Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
CMMC 2.0 vs CMMC 1.0: What Changed and Why It Matters
If you have been following CMMC since its introduction, you may remember a more complex framework with five maturity levels and additional practices beyond NIST standards. That was CMMC 1.0. The program you see today—CMMC 2.0—is significantly different, streamlined based on industry feedback and practical implementation concerns.
CMMC stands for Cybersecurity Maturity Model Certification—the DoD’s mandatory cybersecurity program for defense contractors.
Understanding what changed helps you interpret older guidance correctly and appreciate why the current framework works the way it does.
The Original CMMC 1.0 Framework
When the DoD first announced CMMC in 2019 and released version 1.0 in January 2020, it featured:
Five Maturity Levels
| Level | Name | Controls | Focus |
|---|---|---|---|
| Level 1 | Basic | 17 practices | Basic cyber hygiene |
| Level 2 | Intermediate | 72 practices | Intermediate cyber hygiene |
| Level 3 | Good | 130 practices | Good cyber hygiene (NIST 800-171) |
| Level 4 | Proactive | 156 practices | Proactive security |
| Level 5 | Advanced | 171 practices | Advanced/progressive security |
CMMC-Unique Practices
CMMC 1.0 included practices beyond NIST SP 800-171, adding requirements the DoD considered important but that were not in existing standards.
Maturity Processes
Each level included “process maturity” requirements beyond technical practices, requiring documented processes, policies, and management oversight at increasing levels of sophistication.
Third-Party Assessment for All Levels
Every level required third-party assessment by a C3PAO—even Level 1, which covers basic safeguarding.
C3PAO stands for Certified Third-Party Assessment Organization—companies authorized to conduct CMMC assessments.
No Self-Assessment Option
Contractors could not self-assess and self-attest. All certifications require external verification.
No POA&M Allowed
Plans of Action and Milestones were not permitted. Contractors had to fully implement all controls before assessment—no gaps allowed.
POA&M stands for Plan of Action and Milestones—documents tracking security gaps and remediation plans.
Why CMMC 1.0 Faced Criticism
Industry feedback on CMMC 1.0 was significant:
Cost Concerns
Requiring third-party assessment for all contractors, including small businesses at Level 1, created substantial cost burdens. Many small contractors questioned whether they could afford compliance.
Complexity
Five levels with unique practices beyond established standards created confusion. Contractors struggled to understand requirements that did not map to existing frameworks.
Assessment Bottleneck
Requiring C3PAO assessment for everyone raised concerns about whether enough assessors would be available to certify the entire defense industrial base.
Rigidity
No self-assessment option and no POA&M allowance meant contractors either achieved perfect compliance or received nothing—no middle ground for organizations making genuine progress.
Timeline Concerns
The aggressive implementation timeline, combined with the above issues, led many to question the feasibility.
The DoD listened to this feedback and initiated a comprehensive review in 2021.
The CMMC 2.0 Overhaul
In November 2021, the DoD announced CMMC 2.0 with fundamental changes:
Three Levels Instead of Five
| Level | Name | Controls | Assessment Type |
|---|---|---|---|
| Level 1 | Foundational | 15 (FAR 52.204-21) | Self-assessment |
| Level 2 | Advanced | 110 (NIST 800-171) | Self or C3PAO |
| Level 3 | Expert | 110+ (800-171 + 800-172) | Government-led |
The intermediate levels (old Levels 2 and 4) were eliminated. The framework now aligns directly with existing standards.
Alignment with Existing Standards
CMMC 2.0 eliminated unique practices:
- Level 1 maps exactly to FAR 52.204-21 (15 requirements)
- Level 2 maps exactly to NIST SP 800-171 (110 requirements)
- Level 3 adds NIST SP 800-172 requirements
No more CMMC-unique controls that contractors had to learn separately.
Self-Assessment Options
Level 1 allows annual self-assessment with executive affirmation. Level 2 allows self-assessment for some contracts (those without critical CUI) with C3PAO assessment required only for prioritized acquisitions involving critical national security information.
CUI stands for Controlled Unclassified Information—sensitive government data requiring protection.
POA&M Allowed
Conditional certification is now possible when contractors meet 80% or more of the requirements. Remaining gaps can be documented in a POA&M with 180 days to remediate.
Reduced Assessment Burden
By allowing self-assessment for Level 1 and some Level 2 situations, the assessment bottleneck concern was addressed. Third-party assessment is reserved for higher-risk situations.
