Compliance & GRC

CMMC 2.0 Is Live. Most of the Defense Supply Chain Is Not Ready.

Aug 22, 20265 min read

The SPRS portal has your score. You entered it yourself. The question is whether anyone would recognize it as accurate.

The Department of Defense's CMMC 2.0 final rule became effective in December 2024, and contracts carrying the CMMC requirement have been flowing into the defense industrial base since early 2025. Organizations that were paying attention have spent the last eighteen months figuring out what NIST SP 800-171 actually requires and how far from compliance they actually are. Organizations that were not paying attention are finding out now, which is a worse time to find out.

What CMMC 2.0 Actually Is

CMMC is a certification framework that makes cybersecurity requirements in DoD contracts enforceable in a new way. The requirements themselves are not new. NIST SP 800-171, which specifies 110 security practices for protecting Controlled Unclassified Information in non-federal systems, has been a DFARS contract requirement since 2017. What was missing was any meaningful verification that contractors were actually complying with it.

The previous approach was self-attestation. You submitted a Supplier Performance Risk System (SPRS) score representing your implementation of the 110 practices. The DoD had limited means to verify that score. Many contractors submitted optimistic numbers. CMMC addresses that by introducing third-party assessment requirements for contractors handling more sensitive information and by adding certification as a contract award condition rather than a terms-of-performance obligation.

Three Levels with Very Different Requirements

CMMC 2.0 defines three maturity levels.

Level 1 applies to contractors handling only Federal Contract Information (FCI), not CUI. The requirements are 17 basic cybersecurity practices drawn from FAR 52.204-21. Self-attestation by a senior official confirms compliance. Most large primes and their direct subs will be above Level 1.

Level 2 covers contractors handling CUI. The requirement is all 110 practices from NIST SP 800-171. For most contracts, Level 2 requires a third-party assessment by a Certified Third-Party Assessor Organization (C3PAO). A subset of less critical programs may still allow annual self-attestation, but those cases are narrower than many assumed. The C3PAO assessment is a multi-day engagement that produces a score against each practice, a final score, and a Plan of Action and Milestones for anything not fully implemented.

Level 3 applies to contractors handling CUI on higher-risk programs. It builds on Level 2 and adds requirements from NIST SP 800-172. Assessment for Level 3 is conducted by the Defense Contract Management Agency, not a commercial C3PAO. Very few companies will need this, and the ones who do will know it.

The Score Problem

Since 2017, contractors have submitted SPRS scores based on self-assessment of their 110-practice implementation. A perfect score is 110. Deductions are specified by practice, ranging from 1 to 5 points. Contractors were supposed to calculate their actual score and report it accurately.

Many did not. Scores clustering near 110 across a wide range of contractor sophistication was a clear signal that self-assessment was not producing accurate data. The False Claims Act creates liability for contractors who submit false certifications to the federal government. A company that submitted a SPRS score of 95 when the actual state of their controls would produce a score of 42 may have False Claims Act exposure, regardless of whether CMMC certification is separately required.

The civil investigation and qui tam suit avenue under the FCA has become a real risk for defense contractors following the DoJ's Civil Cyber-Fraud Initiative, which explicitly targets cybersecurity misrepresentations in federal contracts. A few enforcement actions have made the exposure concrete enough that contractors can no longer treat inaccurate SPRS scores as a low-probability problem.

The FCI vs. CUI Distinction Trips Organizations Up

The first thing most companies get wrong is determining which level applies to them.

FCI is information provided by or generated for the government under a contract, not intended for public release. CUI is information the government designates as requiring safeguarding under law, regulation, or policy, with a specific marking category under the National Archives CUI registry.

The practical difference: FCI is broad and covers most defense contract work. CUI is a narrower designation applied to specific types of sensitive information, and it triggers the more demanding Level 2 requirements. Technical data for weapons systems, certain design specifications, export-controlled information, and specific categories of contract information frequently qualify as CUI. Organizations that have not formally assessed which of their information assets qualify have not answered the threshold question for their own compliance requirements.

This matters because the gap between Level 1 and Level 2 is substantial. A company that classified itself at Level 1 and discovers during a contract review that it actually handles CUI is facing a remediation timeline that may run longer than the contract award process allows.

Flow-Down Is Where the Supply Chain Problem Lives

Prime contractors who receive a CMMC requirement flow it down to subcontractors when those subs handle the same FCI or CUI. The prime is responsible for ensuring their subs meet the applicable CMMC level.

This creates a problem at the sub-tier level. A small engineering firm that has been a subcontractor on defense programs for fifteen years may have no formal security program, no NIST SP 800-171 assessment, and a SPRS score submitted because a prime required it without real understanding of what it meant. When a prime now asks them to provide their C3PAO assessment report as a condition of the subcontract, they have a compliance gap that takes months to close.

Primes that have not audited their supply chain for CMMC readiness are accepting risk they have probably not measured. A breach originating from a sub-tier contractor that was not CMMC-compliant, on a contract where the prime attested to supply chain compliance, creates problems extending well beyond the incident itself.

What the Assessment Process Actually Involves

A Level 2 C3PAO assessment is not a questionnaire. It involves an assessor team reviewing policies, configurations, system architectures, and controls across all 110 NIST SP 800-171 practices. Evidence review, technical testing, and personnel interviews are part of the process.

Organizations that have not done a thorough internal assessment against 800-171 before scheduling a C3PAO engagement are making an expensive mistake. The assessment itself typically runs tens of thousands of dollars. Arriving without a complete System Security Plan, without documented evidence of control implementation, or without a realistic understanding of your current score wastes that budget and produces a remediation workload that delays certification.

The right sequence is internal assessment, gap remediation, mock assessment, then C3PAO. The timeline from that sequence to a certification that can appear in a contract clause is typically six to eighteen months for organizations starting from a meaningful gap.

If your business depends on DoD prime contracts or sub-tier work, the time to find out where you stand was last year. The second best time is now, before the next solicitation carrying the clause arrives and the decision is made for you.