What Is CMMC?
CMMC is the Department of Defense's cybersecurity assessment program for organizations handling certain information within the Defense Industrial Base. What your business needs depends largely on the information you handle and the requirements in your contracts.
If your business performs work for the Department of Defense, directly or through another contractor, your contracts may require specific cybersecurity protections. CMMC provides a framework for assessing whether applicable requirements are being implemented.
CMMC obligations depend on contracts, information handled, system scope, and other factors. This page provides general educational information and is not legal advice or a guarantee of certification. Verify current requirements against official DoD CMMC guidance and your applicable contracts.
Start with the data, not the checklist
A company should not begin its CMMC journey by blindly trying to apply every possible control to every computer.
CMMC is partly a cybersecurity problem, but it is also a data-flow and scoping problem.
Thoughtful scoping may help an organization avoid unnecessarily bringing unrelated systems into the CMMC environment. Scope decisions must reflect actual data flows and applicable CMMC scoping guidance. Segmentation or enclaving does not automatically reduce scope unless the architecture, data flows, and controls actually support that boundary.
FCI vs. CUI: the first big distinction
Different information types carry different safeguarding requirements. Knowing which you handle determines what applies.
Federal Contract Information (FCI)
Federal Contract Information (FCI) is information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service. Not every file from a DoD contractor is FCI, but it commonly appears in contracts that include the standard FAR clause for safeguarding covered defense information.
Controlled Unclassified Information (CUI)
Controlled Unclassified Information (CUI) is information the Government creates or owns, or that an entity creates or owns for or on behalf of the Government, that requires safeguarding or dissemination controls under law, regulation, or Government-wide policy. CUI is not classified information, but it requires protection under applicable federal requirements. The National Archives CUI Program maintains the official CUI Registry of categories.
Not every file received from a DoD contractor is automatically CUI. The category depends on the markings, the contract, and the applicable CUI categories. The National Archives CUI Registry is the authoritative source for what counts as CUI.
The three CMMC levels
Each level addresses a different information concern and a different assessment mechanism. Verify current DoD rules for your situation.
CMMC Level 1
Protecting FCI
Level 1 focuses on protecting Federal Contract Information and incorporates the basic safeguarding requirements found in FAR 52.204-21. Level 1 is less complex than Level 2, but organizations still need to implement and verify the applicable requirements. Under current CMMC rules, Level 1 involves an annual self-assessment with an annual affirmation by a company executive.
CMMC Level 2
Protecting CUI
Level 2 is generally associated with organizations handling CUI and aligns with the security requirements of NIST SP 800-171, subject to current CMMC requirements. Depending on the contract and the type of CUI involved, Level 2 may involve either a self-assessment with annual affirmation or an assessment by an authorized C3PAO on a triennial cycle. Verify the current rules for your specific situation.
CMMC Level 3
Higher-risk CUI
Level 3 is intended for higher-risk situations involving CUI and includes additional requirements beyond Level 2, drawing on NIST SP 800-171 and NIST SP 800-172. Level 3 involves a government-led assessment. This level is not commonly required for ordinary small defense subcontractors. Verify current DoD requirements before assuming Level 3 applies.
CMMC Level 1 vs. Level 2
| Question | Level 1 | Level 2 |
|---|---|---|
| Primary information concern | FCI | CUI |
| Security requirements | FAR 52.204-21 basic safeguarding requirements | NIST SP 800-171 requirements under applicable CMMC rules |
| Assessment type | Annual self-assessment with annual affirmation | Self-assessment or C3PAO assessment depending on applicable requirement |
| Complexity | Foundational | Significantly more extensive |
| Documentation | Required as applicable | Substantially more extensive, including a System Security Plan |
Do not hard-code counts of practices, assessment intervals, or affirmation periods without verifying them against current official CMMC sources, as these can change.
Where does NIST 800-171 fit?
CMMC did not simply invent an entirely new cybersecurity framework for Level 2. NIST SP 800-171 plays a central role in the underlying safeguarding requirements for CUI. At a high level, the relationship runs through DFARS, NIST SP 800-171, CMMC, and CUI.
Defense contracts commonly require contractors handling CUI to implement the security requirements in NIST SP 800-171. CMMC Level 2 aligns with those same requirements, subject to current CMMC rules. This is why two businesses can both say they are "doing NIST 800-171" but face very different CMMC assessment paths.
