If your company holds a Department of Defense contract, CMMC is now a condition of award rather than a plan. The CMMC Program rule took effect on December 16, 2024 (89 FR 83092, published October 15, 2024), and the acquisition rule that puts the requirement into contracts took effect on November 10, 2025 (90 FR 43560, published September 10, 2025). This page covers which level applies to you, what each one requires, how SPRS scoring works, what a plan of action and milestones can and cannot cover, the phase-in timeline, and which parts of the work an MSP does versus which parts stay with you.

Which level do I need?

The level follows the information in the contract, not your company’s size.

  • Federal Contract Information only, and no CUI. Level 1. Annual self-assessment, submitted in the Supplier Performance Risk System (SPRS), with an annual affirmation.
  • Controlled Unclassified Information. Level 2. The contract states whether a self-assessment is acceptable or a certification assessment by an authorized third-party assessment organization (a C3PAO) is required.
  • CUI on a program the Department has flagged for the highest risk. Level 3, assessed by the Defense Contract Management Agency’s DIBCAC, after a Level 2 certification is already in place.

Most Los Angeles and Orange County subcontractors we work with land at Level 1 or Level 2 (self). The practical first step is not a gap assessment. It is reading your contract and your prime’s flow-down clauses to find out which category of information you actually receive, because a large share of companies preparing for Level 2 turn out never to have been given CUI at all.

What Level 1 Requires

Level 1 is the 15 basic safeguarding requirements in the Federal Acquisition Regulation clause at 48 CFR 52.204-21(b)(1)(i) through (xv), adopted directly by the CMMC model at 32 CFR 170.14(c)(2). They are the familiar basics: limit system access to authorized users, control who can execute what, sanitize media before disposal, limit physical access, monitor and control communications at system boundaries, use antivirus software and keep it current, and so on.

Two rules make Level 1 unforgiving in a way people do not expect. All 15 requirements must be assessed as either met or not met in their entirety, with no partial scores. And no plan of action or milestones are permitted at Level 1 at any time, so there is no mechanism to close a gap after the fact. You either meet all 15 on the day you self-assess, or you are not eligible for the award.

What Level 2 Requires

Level 2 is identical to NIST SP 800-171 Revision 2: 110 security requirements across 14 families, from access control and audit and accountability through to system and information integrity. The assessment objectives come from NIST SP 800-171A.

The mechanics:

  • Self-assessment path. Assess every requirement, submit the score to SPRS, affirm annually, and reassess every three years.
  • Certification path. A C3PAO performs the assessment, results are submitted through the CMMC instance of eMASS to SPRS, and the assessment must be repeated within three years.
  • Affirmation is separate from assessment. A senior official affirms continuing compliance annually in both paths, and the affirmation carries personal weight.
  • A System Security Plan is not optional and is not something you can defer, which we return to below.

SPRS Scoring, Plainly

The maximum score is the number of requirements at that level, so 110 for Level 2. Every requirement assessed as not met subtracts its point value from the maximum. Values are 1, 3, or 5 depending on the requirement, and because the subtraction is unbounded, the score can go negative. A score of 105 out of 110 is the kind of figure the rule itself uses as an example at 32 CFR 170.16.

Three points that catch people out:

  • A requirement is met only when all of its assessment objectives are satisfied by evidence, and the evidence must be final. Draft policies and working papers are not acceptable.
  • A requirement that genuinely does not apply is scored not applicable, which counts the same as met.
  • An enduring exception documented in the System Security Plan with its mitigations is assessed as met, and a temporary deficiency being tracked in an operational plan of action is also assessed as met. Documentation is what converts a known gap from a deduction into a defensible position.

What a POA&M can and cannot cover

A plan of action and milestones lets you achieve a conditional CMMC status while you close specific gaps. The rules are narrow and set forth in 32 CFR 170.21.

  • No POA&M at Level 1, ever.
  • At Level 2, you need at least 80 percent of the requirements met: the score divided by the total number of requirements must be 0.8 or higher.
  • Only 1-point requirements are eligible, with one exception. CUI encryption (SC.L2-3.13.11) may sit on a POA&M if encryption is in use but is not FIPS validated, which scores 3.
  • Six requirements are never POA&M eligible: external connections (AC.L2-3.1.20), control of public information (AC.L2-3.1.22), the System Security Plan (CA.L2-3.12.4), escorting visitors (PE.L2-3.10.3), physical access logs (PE.L2-3.10.4), and managing physical access (PE.L2-3.10.5).
  • 180 days to close out. A closeout assessment must confirm remediation within 180 days of the conditional status date, or the conditional status expires, and you become ineligible for further awards at that level until you achieve a new status.

