| CMMC Level 1 |
All DoD contractors handling Federal Contract Information — the baseline requirement for any DoD contract or subcontract flowing down FAR 52.204-21. Applies to every business in the Greater Washington defense supply chain, regardless of size or tier |
17-practice gap assessment mapped to FAR 52.204-21, control implementation for all unmet practices, annual self-attestation preparation for senior official signature, documentation package for prime contractor supply chain audits, annual review to maintain attestation currency |
Written gap assessment report, implemented and verified controls across all 17 practices, self-attestation documentation package, evidence binder for prime audit requests, annual review schedule |
| CMMC Level 2 (Self-Attestation) |
Non-critical DoD programs at Secretary of Defense discretion — a limited subset of Level 2 programs designated eligible for contractor self-attestation rather than C3PAO third-party assessment. Contractors must confirm their program falls into this subset before assuming self-attestation is permissible |
All 110 Level 2 practices documented and implemented, SSP developed with practice-specific implementation descriptions, POA&M developed for any gaps with remediation timelines, evidence package assembled for senior official self-attestation, annual review for attestation renewal, False Claims Act risk counseling for self-attestation accuracy |
SSP covering all 110 NIST 800-171 practices, POA&M with remediation tracking, evidence package supporting self-attestation, annual compliance review report |
| CMMC Level 2 (C3PAO Assessment) |
Most CMMC Level 2 programs — contractors handling CUI on critical DoD programs who must undergo third-party assessment by an accredited C3PAO prior to contract award or renewal. Required from November 10, 2026 (Phase 2) for most CUI contracts in the Greater Washington defense industrial base |
Full 110-practice gap remediation across all 14 NIST 800-171 requirement families, SSP and POA&M development to C3PAO assessment standards, pre-assessment readiness review simulating C3PAO evidence requests, pre-assessment gap closure, evidence package organization for each practice, C3PAO selection guidance from the Cyber AB marketplace, and assessment coordination support |
C3PAO-ready evidence package with documentation for all 110 practices, remediated technical controls with configuration exports, SSP and POA&M in assessment-ready format, pre-assessment readiness report identifying any remaining risk items |
| NIST SP 800-171 Rev 2 |
All CMMC Level 2 contractors — the 110 practices of NIST 800-171 Rev 2 are the technical foundation of CMMC Level 2, organized across 14 security requirement families. Also required for DFARS 252.204-7012 compliance in active contracts |
Control implementation mapped to all 14 NIST families: Access Control (AC), Awareness and Training (AT), Audit and Accountability (AU), Configuration Management (CM), Identification and Authentication (IA), Incident Response (IR), Maintenance (MA), Media Protection (MP), Personnel Security (PS), Physical Protection (PE), Risk Assessment (RA), Security Assessment (CA), System and Communications Protection (SC), System and Information Integrity (SI) |
NIST 800-171 SSP with implementation description and evidence for each of the 110 controls, organized by requirement family, with practice-level compliance status documentation |
| DFARS 252.204-7012 |
All DoD contractors with covered defense information — applies independently of CMMC and is already a clause in most active DoD contracts and subcontracts in the Greater Washington defense industrial base. Requires immediate action, not future planning |
Cloud service provider verification and documentation (FedRAMP Moderate minimum for CDI/CUI — GCC or GCC High configuration for M365 environments), 72-hour DoD DC3 incident reporting capability and runbook, 90-day data preservation procedure, media sanitization procedure implementation, adequate security verification across the covered defense information environment, and DFARS flowdown verification for subcontractor relationships |
DFARS compliance documentation package including CSP authorization records, incident reporting runbook with 72-hour DC3 notification procedures and contact information, 90-day data preservation policy, media sanitization log templates, covered defense information environment boundary map |
| FedRAMP / GCC Requirement for CUI |
Any Greater Washington defense contractor using a cloud service provider to store, process, or transmit covered defense information. Commercial Microsoft 365, Google Workspace, Dropbox, and similar platforms do not qualify. GCC or GCC High is required for M365 environments handling CUI |
Current CSP authorization assessment, GCC or GCC High tenant provisioning and migration, conditional access policy configuration, DLP policy for CUI, MFA enforcement, audit logging, and documentation of the CSP’s FedRAMP authorization status for inclusion in the contractor’s DFARS compliance record |
GCC or GCC High tenant configuration with documented FedRAMP Moderate or High authorization, data migration completion report, access control and DLP policy documentation, DFARS CSP authorization record |
| Cyber Insurance Alignment |
Any Greater Washington defense contractor maintaining cyber insurance — insurers increasingly audit CMMC and NIST 800-171 controls at renewal and deny claims when documented controls were absent or misrepresented at policy issuance. CMMC compliance documentation directly supports the evidence trail insurers require |
Control mapping from CMMC and NIST 800-171 implementation to cyber insurance application requirements, evidence documentation aligned to carrier audit standards, MFA and backup verification documentation, and annual control review timed to policy renewal to ensure documentation currency |
Insurance-aligned control documentation package, MFA and backup verification records, annual compliance review report timed to policy renewal, evidence binder formatted for carrier audit review |