Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
Where to start with CMMC?
CMMC…where do you start?
If you’re a defense contractor facing CMMC requirements for the first time, the question “where do I start?” is completely natural. The Cybersecurity Maturity Model Certification program involves new regulations, technical requirements, and assessment processes that can feel overwhelming at first glance.
The good news is that starting CMMC compliance doesn’t require deep cybersecurity expertise or a massive budget. It requires a clear understanding of what applies to you, an honest assessment of where you stand today, and a structured approach to closing the gaps.
This guide walks you through exactly where to start with CMMC, step by step, so you can move from confusion to action.
Step 1: Understand What CMMC Is and Why It Exists
Before diving into compliance activities, take time to understand what CMMC actually requires and why the Department of Defense created it.
CMMC stands for Cybersecurity Maturity Model Certification. It’s a DoD program designed to protect sensitive information shared with defense contractors. The program was formalized through 32 CFR Part 170, published in October 2024, with phased enforcement beginning in 2025.
The program exists because adversaries have been targeting defense contractors to steal sensitive data. Previous self-attestation requirements weren’t working. Contractors claimed compliance but often weren’t actually implementing required security controls. CMMC adds verification to the process.
CMMC has three certification levels:
Level 1 protects Federal Contract Information (FCI) with 15 basic security practices. FCI is information provided by or generated for the government under contract that isn’t intended for public release. Level 1 requires a self-assessment.
Level 2 protects Controlled Unclassified Information (CUI) with 110 security requirements from NIST SP 800-171 Revision 2. CUI is more sensitive information that requires safeguarding per government regulations. Most Level 2 certifications require a third-party assessment by a C3PAO.
Level 3 provides enhanced protection for the most sensitive CUI with additional requirements from NIST SP 800-172. It requires a government-led assessment by DIBCAC.
Your required level depends on the type of information you handle for DoD contracts. Understanding this is your true starting point.
Step 2: Determine Your Required CMMC Level
Your next step is figuring out which CMMC level your contracts require. This determines everything else about your compliance journey.
Review your current contracts. Look for these DFARS clauses:
DFARS 252.204-7012 indicates you’re handling CUI and likely need Level 2. This clause has been in contracts since 2017 and requires compliance with NIST SP 800-171.
DFARS 252.204-7019 and 252.204-7020 relate to DoD assessments of your NIST SP 800-171 implementation.
DFARS 252.204-7021 specifically addresses CMMC requirements and will specify the required certification level.
Talk to your contracting officer. If your contracts don’t clearly specify, ask your contracting officer or prime contractor what level is required. As CMMC rolls out through 2025 and beyond, new solicitations will explicitly state the required level.
Evaluate future contracts. Consider what contracts you want to pursue. If you plan to bid on work involving CUI, you’ll need Level 2 regardless of current contract requirements. Planning ahead prevents scrambling later.
When in doubt, assume Level 2. If you handle any information marked as CUI or if your contracts include DFARS 252.204-7012, plan for Level 2. It’s better to prepare for a higher level than to discover you’re underprepared when a contract opportunity arises.
Step 3: Identify What Information You Handle
CMMC compliance is all about protecting specific types of information. Before you can protect it, you need to know what you have and where it lives.
Federal Contract Information (FCI) is information provided by or generated for the government under contract that isn’t intended for public release. Examples include contract documents, project schedules, meeting notes, and technical data that isn’t publicly available.
Controlled Unclassified Information (CUI) is information that requires safeguarding or dissemination controls per law, regulation, or government policy. CUI is marked or should be marked with specific designations. Common CUI categories in defense contracting include:
- Technical data and specifications
- Export-controlled information (ITAR/EAR)
- Proprietary business information
- Critical infrastructure information
- Privacy information
Conduct an information audit. Work through your organization to identify:
- What FCI and CUI do you receive from the government or prime contractors?
- What FCI and CUI do you create or generate?
- Where is this information stored (servers, workstations, cloud services, paper files)?
- How does it flow through your organization?
- Who has access to it?
