Do I Need CMMC? Understanding When It Applies to You

Do I Need CMMC? Understanding When It Applies to You

"Do I need CMMC?" might be the most-googled question in defense contracting right now, and for good reason.

The Department of Defense (DoD) estimates that the Cybersecurity Maturity Model Certification (CMMC) will affect more than 300,000 organizations, and a surprising number of them don't yet know they're on that list.

That's because the requirement doesn't follow job titles or industries. It follows data. Companies that have never thought of themselves as defense businesses are discovering that a single subcontract puts them squarely in scope.

In this guide, we'll break down exactly who needs CMMC, who's exempt, which level applies to you, and how to check your own status in a few minutes.

TL;DR

  • CMMC applies to any organization that processes, stores, or transmits FCI or CUI under DoD contracts: primes, subcontractors at every tier, and even MSPs with access to defense clients' systems.
  • The data decides your level. FCI alone means Level 1 and an annual self-assessment, while handling CUI puts you at Level 2 with all 110 NIST 800-171 controls and, for most contracts, a C3PAO assessment.
  • The exemptions are narrow. Only pure commercial off-the-shelf suppliers and companies with zero FCI or CUI contact fall outside the program's scope.
  • The requirement is live now. CMMC began appearing in new DoD contracts in November 2025, and the status must be in hand at contract award, not after.
  • MotherBear gives contractors and consultants one workspace to build and store their entire CMMC program, so scope, evidence, and affirmations stay organized for every contract and client.

What Is CMMC?

CMMC is the DoD's program for verifying that companies in its supply chain actually protect the sensitive information their contracts involve.

It's built primarily on the NIST 800-171 cybersecurity standard, and it turns those security controls into something contracts can check: a formal CMMC status, achieved through self-assessment or independent assessment depending on the level.

The CMMC program exists because sensitive data kept leaking through the supply chain. Contractors self-reported strong cybersecurity, audits found otherwise, and adversaries exploited the gap.

CMMC replaces claimed compliance with verified compliance, and since November 2025, it's been rolling into new DoD contracts in phases.

Who Needs CMMC Compliance?

CMMC applies to any organization that processes, stores, or transmits Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) under DoD contracts.

Company size, industry, and location don't matter. Position in the supply chain doesn't matter either, and that catches more organizations than you'd think.

Prime Contractors

If you hold a contract directly with the DoD, CMMC lands on you first. Solicitations name the required CMMC level as a condition of contract award.

Primes also carry a second obligation: verifying that every subcontractor holding FCI or CUI has the required CMMC status before flowing work down to them.

Subcontractors at Every Tier

CMMC doesn't stop at the first tier. If a prime passes FCI or CUI to you, or your customer passes it to their suppliers, the requirement travels with the data. Second-tier and third-tier subcontractors are in scope the moment protected information touches their systems.

Many discover this not from the DoD, but from a prime suddenly asking for proof of compliance.

Managed Service Providers and Managed Security Service Providers

Managed service providers (MSPs) and managed security service providers (MSSPs) often assume CMMC is their clients' problem. It usually isn't.

If your client sits in the DoD supply chain and you have access to their data, systems, or network infrastructure, your services fall inside their CMMC assessment scope. Security service providers that can't demonstrate compliance become a liability their defense clients can no longer afford.

The Companies That Don't See It Coming

The Defense Industrial Base (DIB) is far broader than aerospace and weapons manufacturers. Universities with DoD research awards, machine shops, construction firms, logistics companies, and software vendors all end up handling FCI or CUI.

If any contract in your pipeline traces back to the DoD and involves non-public information, assume you're in scope until you've verified otherwise.

Who Doesn't Need CMMC?

The exemptions are narrower than most companies hope, but they exist.

Commercial Off-the-Shelf (COTS) Suppliers

If you sell only COTS items, meaning standard commercial products offered to the government without significant modification, you're exempt under federal acquisition rules.

The exemption is strict, though. Customize the product for the DoD, or handle FCI alongside the sale, and you're back in scope.

Companies With No FCI or CUI Contact

If nothing in your work touches non-public government information, CMMC doesn't apply to you. The catch is that FCI is a low bar.

Contract performance details, technical drawings, and even certain email threads with a prime can qualify. Plenty of companies believe they're in this category and aren't.

Contractors Outside the DoD's Orbit

CMMC is a DoD program. If your federal work involves other agencies, different cybersecurity regulations apply, like FedRAMP for cloud providers selling to the federal government.

That said, other agencies are watching CMMC closely, so the safe assumption is that verification-based compliance is where federal contracting is heading.

If you're unsure which bucket you fall into, that uncertainty is itself the answer to act on. The next two sections cover how to tell which level applies and how to check your status quickly.

Which CMMC Level Do You Need?

The CMMC model has three levels, and the data you handle decides which one applies. Not your size, not your revenue, not how important the contract feels.

Each solicitation specifies its required level, but you can predict yours by answering one question: does your work touch only Federal Contract Information, or Controlled Unclassified Information as well?

CMMC Level 1: For Contractors Handling FCI

If your work only touches FCI, Level 1 applies. It covers basic safeguarding of DoD data through 15 security requirements, often described as basic cyber hygiene: things like access restrictions, password practices, and physical security.

Verification is light. Level 1 requires an annual self-assessment, scored and posted to the Supplier Performance Risk System (SPRS), with a senior official affirming the results. No outside assessor is involved, which keeps the compliance burden manageable for small government contractors.

CMMC Level 2: For Contractors Who Handle Controlled Unclassified Information

The moment CUI enters your environment, the more stringent Level 2 requirements apply. That means implementing all 110 cybersecurity controls from NIST 800-171 to protect Controlled Unclassified Information, plus documenting how each control works.

