Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
Artificial Intelligence (AI)
1CMMC Fundamentals
6CMMC Levels & Requirements
6The 14 Control Families
14- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
Implementation Roadmaps
5Industry-Specific Guides
5CMMC Documentation & Evidence
5SPRS & Self-Assessment
5CMMC Costs & Budgeting
3Technology & Tools
6CMMC Training & Awareness
5Policies & Procedures
5- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
Supply Chain & Third-Party Risk
3Incident Response & Breach Reporting
3Common Mistakes & Failures
3Advanced Topics & Level 2
4Updates & Regulatory Changes
3Featured Articles
- How to Calculate Your SPRS Score: NIST 800-171 Scoring Guide for DoD Contractors [Updated July 2026]
- How Much Does CMMC Certification Cost? [Updated July 2026]
- CMMC Level 1 Self-Assessment Guide
- Backup and Disaster Recovery for CMMC Compliance
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Level 2 Self-Assessment Requirements
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- 72-Hour DoD Breach Notification: DFARS Reporting Requirements
- Physical Protection (PE)
- Personnel Security (PS)
- Access Control (AC)
- What is CMMC Compliance?
- What Happens if You Don't Get CMMC Certified?
- Can You Use AI and CUI?
- Understanding the 110 NIST 800-171 Controls for CMMC Level 2
- Can You Use AI and CUI?
- CMMC Implementation Timeline and Phased Rollout
- 32 CFR Part 170: The CMMC Program Rule Explained
- CMMC 2.0 vs CMMC 1.0: What Changed and Why It Matters
- Achieving Conditional CMMC Level 2 Certification with POA&M
- CMMC Level 2 C3PAO Assessment: What to Expect
- Understanding the 110 NIST 800-171 Controls for CMMC Level 2
- Top CMMC Implementation Mistakes Small Contractors Make
- CMMC Documentation Mistakes That Derail Certification
- Common CMMC Assessment Failures and How to Avoid Them
- How to Build an Incident Response Plan for CMMC Compliance
- 72-Hour DoD Breach Notification: DFARS Reporting Requirements
- CMMC Incident Response Requirements: The Three IR Controls Explained
- CMMC Requirements for Managed Service Providers
- Managing Third-Party Risk for CMMC Compliance
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- CMMC Level 2 Self-Assessment Requirements
- CMMC Level 1 Self-Assessment Guide
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- How Much Does CMMC Certification Cost? [Updated July 2026]
- How to Calculate Your SPRS Score: NIST 800-171 Scoring Guide for DoD Contractors [Updated July 2026]
- What is SPRS?
- Can You Use AI and CUI?
- CMMC Incident Response Requirements: The Three IR Controls Explained
- 72-Hour DoD Breach Notification: DFARS Reporting Requirements
- Common CMMC Assessment Failures and How to Avoid Them
- Top CMMC Implementation Mistakes Small Contractors Make
- Understanding the 110 NIST 800-171 Controls for CMMC Level 2
- CMMC Level 2 C3PAO Assessment: What to Expect
- CMMC 2.0 vs CMMC 1.0: What Changed and Why It Matters
Frequently Asked Questions
Short Answer: Certification audits are suspended as of July 13, 2026 — but if you have DoD contracts or subcontracts involving Controlled Unclassified Information (CUI), you absolutely still need the underlying compliance, and you need a self-assessed CMMC status in SPRS.
Full Answer: Here's the current state:
What you still need:
- NIST SP 800-171 implementation — DFARS 252.204-7012 has required all 110 controls since 2017, and both July 13 memos state it remains fully in effect
- CMMC Level 1 (Self) or Level 2 (Self) — Phase 1 self-assessment requirements remain in force; these are the only CMMC designations contracts may currently include
- A current SPRS score and annual affirmation — this is now the government's primary enforcement surface
- 72-hour cyber incident reporting under DFARS 7012
What's suspended:
- CMMC Level 2 (C3PAO) third-party certification — cannot be required in any solicitation or contract during the review
- Level 3 (DIBCAC) assessments and all later rollout phases
- Existing contract requirements for third-party assessment (being removed by modification)
You still don't need any of it if:
- You only handle publicly available information (no CUI, no FCI)
- You work exclusively with non-DoD federal agencies (they have different requirements)
- You provide only commercial off-the-shelf (COTS) products with no customization
What CUI includes: Technical data, engineering drawings, specifications, export-controlled data, certain performance and operational information — generally anything marked CUI or that would previously have been "For Official Use Only."
