Answer seven questions about your DoD contracts and systems. We'll tell you which CMMC level applies — and what to do next.
2 minutesNo email requiredHonest result
Question 1 of 7
0%
Question 01 / 07
Does your organization hold or bid on contracts with the U.S. Department of Defense?
This includes prime contracts, subcontracts, and any agreement where DoD is the ultimate customer.
Question 02 / 07
Does your contract involve Controlled Unclassified Information (CUI)?
CUI is government information requiring protection but not classified — technical data, export-controlled information, contract-sensitive details, or personnel records. Look for terms like CUI, ITAR, FOUO, or Export Controlled in your contract.
Question 03 / 07
Do any of your IT systems process, store, or transmit that CUI?
Email servers, file shares, cloud storage, laptops, or any device where CUI is created, accessed, or sent. If your team reads or writes CUI using any device, those systems are likely in scope.
Question 04 / 07
Does your contract contain a DFARS 252.204-7012 clause or a CMMC requirement?
DFARS 252.204-7012 is the safeguarding clause requiring NIST 800-171 compliance since 2017. CMMC requirements may appear as a separate clause. Check your contract's terms and conditions section.
Question 05 / 07
Are you a prime contractor or a subcontractor on these DoD contracts?
Subcontractors inherit their prime's CMMC requirements when they handle CUI that flows down. Even if your contract doesn't mention CMMC yet, your prime's requirement may apply to you.
Question 06 / 07
Are you planning to bid on new DoD contracts in the next 12–18 months?
Starting with Phase 2 (November 2026), new DoD solicitations involving CUI will broadly include CMMC Level 2 requirements. Certification status will increasingly affect competitive eligibility.
Question 07 / 07
How many people work at your organization?
Helps us give you a realistic picture of what implementation looks like for a firm your size.
◆ CMMC Level 2 Required
Your contracts likely require CMMC Level 2.
Based on your answers, your organization handles CUI through your own systems under a DoD contract. That puts you in CMMC Level 2 territory — which requires a third-party C3PAO assessment and compliance with all 110 NIST 800-171 controls.
Your situation at a glance
Certification required
CMMC Level 2 — C3PAO third-party assessment
Self-attestation
Not sufficient for CUI-handling contracts
Controls to implement
All 110 NIST 800-171 requirements
When it affects you
When your contract contains a CMMC clause
Recommended next steps
1
Define your CUI boundary. Identify exactly which systems handle CUI before anything else. Correct scoping reduces cost by 30–60%.
2
Review your contract language. Look for DFARS 252.204-7012 and any CMMC clause — the specific clause determines your timeline and requirements.
3
Assess your current posture. A gap assessment against NIST 800-171 tells you where you stand and what needs to close before a C3PAO assessment.
4
Book a free scoping session. We'll define your assessment boundary, identify in-scope systems, and map out your path to Level 2 certification.
Book a free scoping session
45 minutes. We define your CUI boundary and give you a clear picture of what Level 2 requires for your situation.
Based on your answers, your contracts appear to involve Federal Contract Information (FCI) but not CUI. CMMC Level 1 applies — annual self-attestation against 15 basic cybersecurity practices, not a C3PAO assessment.
Your situation at a glance
Certification required
CMMC Level 1 — annual self-attestation
C3PAO assessment needed
No — self-attestation is sufficient
Controls to implement
15 basic practices (FAR 52.204-21)
Important note
Bidding on CUI contracts requires Level 2 for those bids
Recommended next steps
1
Verify your CUI status. Confirm with your contracting officer whether your work involves CUI. If it does, this result changes to Level 2.
2
Implement the 15 Level 1 practices. Access control, identification and authentication, media protection, and more — most are straightforward for small firms.
3
Complete your annual self-attestation. Level 1 requires affirming compliance annually in the Supplier Performance Risk System (SPRS).
Not sure if CUI is involved?
A 30-minute scoping conversation confirms your status and ensures you're not over- or under-certified.
Whether CMMC applies to your contracts — and at what level — isn't clear enough for a definitive answer here. CUI classification, contract language, and subcontractor flow-down rules can be genuinely ambiguous. The right answer requires reviewing your specific contract language.
What's making this unclear
!
Whether your work involves CUI isn't confirmed — this is the most important factor to resolve first.
!
If you're a subcontractor, your prime's CMMC requirement may flow down even if your contract doesn't mention it.
!
CMMC requirements are contract-driven — two firms in the same industry can have completely different obligations.
How to get clarity
1
Pull your contract's terms and conditions. Search for "CUI," "DFARS 252.204-7012," and "CMMC." The presence of any of these triggers specific requirements.
2
If you're a subcontractor, ask your prime. Request the relevant contract clause — they're required to pass CMMC requirements down when CUI is involved.
3
Book a free scoping session. We review this question with contractors every week. A 30-minute call is usually enough for a definitive answer.
Get a definitive answer in 30 minutes
Bring your contract or a description of your work. We'll tell you exactly where you stand — even if the answer is "you don't need CMMC."
Based on your answers, your organization doesn't appear to handle CUI under a DoD contract, or your work doesn't involve systems that touch CUI. CMMC requirements are contract-driven — if your current work doesn't meet these criteria, you're not obligated to certify.
What this means
→
No CMMC certification is required based on your current answers.
→
If you plan to bid on DoD contracts involving CUI in the future, CMMC Level 2 will be required for those bids.
→
If your situation changes — new contract, new prime, new type of work — re-run this tool or book a session to confirm.
Planning to pursue CUI contracts in the future?
A scoping session helps you understand what certification would look like when you're ready.
This tool provides a general indication based on your answers and is not legal or compliance advice. CMMC requirements are driven by specific contract language and your organization's unique situation. Some contractors may not receive CMMC requirements even after Phase 2 depending on their contract vehicle and contracting officer. Always review your contract terms and consult a qualified CMMC practitioner for a definitive determination. Greypike is a Cyber AB Registered Practitioner Advanced firm.