Interweave Technologies
Aug 11
3 min

How to Get CMMC Certification and What DoD Suppliers Should Expect

Getting CMMC certification means implementing the security controls your contract requires, documenting how each one works in your environment, scoring yourself against all of them, and posting that score to a Department of Defense database. Level 1 requires 15 controls and an annual self-assessment. Level 2 requires 110 controls from NIST SP 800-171 Revision 2. Level 3 adds 24 enhanced controls on top of Level 2.

Something big changed in July 2026. The Department of War suspended Phase 2 of the CMMC rollout and opened a 60-day review of the whole program. Plenty of contractors saw that headline and eased off.

We think that is a mistake, and there is a $507,144 settlement from June 2026 that shows exactly why. This article covers what CMMC certification requires right now, what the suspension changed, what it did not change, and what the certification process actually looks like from first scoping call to annual affirmation.

What Is CMMC Certification?

CMMC certification is the Department of Defense program that verifies a contractor has implemented required cybersecurity controls before that contractor can win or keep a defense contract. CMMC stands for Cybersecurity Maturity Model Certification. The program checks two things: whether you implemented the controls, and whether you can prove it.

Proof is the part that changed defense contracting. For years, contractors simply attested that they met the cybersecurity rules. A 2019 Department of Defense Inspector General report found that defense industrial base companies were not consistently implementing the rules they had already agreed to follow. That finding produced CMMC.

The controls themselves are not new. Contractors handling covered defense information have owed the government NIST compliance since DFARS clause 252.204-7012 took effect at the end of 2017. What CMMC added was verification: a score, a database, a signature, and consequences.

Two rules built the program. The 32 CFR Part 170 program rule took effect December 16, 2024 and defined the levels, the scoring, and the assessment methods. The 48 CFR acquisition rule was published in the Federal Register on September 10, 2025 and took effect 60 days later on November 10, 2025. That second rule is the one that matters commercially, because it authorized contracting officers to write CMMC into solicitations through DFARS provision 252.204-7025 and clause 252.204-7021.

Is CMMC Still Required After the July 2026 Suspension?

Yes, CMMC is still required. On July 13, 2026, the Department of War issued policy memorandum 26-P-1023 suspending the transition to Phase 2, which had been set for November 10, 2026, along with pending and future implementation milestones. Phases 3 and 4 froze as well. A CMMC Reform Task Force began a 60-day review, and a public request for information closed August 14, 2026.

The review is real and its outcome is not yet public. What the suspension did not touch is the part that affects your next bid.

  • Phase 1 self-assessments stay mandatory. Level 1 and Level 2 self-assessment requirements that took effect November 10, 2025 still apply to contracts that carry them. The DoW CIO states plainly that all Phase 1 self-assessment requirements remain in place.
  • DFARS 252.204-7012 never moved. Your duty to safeguard covered defense information and report cyber incidents sits outside the CMMC rollout schedule entirely.
  • SPRS scores still decide awards. A contracting officer can require a current posted score before award. No score, no award.
  • NIST SP 800-171 Rev 2 is still the standard. The Department has said it will enforce that standard during the interim through self-assessments and select government-led assessments.
  • Prime flow-downs are private contracts. Your agreement with your prime is a commercial contract between two companies. A Pentagon memo does not rewrite it.
  • Existing certifications keep their value. Contractors who already earned Level 2 did not waste the money.

One structural point deserves attention. The suspension arrived as a memorandum, not as a regulation. 32 CFR Part 170 is still law. A memorandum changes what contracting officers may require, and a memorandum can be reversed as quickly as it was signed.

Your real deadline was never the rollout calendar anyway. It is the date your next solicitation, option exercise, or prime flow-down asks for a status. That date did not move, which is why we keep compliance for government contractors running on contract timelines rather than program timelines.

Which Companies Need To Be CMMC Certified?

Companies that need CMMC certification are every organization in the defense supply chain that processes, stores, or transmits Federal Contract Information or Controlled Unclassified Information under a Department of Defense contract. That covers primes, subcontractors, and suppliers at every tier.