The Reality: Contractors are hearing "CMMC is suspended" and concluding "compliance is optional." Those are very different statements. The audit is gone; the legal obligation — and the False Claims Act liability attached to the score you affirm — isn't. A 60-day task force will recommend what comes next, and every plausible outcome is built on the same 110 controls you're contractually required to implement today.
Short Answer: Level 1 = 15 basic safeguarding requirements for FCI, self-assessed annually. Level 2 = all 110 NIST 800-171 controls for CUI — self-assessed during the suspension, previously headed for third-party audit. Your contract tells you which; handling CUI generally means Level 2.
Full Answer:
CMMC Level 1:
- 15 basic safeguarding requirements (from FAR 52.204-21)
- Self-assessment, entered in SPRS, with an annual senior-official affirmation
- For contracts with Federal Contract Information (FCI) only — contract performance info, pricing, delivery schedules
- Cost: $3,000–$15,000 for most small contractors (Greypike's fixed-fee Level 1 packages run $3,500–$9,500)
- Timeline: 60–90 days typically
- Never required a third-party audit — nothing about Level 1 changed on July 13
CMMC Level 2:
- All 110 NIST SP 800-171 Rev 2 controls
- Currently: self-assessment only. The C3PAO third-party requirement is suspended; contracts may only include Level 2 (Self)
- For contracts with CUI — technical data, drawings, export-controlled information
- Cost: implementation typically $50,000–$150,000+ depending on maturity and scope; see our full cost breakdown — a tightly scoped enclave changes this math dramatically
- Timeline: 4–6 months to a defensible posture, longer with significant gaps
- Self-assessments must stay current within three years, with annual affirmation
How to know which you need:
- Check your contract — it states the CMMC level and (during the suspension) will only say "Self"
- Check whether you handle CUI — if yes, you're a Level 2 shop
- Ask your contracting officer or prime
The trend: Most contractors doing anything beyond basic supplies or non-technical services handle CUI somewhere and should plan for Level 2 requirements — under whatever verification model the reform task force produces.
Short Answer: Level 1: $3,000-$8,000. Level 2: $15,000-$50,000+. Depends on your current security posture and company size.
Full Answer:
CMMC Level 1 Costs:
- Technology/Tools: $1,500-$3,000 (MFA, EDR, encrypted email, password manager, backups)
- Consultant/Implementation: $2,000-$5,000 (if you hire help)
- Internal labor: $1,000-$2,000 (your time configuring and documenting)
- Total: $3,000-$8,000 for most small contractors
CMMC Level 2 Costs:
- Gap assessment: $2,000-$5,000
- Technology/Tools: $5,000-$15,000 (more advanced security tools)
- Implementation consultant: $10,000-$30,000
- Documentation/Policies: $3,000-$8,000 (if done for you)
- C3PAO assessment fee: $5,000-$25,000 (depends on scope)
- Internal labor: $5,000-$15,000 (your staff's time)
- Total: $15,000-$50,000+ for small-medium contractors
What drives costs up:
- Multiple locations or networks
- Complex IT environments
- Poor current security posture (lots of gaps)
- Large scope (many systems handling CUI)
- Needing to replace old hardware/software
What drives costs down:
- Good existing security practices
- Small, simple network environment
- Cloud-based operations (AWS GovCloud, Azure Government)
- Doing some work yourself vs. full outsource
- Already have MFA, EDR, encrypted communications
Hidden costs people forget:
- Annual maintenance (ongoing monitoring, updates, training)
- Recertification every 3 years (Level 2)
- Staff time for evidence collection
- Potential downtime during implementation
ROI Perspective: If you have $500K-$2M+ in DoD contracts, spending $15K-$50K to protect them is a no-brainer. The cost of NOT certifying = losing all DoD revenue.
