O Oluma Cyber Security Framework Files · No. 13 Program · Defense Supply Chain CMMC The Pentagon’s answer to a leaky supply chain — no certificate, no contract. A tiered model that finally puts teeth behind protecting the defense industry’s sensitive data. 3 Levels32 CFR + DFARS800-171 basedPhase 1 live 2025 CMMC L1L2L3 How we’ll read this 01 The Problem02 Why It Exists03 The Story04 How It Works05 Example06 Who Uses It07 Career08 Strengths & Challenges09 Takeaway 01 The Problem Rules with no enforcement For years, defense contractors were told to protect sensitive government information — Controlled Unclassified Information (CUI) — largely on the honor system. They self-attested compliance, and often that was the end of it. Meanwhile, adversaries were quietly bleeding the defense supply chain of designs, specs, and technical data. The requirements existed; the verification didn’t. A contractor could promise it met the standard and never be checked — until a breach proved otherwise. 02 Why It Was Created Trust, but verify — before the contract The Cybersecurity Maturity Model Certification exists to replace self-attestation with verification. The Defense Department made a certified level of cybersecurity a condition of doing business — you must prove it to win or keep a contract. The core ideaTake the security controls contractors were already supposed to follow, and require independent proof scaled to how sensitive the data is. No certificate at the right level, no award. It turns cybersecurity from a paperwork promise into a gate on federal revenue — the most powerful incentive there is. 03 The Story Behind It From a five-level plan to a leaner, real one 2020CMMC 1.0The original model proposed five maturity levels — ambitious, but widely seen as too complex and costly for small contractors. 2021Streamlined to CMMC 2.0A major overhaul cut five levels to three, reintroduced self-assessment for lower-risk work, and aligned directly with existing NIST standards. 2024The program rule (32 CFR)The Defense Department finalized the rule establishing the program’s structure, assessment process, and enforcement. 2025 · liveInto contractsThe acquisition rule (DFARS 252.204-7021) took effect and the phased rollout began on 10 November 2025, putting CMMC requirements into real solicitations — with later phases still being refined. 04 How It Works Three levels, matched to the data’s sensitivity The level you need depends on the information you handle. Handle basic contract info and you need Level 1; touch CUI and you’re at Level 2; work on the most critical programs and Level 3 applies. L1 · FoundationalL2 · AdvancedL3 · Expert Level 1 · FCIFoundationalBasic safeguarding of Federal Contract Information — an annual self-assessment against a small set of practices. Level 2 · CUIAdvancedThe 110 controls of NIST SP 800-171 — met by self-assessment or, for sensitive work, a third-party (C3PAO) certification. Level 3 · High-priority CUIExpertLevel 2 plus a subset of NIST SP 800-172, assessed by the government itself (DIBCAC) — for the most critical programs facing advanced threats. Level 2 is where most of the industry lives — and it maps to the 14 control families of NIST 800-171: AC Access Control AT Awareness & Training AU Audit & Accountability CM Configuration Management IA Identification & Auth IR Incident Response MA Maintenance MP Media Protection PS Personnel Security PE Physical Protection RA Risk Assessment CA Security Assessment SC System & Comms Protection SI System & Info Integrity CMMC vs. 800-171NIST 800-171 is the control set. CMMC is the program that verifies and enforces it — adding assessment, certification, and the contract clause that makes it mandatory. It also flows down to subcontractors. 05 Real-World Example A machine shop keeps its DoD work A small precision machine shop makes parts from CUI drawings for a prime contractor. Under the new rules, it can’t stay on the contract without the right CMMC level — so it treats certification as keeping the lights on. Their road to Level 2Certify, or lose the contract Confirm it handles CUI → Level 2 applies Implement the 110 NIST 800-171 controls Score itself and post the result in SPRS Bring in a C3PAO for third-party certification Flow the right requirements down to its own suppliers The certificate isn’t bureaucracy — it’s the difference between winning the next award and being locked out of defense work entirely. 06 Who Uses It The entire defense industrial base 🛡️Prime contractorsLarge defense firms that must certify — and ensure their whole supply chain does too. 🔧Subcontractors & SMBsThe thousands of smaller suppliers to whom requirements flow down, often at Level 1 or 2. 🔎C3PAOs & assessorsCertified third-party organizations that conduct the Level 2 assessments. It sits on the NIST foundation and connects to the wider federal ecosystem. built on NIST 800-171800-172relates to FISMAreciprocity with FedRAMP 07 Career Relevance A whole industry racing to comply With tens of thousands of contractors needing to certify, CMMC has created enormous, sustained demand for people who understand 800-171, scoping, and assessment. If you can guide a company to Level 2, you’re in a hot market. CMMC consultantPrep for certificationScope CUI boundaries, close 800-171 gaps, and ready contractors for assessment. Certified assessorConduct the auditWork at a C3PAO to perform the Level 2 assessments the whole base now needs. GRC analystEvidence & SPRSManage POA&Ms, maintain the System Security Plan, and keep scores current — the ongoing work of staying certified. CMMC turns 800-171 knowledge into one of the most bankable skills in government-contract security. 08 Strengths & Challenges Honest trade-offs ✦ Strengths Real enforcement — tied directly to contract awards Tiered to the sensitivity of the data Built on the established NIST 800-171 baseline Independent verification, not self-attestation Flows protection down the whole supply chain ⚠ Challenges Costly and heavy for small contractors A long, phased rollout with shifting timelines Scoping CUI boundaries is genuinely hard Defense-sector-specific Certification must be re-earned and maintained 09 Final Takeaway CMMC is the moment defense cybersecurity got teeth — no certificate, no contract.It takes the controls contractors were always supposed to follow and finally verifies them, scaled to the data at stake. For anyone in or around the defense industrial base, the message is simple: certification isn’t optional overhead — it’s the price of staying in the game.