The numbers are larger than most people expect. The Department of Defense regulatory impact analysis behind the final DFARS rule identifies 337,968 impacted entities, of which 229,818 are small businesses. That is roughly 68% small business. The same analysis expects the phased approach to touch 1,104 small entities in year one, 5,565 in year two, 18,554 in year three, and 229,818 by year four and beyond.

The information type in your systems sets your level. Federal Contract Information, defined in FAR 4.1901, is non-public information the government gives you or that you generate under a contract to deliver a product or service. Controlled Unclassified Information, defined in 32 CFR 2002.4(h), is information a law or government-wide policy requires you to safeguard. Export-controlled technical data, cybersecurity vulnerability details, and operationally sensitive program information all land in the CUI bucket.

That distinction bites harder in our region than almost anywhere. Redstone Arsenal, the Missile Defense Agency, and Army Materiel Command sit at the top of a supplier network that runs thousands of companies deep, and CUI travels down every tier of it. A machine shop receiving a technical drawing by email is handling CUI whether or not anyone has scoped it that way.

Scoping is where most contractors discover surprises. A proper gap analysis usually finds CUI sitting in email archives, shared drives, and engineering workstations nobody considered in scope.

What Is the Difference Between CMMC Level 1, Level 2, and Level 3?

The difference between the three CMMC levels is the sensitivity of the data each one protects, the number of controls required, and how the government verifies you implemented them. Level 1 protects FCI with 15 controls. Level 2 protects CUI with 110 controls. Level 3 protects critical CUI with 110 controls plus 24 enhanced ones.

The figures below come from the Department of Defense 32 CFR Part 170 final rule, the regulatory impact analysis published with it, and the DoW CIO CMMC program page as updated after the July 2026 suspension.

Attribute

Level 1 (Foundational)

Level 2 (Advanced)

Level 3 (Expert)

Data protected

FCI only

CUI

Critical CUI

Controls required

15, per FAR 52.204-21

110, per NIST SP 800-171 Rev 2

110 plus 24 from NIST SP 800-172

Verification today

Annual self-assessment

Self-assessment every 3 years; third-party expansion suspended July 2026

Government-led DIBCAC; suspended July 2026

POA&M allowed

No, per DoW CIO

Yes, closed within 180 days

Yes, closed within 180 days

DoD assessment cost estimate

$5,977 small entity; $4,042 larger

$37,000 to $49,000 self; $105,000 to $118,000 third-party

$7,000 small entity; $36,000 larger

Share of the defense base

About 63%, per DoD estimate

About 80,000 organizations

Under 1%, per DoD estimate

Level 2 carries most of the weight and most of the cost. The 110 controls span 14 families including access control, audit and accountability, configuration management, incident response, and risk assessment. Meeting all 14 families and keeping them met is a permanent operating function, which is why we deliver it as a managed compliance program rather than a project with an end date.

What Score Do You Need To Pass CMMC?

The score you need to pass CMMC Level 2 is 88 out of 110, which is 80% of the security requirements. Each of the 110 requirements in NIST SP 800-171 Rev 2 carries a point value. You start at 110 and subtract 5, 3, or 1 points for each control that is not fully implemented. The scale runs from 110 at the top down to negative 203 at the bottom.

There is no partial credit. A control is fully implemented or it is not.

Score between 88 and 109 and you can receive a Conditional CMMC Status carrying a Plan of Action and Milestones. Every POA&M item must close within 180 days through a formal closeout assessment. Certain critical controls cannot go on a POA&M at all and must be met on assessment day. Score below 88 and you receive no status.

Level 1 works differently. There is no numerical threshold. All 15 controls must be implemented, results go into the Supplier Performance Risk System, and the DoW CIO confirms POA&Ms are not permitted at Level 1 at all.

What Happens If Your SPRS Score Is Wrong?