- Do you share it with subcontractors or external parties?
This audit forms the foundation of your scoping effort in the next step.
Step 4: Define Your Scope
Scope determines which systems, people, and processes fall under CMMC requirements. Proper scoping is critical because it directly affects your compliance effort and cost.
Use the official scoping guidance. The DoD has published scoping guidance for each CMMC level. These documents explain how to categorize your assets and determine what’s in scope.
The CMMC Level 1 Scoping Guidance addresses FCI environments. The CMMC Level 2 Scoping Guidance provides detailed asset categories for CUI environments.
For Level 2, understand the asset categories:
CUI Assets are systems that process, store, or transmit CUI. These are definitely in scope.
Security Protection Assets are systems that provide security functions for the CUI environment (firewalls, SIEM, authentication servers). These are in scope.
Contractor Risk Managed Assets are systems that can but are not intended to process CUI. You document these and manage the risk, but they have limited assessment requirements.
Specialized Assets include IoT devices, operational technology, and other systems with constraints that limit security implementation. These require special consideration.
Out-of-Scope Assets are systems completely isolated from CUI processing with no connectivity to in-scope systems.
Consider scope reduction. The smaller your scope, the faster and cheaper your compliance effort. Strategies include:
- Creating a separate CUI enclave with dedicated systems
- Network segmentation to isolate CUI processing
- Limiting personnel with CUI access
- Using FedRAMP-authorized cloud services for CUI
- Outsourcing CUI processing to already-compliant service providers
Scope reduction isn’t about avoiding compliance. It’s about focusing your resources where they matter most.
Step 5: Conduct a Gap Assessment
Now that you know your required level and scope, you need to understand where you stand today. A gap assessment compares your current security posture against CMMC requirements.
For Level 1, assess your implementation of the 15 basic practices. These cover:
- Access control basics
- Identification and authentication
- Media protection
- Physical protection
- System and communications protection
- System and information integrity
The CMMC Level 1 Self-Assessment Guide provides the specific practices and assessment objectives.
For Level 2, assess all 110 requirements from NIST SP 800-171. The CMMC Level 2 Assessment Guide provides detailed assessment objectives for each requirement across the 14 control families.
Document your findings honestly. For each requirement, determine:
- Implemented: The control is fully in place with documentation and evidence
- Partially Implemented: Some elements are in place but gaps remain
- Not Implemented: The control is missing or not functional
Calculate your SPRS score. For Level 2, your gap assessment produces a score for the Supplier Performance Risk System. A perfect score is 110. Each unimplemented requirement reduces your score by 1, 3, or 5 points depending on the requirement’s weight. Your current SPRS score gives you a measurable starting point.
Prioritize gaps. Not all gaps are equal. Prioritize based on:
- Impact on overall security posture
- Number of other requirements affected
- Difficulty and cost of remediation
- Visibility to assessors
Step 6: Choose Your Implementation Approach
With gaps identified, decide how you’ll address them. You have several options, and most organizations use a combination.
Do it yourself. If you have internal IT and security expertise, you can implement many controls without outside help. This approach costs less in consulting fees but takes longer and risks mistakes from inexperience.
Hire a consultant. Registered Provider Organizations (RPOs) and CMMC consultants specialize in helping contractors achieve compliance. They bring experience, templates, and proven approaches that accelerate implementation. Costs vary widely based on scope and level.
Use a compliance platform. Purpose-built compliance platforms provide structure, templates, and automation that dramatically accelerate implementation. Greypike’s Obolix platform, for example, enables contractors to achieve Level 1 compliance in just one week. Instead of figuring out requirements from scratch, you follow guided workflows with pre-built templates and automated evidence collection.
Outsource your CUI environment. Some contractors choose to move CUI processing to a managed service provider with an already-compliant environment. This transfers much of the compliance burden but requires careful vendor selection and ongoing oversight.
Blend approaches. Most contractors combine methods. You might use a platform for Level 1, hire a consultant for Level 2 planning, implement technical controls internally, and outsource specific functions like security monitoring.
