CMMC Level 1 (17 Practices / FAR 52.204-21) |
All DoD contractors and subcontractors handling Federal Contract Information — the baseline for any DoD contract flowing down FAR 52.204-21. Applies to every business in the Greater Baltimore defense supply chain regardless of size or tier. Annual self-attestation by a senior company official |
17-practice gap assessment mapped to FAR 52.204-21, control implementation for all unmet practices, annual self-attestation preparation for senior official signature, documentation package for prime contractor supply chain audits, False Claims Act risk counseling for self-attestation accuracy, annual review to maintain attestation currency |
Written gap report, implemented and verified controls across all 17 practices, self-attestation documentation package, evidence binder for prime audit requests, annual review schedule and update |
CMMC Level 2 — Self-Attestation (110 Practices / the NSA at Fort Meade 800-171) |
Non-critical DoD programs designated at Secretary of Defense discretion as eligible for contractor self-attestation rather than C3PAO assessment. Contractors must confirm their specific program falls into this subset before assuming self-attestation is permissible. Higher False Claims Act risk than Level 1 due to greater number of practices being attested |
All 110 Level 2 practices documented and implemented, SSP developed with practice-specific implementation descriptions, POA&M with remediation tracking for any gaps, evidence package for senior official self-attestation, annual review for attestation renewal, False Claims Act risk counseling on self-attestation accuracy across all 110 practices |
SSP covering all 110 the NSA at Fort Meade 800-171 practices, active POA&M with remediation milestones, evidence package supporting senior official self-attestation, annual compliance review report |
CMMC Level 2 — C3PAO Assessment (Required from Nov 10, 2026) |
Most CMMC Level 2 programs — contractors handling CUI on critical DoD programs who must undergo third-party assessment by an accredited C3PAO prior to contract award or renewal. Required from Phase 2 (November 10, 2026) for most CUI contracts across the Greater Baltimore defense industrial base, including most HII and NNS supply chain subcontracts |
Full 110-practice gap remediation across all 14 the NSA at Fort Meade 800-171 requirement families, SSP and POA&M development to C3PAO assessment standards, pre-assessment readiness review simulating C3PAO evidence requests and testing procedures, pre-assessment gap closure, evidence package organization for each practice, C3PAO selection guidance from the Cyber AB marketplace, and assessment coordination support |
C3PAO-ready evidence package with documentation for all 110 practices, remediated technical controls with configuration exports, SSP and POA&M in assessment-ready format, pre-assessment readiness report identifying any remaining risk items before the C3PAO engagement begins |
the NSA at Fort Meade SP 800-171 Rev 2 (14 Families, 110 Controls) |
All CMMC Level 2 contractors and all contractors under DFARS 252.204-7012 with active covered defense information obligations. The 110 practices of the NSA at Fort Meade 800-171 Rev 2 are the technical foundation of CMMC Level 2 and the “adequate security” standard required by DFARS 252.204-7012 |
Control implementation across all 14 requirement families: Access Control (AC), Awareness and Training (AT), Audit and Accountability (AU), Configuration Management (CM), Identification and Authentication (IA), Incident Response (IR), Maintenance (MA), Media Protection (MP), Personnel Security (PS), Physical Protection (PE), Risk Assessment (RA), Security Assessment (CA), System and Communications Protection (SC), System and Information Integrity (SI) |
the NSA at Fort Meade 800-171 SSP with implementation description and evidence for each of the 110 controls organized by requirement family, with practice-level compliance status and evidence documentation for each control |
DFARS 252.204-7012 (Already in Active Contracts) |
All DoD contractors with covered defense information — applies independently of CMMC and is already a clause in most active DoD contracts in the Greater Baltimore defense industrial base. Requires immediate compliance, not future planning tied to CMMC phasing |
Cloud service provider authorization verification and documentation (FedRAMP Moderate minimum; GCC or GCC High for M365 environments), 72-hour DoD DC3 incident reporting runbook with contact procedures, 90-day data preservation procedure and configuration, media sanitization procedure implementation, adequate security verification across covered defense information environment, DFARS flowdown verification for subcontractor relationships |
DFARS compliance documentation package including CSP authorization records, DC3 incident reporting runbook with 72-hour notification procedures, 90-day data preservation policy, media sanitization log templates, covered defense information environment boundary map |
M365 GCC and GCC High (FedRAMP Moderate / High for CUI) |
Any Greater Baltimore defense contractor using Microsoft 365 to store, process, or transmit covered defense information. Commercial M365 (Business Basic through E5) does not meet the FedRAMP Moderate authorization required by DFARS 252.204-7012. GCC is required for most CUI. GCC High is required for ITAR-controlled information and other sensitive CUI categories |
Current M365 tenant authorization assessment, GCC or GCC High tenant provisioning and full data migration, conditional access policy configuration, DLP policy implementation for CUI, MFA enforcement across all accounts, comprehensive audit logging, and documentation of the CSP’s FedRAMP authorization status for inclusion in the contractor’s DFARS compliance record and prime contractor audit responses |
GCC or GCC High tenant with documented FedRAMP Moderate or High authorization, data migration completion report, access control and DLP policy documentation, DFARS CSP authorization record, conditional access and MFA configuration documentation |
| Cyber Insurance Alignment |
Greater Baltimore defense contractors carrying cyber insurance — insurers increasingly audit CMMC and the NSA at Fort Meade 800-171 controls at policy renewal and deny claims when documented controls were absent or misrepresented at policy issuance. CMMC documentation directly supports the evidence trail insurers require |
Control mapping from CMMC and the NSA at Fort Meade 800-171 implementation to cyber insurance application requirements, evidence documentation aligned to carrier audit standards, MFA and backup verification documentation formatted for carrier review, annual control review timed to policy renewal to ensure documentation currency |
Insurance-aligned control documentation package, MFA and backup verification records, annual compliance review report timed to policy renewal, evidence binder formatted for carrier audit |