Resource Guide

What Is CMMC?

CMMC is the Department of Defense's cybersecurity assessment program for organizations handling certain information within the Defense Industrial Base. What your business needs depends largely on the information you handle and the requirements in your contracts.

CMMC in plain English

If your business performs work for the Department of Defense, directly or through another contractor, your contracts may require specific cybersecurity protections. CMMC provides a framework for assessing whether applicable requirements are being implemented.

CMMC obligations depend on contracts, information handled, system scope, and other factors. This page provides general educational information and is not legal advice or a guarantee of certification. Verify current requirements against official DoD CMMC guidance and your applicable contracts.

The First Step

Start with the data, not the checklist

A company should not begin its CMMC journey by blindly trying to apply every possible control to every computer.

1What information do we receive?
2Where does it enter the organization?
3Where is it stored?
4Who can access it?
5Where does it travel?
6Which systems actually need to be in scope?

CMMC is partly a cybersecurity problem, but it is also a data-flow and scoping problem.

Thoughtful scoping may help an organization avoid unnecessarily bringing unrelated systems into the CMMC environment. Scope decisions must reflect actual data flows and applicable CMMC scoping guidance. Segmentation or enclaving does not automatically reduce scope unless the architecture, data flows, and controls actually support that boundary.

The First Big Distinction

FCI vs. CUI: the first big distinction

Different information types carry different safeguarding requirements. Knowing which you handle determines what applies.

Federal Contract Information (FCI)

Federal Contract Information (FCI) is information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service. Not every file from a DoD contractor is FCI, but it commonly appears in contracts that include the standard FAR clause for safeguarding covered defense information.

Controlled Unclassified Information (CUI)

Controlled Unclassified Information (CUI) is information the Government creates or owns, or that an entity creates or owns for or on behalf of the Government, that requires safeguarding or dissemination controls under law, regulation, or Government-wide policy. CUI is not classified information, but it requires protection under applicable federal requirements. The National Archives CUI Program maintains the official CUI Registry of categories.

Not every file received from a DoD contractor is automatically CUI. The category depends on the markings, the contract, and the applicable CUI categories. The National Archives CUI Registry is the authoritative source for what counts as CUI.

The Framework

The three CMMC levels

Each level addresses a different information concern and a different assessment mechanism. Verify current DoD rules for your situation.

1Foundational

CMMC Level 1

Protecting FCI

Level 1 focuses on protecting Federal Contract Information and incorporates the basic safeguarding requirements found in FAR 52.204-21. Level 1 is less complex than Level 2, but organizations still need to implement and verify the applicable requirements. Under current CMMC rules, Level 1 involves an annual self-assessment with an annual affirmation by a company executive.

2Advanced

CMMC Level 2

Protecting CUI

Level 2 is generally associated with organizations handling CUI and aligns with the security requirements of NIST SP 800-171, subject to current CMMC requirements. Depending on the contract and the type of CUI involved, Level 2 may involve either a self-assessment with annual affirmation or an assessment by an authorized C3PAO on a triennial cycle. Verify the current rules for your specific situation.

3Expert

CMMC Level 3

Higher-risk CUI

Level 3 is intended for higher-risk situations involving CUI and includes additional requirements beyond Level 2, drawing on NIST SP 800-171 and NIST SP 800-172. Level 3 involves a government-led assessment. This level is not commonly required for ordinary small defense subcontractors. Verify current DoD requirements before assuming Level 3 applies.

Side by Side

CMMC Level 1 vs. Level 2

QuestionLevel 1Level 2
Primary information concernFCICUI
Security requirementsFAR 52.204-21 basic safeguarding requirementsNIST SP 800-171 requirements under applicable CMMC rules
Assessment typeAnnual self-assessment with annual affirmationSelf-assessment or C3PAO assessment depending on applicable requirement
ComplexityFoundationalSignificantly more extensive
DocumentationRequired as applicableSubstantially more extensive, including a System Security Plan

Do not hard-code counts of practices, assessment intervals, or affirmation periods without verifying them against current official CMMC sources, as these can change.

The Relationship

Where does NIST 800-171 fit?

CMMC did not simply invent an entirely new cybersecurity framework for Level 2. NIST SP 800-171 plays a central role in the underlying safeguarding requirements for CUI. At a high level, the relationship runs through DFARS, NIST SP 800-171, CMMC, and CUI.

Defense contracts commonly require contractors handling CUI to implement the security requirements in NIST SP 800-171. CMMC Level 2 aligns with those same requirements, subject to current CMMC rules. This is why two businesses can both say they are "doing NIST 800-171" but face very different CMMC assessment paths.