Step 7: Build Your Compliance Team
CMMC compliance isn’t a solo effort. You need people across your organization involved and accountable.
Executive sponsor. Someone at the leadership level must own the compliance initiative. This person secures budget, removes obstacles, and keeps the project prioritized. Without executive sponsorship, compliance efforts stall.
Project manager. Someone needs to manage timelines, track progress, coordinate activities, and keep the project moving. This could be a dedicated role or an additional responsibility for someone with project management experience.
IT/Security lead. Technical implementation falls primarily on your IT team. If you don’t have dedicated IT staff, you may need to bring in external support for technical controls.
Compliance lead. Someone should own documentation, policies, procedures, and evidence collection. This person ensures you can prove your implementation to assessors.
Department representatives. Each department that touches FCI or CUI needs a representative who understands processes, can implement changes, and ensures staff compliance.
For small businesses, one or two people might wear multiple hats. For larger organizations, you may have dedicated teams. Scale your team to your organization size and compliance scope.
Step 8: Create Your Roadmap
With your team in place, build a detailed roadmap from current state to certification.
Set a target date. Work backward from when you need certification. Consider:
- Contract requirements and deadlines
- Time needed for implementation
- Assessment scheduling and availability
- Buffer for unexpected issues
Break work into phases. Organize your implementation into logical phases:
- Documentation development (SSP, policies, procedures)
- Technical implementation (controls, configurations, tools)
- Process implementation (training, incident response, access management)
- Evidence collection and organization
- Internal review and remediation
- Formal assessment
Assign responsibilities. Each task needs an owner with a deadline. Vague assignments create gaps. Specific accountability drives progress.
Identify dependencies. Some activities depend on others. Map these dependencies so you don’t create bottlenecks. For example, you can’t collect evidence for a control you haven’t implemented.
Build in checkpoints. Schedule regular reviews to assess progress, identify obstacles, and adjust the plan as needed. Monthly checkpoints work well for most implementation timelines.
Step 9: Start with Quick Wins
Beginning with quick wins builds momentum and demonstrates progress. Early successes also give your team confidence and experience before tackling harder challenges.
Level 1 quick wins:
- Enable antivirus and ensure it’s updating
- Verify screen locks activate after inactivity
- Review and limit user access to FCI systems
- Secure physical access to server rooms and IT equipment
- Create basic security awareness training
Level 2 quick wins:
- Enable multi-factor authentication where possible
- Verify encryption for data in transit (TLS/HTTPS)
- Document your existing security practices
- Update and patch systems on a regular schedule
- Review and document your network architecture
These early activities often close multiple gaps and create foundation for more complex controls.
Step 10: Tackle Documentation Early
Many contractors implement security controls but fail to document them properly. CMMC assessors evaluate both implementation and documentation. Start documentation early and build it as you go.
System Security Plan (SSP). This is your primary compliance document for Level 2. It describes your CUI environment and how you implement each of the 110 requirements. Start your SSP early and update it continuously as you implement controls.
Policies. Create or update policies for each control family. Policies state what you do and why. They establish expectations and requirements for your organization.
Procedures. Procedures explain how to implement policies step by step. They provide the detailed instructions staff need to follow.
Evidence. Collect evidence as you implement each control. Screenshots, configuration exports, training records, and logs prove you’ve done what you claim.
Keep everything organized. Create a logical folder structure mapped to CMMC requirements. When assessment time comes, you’ll be able to quickly locate evidence for any requirement.
Step 11: Address Technical Gaps
Technical controls often require the most time and investment. Plan these implementations carefully.
Common technical gaps for Level 2:
Access Control. Implement role-based access, privileged access management, and session controls. Limit access to CUI based on job function.
Multi-Factor Authentication. Enable MFA for all remote access, privileged access, and access to CUI systems.
Encryption. Encrypt CUI at rest and in transit. This includes full-disk encryption, database encryption, and TLS for network communications.
Audit Logging. Configure centralized logging that captures security events. Implement log retention, review, and alerting.