Short Answer: Level 1: 60–90 days on average. Level 2: 4–6 months to a defensible posture. The November 2026 audit deadline is gone — but that's a reason to do it right, not a reason to stop.
Full Answer:
CMMC Level 1 Timeline:
- Weeks 1–2: Gap assessment against the 15 requirements, scope your FCI
- Weeks 3–6: Implement technology (MFA, endpoint protection, backups)
- Weeks 7–8: Write policies and procedures
- Weeks 9–10: Train staff, collect evidence
- Weeks 11–12: Self-assess, enter results, senior-official affirmation
- Total: 60–90 days for most companies
CMMC Level 2 Timeline:
- Month 1: Gap assessment and roadmap, boundary definition
- Months 2–3: Technology implementation, policy development
- Month 4: Training, evidence collection, internal testing
- Months 5–6: Validation pass, corrected SPRS scoring, affirmation
- Total: 4–6 months average — significant gaps or mixed on-prem environments run longer
What changed on July 13: The old timeline ended with "schedule your C3PAO 2–3 months out and pass the audit." The new timeline ends with "submit a score you can defend and affirm it." Same work, different finish line — and no more assessor scheduling bottleneck.
Fast-track is realistic if: you're cloud-based in a compliant environment, your scope is tight (an enclave compresses everything), you have executive buy-in, and someone experienced is driving. A bounded enclave deployment can stand up a compliant Level 2 environment in weeks rather than months.
Why it takes longer than expected: scope creep (finding more systems touching CUI than you thought), waiting on hardware or licensing, staff turnover mid-project, and treating documentation as an afterthought — the SSP isn't paperwork at the end; without it, no valid score exists at all.
Pro tip: The suspension removed the deadline, not the obligation. Contractors who use this window to build honestly will onboard to whatever the reform task force produces with minimal friction. Contractors who freeze will be starting from behind — again — when the replacement lands.
Short Answer: Level 1 — yes, if you're tech-savvy and small. Level 2 — possible but hard; 110 controls with evidence behind each is a serious lift, and post-suspension there's no auditor to catch honest mistakes before the government relies on your score.
Full Answer:
You CAN do it yourself if:
- You have IT experience or technical background
- Your company is small and simple — one location, few systems, tight CUI footprint
- You have realistic time to invest (expect 40–80+ hours for Level 1, far more for Level 2)
- You're comfortable working from NIST SP 800-171A assessment objectives, not just the control titles
- You're willing to use quality templates and tooling
You SHOULD hire help if:
- You have no IT department or technical staff
- Your environment is complex — multiple locations, cloud plus on-prem
- You're a Level 2 shop (110 controls, ~320 assessment objectives, evidence for each)
- You need it done fast or need it defensible on the first pass
- Your time is worth more than the consulting fee
Hybrid approach (best for many):
- Hire out: gap assessment, boundary/architecture design, score validation
- Do yourself: policy customization from templates, some tool rollout, training
- Typical savings: 30–40% versus full outsource, with far better odds than pure DIY
The DIY risk that changed on July 13: It used to be "fail your C3PAO audit and pay to remediate and reassess." Now it's subtler and worse: nobody fails you. You self-assess, misread a requirement, post an inflated score, and your Affirming Official signs it annually — until a government-led assessment, a prime's due diligence, or a whistleblower surfaces the gap. The most common DIY errors — confusing policy with implementation, misapplying the two partial-credit rules, missing systems in scope — all inflate scores. That's exactly the fact pattern the DOJ's Civil Cyber-Fraud Initiative pursues.
A sensible middle path: DIY the implementation if you're capable, then get independent eyes on the score before anyone affirms it. That validation engagement costs a flat $7,500–$15,000 — a fraction of the audit it replaces and of the exposure it insures against.
Short Answer: Two failure modes now. Don't implement and don't bid: you lose DoD eligibility as contracts require CMMC Self statuses. Don't implement but keep affirming a compliant score: you convert a compliance gap into False Claims Act exposure. The second is far worse.