Do not mix requirements from different NIST 800-171 revisions without understanding which revision currently applies under the applicable CMMC and DoD rules. Verify the current revision before relying on any specific control wording.
CMMC Level 2 aligns with NIST SP 800-171. The official NIST publication is the authoritative source for the underlying security requirements. Link directly to the current revision before acting on any specific control.
What is a C3PAO?
A C3PAO is a Certified Third-Party Assessment Organization authorized to perform applicable CMMC Level 2 assessments. Not every IT or compliance company is a C3PAO.
The distinction between a readiness partner and an authorized assessor is important. A readiness partner helps you prepare, scope, remediate, and document. The C3PAO performs the official assessment. These are different engagements with different roles and responsibilities.
CMMC readiness and an official CMMC assessment are not the same engagement.
What is SPRS?
SPRS, the Supplier Performance Risk System, is a DoD system where contractors may enter cybersecurity assessment information, including the results of NIST SP 800-171 assessments. DoD contractors may encounter it in connection with reporting assessment methodology and scores.
Having an SPRS score does not mean a business is CMMC certified. SPRS is a reporting and risk-management tool, not a certification. Verify all current SPRS requirements and relationships against official DoD sources.
What does CMMC actually affect?
Depending on scope, CMMC readiness can touch many parts of your technology environment.
CMMC is not a product you install. No firewall, EDR platform, Microsoft license, or compliance dashboard makes an organization CMMC compliant by itself.
Microsoft 365 and CMMC
Organizations handling CUI need to evaluate whether their cloud services and configurations satisfy applicable requirements. This can involve Microsoft 365 environment, identity, MFA, data location, email, SharePoint, OneDrive, Teams, logging, administrative access, and applicable federal cloud and security requirements.
Microsoft 365 Commercial and government-focused Microsoft cloud environments are not automatically interchangeable for every CMMC or CUI use case. Do not make a universal recommendation to migrate to GCC, GCC High, or another environment without evaluating your contracts, CUI, export-control considerations, and applicable requirements.
Does every computer have to be CMMC compliant?
Not necessarily. Scope matters. The correct question is: which people, systems, applications, security assets, and service providers are within the applicable CMMC assessment scope?
Consider a 40-person contractor where only a subset of employees need access to CUI. Instead of assuming all 40 users and every system belong in the same environment, the company maps who needs CUI, where CUI is stored, how CUI is accessed, and what systems protect that environment. Then scope is determined according to current official CMMC scoping guidance.
Smaller scope does not mean weaker security. It means accurately identifying the environment that must meet the applicable requirements.
What is an enclave?
A business may design a controlled environment where applicable sensitive information is handled rather than allowing that information to spread throughout the entire organization. This is the concept of an enclave.
An enclave can potentially help manage scope, but only if architecture, data flows, and controls actually support that boundary. An enclave does not automatically solve CMMC. It is a design approach that must be validated against your actual environment and the applicable scoping guidance.
Can we just use a CMMC compliance tool?
No tool alone makes a company CMMC compliant. Compliance platforms can be useful for tracking requirements, evidence management, documentation, tasks, assessments, and POA&M management where permitted. But the organization still has to implement the underlying technical and operational requirements.
A compliance dashboard can help you track the work. It doesn't perform the work for you.
What is a System Security Plan, and what is a POA&M?
System Security Plan (SSP)
The SSP documents the relevant system environment and how applicable security requirements are implemented. Documentation must match reality. Your SSP should describe the environment you actually operate, not the environment you hope to have someday.
Plan of Action and Milestones (POA&M)
A POA&M describes how the organization plans to address requirements not yet fully implemented. Current CMMC rules place limitations and conditions around the use of POA&Ms. Not every missing requirement can simply be placed on a POA&M. Verify current DoD requirements before relying on a POA&M strategy.
CMMC isn't just an IT project
CMMC can involve leadership, IT, cybersecurity, HR, operations, contracts, facilities, employees, and external service providers. Technology is only one component. Policies that aren't followed do not solve the problem. Technology without documentation doesn't solve the entire problem either.
Common CMMC mistakes
Where should I start with CMMC?
This educational tool helps you think through where you are in the CMMC process. It cannot determine your contractual obligations.
Does your company perform work for the Department of Defense or a DoD prime or subcontractor?