Do not mix requirements from different NIST 800-171 revisions without understanding which revision currently applies under the applicable CMMC and DoD rules. Verify the current revision before relying on any specific control wording.

CMMC Level 2 aligns with NIST SP 800-171. The official NIST publication is the authoritative source for the underlying security requirements. Link directly to the current revision before acting on any specific control.

The Assessor

What is a C3PAO?

A C3PAO is a Certified Third-Party Assessment Organization authorized to perform applicable CMMC Level 2 assessments. Not every IT or compliance company is a C3PAO.

The distinction between a readiness partner and an authorized assessor is important. A readiness partner helps you prepare, scope, remediate, and document. The C3PAO performs the official assessment. These are different engagements with different roles and responsibilities.

CMMC readiness and an official CMMC assessment are not the same engagement.

The DoD System

What is SPRS?

SPRS, the Supplier Performance Risk System, is a DoD system where contractors may enter cybersecurity assessment information, including the results of NIST SP 800-171 assessments. DoD contractors may encounter it in connection with reporting assessment methodology and scores.

Having an SPRS score does not mean a business is CMMC certified. SPRS is a reporting and risk-management tool, not a certification. Verify all current SPRS requirements and relationships against official DoD sources.

The Impact

What does CMMC actually affect?

Depending on scope, CMMC readiness can touch many parts of your technology environment.

Microsoft 365User identitiesMFAEndpointsServersFile storageEmailRemote accessFirewallsNetwork segmentationLoggingSecurity monitoringEndpoint protectionVulnerability managementPatch managementBackupsAdministrative accessPolicies and proceduresEmployee security responsibilitiesIncident responsePhysical securityVendors and external service providers

CMMC is not a product you install. No firewall, EDR platform, Microsoft license, or compliance dashboard makes an organization CMMC compliant by itself.

Microsoft 365

Microsoft 365 and CMMC

Organizations handling CUI need to evaluate whether their cloud services and configurations satisfy applicable requirements. This can involve Microsoft 365 environment, identity, MFA, data location, email, SharePoint, OneDrive, Teams, logging, administrative access, and applicable federal cloud and security requirements.

Microsoft 365 Commercial and government-focused Microsoft cloud environments are not automatically interchangeable for every CMMC or CUI use case. Do not make a universal recommendation to migrate to GCC, GCC High, or another environment without evaluating your contracts, CUI, export-control considerations, and applicable requirements.

Check My Microsoft 365 Security
Scope

Does every computer have to be CMMC compliant?

Not necessarily. Scope matters. The correct question is: which people, systems, applications, security assets, and service providers are within the applicable CMMC assessment scope?

Consider a 40-person contractor where only a subset of employees need access to CUI. Instead of assuming all 40 users and every system belong in the same environment, the company maps who needs CUI, where CUI is stored, how CUI is accessed, and what systems protect that environment. Then scope is determined according to current official CMMC scoping guidance.

Smaller scope does not mean weaker security. It means accurately identifying the environment that must meet the applicable requirements.

Architecture

What is an enclave?

A business may design a controlled environment where applicable sensitive information is handled rather than allowing that information to spread throughout the entire organization. This is the concept of an enclave.

An enclave can potentially help manage scope, but only if architecture, data flows, and controls actually support that boundary. An enclave does not automatically solve CMMC. It is a design approach that must be validated against your actual environment and the applicable scoping guidance.

Tools

Can we just use a CMMC compliance tool?

No tool alone makes a company CMMC compliant. Compliance platforms can be useful for tracking requirements, evidence management, documentation, tasks, assessments, and POA&M management where permitted. But the organization still has to implement the underlying technical and operational requirements.

A compliance dashboard can help you track the work. It doesn't perform the work for you.

Documentation

What is a System Security Plan, and what is a POA&M?

System Security Plan (SSP)

The SSP documents the relevant system environment and how applicable security requirements are implemented. Documentation must match reality. Your SSP should describe the environment you actually operate, not the environment you hope to have someday.

Plan of Action and Milestones (POA&M)

A POA&M describes how the organization plans to address requirements not yet fully implemented. Current CMMC rules place limitations and conditions around the use of POA&Ms. Not every missing requirement can simply be placed on a POA&M. Verify current DoD requirements before relying on a POA&M strategy.

The Reality

CMMC isn't just an IT project

CMMC can involve leadership, IT, cybersecurity, HR, operations, contracts, facilities, employees, and external service providers. Technology is only one component. Policies that aren't followed do not solve the problem. Technology without documentation doesn't solve the entire problem either.

