← All ArticlesJune 18, 2026·5 min read

CMMC 2.0: What Every Defence Contractor Needs to Know

Published by the 0g0 research team

The Cybersecurity Maturity Model Certification (CMMC) programme represents the most significant change to defence contractor cybersecurity requirements in a generation. Moving from a self-attestation model — where contractors simply declared their compliance with NIST SP 800-171 — to a third-party assessment model for the most sensitive contracts, CMMC is reshaping the defence industrial base's approach to cybersecurity.

For the hundreds of thousands of companies in the defence supply chain, understanding CMMC is not optional. Non-compliance means inability to bid on contracts that require it, and that universe of contracts is expanding.

What CMMC Is and Why It Was Created

CMMC was created in response to documented, widespread failures to protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) within the defence industrial base. Adversaries — primarily China's People's Liberation Army-affiliated threat actors — systematically targeted defence contractors to steal intellectual property related to weapons systems, advanced technology, and military capabilities.

The self-attestation model failed because it created no meaningful accountability. Companies attested to compliance they had not actually achieved, and the Department of Defense had no way to verify the attestation. The resulting security gaps were extensively exploited.

CMMC replaces this model with independent assessment for contracts involving sensitive information, creating genuine accountability for security outcomes.

CMMC 2.0: The Three Levels

CMMC 2.0, the current version of the programme as of 2024, defines three certification levels:

Level 1 (Foundational): 17 security practices drawn from FAR clause 52.204-21, covering basic cyber hygiene. Self-attestation by company leadership is sufficient for Level 1. Required for contracts involving Federal Contract Information (FCI) but not CUI.

Level 2 (Advanced): 110 security practices aligned exactly with NIST SP 800-171. For most companies handling CUI, third-party assessment by a C3PAO (CMMC Third Party Assessment Organization) is required. A subset of Level 2 contracts may allow self-attestation for non-critical programmes.

Level 3 (Expert): Based on NIST SP 800-172, Level 3 adds enhanced requirements beyond 800-171 for the highest-sensitivity programmes. Assessment is conducted by government assessors from DCSA (Defense Counterintelligence and Security Agency).

What NIST SP 800-171 Actually Requires

Since Level 2 — which applies to most CUI-handling contractors — is built on NIST SP 800-171, understanding those requirements is essential. The 110 security requirements span 14 requirement families:

Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, System and Information Integrity.

For each requirement, the contractor must implement a specific control, document that implementation in a System Security Plan (SSP), and address any gaps in a Plan of Action and Milestones (POA&M).

Common areas where contractors fall short:

Multi-factor authentication: Required for all access to systems processing CUI, including remote access and access to privileged accounts. Many contractors still use single-factor authentication for some access scenarios.

System audit logging: Comprehensive logging of all access and actions on CUI systems, with logs retained for defined periods and regularly reviewed. Many contractors lack the logging infrastructure to meet this requirement.

Incident response: A documented, tested incident response capability including reporting to DoD within 72 hours of discovering a cyber incident affecting CUI. Many contractors have not tested their incident response plans.

Supply chain risk management: Flowing down security requirements to subcontractors who handle CUI. Many prime contractors have not assessed their subcontractor compliance.

The Assessment Process

For contracts requiring Level 2 third-party assessment, the process involves:

Pre-assessment preparation, typically taking 6-18 months for contractors without mature security programmes. This involves implementing all required practices, documenting them in an SSP, and conducting internal assessments against the 110 requirements.

CMMC Assessment by a C3PAO — an authorized third-party assessment organisation. The assessment includes document review, interview of personnel, and technical testing. The C3PAO submits findings to the CMMC Accreditation Body (CyberAB), which determines certification.

Certification is granted at the assessed level and is valid for three years, with annual affirmations of continued compliance.

The Cost and Timeline Reality

Companies that have not invested in cybersecurity will find CMMC compliance expensive and time-consuming. Industry estimates for bringing a mid-sized contractor to Level 2 compliance range from $100,000 to several million dollars, depending on current security maturity and IT complexity. The timeline for a company starting from scratch ranges from 12 to 24 months.

The most expensive approach is waiting until a contract requirement forces emergency compliance activity. The most cost-effective approach is beginning the compliance journey now, building security improvements systematically, and having a defensible compliance posture before CMMC requirements are imposed on specific contracts.

Common Implementation Mistakes

Treating CMMC as a documentation exercise: Many contractors make the mistake of writing policies and procedures without actually implementing the security practices they describe. Assessors will test actual implementation — reviewing configurations, observing processes, interviewing staff — not just documentation.

Scope creep: CMMC requirements apply to systems that process, store, or transmit CUI. Defining this scope accurately — neither too broad (imposing unnecessary costs) nor too narrow (leaving unprotected systems in scope) — is a critical early decision that has significant cost and complexity implications.

Neglecting subcontractors: Prime contractors are responsible for flowing CMMC requirements to subcontractors who handle CUI. Many primes have not assessed their subcontractor population or have not included appropriate requirements in subcontracts.

Underestimating the human element: Many CMMC requirements have a personnel component — training, role accountability, background screening. These are often neglected in favour of technical controls.

0g0 Aegis and CMMC

0g0 Aegis provides CMMC readiness assessment and implementation support for defence contractors at all levels. Our team includes professionals with direct experience in the defence acquisition environment who understand the intersection of CMMC requirements with the operational realities of defence contracting. We provide gap assessments against NIST SP 800-171, SSP development, remediation implementation, and pre-assessment readiness reviews designed to identify and address issues before the formal C3PAO assessment.

Need a product briefing?

Talk about the 0g0 Appliance for your environment — available now. Services are light support as the practice grows.

Request a Briefing

Free Assessment Tools

Test your own security posture with our free tools — no account required.

Explore free tools
Next step

Protect your organisation

Request a briefing on the 0g0 Appliance. Research is context — the product conversation is next.

Request a Briefing