Do your contracts contain cybersecurity requirements such as FAR 52.204-21 or DFARS 252.204-7012?
Does your organization receive, store, process, or transmit FCI?
Does your organization receive, store, process, or transmit CUI?
Do you know exactly where that information is stored?
Do you know which employees and systems can access it?
Do you have a documented system or security scope?
Do you have a current System Security Plan where applicable?
Answer all 8 questions to see your starting-point summary.
A practical CMMC roadmap
Compliance is a process, not a single purchase. Here is a practical sequence from contract review through ongoing maintenance.
Contract review
Determine applicable cybersecurity clauses and requirements in your contracts.
Identify FCI and CUI
Understand what information the business actually handles.
Map data flows
Determine where that information enters, lives, and travels.
Determine scope
Identify applicable users, devices, systems, and service providers.
Gap assessment
Compare current controls with applicable requirements.
Remediation
Correct technical and operational gaps.
Documentation
Build or update SSP, policies, procedures, and evidence as applicable.
Internal readiness review
Verify that documentation and technical reality match.
Required assessment
Complete the applicable self-assessment or authorized third-party or government assessment based on the CMMC requirement.
Maintain the environment
Compliance is not finished the day an assessment is completed.
Compliance is not finished the day an assessment is completed. The environment must be maintained, documented, and verified on an ongoing basis.
How much does CMMC cost?
There is no single number. Cost depends heavily on your current security maturity, CMMC level, number of users, number of systems in scope, existing Microsoft or cloud environment, current cybersecurity tools, documentation maturity, required remediation, and external assessment requirements.
Scoping before buying technology can materially affect the size and complexity of a CMMC project. Starting with scope rather than a shopping list often produces a more manageable, less expensive effort.
Can Titan certify us?
No. Titan IT Management does not represent itself as a C3PAO and does not issue CMMC certifications.
Official CMMC assessments must be performed according to current CMMC program requirements by the appropriate authorized assessment entity. Titan is a technical readiness partner, not an authorized certifier.
What Titan can help with
- CMMC readiness support
- Technical scoping
- FCI and CUI technology mapping
- Gap identification
- NIST SP 800-171 technical remediation
- Microsoft 365 and security architecture
- Endpoint security
- Identity and access controls
- Logging and monitoring
- Backup and recovery
- Network security
- Documentation support
- Preparing the technical environment for an applicable assessment
What Titan does not do
- Issue CMMC certifications
- Perform official CMMC assessments as a C3PAO
- Determine which CMMC level your contracts require
- Guarantee certification outcomes
- Provide legal advice on regulatory obligations
A technical CMMC readiness partner
Titan IT Management helps organizations understand what they actually have, what information they are protecting, which systems are in scope, what technical gaps exist, and what needs to happen before an assessment.
Our philosophy is simple: compliance must come before claim. We will not promise instant certification, and we will not pretend a product purchase replaces the work of scoping, implementing, and documenting a real security environment.
Titan serves businesses across Florida's Treasure Coast, including Stuart, Port St. Lucie, Jensen Beach, and Fort Pierce, and can support organizations with DoD contracting requirements throughout the region.
CMMC questions, answered
What is CMMC?+
CMMC, the Cybersecurity Maturity Model Certification, is the Department of Defense's cybersecurity assessment program for organizations handling certain information within the Defense Industrial Base. It provides a framework for assessing whether applicable cybersecurity requirements are being implemented. What your business needs depends largely on the information you handle and the requirements in your contracts.
Who needs CMMC?+
CMMC applies to organizations within the Defense Industrial Base that handle FCI or CUI under DoD contracts. Whether you need CMMC, and at what level, depends on your contracts and the information you handle. Not every DoD contractor automatically needs the same level. Review your contracts and applicable clauses with qualified compliance or legal resources.
What is the difference between CMMC Level 1 and Level 2?+
Level 1 focuses on protecting FCI and incorporates the basic safeguarding requirements in FAR 52.204-21, with an annual self-assessment and affirmation. Level 2 is generally associated with handling CUI and aligns with NIST SP 800-171, with either a self-assessment or a C3PAO assessment depending on the applicable requirement. Level 2 is significantly more extensive than Level 1.