The System Security Plan appearing on the ineligible list is the item worth planning around. You cannot promise to write it later. It has to exist and be accurate before the assessment.

The Phase-in Timeline

32 CFR 170.3(e) sets out four phases, each beginning one year after the previous one, starting from the effective date of the acquisition rule on November 10, 2025.

Phase Begins What DoD intends to include in solicitations
Phase 1 November 10, 2025 Level 1 (Self) or Level 2 (Self) as a condition of award on all applicable solicitations, with Level 2 (C3PAO) at the Department’s discretion.
Phase 2 November 10, 2026 Adds Level 2 (C3PAO) as a condition of award, with Level 3 (DIBCAC) at the Department’s discretion.
Phase 3 November 10, 2027 Level 2 (C3PAO) on all applicable solicitations, including option exercises, and Level 3 (DIBCAC) as a condition of award.
Phase 4 November 10, 2028 Full implementation across all applicable solicitations and contracts, including options on earlier awards.

The practical read for a subcontractor: if your work involves CUI and you have not started, the certification path has an assessor-scheduling queue ahead of it, and Phase 2 is the date that matters.

What an MSP does, and what stays with you

This split is the most common source of a stalled CMMC project, because both sides assume the other owns the middle column.

Work Owned by
Deciding whether you receive CUI and defining the assessment scope You, with your contracts officer and prime
Enclave design so CUI is contained rather than spread across the whole network Joint
Technical implementation: access control, MFA, FIPS-validated encryption, logging, boundary protection, endpoint security MSP
Continuous monitoring, patching, vulnerability management, and log retention MSP
The System Security Plan Joint, and you sign it
Policies, procedures, and evidence of practice You, with MSP input on the technical ones
Physical security, visitor escorting, and access logs You
Personnel screening and training records You
SPRS submission and the annual affirmation You, by a senior official
The assessment itself You (self) or an authorized C3PAO

Note the last two rows. No MSP can submit your affirmation or perform your certification assessment. We help you meet the requirements; we do not issue the certification itself. We are not an official certifying body or auditor, and we describe our role as support and readiness.

Our CMMC credentials

Be Structured’s founder and CTO, Chad Lauterbach, is a CMMC Registered Practitioner Advanced (RPA) with the Cyber AB, the accreditation body for the CMMC program. That credential covers CMMC consulting and readiness work. It is not an assessor authorization, and it does not make Be Structured a certifying body. Be Structured Technology Group is a CMMC Registered Provider Organization (RPO).

A Realistic Timeline

For a Los Angeles or Orange County manufacturer or engineering firm of 20 to 150 people moving toward Level 2:

  • Weeks 1 to 4. Scope determination and a gap assessment against all 110 requirements, producing an initial SPRS score.
  • Months 2 to 6. Technical remediation and enclave work. FIPS-validated encryption, multi-factor authentication everywhere, logging with retention, and boundary controls are the items with the longest tails.
  • Months 3 to 8. Documentation, running in parallel: the System Security Plan, policies, and the evidence that practices are actually performed. This is where most projects slip, because it cannot be bought.
  • Months 6 to 9. A readiness assessment against the NIST SP 800-171A objectives, then remediation of what it finds.
  • Months 9 onward. Self-assessment and SPRS submission, or C3PAO scheduling, which has its own queue.

Nine to twelve months is normal from a standing start. Companies that already run mature IT operations move faster; companies whose CUI lives on a general-purpose file server move slower, because scope reduction has to happen first.

Related reading

Background articles we have published on CMMC, kept for reference and superseded by this page, where they disagree with it:

Contact Be Structured to schedule a compliance assessment for your defense contract work.

➤ Schedule Your Free IT Assessment

Frequently Asked Questions About CMMC and NIST SP 800-171

Which CMMC level does my company need?

It follows the information in your contract. If you only receive Federal Contract Information and no Controlled Unclassified Information, you need Level 1: an annual self-assessment submitted to SPRS with an annual affirmation. If you receive CUI, you need Level 2, and the contract states whether a self-assessment is acceptable or a C3PAO certification assessment is required. Level 3 applies to the highest-priority programs and is assessed by DIBCAC. Read the contract and the flow-down clauses from your prime before commissioning any assessment, because many companies preparing for Level 2 turn out never to have received CUI.

