Skip to content
Oluma Cyber Security Awareness
Program · Defense Supply Chain

CMMC

The Pentagon’s answer to a leaky supply chain — no certificate, no contract. A tiered model that finally puts teeth behind protecting the defense industry’s sensitive data.

3 Levels32 CFR + DFARS800-171 basedPhase 1 live 2025
01 The Problem

Rules with no enforcement

For years, defense contractors were told to protect sensitive government information — Controlled Unclassified Information (CUI) — largely on the honor system. They self-attested compliance, and often that was the end of it. Meanwhile, adversaries were quietly bleeding the defense supply chain of designs, specs, and technical data.

The requirements existed; the verification didn’t. A contractor could promise it met the standard and never be checked — until a breach proved otherwise.

03 The Story Behind It

From a five-level plan to a leaner, real one

2020
CMMC 1.0
The original model proposed five maturity levels — ambitious, but widely seen as too complex and costly for small contractors.
2021
Streamlined to CMMC 2.0
A major overhaul cut five levels to three, reintroduced self-assessment for lower-risk work, and aligned directly with existing NIST standards.
2024
The program rule (32 CFR)
The Defense Department finalized the rule establishing the program’s structure, assessment process, and enforcement.
2025 · live
Into contracts
The acquisition rule (DFARS 252.204-7021) took effect and the phased rollout began on 10 November 2025, putting CMMC requirements into real solicitations — with later phases still being refined.
04 How It Works

Three levels, matched to the data’s sensitivity

The level you need depends on the information you handle. Handle basic contract info and you need Level 1; touch CUI and you’re at Level 2; work on the most critical programs and Level 3 applies.

L1 · FoundationalL2 · AdvancedL3 · Expert
Level 1 · FCI
Foundational
Basic safeguarding of Federal Contract Information — an annual self-assessment against a small set of practices.
Level 2 · CUI
Advanced
The 110 controls of NIST SP 800-171 — met by self-assessment or, for sensitive work, a third-party (C3PAO) certification.
Level 3 · High-priority CUI
Expert
Level 2 plus a subset of NIST SP 800-172, assessed by the government itself (DIBCAC) — for the most critical programs facing advanced threats.

Level 2 is where most of the industry lives — and it maps to the 14 control families of NIST 800-171:

AC Access Control
AT Awareness & Training
AU Audit & Accountability
CM Configuration Management
IA Identification & Auth
IR Incident Response
MA Maintenance
MP Media Protection
PS Personnel Security
PE Physical Protection
RA Risk Assessment
CA Security Assessment
SC System & Comms Protection
SI System & Info Integrity
CMMC vs. 800-171

NIST 800-171 is the control set. CMMC is the program that verifies and enforces it — adding assessment, certification, and the contract clause that makes it mandatory. It also flows down to subcontractors.

06 Who Uses It

The entire defense industrial base

🛡️
Prime contractors
Large defense firms that must certify — and ensure their whole supply chain does too.
🔧
Subcontractors & SMBs
The thousands of smaller suppliers to whom requirements flow down, often at Level 1 or 2.
🔎
C3PAOs & assessors
Certified third-party organizations that conduct the Level 2 assessments.

It sits on the NIST foundation and connects to the wider federal ecosystem.

built on NIST 800-171800-172relates to FISMAreciprocity with FedRAMP
07 Career Relevance

A whole industry racing to comply

With tens of thousands of contractors needing to certify, CMMC has created enormous, sustained demand for people who understand 800-171, scoping, and assessment. If you can guide a company to Level 2, you’re in a hot market.

CMMC consultant
Prep for certification
Scope CUI boundaries, close 800-171 gaps, and ready contractors for assessment.
Certified assessor
Conduct the audit
Work at a C3PAO to perform the Level 2 assessments the whole base now needs.
GRC analyst
Evidence & SPRS
Manage POA&Ms, maintain the System Security Plan, and keep scores current — the ongoing work of staying certified.

CMMC turns 800-171 knowledge into one of the most bankable skills in government-contract security.

09 Final Takeaway

CMMC is the moment defense cybersecurity got teeth — no certificate, no contract.

It takes the controls contractors were always supposed to follow and finally verifies them, scaled to the data at stake. For anyone in or around the defense industrial base, the message is simple: certification isn’t optional overhead — it’s the price of staying in the game.