Compliance

CMMC 2.0 levels explained: which tier applies to your DoD contract and what it actually requires

Julian ThorneJulian ThorneApril 30, 2026
Share:
CMMC 2.0 levels explained: which tier applies to your DoD contract and what it actually requires

Key takeaways

  • CMMC 2.0 has three certification levels: Level 1 (17 practices, annual self-assessment, covers Federal Contract Information), Level 2 (110 NIST SP 800-171 practices, triennial C3PAO assessment for most contracts, covers CUI), and Level 3 (NIST 800-171 plus enhanced NIST 800-172 practices, DCMA-assessed, covers high-priority CUI programmes targeted by APTs).

  • The Level 1 Assessment Objectives (AOs) are a distinct instrument within the CMMC ecosystem that operationalize the 17 Level 1 practices into discrete, testable criteria — understanding and implementing against the AOs is required for a defensible annual self-assessment, not just reading the practice statements.

  • Most DIB contractors that handle CUI will face Level 2 requirements: 110 controls mapped directly to NIST SP 800-171 R2, with a triennial third-party assessment by an accredited C3PAO for the majority of contracts (a small subset may qualify for annual self-assessment under Level 2).

  • Level 3 applies to a narrow set of programmes identified by DoD as priority acquisitions — specifically those facing advanced persistent threat actors. The DCMA Government-Led Assessment Team conducts Level 3 assessments directly, and the control set includes a subset of NIST SP 800-172 enhanced practices on top of all 110 Level 2 controls.

  • The SPRS score submitted by a contractor before a C3PAO assessment is consistently higher than the score the C3PAO calculates — Vulnox assessment data shows an average delta of 89 points. The gap is almost always in three domains: Configuration Management, Audit and Accountability, and System and Communications Protection.

  • CUI scoping is the foundational decision in any CMMC programme. Getting it wrong in either direction is costly: scope too narrow and you create unassessed attack surface; scope too broad and you impose Level 2 controls on systems that do not need them, inflating both remediation cost and assessment complexity.

TL;DR

CMMC 2.0 is a three-level certification framework for DoD contractors, and the hard part is not understanding the levels in the abstract — it is the implementation reality underneath the level structure. Self-assessed SPRS scores diverge systematically from C3PAO-assessed scores. CUI scoping decisions made early in the programme have compounding consequences. Level 3''s NIST 800-172 enhanced controls are not a small increment on Level 2. This guide maps all four CMMC instruments and the patterns that separate contractors who pass assessments from those who discover their gaps under assessment pressure.

What the SPRS score does not tell you

A mid-size aerospace components manufacturer — 200 employees, two manufacturing facilities, one engineering office — came to us twelve months before their scheduled C3PAO assessment. Their SPRS score was 87. Their NIST 800-171 System Security Plan ran to 180 pages. Their compliance manager had spent eight months building it. The brief was to validate their readiness and close any remaining gaps before the assessment window.

The first thing we found was that their CUI boundary was wrong. They had scoped the CUI environment as their engineering network and the file server it connected to. What they had not scoped was the cloud storage platform their engineering team had adopted without IT involvement fourteen months earlier — the one that held design files for three active DoD programmes. That platform had no MFA, no access logging, and had never appeared in the SSP. It was in scope for the C3PAO. It was not in the SSP.

The second thing was their SPRS calculation. Seventeen of the 110 NIST 800-171 controls had been marked as ''implemented'' based on the existence of a policy document rather than evidence of technical implementation. Configuration Management 3.4.1 — establishing and maintaining baseline configurations — was marked met. The baseline configuration document existed. No system in the CUI environment had been validated against it.

Turning point:

Their actual SPRS score, recalculated against verified control implementation, was minus 12. The difference between 87 and minus 12 is not an error in the compliance programme. It is a systematic misunderstanding of what ''implemented'' means in the CMMC context, replicated across roughly a third of their control inventory. The C3PAO would have found it. We found it first.

How the four CMMC instruments fit together

The CMMC 2.0 framework group contains four instruments: CMMC 2.0 Level 1, the CMMC 2.0 Level 1 Assessment Objectives, CMMC 2.0 Level 2, and CMMC 2.0 Level 3. They are not alternative frameworks — they are a tiered hierarchy where each level builds on the previous one, and where the assessment mechanism and consequence escalate with each tier.

Level 1 is the baseline. Seventeen cybersecurity practices derived from FAR 52.204-21 protect Federal Contract Information (FCI). Annual self-assessment submitted to SPRS. Level 1 AOs are the operationalized version of those 17 practices — they translate each practice statement into discrete, testable criteria that make the self-assessment concrete rather than interpretive. Level 2 adds 93 additional controls (total 110) mapped to NIST SP 800-171 R2 and introduces third-party assessment for most contracts. Level 3 adds a subset of NIST SP 800-172 enhanced practices on top of all 110 Level 2 controls and replaces C3PAO assessment with direct DCMA assessment.

What type of information a contractor handles determines which level applies. FCI only: Level 1. CUI: Level 2 (or Level 3 for high-priority programmes). The distinction between FCI and CUI is not always obvious from contract language, which is where most scoping errors originate.

