CMMC Compliance: 3 Levels, 9 Requirements & 7 Best Practices
See Venn first in Google Search
Add as a preferred source on GoogleWhat Is CMMC Compliance?
CMMC (Cybersecurity Maturity Model Certification) compliance is a mandatory cybersecurity framework for Department of Defense contractors designed to protect sensitive government data, though advanced third-party rollout rules were suspended for a comprehensive review in July 2026. Compliance may require a self-assessment or an assessment by an authorized third party, depending on the CMMC level and contract requirements.
Current status:
- Phase I rules: Basic self-assessment requirements remain firmly in place.
- Phase II suspension: The Department suspended advanced Phase II requirements to review and align the program with new acquisition directives.
The three compliance levels:
- Level 1 (Foundational): Focuses on basic cyber hygiene. It requires 17 practices for companies that handle Federal Contract Information (FCI).
- Level 2 (Advanced): Aligns directly with NIST SP 800-171. It requires 110 security practices for companies that handle Controlled Unclassified Information (CUI).
- Level 3 (Expert): Built on enhanced requirements from NIST SP 800-172 for specialized, high-risk defense programs.
Who must comply:
- Department of Defense contractors: Applies to most prime contractors and subcontractors in the Defense Industrial Base (DIB).
- Subcontractors and suppliers: Must meet applicable CMMC requirements when their work involves handling FCI or CUI received through the defense supply chain.
- Organizations handling Federal Contract Information (FCI): Generally require CMMC Level 1 when the relevant contract includes CMMC requirements.
- Organizations handling Controlled Unclassified Information (CUI): May require CMMC Level 2 or Level 3 depending on the contract and sensitivity of the information.
This is part of a series of articles about compliance frameworks
Achieve PCI DSS Compliance on Unmanaged Laptops
Learn how to keep sensitive data secure and PCI DSS compliant when contractors and remote workers use personal laptops.

In this article:
Who Needs to Comply with CMMC?
Department of Defense Contractors
Prime contractors that work directly with the DoD may need to meet a specified CMMC level as a condition of contract award. The solicitation or contract identifies the required level and, where applicable, whether the organization needs a self-assessment or third-party certification.
Contractors also need to maintain compliance after an assessment. This includes:
- Operating required security controls
- Keeping security documentation current
- Completing required affirmations
- Addressing permitted deficiencies within applicable deadlines
Significant changes to systems that handle covered information can also affect the organization’s compliance posture. Prime contractors have an additional supply-chain responsibility. When covered information must be shared with subcontractors, the prime must determine which CMMC requirements flow down and verify that subcontractors meet the requirements applicable to their work.
Subcontractors and Suppliers
CMMC is not limited to companies with direct DoD contracts. Subcontractors and suppliers can also be subject to CMMC when their work requires them to handle FCI or CUI received through a prime contractor or another subcontractor.
The required level depends on the information the subcontractor handles, not simply the CMMC level assigned to the prime contractor. For example, a supplier receiving only FCI may have different requirements from an engineering subcontractor that receives technical CUI.
Organizations should map how covered information moves through the supply chain. This helps determine which subcontractors need CMMC requirements in their agreements and prevents CUI from being shared with systems or organizations that do not meet the required security standard.
Organizations Handling Federal Contract Information (FCI)
Organizations that handle FCI generally need CMMC Level 1 when the applicable contract requires CMMC. FCI includes nonpublic information provided by or generated for the federal government under a contract, excluding information intended for public release and certain basic transactional information.
Level 1 focuses on fundamental safeguards for federal information. Its requirements are based on FAR 52.204-21 and cover areas such as:
- Access control
- Identification and authentication
- Physical protection
- Communications protection
- System integrity
Level 1 uses annual self-assessments rather than third-party certification. Organizations must still implement all applicable requirements and provide the required affirmation of continuing compliance. Simply having security policies or planning to implement a safeguard is not sufficient to satisfy an assessment objective.
Organizations Handling Controlled Unclassified Information (CUI)
Organizations that process, store, or transmit CUI face more extensive requirements because CUI requires safeguards beyond those used for FCI. Depending on the DoD program and contract, these organizations may need CMMC Level 2 or Level 3.
Level 2 requirements align with the 110 security requirements in NIST SP 800-171 Revision 2. They cover areas such as:
- Access control
- Incident response
- Audit logging
- Configuration management
- Risk assessment
- Protection of systems and communications
Depending on the contract, Level 2 may require either a self-assessment or certification by an authorized CMMC third-party assessment organization.