Full Answer:
If you simply don't comply and don't submit:
- Contracts with CMMC Level 1 (Self) or Level 2 (Self) requirements — which remain fully in force — are off the table
- Contracts with DFARS 7019/7020 require a current SPRS score; no score, no award
- Primes will route around you — they own supply-chain risk regardless of what the certification program does, and with government verification suspended, many are leaning harder on their own supplier requirements
If you don't comply but affirm anyway (the dangerous one):
- Your annual SPRS affirmation is a personal attestation to the federal government by a named senior official
- A knowingly inaccurate score or affirmation sits squarely inside the False Claims Act: treble damages, per-claim penalties, and cases frequently initiated by whistleblowers — often a former IT employee who knows exactly which controls existed on paper only
- The DOJ's Civil Cyber-Fraud Initiative was created for precisely this, and has already produced multimillion-dollar settlements with defense contractors over misrepresented cybersecurity
- Contract termination and suspension/debarment are also on the table
What about POA&Ms?
Contrary to a common misconception, CMMC 2.0 does allow POA&Ms for Level 2 — within limits. Conditional status requires a minimum score of 88 out of 110, POA&M items must close within 180 days, and certain critical requirements can't be POA&M'd at all. An honest score with a real POA&M is a legitimate, defensible position. That's the whole point: the system is built to reward accuracy, not perfection.
Timeline of consequences (revised):
- Now: Phase 1 self-assessment requirements in force; SPRS score checked before award; FCA enforcement active
- ~September 2026: Reform task force reports; the replacement framework takes shape
- After: Whatever returns will be built on NIST SP 800-171 — contractors with an honest, current posture onboard easily; everyone else scrambles again
Bottom line: The suspension didn't make compliance optional. It changed who catches you — from an auditor you hired to a government you certified to.
Short Answer: Your SPRS score is your self-assessed NIST 800-171 compliance, reported to the government. CMMC was the program built to verify those self-reports with third-party audits. As of July 13, 2026, the verification layer is suspended — which makes your SPRS score not a historical footnote but the whole ballgame.
Full Answer:
SPRS (Supplier Performance Risk System):
- Your self-assessment score against the 110 NIST 800-171 Rev 2 controls, on a scale from -203 to 110
- Required by DFARS 252.204-7019/7020; entered via the PIEE portal; visible to contracting officers before award
- Affirmed annually by a named senior company official
- Not an honor system in any meaningful sense anymore: the affirmation is enforceable under the False Claims Act, and government-led (DIBCAC) assessments explicitly continue during the suspension
CMMC:
- The Department's program for verifying that self-reports match reality — self-assessment at Level 1 and (until July 13) third-party C3PAO audits at Level 2
- Phase 1 (Level 1 Self and Level 2 Self statuses, entered in SPRS with affirmations) remains fully in force
- Phase 2+ (third-party verification) is suspended pending the 60-day reform review
The relationship, corrected: CMMC was never "replacing" SPRS — SPRS is the system of record where CMMC statuses, scores, and affirmations live. They're not competitors; one is the database, the other was the verification regime. With the verification regime suspended, the database entry is the compliance record.
Why verification existed at all: DoD's own assessments repeatedly found large gaps between what contractors self-reported and what government assessors found on-site — that gap is the entire reason CMMC was created. The suspension didn't declare the gap fixed; it concluded the audit model was unaffordable. The government's remaining tools for the gap are select government-led assessments and the False Claims Act.
What to do right now:
- Submit an honest score, even if it's low — accuracy is the defensible position
- If you're below 88, you have real gaps against the conditional benchmark; prioritize the 5-point controls
- If your posted score is higher than your environment supports, correcting it is the most urgent compliance task you have
- Get independent validation before your Affirming Official signs the next annual affirmation
Bottom line, inverted from the old advice: CMMC certification was the test; it's postponed. Your SPRS score is the real deal now — it's what contracting officers see, what primes check, and what the Department of Justice can hold you to.