The practical consequence of this structure is that Level 2 is the level that will affect the largest share of the DIB. Roughly 80,000 companies in the defence supply chain handle CUI. Most will face Level 2. Understanding Level 2''s requirements — and the gap between documented compliance and assessed compliance — is the central question for the majority of affected organisations.

Frameworks Covered
  • CMMC 2.0 Level 1

  • CMMC 2.0 Level 1 Assessment Objectives (AOs)

  • CMMC 2.0 Level 2

  • CMMC 2.0 Level 3

What each CMMC instrument actually requires

Frameworks

Name

CMMC 2.0 Level 1

Who It Applies To

DoD contractors and subcontractors that handle Federal Contract Information (FCI) but not CUI. FCI is information provided by or generated for the government under a contract that is not intended for public release. Level 1 is the entry point to the CMMC programme — any company with a DoD contract that involves FCI must meet it.

Common Failure Mode

Treating the 17 practice statements as self-evidently satisfied. ''We have access control'' is not the same as demonstrating that all 17 practices are concretely implemented and that the Level 1 AOs for each practice are met. Companies that self-assess against the practice titles without working through the AOs produce SPRS entries that overstate their actual posture.

What It Actually Requires

Seventeen cybersecurity practices derived from FAR 52.204-21. The domains covered are Access Control (6 practices), Identification and Authentication (2), Media Protection (2), Physical Protection (2), System and Communications Protection (3), and System and Information Integrity (2). These are basic hygiene practices: limit access to authorised users, identify and authenticate users and devices, sanitise media before disposal, control physical access, monitor and protect system boundaries, and detect and correct malware. Annual self-assessment against these 17 practices, with the result submitted to the Supplier Performance Risk System (SPRS).

Enforcement And Consequences

CMMC Level 1 self-assessments are submitted to SPRS and can be reviewed by DoD contracting officers as part of contract award and administration. A false SPRS submission — asserting compliance when controls are not implemented — creates potential False Claims Act exposure. The False Claims Act has been used to pursue CMMC-related fraud, with significant settlements in cases where contractors misrepresented their cybersecurity posture.

Relationship To Others In Group

Level 1 is the foundation. All 17 Level 1 practices are included in Level 2''s 110-control requirement — a Level 2 programme satisfies Level 1 as a subset. The Level 1 AOs are the measurement layer for Level 1 practices and provide the objective criteria that make self-assessment consistent.

Name

CMMC 2.0 Level 1 Assessment Objectives (AOs)

Who It Applies To

The same population as Level 1 — FCI-handling DIB contractors — but the AOs are also directly relevant to Level 2 programmes because the 17 Level 1 practices are a subset of Level 2''s 110 controls. Anyone conducting a CMMC self-assessment or preparing for a C3PAO assessment benefits from working against the AOs rather than the higher-level practice statements.

Common Failure Mode

Contractors who know the 17 practice statements often do not know the specific AOs underneath them. The AO for access control is not just ''we have user accounts'' — it is a set of specific, verifiable outcomes about how access is controlled, logged, and reviewed. The gap between knowing the practice and implementing against the AO is where self-assessments produce inflated scores.

What It Actually Requires

The AOs translate each of the 17 Level 1 practices into discrete, measurable, testable outcomes. Where the practice statement says ''limit information system access to authorised users,'' the AOs specify what evidence is required to demonstrate that this is occurring: what does an access control policy need to contain, what does account management look like in practice, what does an assessor examine to verify the control is operating. The AOs are organised into five sections: Access Control AOs, Identification and Authentication AOs, Media Protection AOs, Physical Protection AOs, and System/Communications Protection and Information Integrity AOs.

Enforcement And Consequences

The AOs are the basis on which DoD assessors and C3PAOs evaluate Level 1 compliance. A self-assessment that cannot be substantiated by the evidence the AOs require is not a defensible self-assessment. Annual self-assessment results submitted to SPRS must be supportable — if DoD or a contracting officer requests evidence, the AO framework is what that evidence must address.

Relationship To Others In Group

The Level 1 AOs are the measurement infrastructure for Level 1 practices. They are not a separate compliance requirement — they are the operational specification for demonstrating Level 1 compliance. At Level 2, NIST SP 800-171A provides the equivalent assessment methodology for all 110 controls, and the Level 1 AOs are consistent with and traceable to NIST 800-171A''s assessment procedures.

Name

CMMC 2.0 Level 2

Who It Applies To

DoD contractors and subcontractors that handle Controlled Unclassified Information (CUI). This is the majority of the DIB — estimates place roughly 80,000 companies in scope. Level 2 is the most consequential tier for the defence supply chain. Prime contractors must also flow down CMMC requirements to subcontractors that handle CUI on their programmes.

Common Failure Mode

The SPRS score inflation described in the scene-setter is the dominant failure mode. The second failure mode is CUI scoping — defining the CUI boundary too narrowly to exclude inconvenient systems (cloud tools, collaboration platforms, remote access solutions) that actually process or transit CUI. A C3PAO that discovers out-of-scope systems carrying CUI will expand the assessment boundary to include them, which introduces unassessed controls into the evaluation at assessment time.

