CMMC
CMMC Fact Sheet
CMMC Level 1 (L1)
This level focuses on basic security practices and is intended for contractors who handle Federal Contract Information (FCI). L1 includes practices like ensuring physical security, safeguarding sensitive data, and implementing basic cyber hygiene. L1 does not require a formal certification, but contractors must still self-assess and adhere to the basic practices.
CMMC 2.0/Level 2 (L2)
- L2 is a mid-level security requirement for contractors who handle Controlled Unclassified Information (CUI). This level builds upon L1 but adds more detailed security practices (including risk management, incident response, and training). L2 requires formal third-party certification for contractors to demonstrate compliance.
- Phase 1 of CMMC applies to the L2 rollout, meaning Level 2 will be the starting point for new contracts and solicitations starting November 10, 2025.
- Refer to Slide 16 for timeline and details of the phased rollout plan.
Phase 1 Rollout of CMMC L2
Beginning November 10, 2025, CMMC Level 2 requirements will be included in all new DoD contracts, contract awards, orders, and solicitations. This means any contractor bidding for a DoD project must meet L2 security standards before being awarded a contract.
CMMC 2.0: Phased Roll-out Update
Overview: How CMMC Affects Contracts and Supplier
Starting November 10th, 2025, CMMC requirements officially enter into force for new DoD contracts when the DFARS 252.204-7021 clause (“the flow-down”) is included. For new contracts with this clause, compliance is required before award, and existing contracts transition to CMMC only upon modification, extension, or option exercise with the clause added. Full enforcement for all in-scope contracts is expected within three years, culminating in late 2028.
|
Current Contracts CMMC does NOT retroactively apply to existing contracts unless modified or extended; these contracts remain governed by NIST 800-171 (DFARS 7012) until transitioned. |
New Contracts Any new contract awarded with the 7021 flow-down after Nov. 10th, 2025 requires suppliers to prove compliance with CMMC before award. |
Transition
As contracts are renewed, modified, or options exercised, the 7021 clause will be added and CMMC requirements enforced, per the discretion of DoD contracting officers.
* This is why we recommend gathering the self-attestation and SPRS screenshots now, as we don’t know when the contracting officer will add the 7021 clause to extensions, amendments, or modifications of existing contracts.
As contracts are renewed, modified, or options exercised, the 7021 clause will be added and CMMC requirements enforced, per the discretion of DoD contracting officers.
* This is why we recommend gathering the self-attestation and SPRS screenshots now, as we don’t know when the contracting officer will add the 7021 clause to extensions, amendments, or modifications of existing contracts.
Supplier: Who Must Comply & WheN
- Prime contractors and all relevant suppliers on new contracts with the CMMC clause (7021) must certify compliance according to the contract’s required level.
- Primes are responsible for verifying supplier status before awarding subcontracts – documentation is required and primes do not have direct SPRS access for subs.
- Suppliers on legacy contracts do not need immediate CMMC evidence unless the contract transitions but should prepare for eventual enforcement.
Phased CMMC Rollout: How It Works
The rollout proceeds in four phases over three years, with increasing enforcement and contract coverage until universal compliance is mandated.
Phase 1 (Nov. 10th, 2025)
Phase 1 (Nov. 10th, 2025)
- CMMC clauses selectively added to new contracts/programs at DoD officers’ discretion. (Again, at the contracting officer’s discretion so this is why we recommend confirming compliance with all suppliers – you don’t know when that clause will be included)
- Compliance (self-assessment for Level 1/2 or third-party certification if required) must be demonstrated before award.
- Each year, more contracts include the clause, more suppliers are in-scope, and Level 2/3 certifications require third-party assessment.
- Enforcement grows from selective to widespread, often aligned to renewal or modification cycles of major programs.
- All contracts processing FCI/CUI will require CMMC compliance – no exceptions. Suppliers must be certified at the appropriate level, or risk being ineligible for award.
Practical Guidance for Supplier Verification
Document Requests
Primes must ask suppliers to provide a screenshot of their SPRS score (110/110 for Level 2 self-assessment) and a signed annual affirmation of compliance from SPRS.
Program-managed Suppliers
A partner like Apicem can obtain, validate, and deliver this documentation to buyers; non-Apicem program suppliers should be asked directly for evidence.
Green Status
Only “Green” suppliers with documented score and affirmation at time of order are eligible for new contracts with the clause; legacy contracts may defer CMMC requests until transition.
Primes must ask suppliers to provide a screenshot of their SPRS score (110/110 for Level 2 self-assessment) and a signed annual affirmation of compliance from SPRS.
