If your company works on federal projects, as a prime or as a subcontractor, you may have heard that cybersecurity requirements are tightening. The Cybersecurity Maturity Model Certification program, known as CMMC 2.0, is how the Department of Defense verifies that contractors protect sensitive information. It matters to construction and energy firms that build or support military facilities, bases, and related infrastructure.
This explainer covers the basics without the acronym soup.
What CMMC is for
The Department of Defense shares two kinds of unclassified but sensitive information with contractors. Federal Contract Information (FCI) is information provided by or generated for the government under a contract that is not public. Controlled Unclassified Information (CUI) is more sensitive information that requires specific safeguarding. CMMC asks contractors to prove they protect it, rather than simply promising to.
In construction, CUI can show up in drawings, specifications, and site details for certain facilities. Whether your project documents qualify depends on how the contract marks and defines them, so ask your contracting officer or prime contractor rather than assuming.
The three levels
CMMC 2.0 has three levels:
- Level 1 covers basic safeguarding of FCI, with 15 requirements, and is assessed through an annual self-assessment.
- Level 2 covers CUI and aligns with the 110 security requirements in NIST SP 800-171. Depending on the contract, it is assessed by self-assessment or by a third-party assessor.
- Level 3 applies to the most sensitive programs and adds a subset of requirements from NIST SP 800-172, with government-led assessment.
Most small contractors will fall into Level 1 or Level 2, depending on what information their contracts involve.
Where the rules stand
The program rule that establishes CMMC, found in 32 CFR Part 170, took effect on December 16, 2024. Requirements reach individual contracts through the acquisition rules, so contract language is where you will see the level that applies to you. Watch solicitations and prime contractor communications closely, because the level required will be stated there.
Flow-down to subcontractors
Prime contractors must pass requirements to subcontractors who handle FCI or CUI. If you are a sub, expect your prime to ask about your status, and expect questions in contract documents. Waiting for that request leaves little time to prepare.
First steps to take now
- Find out what you handle. Identify contracts that include FCI or CUI and where that information lives: email, file shares, project platforms, laptops, phones.
- Limit the scope. Keeping sensitive information in a defined, protected environment, rather than everywhere, makes compliance easier and cheaper.
- Assess yourself against the requirements. Use the NIST SP 800-171 requirements as a checklist, and document where you stand.
- Write a system security plan and a plan of action. These documents describe how you meet each requirement and how you will close the gaps.
- Close common gaps first. Multi-factor authentication, encryption, device management, logging, access control, and security training come up in nearly every gap list.
- Choose your tools carefully. Cloud services that store CUI have their own requirements, so confirm that a vendor can support them before you rely on it.
Common mistakes
- Assuming that an IT provider's general security covers CMMC without a formal assessment.
- Treating compliance as a one-time project rather than an ongoing practice.
- Storing CUI in personal email or consumer file sharing.
- Waiting until a contract award to start.
What it costs
Costs vary widely with company size, current security, and how much of your environment must be in scope. Rather than guess, get a gap assessment first. It converts an open-ended worry into a defined list with a budget.
How Ironfield Cyber helps
Ironfield Cyber helps contractors understand whether CMMC applies to them and, if so, prepare against NIST SP 800-171. We can start with a scoping conversation and a gap review, so you know what to fix before a contract requires it.