What CMMC Requirements Apply to Defense Contractors

What CMMC Requirements Apply to Defense Contractors

One of the most common questions defense contractors ask is:

"What CMMC compliance requirements apply to my organization?"

It's a fair question. Between different contract requirements, multiple assessment paths, and ongoing changes to the Cybersecurity Maturity Model Certification (CMMC) program, it can be difficult to know where to start.

The short answer: CMMC requirements depend on the type of information you handle under each contract. Contracts involving Federal Contract Information (FCI) require CMMC Level 1 self-affirmation. Contracts involving Controlled Unclassified Information (CUI) require CMMC Level 2, self-assessment or a third-party certification. The level specified in the contract is what ultimately determines your compliance level.

Determining which requirements apply is usually more straightforward than many organizations think.

Determining Applicability Starts with Three Questions:

  • What information is being handled

  • Which contracts require that information to be protected

  • Where that information is being processed, stored, or transmitted

Before investing time and resources into remediation efforts or assessment preparation, it's important to understand what CMMC compliance requirements apply in the first place.

That's the purpose of a CMMC applicability assessment: understanding what applies to your organization before spending resources on requirements that may not be relevant.

How to Determine Which CMMC Compliance Requirements Apply to Your Organization

A simple way to think about CMMC applicability is:

Information → Contract → Systems → Assessment Requirements

Many organizations jump straight to questions about assessments. In reality, those answers usually become much clearer after identifying the information, contracts, and systems involved.

Start by Asking:

  • Do we handle Federal Contract Information (FCI)?

  • Do we handle Controlled Unclassified Information (CUI)?

  • Which contracts involve that information, and does any of it come to us through a prime contractor?

  • Which systems process, store, or transmit FCI/CUI?

  • Look for the CMMC level identified in the solicitation, including any applicable DFARS provisions and clauses that specify cybersecurity requirements.

  • What assessment requirements apply?

The answers help establish the boundaries of an organization's CMMC obligations and prevent unnecessary assumptions about what may or may not be required.

Most importantly, organizations shouldn't assume they have one universal CMMC requirement simply because they operate in the Defense Industrial Base (DIB). Requirements often need to be evaluated on a contract-by-contract basis.

Special Considerations for Subcontractors

This applies to subcontractors too.

Prime contractors are expected to flow CMMC requirements down to their suppliers, and the level that applies to a subcontractor depends on the information shared under that subcontract. It is not necessarily the level the prime holds. Most large primes have sent open letters to their suppliers requiring a CMMC level regardless of what the DoW has on pause.

If You Only Handle FCI, What Does That Mean for CMMC?

When a contract includes CMMC Level 1 requirements, organizations that handle Federal Contract Information (FCI) need to meet them.

What is FCI?

FCI is information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service.

It does not include information the government makes public or simple transactional information, such as what’s needed to process payments.

What Does Level 1 Require?

CMMC Level 1 focuses on basic safeguards for protecting FCI and includes the 15 security requirements outlined in DFARS clause 252.204-7021.

Those safeguarding requirements already apply to contracts that include the FAR clause, whether or not CMMC is specified.

This is also where many contractors get confused.

Why Scope Matters

Determining whether you have FCI is important, but it isn't the whole story.

Organizations also need to understand:

  • Which contract the information supports

  • Where the information is processed, stored, or transmitted

  • Which systems are involved

  • Who has access to the information

Identifying FCI is only one part of determining CMMC scope.

Without that context, organizations can end up including far more of their environment than necessary or overlooking systems that should be considered.

A good place to start is by tracing where the information travels throughout the organization. Any computer, cloud service, email inbox, or individual that stores, processes, or transmits the data may fall within scope.

From there, organizations can look for opportunities to eliminate unnecessary data flows or limit where the information resides. Keeping FCI contained to specific systems and processes can help reduce scope, making compliance efforts more manageable and focused.

Level 1 serves as a foundation for broader defense contractor compliance efforts.

If You Handle CUI, What Changes?

Handling Controlled Unclassified Information (CUI) brings CMMC Level 2 requirements into the conversation.

What is CUI?

CUI is unclassified information created, possessed, or owned by the U.S. government that requires safeguarding or dissemination controls under applicable laws, regulations, or government-wide policies. While it is not classified information, it is still considered sensitive and requires specific protections.

Level 2 is built around the 110 security requirements in NIST SP 800-171 Revision 2 and serves as the primary mechanism for protecting CUI. Contracts that include DFARS 252.204-7012 already require contractors handling CUI to implement NIST SP 800-171, independent of CMMC verification.