A wrong SPRS score can turn every invoice you submitted under that contract into a false claim against the government. The affirmation you sign is a legal representation, and DFARS 252.204-7020 gives the government the right to come check your work.

A settlement announced on June 18, 2026 shows what that looks like in practice, and it happened to a company in our own city.

The Department of Justice announced that LOGZONE Inc., a Huntsville logistics services provider working two Navy contracts, agreed to pay $507,144 to resolve False Claims Act allegations. Of that, $253,572 was restitution. In October 2021, LOGZONE posted a self-assessed SPRS score of 110. A perfect score. In February 2024, the Defense Industrial Base Cybersecurity Assessment Center completed its own Medium Assessment of the same systems and scored the company at negative 170.

That is a 280-point gap, and Crowell & Moring called it among the largest in public enforcement actions involving cybersecurity noncompliance. The Department of Justice alleged that LOGZONE billed the Navy from May 2021 through March 2025 while that gap existed.

Two details make this case worth studying rather than filing away.

  1. There was no breach. Nobody broke in. No data left the building. The liability came entirely from the difference between the reported score and the implemented reality.
  2. There was no whistleblower. Most cases in this line start with a qui tam filing from a former employee. This one started with a government assessment and a referral, which means you cannot manage the risk by hoping nobody inside talks.

Enforcement is climbing sharply. The Department of Justice reported recovering $52 million across nine cybersecurity False Claims Act settlements in fiscal year 2025, part of a record $6.8 billion in total FCA recoveries. Analysis by the firm Fluet found the aggregate value of 2025 cyber settlements reached $51,849,634, a 233% increase over the $15,556,722 recovered across four settlements in 2024. Deputy Assistant Attorney General Brenna Jenny described the trend in January 2026 as a significant upward trajectory.

Here is why the July 2026 suspension makes this more dangerous rather than less. Third-party assessment was the step where an outside expert checked your math before the government saw it. With that step paused, nobody stands between an optimistic internal score and the affirmation an officer of your company signs. The risk did not go away. It moved onto your signature.

We see the same pattern behind most inflated scores, and it is rarely dishonesty. It is optimism. Multi-factor authentication enabled for administrators but not every user who touches CUI. Encryption on some file shares. Audit logging configured but missing critical events. Each of those feels mostly done. None of them scores as implemented. That gap is exactly what a proper defense contractor compliance review is built to catch before a government assessor does.

How To Get CMMC Certification Step by Step

Getting CMMC certification follows ten steps that move from level determination through scoping, remediation, documentation, self-assessment, and continuous maintenance. The sequence is the same at every level. The depth changes enormously between Level 1 and Level 2.

  1. Determine your required level. Read every current and anticipated contract. Solicitations state the required level through DFARS provision 252.204-7025, and contracts carry it through clause 252.204-7021. Ask your contracting officer in writing to resolve any ambiguity. Chasing the wrong level burns months of budget.
  2. Define your assessment scope. Map every system, network segment, and data flow that touches FCI or CUI. This single decision drives more cost than any other choice in the process.
  3. Run a gap assessment. Compare what you have against every control your level requires. Level 1 is often doable in-house. Level 2 needs outside eyes, because the distance between believing you do something and evidencing that you do it is where scores collapse.
  4. Remediate the gaps. This is the bulk of the work and the bulk of the spend. Technical controls include multi-factor authentication, FIPS-validated encryption, network segmentation, endpoint protection, audit logging, and system hardening. Policy controls include written security policies, incident response plans, access control procedures, and change management records.
  5. Build your documentation. Your system security plan describes how each control actually works in your environment, and an assessor treats it as the primary reference. A mid-sized contractor's plan commonly runs past 200 pages and takes three to four months of dedicated work. Network diagrams, training records, and configuration baselines sit alongside it.
  6. Test yourself internally. Run a mock assessment. Confirm the evidence exists, is current, and matches what the plan claims. Four to eight weeks here costs far less than a failed assessment.
  7. Score and submit to SPRS. Under Phase 1 rules, Level 1 and Level 2 organizations self-assess and post results to the Supplier Performance Risk System with a signed annual affirmation. Level 1 renews annually. Level 2 self-assessment runs on a three-year cycle with annual affirmations in between.
  8. Close your POA&M items. Every open item needs a named owner, a real date, and evidence at closeout. The 180-day clock does not pause.
  9. Maintain continuously. Annual affirmations, ongoing monitoring, current documentation. System changes, network changes, or changes in how you handle CUI can all trigger reassessment outside the normal cycle.
  10. Watch the Reform Task Force. The review may restore CMMC as written, restore it on new dates, or replace it with a different verification model. Across every one of those outcomes, the 110 NIST controls are the constant. Build to those and no result catches you unprepared.