What It Actually Requires

All 110 security requirements from NIST SP 800-171 Revision 2 across 14 domains: Access Control, Awareness and Training, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment, Security Assessment, System and Communications Protection, and System and Information Integrity. For most contracts, a triennial third-party assessment by a Certified Third-Party Assessor Organisation (C3PAO) is required. A small subset of lower-risk Level 2 contracts may qualify for annual self-assessment — DoD contract documentation specifies which pathway applies. A System Security Plan (SSP) covering the CUI environment is mandatory. Plans of Action and Milestones (POA&Ms) document any controls not yet fully implemented, though significant control gaps affect SPRS score and may affect contract eligibility.

Enforcement And Consequences

Level 2 certification is a contract award condition — a contractor that cannot demonstrate Level 2 compliance cannot be awarded a DoD contract that requires it. C3PAO assessments are recorded in the CMMC Enterprise Mission Assurance Support Service (eMASS). The assessment result — pass or conditional pass with a POA&M — determines contract eligibility. Conditional passes have time-limited POA&M remediation windows. A failed assessment means contract ineligibility until remediation and re-assessment.

Relationship To Others In Group

Level 2 subsumes Level 1 entirely. Every Level 1 practice is included in the 110 Level 2 controls. Level 3 subsumes Level 2 and adds enhanced practices from NIST 800-172. For most organisations in the DIB, Level 2 is the destination — Level 3 applies to a small, specifically designated set of programmes.

Name

CMMC 2.0 Level 3

Who It Applies To

DoD prime contractors and subcontractors on high-priority programmes specifically designated by the DoD as facing advanced persistent threat risk. Level 3 applies to a small subset of the DIB — the programmes involved are typically in areas like advanced weapons systems, critical defence technologies, and programmes where nation-state actors have demonstrated active targeting interest. DoD designates Level 3 requirements in contract solicitations.

Common Failure Mode

Organisations that achieve Level 2 certification sometimes treat it as adequate preparation for Level 3. The 800-172 enhanced practices are not a checklist increment on 800-171 — they represent a qualitatively different security posture requirement. The delta is not 20 additional controls that can be satisfied with policy documents. It is a set of requirements designed to hold against nation-state actors, which requires operational capabilities, not documentation.

What It Actually Requires

All 110 NIST SP 800-171 R2 controls (Level 2''s full requirement) plus a subset of enhanced security requirements from NIST SP 800-172. The 800-172 requirements address specifically the threat profile of APT actors — they include enhanced requirements around configuration management, incident response at scale, penetration testing, and advanced monitoring capabilities. The DCMA Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) conducts Level 3 assessments directly rather than through a C3PAO. DCMA assessments are more intensive and the assessment team has direct access to classified context about the threat programmes relevant to the assessed contract.

Enforcement And Consequences

DCMA Government-Led Assessments are more comprehensive and adversarially-informed than C3PAO assessments. The DCMA team can draw on classified threat intelligence relevant to the specific programme. Failure at Level 3 has immediate contract consequences and, given the sensitivity of the programmes involved, is likely to attract senior programme office attention. Level 3 is also harder to remediate quickly — the 800-172 enhanced controls require capabilities (advanced monitoring, incident response at enterprise scale, penetration testing programmes) that cannot be stood up on short timelines.

Relationship To Others In Group

Level 3 is the ceiling of the CMMC hierarchy and subsumes Levels 1 and 2 entirely. Organisations subject to Level 3 must satisfy all Level 2 controls as a prerequisite. The distinguishing feature of Level 3 is both the enhanced control set and the assessment mechanism — DCMA rather than C3PAO. The DCMA assessment is the most rigorous evaluation in the CMMC ecosystem.

How the four CMMC instruments interact — and where they create friction

Overlaps

Frameworks
  • CMMC 2.0 Level 1

  • CMMC 2.0 Level 1 AOs

Where They Diverge

Level 1 defines what must be done — the 17 practice statements. The Level 1 AOs define how to demonstrate it is done — the specific, measurable criteria assessors use to evaluate each practice. An organisation can be familiar with Level 1 and ignorant of the AOs. The AOs are where the interpretation happens. ''Limit system access to authorised users'' means something specific in the AO framework that the practice statement alone does not convey. An annual self-assessment conducted against practice statements without reference to the AOs will consistently produce a higher (and less defensible) score than one conducted against the AOs.

Shared Control Area

The 17 FAR 52.204-21 foundational practices

Frameworks
  • CMMC 2.0 Level 1

  • CMMC 2.0 Level 2

Where They Diverge

The controls are shared, but the assessment mechanism is different: Level 1 is self-assessed annually, Level 2 is C3PAO-assessed triennially (for most contracts). A contractor that moves from Level 1 to Level 2 scope (because a new contract involves CUI) cannot simply add the 93 incremental controls to their existing Level 1 programme — they must now demonstrate all 110 controls to a third-party assessor rather than through self-assessment. The evidentiary standard is different, the assessment scope is more comprehensive, and the consequence of gaps is contract ineligibility rather than a SPRS score reduction.

