations handling Controlled Unclassified Information (CUI) and is expected to be the most common compliance level for defense contractors.
This level aligns with the 110 security controls defined in NIST SP 800-171 and introduces more advanced cybersecurity requirements related to system protection, monitoring, and risk management.
Depending on contract requirements, organizations may need to complete:
-
Annual self-assessments, or
-
Third-party assessments conducted by Certified Third-Party Assessment Organizations (C3PAOs)
Key focus areas include:
-
Multifactor authentication (MFA)
-
Incident response
-
Logging and monitoring
-
Vulnerability management
-
Access governance
Level 3 — Expert
Level 3 is designed for organizations supporting high-priority national security programs or highly sensitive defense operations.
In addition to Level 2 requirements, organizations at this stage must implement additional controls derived from NIST SP 800-172 to strengthen protection against advanced cyber threats and sophisticated attacks.
Level 3 assessments are expected to involve government-led evaluations and focus heavily on advanced threat detection, cyber resilience, and continuous security monitoring.
Who Needs to Comply with CMMC 2.0?
CMMC 2.0 applies to a wide range of organizations that support, supply, or work directly with the U.S. DoD. Any organization that processes, stores, transmits, or has access to sensitive defense-related information may fall within the scope of CMMC requirements.
This includes organizations such as:
-
Prime contractors working directly with the DoD
-
Subcontractors supporting defense-related projects
-
Aerospace and defense manufacturers
-
Engineering and design firms
-
Defense technology providers
-
Software and SaaS vendors
-
Cloud service providers
-
Managed service providers (MSPs)
-
IT support vendors
-
Supply chain partners handling contract-related data
One common misconception is that only large defense contractors need compliance. In reality, even small suppliers may require compliance if they process or access covered defense information.
Understanding Federal Contract Information (FCI) and Controlled Unclassified Information (CUI)
Distinguishing between Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) is one of the most important aspects of CMMC 2.0 compliance. The type of information an organization handles often determines which CMMC level applies, the cybersecurity controls required, and the type of assessment the organization may need to undergo.
For many defense contractors, identifying and properly classifying information is also one of the most challenging parts of the compliance process.
Federal Contract Information (FCI)
Federal Contract Information (FCI) refers to information that is provided by or generated for the government under a contract, but is not intended for public release. This information is generally less sensitive than CUI but still requires basic safeguarding measures to prevent unauthorized access or disclosure.
Examples of FCI may include:
-
Procurement details
-
Contract schedules
-
Project communications
-
Internal contract-related documentation
-
Performance reports
-
Non-public operational information
Organizations that handle only FCI typically fall under CMMC Level 1 requirements, which focus on foundational cybersecurity practices such as access controls, password protection, and basic system security measures. These foundational controls are intended to establish a baseline level of cybersecurity readiness for contractors participating in the Cybersecurity Maturity Model Certification program.
Although Level 1 requirements are considered less complex than higher maturity levels, organizations are still expected to demonstrate that appropriate cybersecurity controls are implemented and consistently maintained.
Controlled Unclassified Information (CUI)
Controlled Unclassified Information (CUI) refers to sensitive government information that requires safeguarding or dissemination controls but is not classified under national security classification systems. CUI is significantly more sensitive than FCI and therefore requires stronger cybersecurity protections aligned with NIST SP 800-171 controls.
Examples of CUI may include:
-
Technical drawings and schematics
-
Engineering specifications
-
Defense-related research data
-
Sensitive operational information
-
Manufacturing processes
-
Export-controlled information
-
System architecture details
Organizations handling CUI generally require CMMC Level 2 compliance and must implement more advanced cybersecurity controls related to areas such as:
-
Multifactor authentication
-
Incident response
-
Security monitoring
-
Vulnerability management
-
Access governance
-
Data protection
Achieving CMMC Level 2 often requires organizations to demonstrate that these controls are consistently implemented, documented, and maintained across in-scope systems.
CMMC 2.0 and the Future of Defense Supply Chain Security
For many defense contractors, CMMC 2.0 is becoming more than a cybersecurity requirement. It is influencing contract readiness, supply chain trust, and how organizations demonstrate operational reliability within the defense ecosystem. As requirements continue expanding across DoD contracts, organizations are placing greater focus on governance maturity, information visibility, and consistent cybersecurity practices rather than approaching compliance as a one-time activity. For many contractors, maintaining CMMC certification is becoming an important component of long-term participation in the defense supply chain.
As an independent certification and assessment body, INTERCERT works with organizations across regulated and high-trust industries navigating evolving cybersecurity expectations. Through structured assessment methodologies and internationally recognized evaluation practices, organizations gain clearer visibility into their cybersecurity posture, governance maturity, and alignment with applicable compliance requirements.
Read More :
What Should Defense Contractors Understand About CMMC Compliance Requirements?
What is CMMC Compliance? A Complete Guide CMMC Compliance 2026