Program-managed Suppliers
A partner like Apicem can obtain, validate, and deliver this documentation to buyers; non-Apicem program suppliers should be asked directly for evidence.
Green Status
Only “Green” suppliers with documented score and affirmation at time of order are eligible for new contracts with the clause; legacy contracts may defer CMMC requests until transition.
Frequently Asked Questions
- Q: Do buyers have direct SPRS portal access for supplier attestations?
No. Buyers must request supporting documentation from suppliers directly—a screenshot of SPRS submission, affirmation, certification, and (optionally) SSPs or POAMs. - Q: What documentation is needed for a “Green” supplier?
A screenshot of their SPRS submission showing all CMMC controls implemented (score of 110), plus their latest signed annual affirmation. Dated within one year, for accuracy and audit readiness. - Q: How often is new documentation needed?
Documentation should reflect the supplier’s current state at time of order for CMMC-covered contracts. Maintain evidence for your contract file and audit needs. - Q: Are all contracts instantly subject to CMMC after Nov. 10, 2025?
No – only those with the clause included, per phased rollout direction. Expect selective addition first, broadening to universal enforcement after three years.
CMMC 2.0 (Level 2) Timeline
CMMC L2 Self-Assessment & Self-Attestation
What is the CMMC Level 2 (L2) Self-Assessment and Self-Attestation process?
CMMC Level 2 Self-Assessment is a method for contractors to evaluate their compliance with the 110 cybersecurity controls in NIST SP 800-171 Rev. 2 during the first 12 months after the 48 CFR rule goes into effect (starting November 10, 2025), eligible contractors may perform a self-assessment and submit a self-attestation in lieu of a third-party certification, unless otherwise instructed by the contracting officer or prime contractor.
How long is the self-assessment and self-attestation option allowed?
The self-assessment and self-attestation pathway is permitted for 12 months from the effective date of the 48 CFR rule — until Nov. 9th, 2026. After this period, CMMC Level 2 contractors will be required to obtain third-party certification from a CMMC Certified Third-Party Assessor Organization (C3PAO), unless otherwise exempted. These cases will be few and far between.
Who is eligible to self-attest for CMMC Level 2 during this transition period?
Organizations that handle Controlled Unclassified Information (CUI) may be eligible. However, DoD or your Prime will specify in each solicitation or contract whether a self-assessment is sufficient or a full C3PAO certification is required.
What are the requirements for a valid CMMC Level 2 self-assessment?
To conduct a valid self-assessment, contractors must:
- Use the DoD Assessment Methodology based on NIST SP 800-171 Rev. 2.
- Document the results in a System Security Plan (SSP).
- Have a Plan of Action & Milestones (POA&M) for any unmet controls (where applicable).
- Submit a score and supporting documentation in the Supplier Performance Risk System (SPRS).
- Ensure the senior company official signs a formal self-attestation statement submitted via SPRS or other designated portal.
Does a self-attestation guarantee future certification?
No. A self-attestation is not a guarantee of passing a C3PAO assessment. Third-party assessments may uncover gaps missed during internal reviews. Treat your self-assessment with the same rigor as a formal audit.
Who should sign the self-attestation?
The senior company official (e.g., CEO, President, or equivalent) must sign and submit the self-attestation. This underscores the accountability and legal responsibility involved in the process.
Can a company simply claim compliance without evidence?
No. A self-attestation must be backed by actual self-assessment results, documentation, and evidence. You cannot simply state you're compliant – doing so without substantiating documentation can result in civil and criminal penalties.
What are the legal implications of a false attestation?
False statements or misrepresentations in a CMMC self-attestation may be considered a violation of the False Claims Act (FCA). This can result in:
- Criminal charges and fines per false claim.
- Treble damages (three times the amount of damages sustained by the government).
- Suspension from future contracts.
What happens after the 12-month transition period ends?
Once the 12-month period ends, organizations handling CUI will need to obtain CMMC Level 2 certification from a C3PAO to remain eligible for applicable DoD contracts – unless otherwise directed by the DoD or your Prime.
How should companies prepare for the transition from self-assessment to third-party assessment?
Companies should:
- Ensure they meet all 110 NIST 800-171 controls during the self-assessment.
- Maintain complete documentation (SSP, POA&M, evidence).
- Conduct a Readiness Assessment to validate control postures and prepare for the official certification process.
- Continuously improve and close identified gaps.
- Engage with a C3PAO early to plan for certification before the 12-month grace period ends.
Where can I find official guidance and tools for CMMC self-assessment?