Level 3 applies to specified organizations supporting the DoD’s highest-priority programs. It builds on Level 2 with additional security requirements selected from NIST SP 800-172 and requires assessment by the Defense Industrial Base Cybersecurity Assessment Center. Its additional controls are intended to reduce the risk posed by advanced persistent threats.
Current Status of CMMC
As of September 2026, CMMC remains in effect, but its rollout has changed significantly from the original implementation schedule. The Department began implementing CMMC requirements through the DFARS on November 10, 2025, with Phase I focused primarily on self-assessment requirements. However, on July 13, 2026, the Department announced the immediate suspension of CMMC Phase II, which had been scheduled to begin on November 10, 2026.
Phase I Requirements Remain in Effect
The suspension of Phase II does not eliminate CMMC requirements. Phase I self-assessment obligations remain in place for applicable contractors, and the Department continues to enforce cybersecurity requirements based on NIST SP 800-171 Rev. 2 through contractor self-assessments and selected government-led assessments.
Contractors may also need to maintain a current CMMC status and an affirmation of continuous compliance depending on the requirements incorporated into their contracts. Current DFARS language defines validity periods for CMMC statuses and requires corresponding affirmations of continuous compliance.
CMMC Phase II Has Been Suspended
Phase II was originally expected to expand the use of C3PAO certification assessments, particularly for organizations handling CUI that require Level 2 certification. That rollout has now been suspended while the Department conducts a broader review of the CMMC program.
The review is intended to examine ways to:
- Reduce unnecessary compliance burden
- Lower barriers for small and non-traditional defense contractors
- Make cybersecurity requirements more scalable
- Better align CMMC with broader defense acquisition reforms
- Focus requirements more directly on meaningful cybersecurity outcomes
CMMC Compliance Requirements
1. Identifying FCI and CUI
The first step is determining whether the organization receives, creates, processes, stores, or transmits FCI or CUI. This requires reviewing contracts, data markings, workflows, repositories, and information exchanged with customers and subcontractors.
Organizations should also map how this information moves between users, devices, applications, cloud services, and external parties. Accurate data-flow mapping helps prevent systems containing regulated information from being incorrectly excluded from the CMMC scope.
2. Defining the CMMC Assessment Scope
The assessment scope identifies the systems, people, facilities, and technology that must be evaluated. For Level 1, this generally centers on assets that process, store, or transmit FCI. Level 2 scoping also accounts for CUI assets and other assets that provide security functions or could affect CUI protection.
Reducing unnecessary data movement can make the scope easier to manage. For example, an organization may isolate CUI within a controlled enclave instead of allowing it across its entire corporate network. The architecture must still follow CMMC scoping requirements and account for dependencies that can affect the enclave.
3. Implementing Required Security Controls
Organizations must implement the safeguards associated with their required CMMC level. Level 1 uses 15 basic safeguarding requirements from FAR 52.204-21. Level 2 incorporates the 110 security requirements from NIST SP 800-171 Revision 2, while Level 3 adds selected requirements from NIST SP 800-172.
These requirements cover areas such as access control, authentication, incident response, configuration management, audit logging, physical security, and system protection. Controls must work in practice and produce sufficient evidence for the applicable assessment.
4. Documenting Cybersecurity Policies and Procedures
Assessors need evidence showing how security requirements are implemented and operated. Organizations should therefore document relevant policies, procedures, system configurations, responsibilities, and recurring security activities.
Documentation should reflect the actual environment rather than describe controls that are planned or no longer used. Supporting evidence can include configuration records, access reviews, logs, training records, screenshots, tickets, and other artifacts demonstrating that required practices are performed.
5. Creating and Maintaining a System Security Plan (SSP)
Organizations subject to Level 2 requirements need a system security plan that describes the system boundary and how NIST SP 800-171 requirements are implemented. The SSP should identify relevant system components, operating environments, connections to other systems, and security responsibilities.
The SSP is a living document. Organizations should update it when architecture, services, security controls, or CUI workflows change. An outdated SSP can create discrepancies between documented controls and what an assessor observes in the environment.
6. Conducting CMMC Assessments
The required assessment depends on the organization’s CMMC level and contract. Level 1 requires an annual self-assessment. Level 2 may require either an annual self-assessment or a certification assessment by an authorized CMMC third-party assessment organization, depending on the procurement.