Key Differences Summary
| Aspect | CMMC 1.0 | CMMC 2.0 |
|---|---|---|
| Levels | 5 | 3 |
| Level 1 assessment | C3PAO required | Self-assessment |
| Level 2 assessment | C3PAO required | Self or C3PAO (contract-dependent) |
| Unique practices | Yes | No (aligns to NIST) |
| Process maturity | Required | Removed |
| POA&M | Not allowed | Allowed (80% threshold) |
| Conditional certification | Not available | Available |
What This Means for Contractors
If You Were Preparing for CMMC 1.0
Your preparation is not wasted:
- NIST SP 800-171 controls remain the core of Level 2
- Documentation and evidence you developed still apply
- Security investments remain valuable
- You may have less to do than originally planned
If You Are Starting Fresh
CMMC 2.0 is more approachable:
- Clear alignment with established NIST standards
- Self-assessment options reduce initial costs
- POA&M provides flexibility for achieving compliance
- Resources and guidance are more readily available
Level Selection
Understand which level applies to you:
- Level 1: You handle only FCI (Federal Contract Information), not CUI
- Level 2 Self-Assessment: You handle CUI, but contracts are not designated as requiring C3PAO assessment
- Level 2 C3PAO: You handle CU,I and contracts require third-party assessment
- Level 3: Rare; only for highest-sensitivity programs
FCI stands for Federal Contract Information—information provided by or generated for the government under contract.
Most contractors handling CUI will need Level 2. The question is whether self-assessment or C3PAO assessment applies—this is determined by contract requirements, not contractor choice.
The Regulatory Journey to CMMC 2.0
CMMC 2.0 required formal rulemaking:
Interim Rule (2020)
DFARS interim rule introduced CMMC 1.0 requirements into contracts.
DFARS stands for Defense Federal Acquisition Regulation Supplement—contract clauses for DoD acquisitions.
CMMC 2.0 Announcement (November 2021)
DoD announced the CMMC 2.0 framework changes but noted that rulemaking would be required.
Proposed Rules (2023-2024)
The DoD published proposed rules for both 32 CFR (program rule) and 48 CFR (DFARS acquisition rule) for public comment.
Final Rule (October 2024)
32 CFR Part 170 (CMMC Program Rule) was finalized, establishing the official CMMC 2.0 requirements.
DFARS Final Rule (2025)
The acquisition rule adding CMMC requirements to contracts was finalized, enabling enforcement.
Common Misconceptions
“CMMC was canceled.”
CMMC was not canceled—it was revised. CMMC 2.0 is the current, active framework now being enforced.
“I can choose self-assessment.”
For Level 2, the contract determines assessment type, not the contractor. If your contract requires C3PAO assessment, self-assessment does not satisfy the requirement.
“CMMC 2.0 is easier.”
CMMC 2.0 is simpler and more aligned with existing standards, but the security requirements are not easier. Level 2 still requires all 110 NIST SP 800-171 controls.
“I can wait until contracts require it.”
While CMMC appears in contracts through phased implementation, compliance with NIST SP 800-171 has been required since 2017 under DFARS 252.204-7012. Waiting is risky.
Looking Ahead
CMMC 2.0 is now the established framework, but evolution continues:
NIST SP 800-171 Revision 3
NIST has released Revision 3 of SP 800-171. The DoD will eventually update CMMC to reference the new revision, though timing is not yet determined.
Continuous Refinement
The DoD continues refining implementation guidance, assessment procedures, and program operations based on experience.
Expansion Beyond DoD
Other federal agencies are watching CMMC as a potential model for their own contractor cybersecurity requirements.
Stay current with DoD announcements and regulatory updates as the program matures.
Key Takeaways
CMMC 2.0 dramatically simplified the original framework by reducing five levels to three, eliminating unique practices, allowing self-assessment for lower-risk situations, and permitting POA&M for conditional certification.
The core security requirements—implementing NIST SP 800-171 controls—remain unchanged. CMMC 2.0 makes the path to compliance more practical, not less secure.
If you prepared for CMMC 1.0, your work still applies. If you are starting now, you benefit from a clearer, more achievable framework aligned with established standards.
Related Articles:
- 32 CFR Part 170: The CMMC Program Rule Explained
- CMMC Implementation Timeline and Phased Rollout
- What is CMMC Level 2?
- CMMC Level 1 Self-Assessment Guide
- 32 CFR Part 170 – CMMC Program Rule
- NIST SP 800-171 Rev 2
- DoD CIO CMMC Website
Official Sources: This article is based on DoD CMMC announcements, 32 CFR Part 170, and the evolution of the CMMC program from 2019-2025.
Confused by CMMC versions and changes? Contact Greypike for clear guidance on what applies to your business today. Ready to get started? Obolix is built for CMMC 2.0 Level 1—our platform gets you compliant in a week or less with the current requirements.