Network Security. Segment your network to isolate CUI systems. Implement firewalls, intrusion detection, and boundary protection.
Endpoint Protection. Deploy endpoint detection and response (EDR), maintain antivirus, and control removable media.
Sequence implementations logically. Some controls depend on others. For example, centralized logging requires log sources to be configured first. Build your sequence based on dependencies.
Step 12: Train Your People
Technology alone doesn’t create compliance. Your people need to understand requirements and follow proper procedures.
Security awareness training. All personnel with access to FCI or CUI need basic security training. Cover topics like phishing, password security, physical security, and incident reporting.
Role-based training. Staff with specific security responsibilities need additional training. IT administrators need training on secure configuration. Managers need training on access control decisions.
Incident response training. Personnel need to know how to recognize and report security incidents. Your incident response team needs training on investigation and response procedures.
Document all training. Keep records of who completed what training and when. Training records are evidence for multiple CMMC requirements.
Make training ongoing. Initial training isn’t enough. Implement refresher training at least annually, plus additional training when threats or procedures change.
Step 13: Prepare for Assessment
As you complete implementation, shift focus to assessment preparation.
Conduct an internal review. Walk through every requirement as an assessor would. Verify controls are implemented and evidence is available. Identify and fix gaps before the formal assessment.
Prepare your team. Staff will be interviewed during the assessment. Brief them on what to expect and how to respond. They should be able to explain their security responsibilities and how controls work.
Organize your evidence. Assessors will request evidence for each requirement. Have it organized and accessible. Create an index that maps evidence to specific requirements.
Schedule your assessment. For Level 2, contact C3PAOs well in advance. Assessment availability may be limited, especially as more contractors pursue certification. Booking early gives you flexibility on timing.
Plan for findings. Few organizations pass assessment without any findings. Understand how Plans of Action and Milestones (POA&Ms) work and be prepared to address findings promptly.
Where to start with CMMC? Getting Started Today
The best time to start CMMC compliance was yesterday. The second best time is today.
If you’re pursuing Level 1, Greypike’s Obolix platform can have you compliant in just one week. You’ll get guided workflows, pre-built templates, automated evidence collection, and clear steps from start to SPRS submission.
If you’re pursuing Level 2 or Level 3, start with scoping and gap assessment. Understand your current state, build your team, and create a realistic roadmap to certification.
Regardless of level, take that first step today. The contractors who start now will be ready when their contracts require certification. Those who wait may find themselves scrambling to compete.
Key Takeaways
Start by understanding your required CMMC level based on the information you handle and your contract requirements.
Define your scope carefully to focus compliance efforts and reduce unnecessary burden.
Conduct an honest gap assessment to understand where you stand and what needs remediation.
Build a team with executive sponsorship, clear roles, and cross-functional representation.
Create a detailed roadmap with phases, milestones, and accountability.
Begin with quick wins to build momentum and demonstrate progress.
Document as you implement rather than scrambling before assessment.
Use available tools and expertise to accelerate your timeline and avoid common mistakes.
Sources and References
- 32 CFR Part 170 — Cybersecurity Maturity Model Certification (CMMC) Program Final Rule
- CMMC Model Overview — Department of Defense
- CMMC Level 1 Scoping Guidance — Department of Defense
- CMMC Level 1 Self-Assessment Guide — Department of Defense
- CMMC Level 2 Scoping Guidance — Department of Defense
- CMMC Level 2 Assessment Guide — Department of Defense
- NIST SP 800-171 Revision 2 — Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- NIST SP 800-172 — Enhanced Security Requirements for Protecting Controlled Unclassified Information
- DFARS Clause 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting
- DFARS Clause 252.204-7021 — CMMC Requirements
- Supplier Performance Risk System (SPRS) — DoD Contractor Assessment Repository
- The Cyber AB — CMMC Accreditation Body
Ready to start your CMMC compliance journey? Contact Greypike for expert guidance, or get started with Obolix to achieve Level 1 compliance in just one week.