FrameworkUnited States

CMMC 2.0

U.S. Department of Defense · Version 2.0 · Final rule effective December 16, 2024

DoD's mandatory cybersecurity certification program for defense contractors handling CUI or FCI.

Overview

Cybersecurity Maturity Model Certification 2.0 is the Department of Defense's program to verify that defense contractors have implemented cybersecurity requirements protecting Federal Contract Information and Controlled Unclassified Information. The final rule was published under 32 CFR Part 170 and became effective on December 16, 2024. CMMC 2.0 has three levels. Level 1 covers 17 basic cyber hygiene practices aligned with FAR 52.204-21 and requires annual self-assessment. Level 2 covers 110 practices from NIST Special Publication 800-171 Revision 2 and requires either triennial assessment by a Certified Third-Party Assessment Organization or annual self-assessment for non-prioritized acquisitions. Level 3 covers 110 Level 2 practices plus additional requirements from NIST 800-172 and requires government-led assessment.

CMMC requirements will appear in DoD contracts through DFARS clauses. Contractors must achieve and maintain the required CMMC level before contract award for affected contracts. The Supplier Performance Risk System records SPRS scores, which are computed by starting at 110 points and deducting the weight of each NIST 800-171 practice not fully implemented. Scores range from negative 203 to positive 110. C3PAOs, Certified Third-Party Assessment Organizations, must be accredited by the CMMC Accreditation Body and use Certified CMMC Assessors to conduct Level 2 assessments. Assessment results are submitted to the DoD's Enterprise Mission Assurance Support Service (eMASS).

Who Needs This

Prime contractors on DoD contracts that involve CUI or FCI

Subcontractors and suppliers in the defense industrial base who handle CUI

Defense contractors currently self-attesting under DFARS 252.204-7019 and 7020

Organizations pursuing DoD contracts that include CMMC clauses

Managed service providers whose infrastructure processes or hosts contractor CUI

Structure at a Glance

ACAccess Control22 controls

Limit system access to authorized users, processes acting on behalf of authorized users, and devices. Control the flow of CUI.

Create and retain audit logs, establish baseline configurations, and authenticate users, processes, and devices before granting access.

Establish incident handling capability, perform controlled maintenance, and protect system media containing CUI.

Limit physical access, screen personnel, periodically assess risk through vulnerability scanning, and evaluate security control effectiveness.

Monitor and protect communications, employ cryptography, identify and correct system flaws, and provide protection from malicious code.

AI Prompt Recipes

Copy these prompts directly into Claude or any capable model. Replace the bracketed placeholders with your organization-specific details.

SSP Narrative for a Practice

Use this to write System Security Plan implementation narratives for NIST 800-171 practices.

You are a CMMC Level 2 SSP author. Write an implementation narrative for NIST 800-171 Rev 2 practice [PRACTICE ID] — [PRACTICE NAME]. My organization is a [TYPE OF DEFENSE CONTRACTOR] with [NUMBER] employees. CUI environment: [DESCRIBE SYSTEMS AND DATA FLOWS]. Current implementation: [DESCRIBE HOW THIS PRACTICE IS IMPLEMENTED]. Write the narrative in present tense. Include: who is responsible, what specific tools or configurations implement this practice, how frequently it is reviewed or tested, and what evidence artifact demonstrates operational effectiveness. Reference any shared responsibilities with your managed service provider if applicable.

POA&M Entry Drafting

Use this to create a Plan of Action and Milestones entry for a gap identified during assessment.

I need to draft a Plan of Action and Milestones entry for a CMMC Level 2 gap. Practice not met: [PRACTICE ID] — [PRACTICE NAME]. SPRS point value: [WEIGHT]. Gap description: [DESCRIBE WHAT IS MISSING OR NOT FULLY IMPLEMENTED]. Root cause: [DESCRIBE]. Proposed remediation: [DESCRIBE PLANNED FIX]. Draft a complete POA&M entry including: weakness description, point of contact, resources required, scheduled completion date, milestones with dates, status, and whether this practice qualifies for POA&M under the CMMC assessment methodology or must be remediated before assessment.

CCA Interview Preparation

Use this to prepare staff for the interview portion of a C3PAO assessment.

You are a Certified CMMC Assessor preparing to interview the system owner for practice [PRACTICE ID] — [PRACTICE NAME]. The organization's SSP states: [PASTE THE SSP NARRATIVE]. Generate: (1) five interview questions a CCA would ask to verify this narrative is accurate and the control is operating as described, (2) the evidence artifacts the CCA will request during fieldwork, (3) the testing procedure the CCA would follow to independently verify the control, and (4) two common findings associated with this practice that the CCA would look for if the implementation is weaker than stated.

SPRS Pre-Assessment Walkthrough

Use this to calculate and analyze a SPRS score before a formal self-assessment or C3PAO engagement.

I am preparing a SPRS self-assessment for our organization. Based on the following practice implementation status: [LIST EACH OF THE 110 NIST 800-171 REV 2 PRACTICES WITH STATUS: MET, NOT MET, OR POA&M]. Calculate: (1) the SPRS score using the DoD assessment methodology point values, (2) the practices contributing the greatest point deductions, (3) practices that are not eligible for POA&M deferral and must be met before assessment, (4) a prioritized remediation roadmap based on point value and implementation effort, and (5) projected SPRS score after POA&M items are remediated.

Common Pitfalls

These are the mistakes practitioners see repeatedly in real assessments and implementation projects.

1

Confusing CMMC Level 2 self-assessment eligibility with C3PAO exemption. Only acquisitions specifically designated as non-critical by DoD allow self-assessment at Level 2. Most CUI contracts will require a C3PAO.

2

SSP narratives that describe intent rather than implementation. A narrative stating the organization plans to implement a control or will implement it using a specific tool does not satisfy the assessment objective. Present-tense operational implementation is required.

3

Claiming POA&M eligibility for practices that are not deferrable. Certain practices, including multi-factor authentication requirements under 3.5.3 and FIPS-validated cryptography under 3.13.11, cannot be placed on a POA&M. They must be fully implemented before a C3PAO will issue a passing assessment.

4

CUI scoping done too narrowly. Contractors who define their CUI boundary too tightly often discover during C3PAO scoping that systems they considered out of scope actually touch CUI. Rescoping during assessment is disruptive and costly.

5

Managed service provider inheritance not documented. If your MSP manages firewalls, identity, or logging, those controls may be inherited. But inheritance requires written documentation of exactly what the MSP implements, and the MSP must also be assessed or have their own CMMC compliance in place.

Cross-Framework Mapping

FedRAMP

CMMC Level 2 uses NIST 800-171, which is a subset of NIST 800-53. FedRAMP-authorized organizations have addressed a larger control set and can map inherited controls into their CMMC SSP.

ISO 27001

ISO 27001 Annex A addresses roughly 70% of NIST 800-171 practices. Certified organizations have a documentation foundation but must address CMMC-specific requirements around CUI handling explicitly.

View Detailed Mapping ↗

NIST CSF 2.0

NIST CSF 2.0 maps to NIST 800-171 through the informative references. The Protect function most closely corresponds to the CMMC Level 2 control families.

All content sourced from official issuing body documentation.

Official source ↗

Framework

CMMC 2.0