CMMC 2.0
Cybersecurity Maturity Model Certification Program
Overview
The Cybersecurity Maturity Model Certification (CMMC) Program is how the U.S. Department of Defense verifies that defense contractors and subcontractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The program rule (32 CFR Part 170) took effect on December 16, 2024, and the acquisition rule that places CMMC requirements in contracts (DFARS, 48 CFR) took effect on November 10, 2025. Requirements are being phased into solicitations over three years, and from November 10, 2028 they apply to all applicable contracts. There are three levels: Level 1 (the 15 requirements of FAR 52.204-21), Level 2 (the 110 requirements of NIST SP 800-171 Revision 2) and Level 3 (24 additional requirements selected from NIST SP 800-172). Access control and identification and authentication are two of the requirement families assessed.
IAM Requirements
Access Control (NIST SP 800-171 R2, 3.1)
- Limit system access to authorized users, processes acting on behalf of authorized users, and devices (3.1.1)
- Limit system access to the types of transactions and functions that authorized users are permitted to execute (3.1.2)
- Separate the duties of individuals to reduce the risk of malevolent activity without collusion (3.1.4)
- Employ the principle of least privilege, including for specific security functions and privileged accounts (3.1.5)
- Use non-privileged accounts or roles when accessing nonsecurity functions (3.1.6)
- Limit unsuccessful logon attempts (3.1.8) and monitor and control remote access sessions (3.1.12)
Identification and Authentication (NIST SP 800-171 R2, 3.5)
- Identify system users, processes acting on behalf of users, and devices (3.5.1)
- Authenticate the identities of users, processes, or devices before allowing access to organizational systems (3.5.2)
- Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts (3.5.3)
- Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts (3.5.4)
- Prevent reuse of identifiers for a defined period and disable identifiers after a defined period of inactivity (3.5.5, 3.5.6)
- Enforce minimum password complexity, prohibit password reuse for a specified number of generations, and store and transmit only cryptographically protected passwords (3.5.7, 3.5.8, 3.5.10)
Levels and Assessment
- Level 1 (Self): annual self-assessment against the 15 FAR 52.204-21 requirements; no POA&Ms are permitted
- Level 2 (Self) or Level 2 (C3PAO): assessment against the 110 NIST SP 800-171 R2 requirements every three years
- Level 3 (DIBCAC): requires a Final Level 2 (C3PAO) status first, then assessment by DCMA DIBCAC
- An affirming official affirms continuing compliance in SPRS after every assessment and annually thereafter
- Conditional status at Levels 2 and 3 lasts no more than 180 days
- Multifactor authentication is scored separately: 3 points are deducted if it covers only remote and privileged users, 5 points if it is not implemented for any users
Level 3 Identity Requirements (NIST SP 800-172)
- Restrict access to systems and system components to information resources that are owned, provisioned, or issued by the organization (AC.L3-3.1.2e)
- Identify and authenticate systems and system components before establishing a network connection, using bidirectional authentication that is cryptographically based and replay resistant (IA.L3-3.5.1e)
- Prohibit system components from connecting unless they are known, authenticated, in a properly configured state, or in a trust profile (IA.L3-3.5.3e)
Implementation Phases
- Phase 1, from November 10, 2025: Level 1 (Self) or Level 2 (Self) as a condition of award in applicable solicitations
- Phase 2, one year after Phase 1 (November 10, 2026): Level 2 (C3PAO) in applicable solicitations
- Phase 3, one year after Phase 2 (November 10, 2027): Level 2 (C3PAO) also for option periods, and Level 3 (DIBCAC) in applicable solicitations
- Phase 4, one year after Phase 3 (November 10, 2028): CMMC requirements in all applicable solicitations and contracts
Compliance Checklist
Penalties for Non-Compliance
The CMMC rules set no fines. Contracting officers must not award a contract, task order or delivery order to an offeror that lacks a current CMMC status in SPRS at the level the solicitation requires.
Quick Facts
- Region
- United States
- Effective Date
- December 16, 2024
- Enforcing Body
- U.S. Department of Defense (Office of the Chief Information Officer); assessments by C3PAOs and DCMA DIBCAC