CMMC

Last updated

Definition

CMMC (Cybersecurity Maturity Model Certification) is the US Department of Defense program that verifies contractors and their subcontractors protect federal contract information (FCI) and controlled unclassified information (CUI). CMMC 2.0 has three levels: Level 1 is an annual self-assessment against the basic safeguarding practices of FAR 52.204-21 for companies handling only FCI; Level 2 is the 110 controls of NIST SP 800-171 for anyone handling CUI, verified every three years by a certified third-party assessor organization (C3PAO) for most contracts; Level 3 adds a subset of NIST SP 800-172 and is assessed by the government itself.

Why it matters to an MSP

CMMC clauses have been in DoD contracts since November 2025, with C3PAO certification becoming a condition of award for Level 2 work through 2026 and 2027. The DoD's own estimates put the Defense Industrial Base at roughly 220,000 companies, with on the order of 75,000 needing Level 2 certification. Few can reach 110 controls alone, which makes this a genuine niche: engagements typically start at $50K for the enclave build plus a monthly managed stack at a 25–35% premium over a comparable commercial client.

The price of entry is your own compliance. An MSP that touches CUI or the systems holding it is an external service provider inside the client's assessment scope; assessors expect a shared responsibility matrix stating which controls you own, and most MSPs here pursue Level 2 themselves to evidence their side. Expect a CUI enclave in a government cloud, US-persons support staff, MFA, FIPS-validated encryption, and audit logs you can produce on demand. Don't enter opportunistically: a failed client assessment is a lost contract, and the fault is yours. See compliance frameworks comparison for how it compares with SOC 2 and HIPAA.

Related terms: Compliance, NIST CSF, SOC 2, MFA