Level 3 requires a government assessment conducted by the Defense Industrial Base Cybersecurity Assessment Center. During an assessment, the organization must demonstrate that applicable requirements are satisfied using evidence such as documentation, interviews, and technical examination.
7. Submitting Assessment Results to SPRS
CMMC assessment information is recorded in the Supplier Performance Risk System (SPRS), the DoD system used to maintain relevant contractor cybersecurity assessment information. Submission requirements vary according to the CMMC level and assessment type.
Organizations should verify that required results are current before bidding on or receiving an applicable contract. Missing, expired, or inadequate assessment information can prevent an organization from satisfying the CMMC condition specified for an award.
8. Completing Annual Affirmations of Compliance
CMMC includes affirmation requirements in addition to assessments. A senior company official must affirm continuing compliance with the applicable CMMC security requirements in SPRS after an assessment and annually thereafter as required.
An affirmation is not a replacement for an assessment. It confirms that the organization continues to meet the required security standard. Organizations therefore need processes for monitoring controls and identifying changes that could affect compliance between assessment dates.
9. Addressing Gaps Through Plans of Action and Milestones (POA&Ms)
A plan of action and milestones documents security requirements that have not yet been fully implemented and specifies how and when the organization will correct them. Under CMMC, POA&Ms are permitted only in defined circumstances and cannot be used for every unmet requirement.
When a POA&M is allowed, the organization must meet the required assessment score and close eligible deficiencies within the specified timeframe. A follow-up assessment verifies that the items have been corrected. Organizations should therefore identify and remediate gaps before their formal assessment rather than rely on POA&Ms as a general path to compliance.
Understanding the CMMC Compliance Levels
CMMC Level 1: Foundational Protection of FCI
CMMC Level 1 applies to organizations that handle FCI but do not handle CUI under the relevant contract. It is based on the 15 safeguarding requirements in FAR 52.204-21, which establish basic protections for federal information stored or processed in contractor systems.
These safeguards cover areas such as:
- Limiting system access
- Authenticating users
- Controlling physical access
- Protecting communications
- Identifying malicious software
Level 1 focuses on fundamental cybersecurity practices rather than the more extensive controls required for CUI. Level 1 requires an annual self-assessment. Organizations must enter the required assessment information in SPRS and complete an annual affirmation of continuing compliance. POA&Ms are not permitted for Level 1, so all applicable requirements must be satisfied.
CMMC Level 2: Protection of CUI
CMMC Level 2 applies to organizations that process, store, or transmit CUI. It incorporates the 110 security requirements from NIST SP 800-171 Revision 2, covering areas such as:
- Access control
- Audit and accountability
- Incident response
- Configuration management
- Risk assessment
- System integrity
The assessment method depends on the DoD procurement. Some Level 2 contracts permit an annual self-assessment, while others require a certification assessment by an authorized CMMC third-party assessment organization. Certification assessments generally remain valid for three years, with annual affirmations required between assessments.
Level 2 also permits limited use of POA&Ms when specified conditions are met. Certain high-value security requirements cannot be deferred, and eligible outstanding requirements must be corrected within the required timeframe. This makes pre-assessment gap analysis important for organizations seeking certification.
CMMC Level 3: Enhanced Protection Against Advanced Threats
CMMC Level 3 is intended for organizations working on selected DoD programs where CUI faces greater cybersecurity risk. It builds on Level 2 requirements and adds selected enhanced security requirements from NIST SP 800-172 designed to address advanced persistent threats.
These additional measures strengthen areas such as:
- Threat awareness
- Security architecture
- Access restrictions
- System monitoring
- The ability to detect and respond to sophisticated attacks
An organization must first achieve the required Level 2 status before completing the Level 3 assessment process. Level 3 assessments are performed by the Defense Industrial Base Cybersecurity Assessment Center rather than a commercial CMMC assessment organization. Level 3 status generally operates on a three-year assessment cycle, with annual affirmations required to confirm continued compliance.
Best Practices for CMMC Compliance
Organizations seeking Cybersecurity Maturity Model Certification should consider the following practices to improve compliance.
1. Minimize the Scope of the CUI Environment
Limit CUI to the systems and services that actually need it. A dedicated CUI enclave can separate regulated workloads from general corporate systems and reduce the number of assets included in the CMMC assessment scope.
Segmentation must be technically enforced rather than based only on policy. Use network controls, identity restrictions, separate storage, and controlled interfaces to prevent CUI from moving into systems outside the approved boundary. Document dependencies because security protection assets and other connected components can still affect assessment scope.
