// Capability Statement — Download PDF
Insights / CMMC
CMMC

CMMC, explained for the defense industrial base.

What the Cybersecurity Maturity Model Certification requires at each level, who needs it, and the scoping and evidence moves that make assessment survivable.

Ausper Technology · July 20, 2026 · Insight · CMMC · Defense industrial base

If your company touches Department of Defense contracts — prime or sub, product or service — the Cybersecurity Maturity Model Certification (CMMC) is the compliance wave that decides whether you stay eligible. It exists for a blunt reason: adversaries steal controlled unclassified information (CUI) from the defense supply chain, and self-attestation didn't stop it.

The levels, without the fog

LevelWho it hitsWhat it takes
Level 1 — FoundationalFCI only (basic contract info)17 practices, annual self-assessment
Level 2 — AdvancedAnyone handling CUI (most of the DIB)NIST 800-171's 110 controls; third-party assessment for most
Level 3 — ExpertHighest-sensitivity programs800-171 + 800-172 enhancements; government-led assessment

The center of gravity is Level 2: NIST 800-171's 110 controls, assessed by a C3PAO for most contractors. If you've followed our ATO explainer, the shape is familiar — controls, evidence, POA&Ms — scaled to companies instead of systems.

How to get ready without panic

Scope ruthlessly. CMMC applies where CUI lives. Segment your environment so CUI touches the smallest possible enclave, and the assessed boundary shrinks with it — often the single highest-ROI move available.

Gap-assess against 800-171 now. Your SPRS score is already reportable. An honest gap assessment with a costed remediation plan beats optimistic self-scoring that an assessor later dismantles.

Fix the recurring offenders. MFA everywhere, FIPS-validated encryption, logging and retention, access reviews, incident response you've rehearsed. The same dozen controls fail in most first assessments.

Make evidence a habit. Assessors accept what they can verify. The same evidence-automation discipline that accelerates ATOs (our home turf) makes CMMC assessments boring — which is the goal.

Common questions

What are the CMMC levels?
Level 1 covers Federal Contract Information and is a set of basic safeguarding requirements verified by annual self-assessment. Level 2 covers Controlled Unclassified Information and aligns to the 110 requirements of NIST SP 800-171; depending on what the contract says, it is either self-assessed or assessed by an accredited third party. Level 3 adds a selected subset of NIST SP 800-172 for the most sensitive programs and is assessed by the government.
Who has to comply with CMMC?
Any organization in the DoD supply chain that handles Federal Contract Information or Controlled Unclassified Information, prime or sub. The level is set by the data the contract involves, not by the size of the company — a ten-person shop holding CUI carries the same requirement as a large integrator holding the same CUI.
How long does it take to get ready?
Scope drives the answer far more than the control count does. The single most effective move is to shrink the boundary: put CUI in a defined enclave, keep it out of general corporate IT, and assess the enclave. A narrow environment with real evidence is faster to prepare and much easier to defend than an enterprise-wide scope with partial coverage everywhere.

Related reading

Put this to work

Need it done, not just explained?

This is the work we do every day. Tell us where your program stands and we'll give you a straight answer.

Talk to Ausper