Pitfalls

Common CMMC mistakes

Starting with products before determining scope
Assuming every DoD contractor automatically needs Level 2
Not knowing whether the business handles FCI or CUI
Allowing CUI to spread throughout the company
Assuming Microsoft 365 licensing alone solves compliance
Writing policies that don't match actual operations
Treating documentation as an afterthought
Assuming an MSP can certify the business
Waiting until a contract opportunity requires CMMC before beginning
Buying a 'CMMC solution' without understanding what requirement it addresses
Interactive Tool

Where should I start with CMMC?

This educational tool helps you think through where you are in the CMMC process. It cannot determine your contractual obligations.

Does your company perform work for the Department of Defense or a DoD prime or subcontractor?

Do your contracts contain cybersecurity requirements such as FAR 52.204-21 or DFARS 252.204-7012?

Does your organization receive, store, process, or transmit FCI?

Does your organization receive, store, process, or transmit CUI?

Do you know exactly where that information is stored?

Do you know which employees and systems can access it?

Do you have a documented system or security scope?

Do you have a current System Security Plan where applicable?

Answer all 8 questions to see your starting-point summary.

The Path

A practical CMMC roadmap

Compliance is a process, not a single purchase. Here is a practical sequence from contract review through ongoing maintenance.

1

Contract review

Determine applicable cybersecurity clauses and requirements in your contracts.

2

Identify FCI and CUI

Understand what information the business actually handles.

3

Map data flows

Determine where that information enters, lives, and travels.

4

Determine scope

Identify applicable users, devices, systems, and service providers.

5

Gap assessment

Compare current controls with applicable requirements.

6

Remediation

Correct technical and operational gaps.

7

Documentation

Build or update SSP, policies, procedures, and evidence as applicable.

8

Internal readiness review

Verify that documentation and technical reality match.

9

Required assessment

Complete the applicable self-assessment or authorized third-party or government assessment based on the CMMC requirement.

10

Maintain the environment

Compliance is not finished the day an assessment is completed.

Compliance is not finished the day an assessment is completed. The environment must be maintained, documented, and verified on an ongoing basis.

Budgeting

How much does CMMC cost?

There is no single number. Cost depends heavily on your current security maturity, CMMC level, number of users, number of systems in scope, existing Microsoft or cloud environment, current cybersecurity tools, documentation maturity, required remediation, and external assessment requirements.

Current security maturity
CMMC level required
Number of users
Number of systems in scope
Existing Microsoft or cloud environment
Current cybersecurity tools
Documentation maturity
Whether CUI can be effectively segmented
Required remediation
External assessment requirements
Consulting, legal, and compliance resources

Scoping before buying technology can materially affect the size and complexity of a CMMC project. Starting with scope rather than a shopping list often produces a more manageable, less expensive effort.

Start With Scope, Not a Shopping List
Transparency

Can Titan certify us?

No. Titan IT Management does not represent itself as a C3PAO and does not issue CMMC certifications.

Official CMMC assessments must be performed according to current CMMC program requirements by the appropriate authorized assessment entity. Titan is a technical readiness partner, not an authorized certifier.

What Titan can help with

  • CMMC readiness support
  • Technical scoping
  • FCI and CUI technology mapping
  • Gap identification
  • NIST SP 800-171 technical remediation
  • Microsoft 365 and security architecture
  • Endpoint security
  • Identity and access controls
  • Logging and monitoring
  • Backup and recovery
  • Network security
  • Documentation support
  • Preparing the technical environment for an applicable assessment

What Titan does not do

  • Issue CMMC certifications
  • Perform official CMMC assessments as a C3PAO
  • Determine which CMMC level your contracts require
  • Guarantee certification outcomes
  • Provide legal advice on regulatory obligations
About Titan

A technical CMMC readiness partner

Titan IT Management helps organizations understand what they actually have, what information they are protecting, which systems are in scope, what technical gaps exist, and what needs to happen before an assessment.

Our philosophy is simple: compliance must come before claim. We will not promise instant certification, and we will not pretend a product purchase replaces the work of scoping, implementing, and documenting a real security environment.

Titan serves businesses across Florida's Treasure Coast, including Stuart, Port St. Lucie, Jensen Beach, and Fort Pierce, and can support organizations with DoD contracting requirements throughout the region.