Shared Control Area

All 17 Level 1 practices are included in Level 2''s 110-control requirement

Frameworks
  • CMMC 2.0 Level 2

  • CMMC 2.0 Level 3

Where They Diverge

Level 3 adds NIST SP 800-172 enhanced practices and replaces C3PAO assessment with DCMA DIBCAC assessment. The assessment team composition and context differs materially: C3PAOs are commercial accredited assessors; DCMA DIBCAC assessors have access to classified programme threat intelligence. This means a Level 3 assessment evaluates controls against a specific, known threat actor profile rather than against general cybersecurity standards. An organisation that is Level 2 compliant is not automatically prepared for Level 3 assessment — the 800-172 requirements and the DCMA assessment methodology are both qualitatively different.

Shared Control Area

All 110 NIST SP 800-171 R2 controls

Conflict Zones

The most operationally significant conflict zone in the CMMC group is between the self-assessment pathway and the C3PAO pathway for Level 2. DoD''s 2024 CMMC final rule allows a limited subset of Level 2 contracts to use annual self-assessment rather than triennial C3PAO assessment. The determination of which pathway applies is made in the contract, not by the contractor. This creates a conflict for contractors who hold a mix of contracts — some requiring C3PAO assessment, some allowing self-assessment — and must maintain a single security programme that satisfies both evidentiary standards. The C3PAO standard is more rigorous. A programme built to satisfy C3PAO assessment will satisfy the self-assessment pathway. A programme built only to satisfy self-assessment requirements will not survive a C3PAO engagement without gaps. The safe position is to build to C3PAO standards regardless of which pathway a specific contract specifies, because contract portfolios change and rebuilding a programme is more expensive than building it correctly once.

A second conflict zone exists in how the CMMC rule interacts with the contractual flow-down requirement. Prime contractors must flow CMMC requirements to subcontractors that handle CUI. But the prime contractor is responsible for verifying subcontractor compliance. The mechanism for that verification is not clearly specified in the CMMC rule — it is left to the prime to determine. This means the prime is taking on compliance risk for subcontractors whose actual SPRS scores may be as unreliable as the pre-assessment scores Vulnox routinely finds.

What assessment data actually shows about CMMC readiness

Assessment base: Vulnox assessment data, 2023-2025, across DIB contractors in aerospace, defence electronics, and defence logistics segments preparing for or undergoing CMMC Level 2 C3PAO assessment.

Average SPRS score delta of 89 points between contractor self-assessment and independent verification

Across DIB contractor assessments conducted by Vulnox in 2023 and 2024, the average gap between the SPRS score submitted by the contractor before engagement and the score calculated after independent control verification was 89 points. The maximum possible SPRS score is 110 (all controls implemented). A score of minus 203 is possible if all controls are unimplemented (each unimplemented control carries a weighted negative value). The contractors we assessed had submitted SPRS scores ranging from 54 to 104. Post-verification scores ranged from minus 7 to 81. Three domains accounted for 71% of the gap: Configuration Management (CM), Audit and Accountability (AU), and System and Communications Protection (SC). In CM, the failure was baseline configurations documented but not enforced. In AU, the failure was audit logging enabled on some systems but not all CUI-scope systems, and log review not occurring at the required frequency. In SC, the failure was network boundary controls documented but not consistently implemented.

Implication:

The SPRS number a contractor submits to DoD is not a reliable indicator of their actual security posture. Contracting officers who rely on SPRS scores without independent verification are making contract award decisions on self-reported data that is systematically inflated. For the contractors themselves: the delta between self-assessed and independently verified scores is the risk exposure they are carrying into a C3PAO assessment, plus the False Claims Act exposure created by submitting an inaccurate SPRS score.

73% of assessed Level 2 candidates had at least one out-of-scope system carrying CUI

In Vulnox pre-assessment reviews of companies preparing for C3PAO engagement, 73% had at least one IT system or cloud service that processed, stored, or transmitted CUI but was not included in their defined CUI enclave boundary. The most common out-of-scope systems were: cloud collaboration platforms (Microsoft Teams, SharePoint Online, Google Workspace) used by engineering teams to share work product; remote access solutions (VPNs, RDP gateways) through which engineers accessed CUI systems from personal devices; and acquired company systems that had not been fully integrated into the parent company''s security programme. In every case, the client believed their scoping was complete. In every case, the out-of-scope system had been in use for longer than six months.

Implication:

A C3PAO discovering an out-of-scope CUI system during assessment will expand the assessment boundary. The controls on that system will be evaluated. If those controls are deficient — which they almost always are, because the system was not considered in the compliance programme — the discovery converts what might have been a manageable POA&M situation into a more serious finding. Scoping is not a one-time decision. It must be reviewed whenever new systems, services, or work scopes are added.

Incident response plans at Level 2 contractors had an average of 4.2 roles listed with no named individual assigned

NIST SP 800-171 control 3.6.1 requires that incident response capabilities be established, including defined roles. In Vulnox assessments of contractor incident response plans, the average plan listed 4.2 distinct roles (Incident Commander, Security Lead, Communications Lead, Legal Counsel, and so on) with no named individual assigned to any of them. The plans documented what roles should exist, not who fills them. The plans also contained notification procedures listing external contacts (US-CERT, contracting officer) with contact information that had not been verified within the past 12 months in 67% of cases.