How Do You Scope a CMMC Assessment?

You scope a CMMC assessment by drawing a boundary around only the systems that process, store, or transmit FCI or CUI, then proving that everything outside the boundary cannot reach the data inside it. Scope is the strongest cost lever in the entire program.

The reasoning is arithmetic. Each of the 110 Level 2 controls has to be implemented, documented, monitored, and evidenced on every system inside your boundary. Cut the boundary in half and you cut the recurring work roughly in half with it.

Three approaches shrink a boundary reliably. Network segmentation separates CUI systems from your general corporate network. A dedicated CUI enclave concentrates all defense work into one hardened environment, which is usually the cheapest path for a contractor where defense work is a minority of revenue. Cloud services meeting FedRAMP Moderate or equivalent requirements move part of the control burden to a provider already built for it.

Scoping mistakes are expensive in one direction only. Draw the boundary too wide and you pay to secure systems that never needed it. Draw it too narrow and an assessor finds CUI outside the line, which invalidates the assessment. Getting this right before remediation begins is the reason our advanced security engagements always start with discovery rather than deployment.

How Long Does CMMC Certification Take?

CMMC certification takes 5 to 10 months for Level 1, 18 to 30 months for Level 2, and 24 to 36 months or more for Level 3. Three things move that range: your starting security maturity, how complex your environment is, and how much internal capacity you can genuinely commit.

Level 1 moves fast because it is 15 controls and a self-assessment. Gap assessment takes one to two months, remediation three to six, documentation one to two, and the self-assessment itself a week or two.

Level 2 is a different scale of effort. Implementing 110 controls typically consumes 12 to 18 months on its own for an organization with moderate security maturity. Gap assessment adds two to four months, assessment preparation another two to three. Contractors already operating under NIST 800-171 compress that considerably. Contractors starting from a low baseline should add six to twelve months to any estimate they have been handed.

The July 2026 suspension removed the November 2026 cliff, and that is genuine breathing room. There is a trap inside it. Fewer than 100 authorized third-party assessment organizations exist against roughly 80,000 organizations the Department of Defense expects to need Level 2. If the Reform Task Force restores third-party assessment on a compressed schedule, that bottleneck returns immediately, and the contractors who spent the pause remediating will be the ones who can book a slot.

How Much Does CMMC Certification Cost?

CMMC certification costs roughly $15,000 to $120,000 in the first year for Level 1 and $100,000 to $300,000 for Level 2, with the assessment itself accounting for only part of the total. Remediation is where most of the money goes.

The Department of Defense published assessment-only figures in its regulatory impact analysis. Level 1 annual self-assessment and affirmation runs $5,977 for a small entity and $4,042 for a larger one. Level 2 self-assessment runs about $37,000 for a small entity and $49,000 for a larger one across the triennial cycle plus two annual affirmations. A Level 2 third-party assessment cycle runs about $105,000 for a small entity and $118,000 for a larger one. Level 3 DIBCAC assessment adds roughly $7,000 for a small entity and $36,000 for a larger one per cycle.

Those numbers assume something worth stating plainly. The Department of Defense excluded the cost of implementing NIST 800-171 from its estimates because contractors were already required to have implemented it by December 31, 2017. If you have not, that spend is yours and it is not in any government figure.