What is CUI?+
Controlled Unclassified Information is information the Government creates or owns, or that an entity creates or owns for or on behalf of the Government, that requires safeguarding or dissemination controls under law, regulation, or Government-wide policy. CUI is not classified information, but it requires protection under applicable federal requirements. The National Archives CUI Program maintains the official registry of CUI categories.
What is FCI?+
Federal Contract Information is information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service. It commonly appears in contracts that include the standard FAR clause for safeguarding covered defense information. Not every file received from a DoD contractor is automatically FCI.
Does CMMC Level 2 require NIST 800-171?+
CMMC Level 2 aligns with the security requirements of NIST SP 800-171, subject to current CMMC rules. CMMC did not invent an entirely new cybersecurity framework for Level 2; NIST SP 800-171 plays a central role in the underlying safeguarding requirements for CUI. Verify which revision of NIST 800-171 currently applies under the applicable CMMC and DoD rules.
Do all DoD contractors need CMMC Level 2?+
No. The required level depends on the information you handle and your contract requirements. Organizations handling only FCI may have different requirements than those handling CUI. Do not assume every DoD contractor automatically needs Level 2. Determine what information you actually handle and review applicable contract clauses.
Can an MSP certify my company for CMMC?+
Not unless that MSP is an authorized C3PAO. CMMC readiness support and an official CMMC assessment are not the same engagement. An MSP or IT provider can help you prepare, scope, remediate, and document, but official CMMC assessments must be performed according to current CMMC program requirements by the appropriate authorized assessment entity.
What is a C3PAO?+
A C3PAO is a Certified Third-Party Assessment Organization authorized to perform applicable CMMC Level 2 assessments. The distinction between preparing for CMMC and being officially assessed by a C3PAO is important. A readiness partner helps you get ready; the C3PAO performs the official assessment.
How long does CMMC take?+
There is no universal timeframe. It depends on your current security maturity, CMMC level, number of systems in scope, documentation maturity, required remediation, and assessment scheduling. Scoping before buying technology can materially affect the size and complexity of the project. Starting early is strongly recommended.
How much does CMMC cost?+
There is no single number. Cost depends heavily on current security maturity, CMMC level, number of users and systems in scope, existing cloud environment, current cybersecurity tools, documentation maturity, whether CUI can be effectively segmented, required remediation, and external assessment requirements. Scoping before buying technology can materially affect the size and complexity of a CMMC project.
Official CMMC resources and further reading
Primary government and standards sources for the regulatory claims on this page. Verify all current requirements against official DoD CMMC guidance before acting.
U.S. Department of Defense
- Cybersecurity Maturity Model Certification (CMMC) Program (2024)
The official DoD CMMC Program page, including the CMMC 2.0 final rule (32 CFR Part 170) establishing the three-level framework, assessment requirements, and implementation timelines. This is the primary authority for current CMMC requirements.
NIST
- NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (2024)
The security requirements that underpin CMMC Level 2. Verify which revision currently applies under applicable CMMC and DoD rules, as requirements can differ between revisions.
- NIST SP 800-172, Enhanced Security Requirements (2021)
Additional requirements referenced by CMMC Level 3 for higher-risk CUI situations.
Acquisition.gov / FAR / DFARS
- FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems (2016)
The Federal Acquisition Regulation clause containing the basic safeguarding requirements that underpin CMMC Level 1 protection of FCI.
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (2016)
The Defense FAR Supplement clause requiring contractors to implement NIST SP 800-171 security requirements for protecting CUI and report cyber incidents.
National Archives CUI Program
- CUI Registry (2024)
The official registry of Controlled Unclassified Information categories and markings maintained by the National Archives and Records Administration, the authoritative source for what constitutes CUI.
Cyber AB
- The Cyber AB (CMMC Accreditation Body) (2024)
The authorized accreditation body for the CMMC ecosystem, including information on C3PAOs, Certified Assessors, and the CMMC assessment process. Useful for understanding the authorized assessment landscape.
Microsoft
- Microsoft 365 compliance and GCC High documentation (2025)
Microsoft documentation covering cloud environments relevant to CUI and CMMC, including GCC, GCC High, and data residency considerations. Do not assume any Microsoft environment is automatically appropriate for every CMMC use case without evaluating your contracts and applicable requirements.
Ready to start with scope, not a shopping list?
Whether you are preparing for your first DoD contract or already working through CMMC requirements, Titan can help you understand your environment, map your data, identify gaps, and prepare for an assessment the right way.