A common mistake is assuming that:

"We handle CUI."

automatically means:

"We need a C3PAO assessment."

Not necessarily.

The presence of CUI is a major factor, but the contract ultimately determines what type of level 2 assessment is required and how compliance must be demonstrated.

That's why organizations should avoid assuming every contractor handling CUI follows the exact same path.

What Do Level 1 and Level 2 Requirements Include?

Once the type of information is clear, the next step is understanding what each level asks organizations to do.

Organizations Handling FCI

Organizations required to meet CMMC Level 1 implement basic safeguarding such as:

  • Limiting access to authorized users

  • Verifying the identity of users and devices before granting access

  • Protecting information during transmission

  • Restricting physical access to systems

  • Controlling who can view or use sensitive information

For many contractors, Level 1 establishes a baseline level of cybersecurity for protecting contract-related information.

Organizations Handling CUI

Organizations that handle CUI generally face a much broader set of cybersecurity requirements.

The 110 requirements in NIST SP 800-171 are organized into 14 families, including:

  • Access control

  • Multi-factor authentication

  • Audit logging

  • Incident response

  • Configuration management

  • Vulnerability management

  • Security awareness training

  • Media protection

  • Risk assessments

  • System and communications protection

This is often the point where contractors realize CMMC is about much more than passing an assessment. The requirements are intended to strengthen defense industry cybersecurity and improve the protection of sensitive government information throughout the supply chain.

A Quick Look at Common Requirement Scenarios

While requirements should always be verified against the contract, most defense contractors fit into one of the following categories:

Contract performance information (4)

Self-assessment results are submitted in the Supplier Performance Risk System (SPRS), and a senior company official must affirm compliance, so accuracy matters as much as completion.

This isn't a substitute for reviewing the contract, but it provides a useful starting point for understanding where an organization may fit within the CMMC framework.

Contract performance information (3)

Does Every Defense Contractor Handling CUI Need a C3PAO Assessment?

No.

One of the biggest misconceptions surrounding CMMC is that handling CUI automatically requires a third-party assessment from a Certified Third-Party Assessment Organization (C3PAO).

Under the current CMMC framework, Level 2 can involve either a self-assessment or a C3PAO assessment, depending on what the contract requires.

What the DoW Pause Means

It's also important to separate assessment requirements from recent changes to the Department of War’s pause in the CMMC Phase 2 rollout.

Following that announcement, some contractors interpreted the pause as a sign that CMMC was going away, or that preparation efforts could stop altogether.

That's not the case.

While the pause changed implementation timelines, it didn't remove existing obligations to protect covered information under FAR 52.204-21 and DFARS 252.204-7012. Level 1 and Level 2 self-assessment requirements also remained in place. It also didn't eliminate the need for contractors to understand where they stand against future CMMC requirements.

In many ways, the pause creates an opportunity for more intentional CMMC preparation. Rather than rushing toward a deadline, organizations have additional time to evaluate their environment, address gaps, strengthen documentation, and build a more strategic readiness plan.

A Better Question to Ask

Instead of asking:

"Do we need a C3PAO assessment right now?"

Ask:

"What does our contract require, and what do we need to be prepared for?"

Instead of assuming a specific assessment path, start by answering a few key questions:

  1. What CMMC level is specified?

  2. Is the requirement Level 1 Self, Level 2 Self, or Level 2 C3PAO?

  3. Which systems support the contract?

  4. What evidence or documentation will need to be demonstrated?

Those answers provide a much clearer picture of what obligations actually apply.

Once You Know What Applies, the Focus Shifts to Readiness

Determining which CMMC requirements apply is only the first step.

Once an organization identifies the information, contracts, systems, and assessment requirements involved, the focus shifts from applicability to readiness.

At that point, organizations can begin:

  • Confirming what is in scope

  • Evaluating current security practices

  • Identifying compliance gaps

  • Prioritizing remediation activities

  • Reviewing required documentation and evidence

  • Building a long-term compliance strategy

Organizations that establish scope early are often in a much stronger position during readiness efforts because they have a clearer understanding of what requirements apply and what they'll eventually need to demonstrate.

For a more detailed look at the preparation process, see How to Prepare for CMMC in 2026: A Defense Contractor's Complete Guide.

Need Help Determining Which CMMC Requirements Apply?

Whether you're trying to determine which CMMC level applies, preparing for an upcoming assessment, or building a long-term compliance strategy, having a clear understanding of your requirements is the first step.

For organizations that self-assess, CMMC Progressing Pathways provides recurring review of documentation and security practices by a Cyber AB-certified expert, helping you find gaps and prepare for CMMC requirements.