The Department of Defense has been talking about the Cybersecurity Maturity Model Certification since 2019. But 2025 is different. With the final CMMC 2.0 rule now embedded in the DFARS clause 252.204-7021, prime contractors and subcontractors handling Controlled Unclassified Information are facing real contract consequences — not just a compliance checkbox.
What Changed With CMMC 2.0
The original framework had five maturity levels and required third-party certification for nearly every contractor. Version 2.0 simplified it to three levels, but the practical enforcement timeline is what catches most organizations off guard.
Level 1 covers Federal Contract Information and requires annual self-assessment against 17 NIST SP 800-171 practices. Doable for small businesses — but the self-assessment has to be conducted by a senior official and submitted to the Supplier Performance Risk System.
Level 2 is where the real work begins. If your contract involves CUI, you’re looking at 110 NIST SP 800-171 practices and — for most contracts — a triennial third-party assessment by a C3PAO (Certified Third-Party Assessment Organization). The wait list for qualified assessors is real and growing.
Level 3 applies to the most sensitive programs and involves additional NIST SP 800-172 practices, with government-led assessments. If you’re at this tier, you likely already know it.
Where Organizations Are Getting It Wrong
After working through dozens of assessments with defense contractors, we keep seeing the same failure patterns.
The “we’re mostly compliant” trap. Organizations that have been working with CUI for years assume their existing security controls are sufficient. NIST 800-171 has specific documentation and process requirements that go beyond having the right technology deployed. A firewall doesn’t check the box — a firewall with an access control policy, documented change management, and incident response procedures might.
Underestimating the System Security Plan. The SSP is not a form you fill out. It’s a living document that describes your entire environment, maps controls to practices, and identifies gaps. Getting this right takes months, not days.
Treating multi-factor authentication as an afterthought. Practice 3.5.3 (multi-factor authentication for local and network access by privileged users) sounds straightforward until you realize how many legacy systems, VPNs, and administrative interfaces in a typical defense contractor environment don’t support MFA without significant rearchitecting.
Ignoring the supply chain. If you’re a prime, you’re responsible for ensuring your subcontractors meet the applicable CMMC level for the CUI they handle. That means contractual flow-down and actual verification — not just asking for a certification letter.
The Assessment Timeline Is Tighter Than You Think
If you need a Level 2 C3PAO assessment and you don’t have one scheduled, you’re already behind. The backlog of qualified assessors means many contractors are looking at 6-12 month lead times just to get on the calendar. Add remediation time before assessment, and the math gets uncomfortable fast.
The phased implementation approach the DoD published is real — but it applies to when the requirement shows up in contracts, not when you need to start preparing. By the time you see a CMMC requirement in a solicitation, you need to already be ready.
A Practical Path Forward
For organizations that are early in the process, prioritize in this order:
- Gap assessment against NIST 800-171 — understand your actual posture before you start spending on remediation
- System Security Plan development — this drives everything else and is required regardless of your timeline
- POA&M management — document your gaps with realistic remediation timelines; assessors expect to see this
- High-priority practice remediation — focus first on the practices most commonly cited in DIBCAC assessments: access control, identification and authentication, and incident response
- Third-party assessment scheduling — get on a C3PAO’s calendar early; you can always reschedule, but you can’t manufacture appointment slots
CMMC 2.0 is not going away, and the DoD’s enforcement posture is tightening. The organizations that treat this as a compliance program rather than a security improvement will spend more time and money than those that do the foundational work right.
Marcman Solutions has supported government contractors through security assessments, SSP development, and NIST 800-171 compliance programs. If you’re evaluating your readiness, we’re happy to talk through what a practical path looks like for your organization.