Implication:

An incident response plan with roles but no named owners is a template, not a capability. A C3PAO evaluating control 3.6.1 will ask who fills these roles and whether those individuals know they do. If the answer is that the IR plan has never been exercised and the people named (if any are named) were assigned without their knowledge, the control fails. The IR plan failure is also a leading indicator: organisations that maintain template plans without operationalising them typically have the same issue across other controls that require both documentation and operational evidence.

Level 1 AO evidence was missing for an average of 6 of 17 practices in self-assessed contractors

In reviews of Level 1 self-assessments ahead of Level 2 C3PAO engagements, Vulnox found that contractors had assessed themselves as fully implementing all 17 Level 1 practices but could not produce the specific evidence the Level 1 AOs require for an average of 6 practices. The most common evidence gaps were in Media Protection (sanitization records for disposed devices), Physical Protection (visitor logs and physical access review records), and Identification and Authentication (documented authentication configuration settings rather than a verbal assertion that MFA is in use). The contractors were not intentionally inflating their scores — they genuinely believed the controls were met. They had not worked through the AOs to understand what evidence ''met'' required.

Implication:

The Level 1 AOs are not an academic exercise. They define the evidentiary standard for annual self-assessment. A contractor that cannot produce AO-specified evidence for a practice it has marked as implemented has a False Claims Act exposure on its SPRS submission. The AOs also preview what a C3PAO will look for when the contractor moves to Level 2 — an organisation that learns to work against AOs for Level 1 is building the evidence management habit that Level 2 C3PAO assessment requires at scale.

The mistakes that appear in every CMMC programme Vulnox has reviewed

Mistakes

Mistake

Scoping the CUI environment to minimise assessment surface rather than to accurately reflect CUI flow

Why It Happens

The incentive to scope narrowly is real. A smaller CUI environment means fewer controls to implement, lower remediation cost, and a shorter assessment timeline. Legal and compliance teams understand this and sometimes scope the CUI boundary to the smallest defensible definition. The problem is that CUI does not respect the boundary they draw — it flows to where engineers actually work, which is often cloud services and collaboration tools that were not in scope when the compliance programme was designed. The CUI boundary should reflect where CUI actually resides and transits, not where the programme team wishes it did.

Actual Consequence

A C3PAO discovering that CUI resides in out-of-scope systems has two options: expand the assessment boundary to include those systems, or find the contractor in material non-compliance for failing to scope correctly. Either outcome is worse than accurate scoping from the start. Option one turns a planned assessment into an unplanned one with systems that have not been hardened. Option two is a compliance failure. The cost of accurate scoping up front is always lower than the cost of rediscovery under assessment conditions.

Mistake

Treating ''implemented'' as ''we have a policy that describes this control''

Why It Happens

Compliance programmes in many industries are documentation-heavy by design. The pattern of ''document the requirement, have legal review the document, file the document'' produces compliance artefacts that satisfy auditors who read documents. CMMC''s assessment methodology, particularly at Level 2 via C3PAO, evaluates whether controls are technically implemented and operating — not whether the documentation is coherent. Configuration Management 3.4.1 requires baseline configurations to be established and maintained. Having a baseline configuration document satisfies the documentation requirement. Having systems that are actually configured to that baseline is what the AO requires.

Actual Consequence

The SPRS score delta described in the Vulnox findings above is the direct consequence of this mistake. A contractor that has marked 90 controls as implemented based on documentation has an SSP that says one thing and a technical environment that says another. A C3PAO will examine both. The gap between the two is the assessment finding. At Level 2, material gaps in control implementation can result in a failed assessment, which means loss of contract eligibility until remediation and re-assessment — a timeline that can run six months or more.

Mistake

Underestimating the flow-down obligation and treating subcontractor compliance as a questionnaire exercise

Why It Happens

Prime contractors are responsible for flowing CMMC requirements to subcontractors that handle CUI. The mechanism is a contract clause. Once the clause is in place, primes often treat their obligation as satisfied. The clause says the subcontractor must comply; the subcontractor affirms compliance; the prime files the affirmation. This is the same self-attestation problem that CMMC was designed to solve at the contractor level, replicated one tier down in the supply chain.

Actual Consequence

A DoD programme office that discovers CUI was mishandled by a subcontractor will trace the breach up through the prime. The prime''s contract clause does not insulate it from consequence if the subcontractor''s SPRS score was inflated and the prime accepted it without verification. The False Claims Act exposure follows the prime if the prime certified the supply chain''s compliance without adequate basis for that certification. The verification mechanism is underdefined in the CMMC rule, which means primes are taking on risk they have not measured.

Mistake

Planning for Level 2 without accounting for the time and cost of C3PAO assessment availability

Why It Happens

The number of accredited C3PAOs relative to the number of DIB contractors that need assessments is a structural bottleneck that the CMMC ecosystem has not resolved. Contractors that plan their remediation timeline against their contract deadline often discover that the C3PAO assessment scheduling window extends well past when they expected to begin. Remediation completed in month six does not guarantee assessment in month seven.