Frequently Asked Questions

CMMC questions, answered

What is CMMC?+

CMMC, the Cybersecurity Maturity Model Certification, is the Department of Defense's cybersecurity assessment program for organizations handling certain information within the Defense Industrial Base. It provides a framework for assessing whether applicable cybersecurity requirements are being implemented. What your business needs depends largely on the information you handle and the requirements in your contracts.

Who needs CMMC?+

CMMC applies to organizations within the Defense Industrial Base that handle FCI or CUI under DoD contracts. Whether you need CMMC, and at what level, depends on your contracts and the information you handle. Not every DoD contractor automatically needs the same level. Review your contracts and applicable clauses with qualified compliance or legal resources.

What is the difference between CMMC Level 1 and Level 2?+

Level 1 focuses on protecting FCI and incorporates the basic safeguarding requirements in FAR 52.204-21, with an annual self-assessment and affirmation. Level 2 is generally associated with handling CUI and aligns with NIST SP 800-171, with either a self-assessment or a C3PAO assessment depending on the applicable requirement. Level 2 is significantly more extensive than Level 1.

What is CUI?+

Controlled Unclassified Information is information the Government creates or owns, or that an entity creates or owns for or on behalf of the Government, that requires safeguarding or dissemination controls under law, regulation, or Government-wide policy. CUI is not classified information, but it requires protection under applicable federal requirements. The National Archives CUI Program maintains the official registry of CUI categories.

What is FCI?+

Federal Contract Information is information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service. It commonly appears in contracts that include the standard FAR clause for safeguarding covered defense information. Not every file received from a DoD contractor is automatically FCI.

Does CMMC Level 2 require NIST 800-171?+

CMMC Level 2 aligns with the security requirements of NIST SP 800-171, subject to current CMMC rules. CMMC did not invent an entirely new cybersecurity framework for Level 2; NIST SP 800-171 plays a central role in the underlying safeguarding requirements for CUI. Verify which revision of NIST 800-171 currently applies under the applicable CMMC and DoD rules.

Do all DoD contractors need CMMC Level 2?+

No. The required level depends on the information you handle and your contract requirements. Organizations handling only FCI may have different requirements than those handling CUI. Do not assume every DoD contractor automatically needs Level 2. Determine what information you actually handle and review applicable contract clauses.

Can an MSP certify my company for CMMC?+

Not unless that MSP is an authorized C3PAO. CMMC readiness support and an official CMMC assessment are not the same engagement. An MSP or IT provider can help you prepare, scope, remediate, and document, but official CMMC assessments must be performed according to current CMMC program requirements by the appropriate authorized assessment entity.

What is a C3PAO?+

A C3PAO is a Certified Third-Party Assessment Organization authorized to perform applicable CMMC Level 2 assessments. The distinction between preparing for CMMC and being officially assessed by a C3PAO is important. A readiness partner helps you get ready; the C3PAO performs the official assessment.

How long does CMMC take?+

There is no universal timeframe. It depends on your current security maturity, CMMC level, number of systems in scope, documentation maturity, required remediation, and assessment scheduling. Scoping before buying technology can materially affect the size and complexity of the project. Starting early is strongly recommended.

How much does CMMC cost?+

There is no single number. Cost depends heavily on current security maturity, CMMC level, number of users and systems in scope, existing cloud environment, current cybersecurity tools, documentation maturity, whether CUI can be effectively segmented, required remediation, and external assessment requirements. Scoping before buying technology can materially affect the size and complexity of a CMMC project.

References

Official CMMC resources and further reading

Primary government and standards sources for the regulatory claims on this page. Verify all current requirements against official DoD CMMC guidance before acting.

U.S. Department of Defense

NIST

Acquisition.gov / FAR / DFARS

National Archives CUI Program

  • CUI Registry (2024)

    The official registry of Controlled Unclassified Information categories and markings maintained by the National Archives and Records Administration, the authoritative source for what constitutes CUI.

Cyber AB

  • The Cyber AB (CMMC Accreditation Body) (2024)

    The authorized accreditation body for the CMMC ecosystem, including information on C3PAOs, Certified Assessors, and the CMMC assessment process. Useful for understanding the authorized assessment landscape.

Microsoft

  • Microsoft 365 compliance and GCC High documentation (2025)

    Microsoft documentation covering cloud environments relevant to CUI and CMMC, including GCC, GCC High, and data residency considerations. Do not assume any Microsoft environment is automatically appropriate for every CMMC use case without evaluating your contracts and applicable requirements.

Ready to start with scope, not a shopping list?

Whether you are preparing for your first DoD contract or already working through CMMC requirements, Titan can help you understand your environment, map your data, identify gaps, and prepare for an assessment the right way.