What is the difference between CMMC Level 1 and Level 2?

Level 1 is the 15 basic safeguarding requirements from FAR clause 48 CFR 52.204-21, scored as met or not met in their entirety, with no plan of action and milestones permitted at any time. Level 2 is all 110 security requirements of NIST SP 800-171 Revision 2, scored numerically, reassessed every three years, and eligible for a limited plan of action and milestones. Level 1 is a shorter list with a stricter pass condition; Level 2 is a much longer list with a narrow allowance for closing gaps afterward.

How does SPRS scoring work?

The maximum score equals the number of requirements at that level, so 110 for Level 2. Each requirement assessed as not met subtracts its point value, which is 1, 3, or 5 depending on the requirement, and the subtraction is unbounded, so a score can be negative. A requirement counts as met only when every assessment objective is satisfied by final evidence, not drafts. A requirement that genuinely does not apply is scored not applicable and counts as met, and an enduring exception documented in the System Security Plan with its mitigations is also assessed as met.

Can I use a POA&M to close CMMC gaps after an assessment?

At Level 2 only, and within narrow limits set by 32 CFR 170.21. Your score divided by the total number of requirements must be at least 0.8; only 1-point requirements are eligible except for CUI encryption, where encryption is used but not FIPS validated, and six requirements are never eligible: external connections, control of public information, the System Security Plan, escorting visitors, physical access logs, and managing physical access. A closeout assessment must confirm remediation within 180 days, or the conditional status expires. No plan of action and milestones are permitted at Level 1.

When do CMMC requirements start appearing in contracts?

They already do. The acquisition rule took effect on November 10, 2025, starting Phase 1 and including Level 1 (Self) and Level 2 (Self) requirements in applicable solicitations as a condition of award. Phase 2 begins November 10, 2026, and adds Level 2 (C3PAO) as a condition of award. Phase 3 begins November 10, 2027, and Phase 4, full implementation, begins November 10, 2028. If your work involves CUI and you need a third-party assessment, Phase 2 is the date to plan against, because assessor scheduling is a queue.

How long does CMMC Level 2 preparation take?

Nine to twelve months is typical from a standing start for a 20 to 150-person company. Scoping and a gap assessment take about a month, technical remediation runs from month two to month six, and documentation runs in parallel from month three to month eight. The long poles are FIPS-validated encryption, multi-factor authentication across every access path, logging with retention, and the System Security Plan. Companies whose CUI is stored on a general-purpose file server take longer because reducing the assessment scope must come first.

Can an MSP make my company CMMC certified?

No, and any provider who says otherwise is describing something that does not exist. An MSP implements and operates the technical requirements, supports the documentation, and prepares you for assessment. Only an authorized C3PAO can perform a Level 2 certification assessment, only DIBCAC performs Level 3, and only a senior official at your company can submit the annual affirmation. We help you meet the requirements; we do not issue the certification itself, nor are we an official certifying body or auditor.

Is Be Structured a CMMC Registered Practitioner Organization?

No. Be Structured is not a Registered Practitioner Organization (RPO) and is not a C3PAO. Our founder and CTO, Chad Lauterbach, holds the individual Registered Practitioner Advanced (RPA) credential from the Cyber AB, which covers CMMC consulting and readiness advice. That is a personal credential rather than an organizational authorization. We implement and operate the technical requirements and prepare you for assessment; only an authorized C3PAO can perform a Level 2 certification assessment, only DIBCAC performs Level 3, and only a senior official at your company can submit the annual affirmation.

What is the relationship between CMMC and NIST SP 800-171?

CMMC Level 2 requirements are identical to the 110 security requirements in NIST SP 800-171 Revision 2, and the assessment objectives come from NIST SP 800-171A. What CMMC adds is verification. Contractors have been contractually obliged to implement 800-171 under DFARS 252.204-7012 for years on the honor system; CMMC makes the assessment, the SPRS submission, and the senior official affirmation a condition of contract award. The security work is the same work. The accountability is new.

Does CMMC apply to subcontractors in Los Angeles and Orange County?

Yes, when the requirement flows down. A prime contractor passes the CMMC requirement to subcontractors who will handle Federal Contract Information or Controlled Unclassified Information under the contract, and the level required of you depends on what you actually receive, rather than on the prime level. Southern California has a dense aerospace and defense supply chain, and most of the companies affected are small manufacturers, machine shops, and engineering firms rather than large primes.