Actual Consequence

Contractors that miscalculate C3PAO scheduling availability miss contract deadlines. In some cases this means a contract modification or delay. In others it means inability to bid on new work while the assessment pipeline clears. The organisations most affected are mid-size contractors with three to twelve months of runway before a critical contract renewal — they complete their technical remediation on schedule and then discover they cannot get an assessment slot in time. Starting the C3PAO engagement earlier than feels necessary is the only available mitigation, because the scheduling constraint is outside the contractor''s control.

The assessment standard gap that only becomes visible across all four CMMC instruments

Insight

When you read CMMC 2.0 Level 1, Level 2, and Level 3 in sequence, you see an escalating control count: 17, 110, 110 plus 800-172 enhanced practices. That framing — more controls at each level — is technically accurate and operationally misleading. The more important escalation is in the evidentiary standard and the assessment methodology.

Level 1 is self-assessed. The Level 1 AOs specify what evidence is required, but no external party verifies it. Level 2 introduces a C3PAO that examines, interviews, and tests — the same controls that were self-assessed at Level 1 are now subject to external scrutiny against the same AO-equivalent criteria in NIST 800-171A. Level 3 introduces DCMA assessors with classified threat context.

What this means in practice: the same control — say, 3.1.1, limiting system access to authorised users — has three different effective standards depending on which tier is assessing it. At Level 1, a self-assessed SPRS entry suffices. At Level 2, a C3PAO will examine access control lists, interview account administrators, and test boundary conditions. At Level 3, a DCMA team will evaluate that control against the specific threat actor profile relevant to the programme.

This graduated evidentiary standard is not documented in any single CMMC instrument. It is only visible when you map the assessment methodology of all four instruments together. The practical implication: a control that is ''implemented'' at Level 1 self-assessment standards may fail at Level 2 C3PAO standards, not because the control changed, but because the standard for demonstrating it changed. Contractors who build their programmes against the C3PAO evidentiary standard from the start — treating every control as if it will be externally examined and tested — build programmes that are assessment-ready at any tier.

Practical Implication

Design your CMMC programme against C3PAO evidentiary standards regardless of which tier you are currently in. If you are at Level 1, build evidence artefacts that would satisfy a C3PAO, not just a self-assessment SPRS entry. The marginal cost of building to the higher standard now is far lower than the cost of rebuilding when a Level 2 contract requires C3PAO assessment.

Why It Is Invisible In Isolation

Each CMMC instrument describes its own requirements and assessment mechanism. None of them describe how the evidentiary standard escalates across tiers, because each instrument is written for its own audience. The escalation pattern is only apparent when you examine all four instruments'' assessment methodologies simultaneously and trace the same control across all three levels.

How to sequence a CMMC programme that does not have to be rebuilt at each level

Start with CUI scoping — not with control implementation. Every decision that follows depends on an accurate answer to the question: where does CUI reside, and where does it flow? This means a data flow mapping exercise that follows CUI from contract delivery through every system, person, and service that touches it. Cloud services, collaboration tools, remote access infrastructure, and contractor-owned devices must all be evaluated against the question of whether they carry CUI. Assume the answer is yes until you can prove otherwise.

Once scoping is accurate, build the System Security Plan against all 110 NIST 800-171 R2 controls, not just the ones that seem obviously applicable. The SSP is the evidence backbone for the C3PAO assessment. It should document what the control requires, what the organisation has implemented, and what evidence substantiates that implementation. Each control entry should be written as if a C3PAO will read it and then go verify it — because they will.

For the Level 1 AOs specifically: use them as the evidence specification for the 17 foundational controls. For each Level 1 practice, identify the specific AOs and collect the evidence each AO requires before marking the control as implemented in SPRS. This is not additional work for Level 1 — it is the work that makes the Level 1 self-assessment defensible and that builds the evidence management discipline needed for Level 2.

Sequencing Logic

Accurate scoping first. SSP development second, covering all 110 controls. Gap assessment against the controls in the SSP, producing a remediation backlog ranked by assessment criticality (the three domains that drive the most SPRS score variation — CM, AU, SC — should be at the top of the list). Technical remediation against the backlog, with evidence collection integrated into the remediation process rather than added after. C3PAO engagement initiated as early as possible in the timeline, not at the end of remediation.

Common Shortcut That Fails

Building a Level 1 programme and treating it as a foundation that can be extended to Level 2 by adding 93 controls. The extension is real — the 17 Level 1 controls are a subset of Level 2''s 110. But the assessment mechanism change from self-assessment to C3PAO requires rebuilding the evidence for all 110 controls to C3PAO standards, not just the 93 incremental ones. Organisations that invest minimally in Level 1 documentation and then try to extend it for Level 2 typically spend more total time than if they had built to C3PAO standards from the beginning.

What the CMMC landscape will look like in 2027

  1. At least three False Claims Act settlements specifically attributable to inflated SPRS scores will be publicly reported by end of 2027, with aggregate settlements exceeding USD 50 million.

