News

Compliance With CMMC 2.0: Top 10 Questions Answered

September 3, 2024

By Sajid Shafique

Sensitive data exfiltration from defense contractors is a major problem that threatens the national and economic security of the United States. Malicious cyber actors, often backed by Nation-state adversaries, continue to target organizations in the Defense Industrial Base (DIB) sector. To improve cybersecurity practices and protect sensitive information, the DoD has developed the Cybersecurity Maturity Model Certification (CMMC) 2.0 program as a crucial update for defense contractors. 

As organizations assess their compliance with CMMC 2.0, here are the top 10 questions they often ask:

1 - What is CMMC 2.0?

CMMC 2.0 is the updated version of the Cybersecurity Maturity Model Certification, developed by the U.S. Department of Defense (DoD), which aims to protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) within the DIB sector. It introduces a streamlined version of the original CMMC model and focuses on aligning it with widely accepted cybersecurity standards like NIST SP 800-171.

2 - How is CMMC 2.0 different from CMMC 1.0?

CMMC 2.0 simplifies the certification model by reducing the number of levels from five to three compliance levels, which are:

  • Level 1: Foundational
  • Level 2: Advanced (aligned with NIST SP 800-171)
  • Level 3: Expert (aligned with NIST SP 800-171 and a subset of NIST SP 800-172)

3 - Who needs to comply with CMMC 2.0?

Once CMMC 2.0 takes effect, all contractors and subcontractors within the DIB that handle FCI or CUI will have to comply with CMMC 2.0. Companies at various levels of the supply chain working on contracts involving the DoD will also need to be compliant. The DoD will specify the required CMMC level in the contracts.

4 - What are the key requirements for each CMMC 2.0 level?

  • Level 1 (Foundational): Focuses on basic cyber hygiene and safeguarding requirements for FCI, certified through annual self-assessment and annual affirmation.
  • Level 2 (Advanced): The requirements for CMMC Level 2 are tied to the 110 control areas defined in the Federal standard NIST SP 800-171. Level 2 requires triennial third-party assessments by an accredited C3PAO (Certified 3rd Party Organization). The DoD can designate that a Level 2 contractor will only be required to conduct an annual self-assessment for compliance; however, the majority will have to undergo a formal external audit. 
  • Level 3 (Expert): Builds on Level 2 and is aligned with NIST SP 800-172 to address advanced persistent threats. Will require triennial assessments conducted by government officials.

5 - How do organizations get certified under CMMC 2.0?

The certification requirements vary by CMMC Level and are defined below: 

  • Level 1 and Some Level 2 Contractors
    • Can perform annual self-assessments
    • No external audits required
  • Most Level 2 Contractors
    • Require formal assessments every three years
    • Assessments conducted by accredited Third-Party Assessment Organizations (C3PAOs)
  • Level 3 Contractors
    • Require assessments led by government officials

Once the assessment is complete, the results must be submitted to the CMMC Enterprise Mission Assurance Support Services (eMASS) database for evaluation.

6 - What is the timeline for CMMC 2.0 implementation?

The DoD will take a phased implementation approach for CMMC 2.0 over the next several years. Phased Rollout: The DoD plans to implement CMMC 2.0 in four phases over approximately 2 and a half years:

  • Phase 1 (Starting Q1 2025): CMMC Level 1 or Level 2 self-assessments become mandatory for contract awards. Some contracts may include third-party CMMC Level 2 assessment requirements.
  • Phase 2 (6 months after Phase 1): CMMC Level 2 certification assessments become mandatory for applicable contract awards. Some contracts may include CMMC Level 3 certification requirements.
  • Phase 3 (1 year after Phase 2): CMMC Level 2 certification requirements extend to existing contracts. CMMC Level 3 certification becomes mandatory for applicable new contract awards.
  • Phase 4 (1 year after Phase 3): Full implementation of CMMC 2.0, with all requirements included in applicable DoD solicitations and contracts, including option periods on existing contracts.

7 - What are the consequences of non-compliance with CMMC 2.0?

The consequences for non-compliance with CMMC can be severe for defense contractors, such as disqualification from bidding on DoD contracts. Additionally, the organization may suffer from security breaches, financial penalties, and reputational damage by failing to protect sensitive information.

8 - What is the relationship between NIST SP 800-171 and CMMC?

The CMMC and NIST standards are closely related, as meeting CMMC requirements involves adhering to NIST standards. DoD contractors will have to either conduct a self-assessment or undergo a third-party assessment to ensure that they comply with the applicable NIST standards specified by the DFARS clause 252.204-7012. Under CMMC 2.0, a Level 2 assessment will be based on the requirements of the NIST SP 800-171 standard. A Level 3 assessment will be conducted against the NIST SP 800-171 standard and a subset of NIST SP 800-172 requirements.

9 - How much will it cost to implement CMMC 2.0?

As part of the rulemaking process, the DoD will publish a detailed cost analysis associated with each level of CMMC 2.0. Compared to CMMC 1.0, costs associated with CMMC 2.0 are projected to be significantly lower due to the streamlined requirements at all levels, elimination of CMMC-unique practices and maturity processes, and the ability for companies to perform self-assessments at certain levels.

10 - How can organizations prepare for CMMC 2.0?

The DoD will require compliance with CMMC 2.0 as a condition of contract award for all contractors starting Q1 2025. Organizations are encouraged to start their compliance efforts as soon as possible to meet future contract requirements.

Preparation for compliance with CMMC 2.0 involves conducting a thorough gap analysis to identify areas needing improvement, implementing necessary cybersecurity practices, and ensuring ongoing compliance through regular self-assessments and training. 

Contractors are strongly advised to begin preparing for compliance immediately. Many prime contractors are already requiring subcontractors to meet CMMC compliance requirements ahead of the official implementation.

Partnering with a cybersecurity firm specializing in CMMC compliance such as Idenhaus can provide valuable guidance and support during the preparation and certification process.

More News

Subscribe To Our Newsletter

Please send me the following content from Idenhaus:*
Select as many boxes as you'd like!
Idenhaus needs the contact information you provide to us to contact you about our products and services. You may unsubscribe from these communications at any time. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, please review our Privacy Policy.