If your company holds a Department of Defense contract, CMMC is now a condition of award rather than a plan. The CMMC Program rule took effect on December 16, 2024 (89 FR 83092, published October 15, 2024), and the acquisition rule that puts the requirement into contracts took effect on November 10, 2025 (90 FR 43560, published September 10, 2025). This page covers which level applies to you, what each one requires, how SPRS scoring works, what a plan of action and milestones can and cannot cover, the phase-in timeline, and which parts of the work an MSP does versus which parts stay with you.
Which level do I need?
The level follows the information in the contract, not your company’s size.
- Federal Contract Information only, and no CUI. Level 1. Annual self-assessment, submitted in the Supplier Performance Risk System (SPRS), with an annual affirmation.
- Controlled Unclassified Information. Level 2. The contract states whether a self-assessment is acceptable or a certification assessment by an authorized third-party assessment organization (a C3PAO) is required.
- CUI on a program the Department has flagged for the highest risk. Level 3, assessed by the Defense Contract Management Agency’s DIBCAC, after a Level 2 certification is already in place.
Most Los Angeles and Orange County subcontractors we work with land at Level 1 or Level 2 (self). The practical first step is not a gap assessment. It is reading your contract and your prime’s flow-down clauses to find out which category of information you actually receive, because a large share of companies preparing for Level 2 turn out never to have been given CUI at all.
What Level 1 Requires
Level 1 is the 15 basic safeguarding requirements in the Federal Acquisition Regulation clause at 48 CFR 52.204-21(b)(1)(i) through (xv), adopted directly by the CMMC model at 32 CFR 170.14(c)(2). They are the familiar basics: limit system access to authorized users, control who can execute what, sanitize media before disposal, limit physical access, monitor and control communications at system boundaries, use antivirus software and keep it current, and so on.
Two rules make Level 1 unforgiving in a way people do not expect. All 15 requirements must be assessed as either met or not met in their entirety, with no partial scores. And no plan of action or milestones are permitted at Level 1 at any time, so there is no mechanism to close a gap after the fact. You either meet all 15 on the day you self-assess, or you are not eligible for the award.
What Level 2 Requires
Level 2 is identical to NIST SP 800-171 Revision 2: 110 security requirements across 14 families, from access control and audit and accountability through to system and information integrity. The assessment objectives come from NIST SP 800-171A.
The mechanics:
- Self-assessment path. Assess every requirement, submit the score to SPRS, affirm annually, and reassess every three years.
- Certification path. A C3PAO performs the assessment, results are submitted through the CMMC instance of eMASS to SPRS, and the assessment must be repeated within three years.
- Affirmation is separate from assessment. A senior official affirms continuing compliance annually in both paths, and the affirmation carries personal weight.
- A System Security Plan is not optional and is not something you can defer, which we return to below.
SPRS Scoring, Plainly
The maximum score is the number of requirements at that level, so 110 for Level 2. Every requirement assessed as not met subtracts its point value from the maximum. Values are 1, 3, or 5 depending on the requirement, and because the subtraction is unbounded, the score can go negative. A score of 105 out of 110 is the kind of figure the rule itself uses as an example at 32 CFR 170.16.
Three points that catch people out:
- A requirement is met only when all of its assessment objectives are satisfied by evidence, and the evidence must be final. Draft policies and working papers are not acceptable.
- A requirement that genuinely does not apply is scored not applicable, which counts the same as met.
- An enduring exception documented in the System Security Plan with its mitigations is assessed as met, and a temporary deficiency being tracked in an operational plan of action is also assessed as met. Documentation is what converts a known gap from a deduction into a defensible position.
What a POA&M can and cannot cover
A plan of action and milestones lets you achieve a conditional CMMC status while you close specific gaps. The rules are narrow and set forth in 32 CFR 170.21.
- No POA&M at Level 1, ever.
- At Level 2, you need at least 80 percent of the requirements met: the score divided by the total number of requirements must be 0.8 or higher.
- Only 1-point requirements are eligible, with one exception. CUI encryption (SC.L2-3.13.11) may sit on a POA&M if encryption is in use but is not FIPS validated, which scores 3.
- Six requirements are never POA&M eligible: external connections (AC.L2-3.1.20), control of public information (AC.L2-3.1.22), the System Security Plan (CA.L2-3.12.4), escorting visitors (PE.L2-3.10.3), physical access logs (PE.L2-3.10.4), and managing physical access (PE.L2-3.10.5).