    The Department of Justice Civil Cyber-Fraud Initiative, launched in 2021, has already produced settlements in cases where contractors misrepresented their cybersecurity posture on federal contracts. CMMC creates a specific, auditable claim — the SPRS score — that DoD relies on for contract decisions. The average 89-point gap between self-assessed and independently verified scores across the DIB means the population of potentially actionable misrepresentations is large. As C3PAO assessments produce more data points on the gap between claimed and actual posture, the DoJ has more referral triggers. The observable signal for this prediction arriving is the first CMMC-specific FCA complaint unsealed from a qui tam relator inside a DIB company.

    Confidence: highNo CMMC-specific FCA settlement is publicly reported before December 2027, or DoJ publicly declines to pursue CMMC-related FCA cases on policy grounds.
  2. C3PAO capacity will remain insufficient to assess all Level 2 contracts within the required timelines through 2026, producing a category of technically non-compliant contractors who are compliant-pending-assessment due to scheduling constraints the market cannot resolve.

    The CMMC Accreditation Body accredits C3PAOs through a process that takes months. The number of DIB companies requiring Level 2 assessment is estimated at 80,000 or more. The number of accredited C3PAOs as of early 2025 is a fraction of what would be needed to assess that population triennially. The assessment market cannot scale fast enough to absorb the demand the CMMC rule creates within its own implementation timeline. The observable signal for this prediction is DoD issuing a policy document that creates a formal grace period or phased compliance schedule for Level 2 contractors who cannot obtain assessment slots.

    Confidence: highThe CMMC AB accredits sufficient C3PAOs to clear the DIB assessment backlog by December 2026, or DoD modifies the CMMC rule to reduce the Level 2 assessment population.

Where the CMMC programme is likely to succeed and where it is structurally set up to fail

CMMC will improve the baseline cybersecurity posture of the DIB. Not because the 110 controls are novel — NIST 800-171 has existed since 2015 and contractors have nominally been compliant with it as a contract clause for years. The improvement will come from the assessment mechanism. Self-attested compliance against NIST 800-171 produced the SPRS score problem. Third-party assessment produces actual accountability. The DIB companies that go through a C3PAO assessment and pass it will have real security programmes, not documentation exercises. That is a genuine improvement.

The structural failure mode is in the subcontractor tier. The DIB is a tiered supply chain. Primes get assessed. Their major subcontractors get assessed. But the small machine shops, the specialised component suppliers, the niche software vendors at the third and fourth tier of the supply chain — their CMMC programmes will be as good as the flow-down enforcement the prime applies. Flow-down enforcement is a questionnaire. A questionnaire produces the same self-attestation problem that CMMC was built to solve. Adversaries who want access to a DoD programme do not need to penetrate the prime. They can take the path of least resistance through the lower tiers of the supply chain that CMMC''s assessment regime does not meaningfully reach.

Counterargument

The counterargument is that perfect should not be the enemy of good — requiring C3PAO assessment of every fourth-tier subcontractor would be economically prohibitive and would collapse the defence supply chain. Raising the bar at the prime and major sub level is a meaningful improvement even if the lower tiers remain weakly enforced. This is a reasonable position. It does not change the fact that a sophisticated attacker with knowledge of the supply chain will route around the assessed tiers.

What to do this week

Pull your most recent SPRS submission and go back through the three domains that account for the most score variation in our assessment data: Configuration Management, Audit and Accountability, and System and Communications Protection. For each control in those three domains that you have marked as implemented, identify the specific evidence you would produce if a C3PAO asked you to demonstrate it tomorrow. Not the policy document. The technical evidence: the configuration baseline with a date, the audit log coverage showing all CUI-scope systems, the network boundary control configurations. If that evidence does not exist or cannot be produced in under 30 minutes, the control is not implemented to C3PAO standards — it is documented. That gap is your starting point.

Further Reading

Frequently Asked Questions

What is the difference between CMMC 2.0 Level 1 and Level 2?

CMMC 2.0 Level 1 applies to DoD contractors handling Federal Contract Information (FCI) and requires annual self-assessment against 17 basic cybersecurity practices derived from FAR 52.204-21. Level 2 applies to contractors handling Controlled Unclassified Information (CUI) and requires implementation of all 110 security requirements from NIST SP 800-171 R2, with triennial third-party assessment by an accredited C3PAO for most contracts. All 17 Level 1 practices are included within Level 2''s 110 controls — Level 2 subsumes Level 1 entirely. The assessment mechanism change from self-assessment to C3PAO is the most operationally significant difference.

What are CMMC Level 1 Assessment Objectives and why do they matter?

The CMMC 2.0 Level 1 Assessment Objectives (AOs) translate each of the 17 Level 1 practice statements into specific, measurable, testable criteria that define what evidence is required to demonstrate each practice is implemented. Where the practice statement says ''limit system access to authorised users,'' the AOs specify what access control records, configuration settings, and account management evidence an assessor examines. Contractors that self-assess against practice statements without working through the AOs consistently produce inflated SPRS scores. Vulnox assessment data found that Level 1 AO evidence was missing for an average of 6 of 17 practices in self-assessed contractors who believed they were fully compliant.

Who does CMMC 2.0 Level 3 apply to?