Cost was a stated driver behind the Phase 2 suspension. Department officials pointed to prohibitive compliance costs and the risk of pushing small suppliers out of the defense market at a time when the country needs them. That is an honest read of a real problem, and it reframes the question for a small contractor. The question is not whether to comply. It is how to comply without the cost structure that was breaking companies in the first place, which is the whole design intent behind CMMC compliance support delivered on a fixed monthly basis.

How Hard Is It To Get CMMC Certified?

Getting CMMC certified is hard because it demands progress on technical implementation, written policy, staff training, and evidence collection at the same time, usually from the same small group of people already running the business. The difficulty is rarely any single control. It is the simultaneity.

Five obstacles account for most failures.

  • Documentation volume. A system security plan past 200 pages, plus policies, procedures, diagrams, and training records, is a writing project most technical teams are not staffed for.
  • Legacy technical debt. Equipment that cannot support multi-factor authentication or FIPS-validated encryption needs upgrading, replacing, or documented compensating controls.
  • Small business resource limits. Implementing 110 controls across 14 families is a full-time role. Most small contractors do not have a full-time person to give it.
  • Workflow resistance. Security controls change how people log in, share files, and do their jobs. Without training and visible leadership backing, staff route around controls and your evidence quietly stops matching reality.
  • Drift after certification. Configurations change, staff turn over, documentation ages. Without a named owner, a compliant environment decays into a noncompliant one without anyone noticing.

That last obstacle is the one we see most, and it is the one that produced LOGZONE's 280-point gap. Manufacturers feel it hardest, because production floors run legacy equipment that resists modern controls, which is why our manufacturing compliance work treats legacy systems as a design constraint rather than a problem to postpone.

Why Continuous Compliance Beats Break-Fix IT

Continuous compliance beats break-fix IT because CMMC measures the state of your environment between incidents, and break-fix providers are only paid when something has already gone wrong. The two models are structurally incompatible.

Most IT companies bill by the hour. Something breaks, they fix it, they invoice. Nothing in that arrangement pays anyone to make sure nothing breaks, and nothing in it pays anyone to keep evidence current on a Tuesday when every system is running fine.

CMMC does not ask whether your network works today. It asks whether 110 specific controls have been implemented, documented, monitored, and evidenced continuously, and whether you can prove it on the day an assessor asks. Audit logging is not a repair. Continuous monitoring is not a service call. An annual affirmation is not a ticket you close.

Every control the framework asks for is preemptive by design. The program was written to stop incidents rather than record them, so the work only counts if it happens before anything goes wrong. A reactive provider cannot deliver preemptive controls, because the business model gives nobody a reason to show up until after the fact.

This is the practical difference between a vendor and a partner, and the managed services distinction is not a marketing one. A vendor responds to what already went wrong. A partner is accountable for the state of your environment in the long stretches between incidents, which is precisely the window CMMC evaluates.

There is a billing consequence too. Under hourly compliance work, every newly discovered gap becomes a change order. Contractors get nickel and dimed through remediation and still cannot produce clean evidence at the end, because nobody was ever responsible for the continuity. We built our Managed IT Department to remove that failure mode: fully managed or co-managed, unlimited remote and onsite support, no additional labor charges for onsite calls or out-of-scope work, one all-inclusive monthly fee instead of a lump sum every time something surfaces.

How Does a Managed IT Partner Simplify CMMC Compliance?

A managed IT partner simplifies CMMC compliance by owning the technical controls, the documentation, the monitoring, and the audit readiness that a small contractor has no realistic way to staff internally. The 110 controls span 14 families, and covering all of them properly is a specialist discipline rather than an extra duty.

In practice that ownership covers gap assessment and remediation planning, implementation of technical controls, system security plan development and maintenance, continuous monitoring and threat detection, incident response planning, security awareness training, and the evidence discipline that determines whether your score survives scrutiny. It converts CMMC from a project with a deadline into a function with an owner, which is what annual affirmations and continuous obligations genuinely require.