- 180 days to close out. A closeout assessment must confirm remediation within 180 days of the conditional status date, or the conditional status expires, and you become ineligible for further awards at that level until you achieve a new status.
The System Security Plan appearing on the ineligible list is the item worth planning around. You cannot promise to write it later. It has to exist and be accurate before the assessment.
The Phase-in Timeline
32 CFR 170.3(e) sets out four phases, each beginning one year after the previous one, starting from the effective date of the acquisition rule on November 10, 2025.
| Phase | Begins | What DoD intends to include in solicitations |
|---|---|---|
| Phase 1 | November 10, 2025 | Level 1 (Self) or Level 2 (Self) as a condition of award on all applicable solicitations, with Level 2 (C3PAO) at the Department’s discretion. |
| Phase 2 | November 10, 2026 | Adds Level 2 (C3PAO) as a condition of award, with Level 3 (DIBCAC) at the Department’s discretion. |
| Phase 3 | November 10, 2027 | Level 2 (C3PAO) on all applicable solicitations, including option exercises, and Level 3 (DIBCAC) as a condition of award. |
| Phase 4 | November 10, 2028 | Full implementation across all applicable solicitations and contracts, including options on earlier awards. |
The practical read for a subcontractor: if your work involves CUI and you have not started, the certification path has an assessor-scheduling queue ahead of it, and Phase 2 is the date that matters.
What an MSP does, and what stays with you
This split is the most common source of a stalled CMMC project, because both sides assume the other owns the middle column.
| Work | Owned by |
|---|---|
| Deciding whether you receive CUI and defining the assessment scope | You, with your contracts officer and prime |
| Enclave design so CUI is contained rather than spread across the whole network | Joint |
| Technical implementation: access control, MFA, FIPS-validated encryption, logging, boundary protection, endpoint security | MSP |
| Continuous monitoring, patching, vulnerability management, and log retention | MSP |
| The System Security Plan | Joint, and you sign it |
| Policies, procedures, and evidence of practice | You, with MSP input on the technical ones |
| Physical security, visitor escorting, and access logs | You |
| Personnel screening and training records | You |
| SPRS submission and the annual affirmation | You, by a senior official |
| The assessment itself | You (self) or an authorized C3PAO |
Note the last two rows. No MSP can submit your affirmation or perform your certification assessment. We help you meet the requirements; we do not issue the certification itself. We are not an official certifying body or auditor, and we describe our role as support and readiness.
Our CMMC credentials
Be Structured’s founder and CTO, Chad Lauterbach, is a CMMC Registered Practitioner Advanced (RPA) with the Cyber AB, the accreditation body for the CMMC program. That credential covers CMMC consulting and readiness work. It is not an assessor authorization, and it does not make Be Structured a certifying body. Be Structured Technology Group is a CMMC Registered Provider Organization (RPO).
A Realistic Timeline
For a Los Angeles or Orange County manufacturer or engineering firm of 20 to 150 people moving toward Level 2:
- Weeks 1 to 4. Scope determination and a gap assessment against all 110 requirements, producing an initial SPRS score.
- Months 2 to 6. Technical remediation and enclave work. FIPS-validated encryption, multi-factor authentication everywhere, logging with retention, and boundary controls are the items with the longest tails.
- Months 3 to 8. Documentation, running in parallel: the System Security Plan, policies, and the evidence that practices are actually performed. This is where most projects slip, because it cannot be bought.
- Months 6 to 9. A readiness assessment against the NIST SP 800-171A objectives, then remediation of what it finds.
- Months 9 onward. Self-assessment and SPRS submission, or C3PAO scheduling, which has its own queue.
Nine to twelve months is normal from a standing start. Companies that already run mature IT operations move faster; companies whose CUI lives on a general-purpose file server move slower, because scope reduction has to happen first.
Related reading
Background articles we have published on CMMC, kept for reference and superseded by this page, where they disagree with it:
- What is CMMC or Cybersecurity Maturity Model Certification?
- Understanding CMMC Levels and Domains
- How Companies Can Prepare for the CMMC Assessment Process
- Your Guide to CMMC
- CMMC: What Are the Benefits?
- Who Needs a Cybersecurity Maturity Model Certification?
- What Business Owners Need to Know About CMMC Compliance
- CMMC Compliance and Cybersecurity
Contact Be Structured to schedule a compliance assessment for your defense contract work.
➤ Schedule Your Free IT Assessment