CMMC 2.0 Level 3 applies to DoD prime contractors and subcontractors on high-priority programmes specifically designated by DoD as facing advanced persistent threat risk. Level 3 requires all 110 NIST SP 800-171 R2 controls (the full Level 2 requirement) plus a subset of enhanced practices from NIST SP 800-172. Assessments are conducted directly by the DCMA Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), not by commercial C3PAOs. DCMA assessors have access to classified threat intelligence relevant to the specific programme being assessed. Level 3 applies to a small subset of the DIB — DoD designates Level 3 requirements in contract solicitations for the most sensitive programmes.

Why is there a gap between self-assessed SPRS scores and C3PAO assessment results?

Vulnox assessment data shows an average 89-point gap between SPRS scores submitted by DIB contractors before independent verification and scores calculated after. The gap occurs because contractors consistently mark controls as ''implemented'' based on the existence of a policy document rather than evidence of technical implementation. The three domains accounting for 71% of the gap are Configuration Management (baseline configs documented but not enforced), Audit and Accountability (logging enabled on some but not all CUI-scope systems), and System and Communications Protection (boundary controls documented but inconsistently deployed). C3PAOs examine technical evidence and test controls, not just documentation — the difference in evidentiary standard is what produces the score delta.

How should a DoD contractor scope their CUI environment for CMMC?

CUI scoping must follow where CUI actually resides and flows, not where a compliance programme wishes it did. The scoping exercise should start with data flow mapping: trace CUI from contract delivery through every system, person, and service that touches it. Cloud collaboration platforms, remote access solutions, personal devices used to access CUI systems, and acquired company infrastructure must all be evaluated against CUI presence. In Vulnox pre-assessment reviews, 73% of Level 2 candidates had at least one out-of-scope system carrying CUI. A C3PAO discovering an out-of-scope CUI system will expand the assessment boundary to include it, introducing unassessed controls into the evaluation at assessment time.

What is the most efficient path to CMMC Level 2 certification?

Start with accurate CUI scoping. Build the System Security Plan covering all 110 NIST 800-171 R2 controls, with each entry written to C3PAO evidentiary standards — documenting what the control requires, what is implemented, and what evidence demonstrates it. Conduct gap assessment prioritising Configuration Management, Audit and Accountability, and System and Communications Protection — the three domains that drive the most SPRS score variation. Initiate C3PAO engagement earlier than feels necessary, because C3PAO scheduling availability is a structural bottleneck across the DIB. Avoid the common shortcut of building a minimal Level 1 programme and extending it — rebuilding Level 1 evidence to C3PAO standards during Level 2 preparation costs more than building to C3PAO standards from the start.

What False Claims Act risk does an inflated SPRS score create?

Submitting an SPRS score that asserts CMMC/NIST 800-171 compliance when controls are not actually implemented creates potential False Claims Act exposure. The DoJ Civil Cyber-Fraud Initiative explicitly targets cybersecurity misrepresentations on federal contracts. A false SPRS submission is an affirmative claim to the government that a contractor meets the security requirements that DoD is relying on for contract award. The average 89-point gap between self-assessed and independently verified SPRS scores across the DIB represents a large population of potentially actionable misrepresentations. The risk is not theoretical — FCA settlements in cybersecurity misrepresentation cases have already been reached, and the CMMC rule creates more specific, auditable claims than predecessor frameworks.

What is the difference between a C3PAO assessment and a DCMA assessment for CMMC?

C3PAO assessments are conducted by commercial organisations accredited by the CMMC Accreditation Body and apply to Level 2 contracts. DCMA DIBCAC assessments are conducted by a government team and apply to Level 3 contracts. The key operational difference is that DCMA assessors have access to classified threat intelligence relevant to the specific programme being assessed — meaning the same control is evaluated against the specific threat actor profile targeting that programme, not against generic cybersecurity standards. DCMA assessments are more intensive and their findings carry immediate programme-level consequences given the sensitivity of Level 3 contracts.

Related Articles

US state privacy and data security laws: the complete compliance map

US state privacy and data security laws: the complete compliance map

Organizations managing multi-state US data compliance face 22 distinct state frameworks with overlapping scope, conflicting timelines, and different enforcement models. In our assessments, the most common gap is not missing a law -- it is believing a single written information security programme satisfies obligations that are actually procedural and consumer-rights-based.

HIPAA compliance framework guide: Security Rule, HICP, and the 2013 Omnibus

HIPAA compliance framework guide: Security Rule, HICP, and the 2013 Omnibus

Vulnox assessments of healthcare organizations found that 71% had never tested their breach notification pipeline against an after-hours discovery scenario. This guide maps all five HIPAA group frameworks — Security Rule, Administrative Simplification, and HICP tiers — and identifies where the gaps actually live.

EMEA compliance frameworks: the complete guide to GDPR, NIS2, DORA, and 40+ regional mandates

EMEA compliance frameworks: the complete guide to GDPR, NIS2, DORA, and 40+ regional mandates

A 60-person SaaS company with a full GDPR programme still had four separate regulatory exposures — PSD2, NIS2, German KRITIS, and BSI C5 — none of which appeared on their compliance register. This guide maps every EMEA framework, where they overlap, and where following one makes another harder to satisfy.

Ready to Secure Your Digital Assets?

Get a comprehensive vulnerability assessment for your website today.