For most small contractors the arrangement also costs less than hiring, training, and retaining internal security staff, and it removes the risk of all that knowledge sitting with one employee who might leave.

The same foundation serves more than one framework. The controls behind CMMC map closely onto HIPAA for healthcare providers, FTC Safeguards for financial institutions, ISO 27001 for manufacturers, and the requirements cyber insurance carriers increasingly demand before they will write or renew a policy. We run the same proactive methodology across all of them: assess the current position, build a roadmap against the specific regulation, then monitor and document continuously. Building once tends to resolve several obligations at the same time.

Frequently Asked Questions

Is CMMC Cancelled?

No, CMMC is not cancelled. The Department of War suspended the transition to Phase 2 on July 13, 2026 and opened a 60-day review. Phase 1 self-assessment requirements remain in force, 32 CFR Part 170 is still law, and DFARS cybersecurity obligations are unchanged. The program paused at Phase 2 rather than ending.

Can You Self-Certify CMMC Level 1?

Yes, you can self-certify CMMC Level 1. It requires an annual self-assessment of the 15 controls in FAR 52.204-21, submission of results to SPRS, and an annual affirmation signed by an affirming official. No third-party assessor is involved, and the DoW CIO confirms POA&Ms are not permitted at this level.

How Many Controls Are in CMMC Level 1?

CMMC Level 1 has 15 controls, drawn from FAR clause 52.204-21. They cover access control, identification and authentication, media protection, physical protection, system and communications protection, and system and information integrity. The Department of Defense estimates about 63% of the defense industrial base falls into Level 1.

Who Provides CMMC Certification?

CMMC status comes from the organization itself at Level 1 and Level 2 self-assessment, from an authorized third-party assessment organization for Level 2 certification assessments, and from the Defense Industrial Base Cybersecurity Assessment Center for Level 3. Since July 2026, third-party and DIBCAC assessment requirements are suspended pending the Reform Task Force review, leaving self-assessment as the active path.

Does CMMC Require US Citizenship?

No, CMMC does not require US citizenship. Foreign suppliers in the defense supply chain face the same CMMC requirements as domestic contractors. Contracts involving classified or ITAR-controlled data may carry separate citizenship or export control conditions, but those obligations sit outside the CMMC program.

Is CMMC for DoD Only?

Yes, CMMC applies to Department of Defense contracts only at present. Other federal agencies have followed the program closely, and a government-wide rule covering Controlled Unclassified Information is moving through separate acquisition rulemaking, so comparable verification requirements may reach civilian agency contracts later.

What Is a System Security Plan for CMMC?

A system security plan for CMMC is the document describing how each required control is implemented across every system inside your assessment boundary. It records the implementation approach, the responsible parties, the testing procedures, and where the supporting evidence lives. Assessors treat it as their primary reference, and a missing or incomplete plan can produce no score at all in SPRS.

The Takeaway

The July 2026 suspension bought the defense industrial base time. It did not hand anyone a pass. Phase 1 self-assessments still decide award eligibility, DFARS obligations never changed, primes are still enforcing flow-downs down every tier, and the affirmation an officer of your company signs still carries False Claims Act exposure with no third-party assessor standing between that signature and the government.

LOGZONE settled for $507,144 without a breach and without a whistleblower. The gap between a reported score and an implemented one was enough on its own. Contractors who use this pause to close that gap will be ready whatever the Reform Task Force decides. Contractors who read the headline and stopped will be doing the same work in half the time, competing for a scarce assessment slot against everyone else who waited.

We have spent more than 20 years building and maintaining compliant IT infrastructure for defense suppliers across Huntsville and North Alabama, and as a minority-owned small business in this supply chain ourselves, we know what these requirements cost a company your size. If you are not certain where you stand, a free scoping audit will map your environment, show you what falls inside your assessment boundary, and tell you the honest distance between your current posture and your next contract. Reach out to Interweave Technologies or call (256) 837-2300.