Level 2 splits into two paths, and the type of CUI decides which one you're on:

  • Level 2 self-assessment: A minority of contracts involving less sensitive CUI allow contractors to self-assess and report to SPRS, the same compliance process as Level 1 but against all 110 controls.
  • Level 2 certification: Most DoD contractors handling CUI need a third-party assessment by a Certified Third-Party Assessor Organization (C3PAO) every three years. This is the actual assessment most people mean when they say "CMMC certified". The Cyber AB, formerly the CMMC Accreditation Body, oversees the ecosystem of assessors that conduct these evaluations.

If you plan to grow your defense work, aim for the certification path even if your current contract allows self-assessment. Once you've done the work to achieve compliance, the third-party certification opens more doors than the self-assessed status does.

CMMC Level 3: For National Security Programs

Level 3 adds requirements from NIST 800-172 on top of the full Level 2 baseline, with the assessment led by the government itself. It applies to a small slice of the defense industrial base working on the most sensitive national security programs.

If Level 3 applies to you, your contracting officer will make that unmistakably clear.

How to Prepare, Whatever Your Level

The certification process rewards early movers at every level. Start with a gap analysis against your required level's controls to understand your current cybersecurity posture. Budget honestly, since compliance costs scale with how much remediation the gap analysis reveals.

Treat the work as ongoing: continuous monitoring, current documentation, and annual affirmations are what maintain eligibility after the initial push, because CMMC compliance requirements don't end on assessment day.

Do I Need CMMC? A Quick Compliance Checklist

If you're still unsure where you stand, run through this CMMC compliance checklist. Answer honestly, and count your yeses.

  • Do you hold a contract or subcontract that traces back to the DoD, directly or through a prime?
  • Does your work touch Federal Contract Information, meaning any government-related information not intended for public release, including contract details, reports, or technical documents?
  • Do you handle CUI, such as controlled technical information, engineering data, or export-controlled material?
  • Do you access a defense client's data, systems, or networks as an MSP, MSSP, or other service provider?
  • Are you planning to bid on DoD work in the next one to two years, even if you hold no defense contracts today?

If you answered yes to any of these, some level of CMMC compliance is required in your future, and the data you touch determines which one. One yes on the FCI question alone points to Level 1. A yes on the CUI question means your organization almost certainly needs CMMC at Level 2.

If every answer is a confident no, backed by an actual review of your contracts rather than a gut feeling, CMMC likely doesn't apply to you today. Just revisit the CMMC checklist whenever a new contract enters the pipeline, because scope changes with a single signature.

When Is CMMC Compliance Required?

The requirement is already live. CMMC began appearing in new DoD contracts in November 2025, and the rollout follows a phased CMMC implementation timeline that runs through full implementation in November 2028.

The practical trigger isn't a calendar date, though. It's your next solicitation. Once a contract or option period names a CMMC level, you need that status at the time of contract award, not after.

Since a Level 2 certification takes months of preparation and assessor calendars fill up, the real deadline is always earlier than the one printed in the solicitation.

The safe rule: if the checklist above produced a yes, start working to achieve CMMC compliance now and let the timeline article and your contracting officer refine the details.

What This Means for Consultants

If you advise defense contractors, "do I need CMMC?" is the opening line of nearly every new client conversation, and the answer is rarely as simple as the client hopes.

Scoping is where engagements are won: tracing where FCI and CUI actually flow, identifying which contracts require CMMC, and separating what's truly in scope from what the client assumed was.

The checklist logic in this article is exactly what consultants run at professional depth. A client who self-diagnosed as Level 1 may be receiving CUI through a prime without realizing it.

Another may be scoping their entire company when an isolated enclave would shrink the project dramatically. Getting these calls right early is the cheapest moment to get them right.

The harder problem is doing this repeatedly. Every client on the roster needs their scope mapped, their level confirmed, and their evidence maintained to make sure CMMC compliance holds between assessments. That multiplication is where advisory work turns into an operations problem.

Achieve CMMC Compliance Faster With MotherBear

Whether the checklist put you in scope or confirmed your clients are, the next step is the same: turning "we need CMMC" into an organized program.

MotherBear simplifies cybersecurity compliance for the defense market with a central place to build and store everything.

Requirements, evidence, documents, and affirmations live in one workspace, organized by the level each contract demands, whether you're managing one program or one for every client you serve.

The organizations that struggle with CMMC aren't the ones that lack security. They're the ones whose proof is scattered.

Book a demo and see how MotherBear keeps everything needed to achieve CMMC in one place.

FAQs About Who Needs CMMC

Which DFARS clause requires CMMC?

DFARS 252.204-7021 is the clause that puts CMMC requirements into contracts, requiring contractors to hold the specified CMMC status at award and maintain it throughout performance. It works alongside DFARS 252.204-7012, the older clause requiring NIST 800-171 implementation for CUI.

What happens if I don't get CMMC-certified?

You become ineligible for contracts that name a CMMC requirement, and primes will drop non-compliant subcontractors to protect their own eligibility.

There's legal exposure, too: misrepresenting compliance has already led to False Claims Act settlements, so an inflated status is riskier than an honest gap.

When did CMMC become mandatory?

CMMC became enforceable on November 10, 2025, when the first phase of the rollout began and self-assessment requirements started appearing in new DoD contracts. Requirements expand in phases through full implementation in November 2028.

Why is CMMC needed?

Because self-reported cybersecurity failed. Contractors claimed compliance with the Department of Defense's cybersecurity requirements while audits and breaches showed otherwise, exposing sensitive defense information to adversaries.

CMMC exists to protect sensitive information by verifying security before contracts are awarded rather than trusting claims after.

Think You Might Need CMMC?

Schedule a demo today to see how MotherBear streamlines CMMC