2. Maintain an Accurate Inventory of In-Scope Assets
Maintain an inventory of hardware, software, cloud services, virtual systems, and other assets relevant to the CMMC environment. Record information such as asset owner, location, function, configuration, and whether the asset processes, stores, or transmits CUI.
Update the inventory when systems are deployed, replaced, reconfigured, or retired. Automated discovery and asset management tools can help identify unmanaged systems that manual records miss. The inventory should remain consistent with network diagrams, data-flow documentation, and the SSP.
3. Isolate Business Data on BYOD and Unmanaged Devices
Personally owned and unmanaged devices can make CUI difficult to control because the organization may not control their storage, applications, backups, or security configuration. Where possible, prevent CUI from being downloaded or stored directly on these endpoints.
If business requirements permit BYOD access, use technologies that keep organizational data inside a managed environment. Virtual desktops, application isolation, managed containers, and browser-based controls can separate CUI from personal applications and local storage. The chosen design must still satisfy applicable CMMC requirements.
4. Enforce Device Security Before Granting Access
Do not grant access based only on a valid username and password. Verify that endpoints meet defined security requirements before allowing them to connect to systems containing CUI.
Conditional access can check factors such as device enrollment, encryption, operating system version, security software, and compliance status. Combine these checks with multifactor authentication and centralized endpoint management. Devices that become noncompliant should have their access limited or blocked until the problem is corrected.
5. Apply Least-Privilege Access Controls
Give users and services only the permissions required to perform their assigned functions. Use role-based access, separate privileged accounts, and approval processes to prevent unnecessary access to CUI.
Review permissions regularly, especially when employees change roles or leave the organization. Administrative access should receive additional protection and monitoring because compromised privileged accounts can bypass many other safeguards. Remove unused accounts and permissions promptly rather than waiting for periodic audits.
6. Control CUI Movement and Data Exfiltration
Identify the approved paths through which CUI can enter, leave, and move within the environment. Apply technical controls to email, cloud storage, removable media, file transfers, printing, and other channels that could move information outside the authorized boundary.
Data loss prevention rules, encryption, egress filtering, and application restrictions can help prevent unauthorized transfers. Logging should provide enough information to investigate suspicious activity. Controls should also account for legitimate transfers so CUI is shared only with authorized recipients through approved methods.
7. Restrict and Monitor Third-Party Access
Vendors, managed service providers, subcontractors, and other external parties can introduce additional access paths into the CUI environment. Grant third parties only the systems and permissions necessary for their work, and remove access when it is no longer required.
Use separate accounts, multifactor authentication, time-limited privileges, and logging for external access. Organizations should also understand whether a provider stores, processes, or can access CUI because this can affect CMMC scope and contractual requirements. Regular reviews help identify dormant accounts, excessive privileges, and third-party connections that are no longer needed.
Related content: Read our article about third-party risk management
Supporting CMMC Compliance on BYOD and Unmanaged Devices with Venn
Venn’s Blue Border™ secures unmanaged and BYOD laptops without the cost and complexity of VDI or restricting users to the browser. It isolates and protects sensitive data, enforces policy-based controls, and helps organizations meet compliance requirements including CMMC, SOC 2, HIPAA, and PCI. Work apps and data live inside a company-controlled Secure Enclave, keeping business activity separate from any personal use on the same computer while personal files, apps, and browsing history remain private.
Key capabilities of Venn’s Blue Border:
- Compliance support: Helps organizations meet PCI, SOC, HIPAA, SEC, FINRA, CMMC, NAIC, and other regulatory requirements.
- Data isolation: Isolates and protects business activity from any personal use on the same computer, keeping company data confined to the Secure Enclave.
- Encryption: Keeps work data encrypted and confined to the company, where it belongs.
- Policy enforcement: Lets IT control policies for network access, peripheral use, copy-paste, and more to protect work data from accidental or malicious leakage.
- Device posture checks: Ensures that only compliant and secure devices can access the organization’s network.
- Fast onboarding and offboarding: Gets users up and running, or removes their access, in minutes.
- Cost reduction: Eliminates the expense of VDI or buying, shipping, and managing company devices.
- Built-in user privacy: Prevents the company or Venn from seeing, accessing, or removing personal files, photos, apps, or browsing history.
Learn more about compliance-ready BYOD security with Venn

Any worker. Any laptop. Any AI workflow. Fully secured.
Schedule a demo to see how Blue Border™ secures company data and apps without shipping laptops, running VDI, or managing personal endpoints.