CMMC — Cybersecurity Maturity Model Certification

CMMC readiness consulting for defence suppliers: FCI/CUI scoping, NIST SP 800-171 gap assessment, SSP preparation and SPRS self-assessment support.

What CMMC Is

The Cybersecurity Maturity Model Certification (CMMC) is the U.S. Department of Defense framework for verifying that contractors and subcontractors handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) implement an appropriate set of cybersecurity controls. Level 2 uses NIST SP 800-171 Rev. 2; the Level 3 model adds selected NIST SP 800-172 requirements. The programme defines self-assessment, C3PAO and DIBCAC assessment routes. Their current procurement use is subject to the suspension described below. Nesil provides readiness consulting and does not issue CMMC certificates.

Current CMMC Implementation Status

Reviewed 12 September 2026. The 13 July 2026 announcement suspended the Phase II transition and subsequent implementation milestones. Phase I self-assessments and DFARS 252.204-7012 information-protection obligations remain in effect.

During the suspension, procurement requirements may specify Level 1 (Self) or Level 2 (Self), but not Level 2 (C3PAO) or Level 3 (DIBCAC). Review solicitation amendments and contract modifications with the contracting officer. Do not treat 10 November 2026 as a confirmed Phase II start date.

Sources: official CMMC announcement, implementation memorandum (PDF) and DFARS 252.204-7021 assessment status definitions.

Türkçe CMMC danışmanlığı sayfası

The Three Levels

  • Level 1 — Foundational (FCI): Basic safeguarding requirements under FAR 52.204-21. Annual self-assessment and affirmation.
  • Level 2 — Advanced (CUI): 110 security requirements aligned with NIST SP 800-171 Rev. 2. Final Level 2 self-assessment status is based on a three-year assessment cycle with annual affirmation.
  • Level 3 — Expert (Critical CUI): The programme model adds 24 selected NIST SP 800-172 requirements to Level 2. DIBCAC is the Level 3 assessor; new Level 3 procurement requirements are suspended.

Engagement Scope

  1. CUI scoping and asset categorisation — identification of CUI assets, security protection assets, contractor risk-managed assets, and out-of-scope assets
  2. Gap assessment against the applicable level using the CMMC Assessment Guide methodology
  3. System Security Plan (SSP) development
  4. Plan of Action and Milestones (POA&M)
  5. Control implementation — policy, procedure, and technical configuration support
  6. Readiness review of control evidence and assessment preparation
  7. Assessment coordination and remediation support where applicable under the current programme requirements

ISO 27001 and Adjacent Frameworks

CMMC Level 2 controls are drawn from NIST SP 800-171. Existing ISO/IEC 27001 policies and control evidence can support readiness. We map that evidence to the applicable requirements and identify remaining gaps; ISO 27001 certification does not automatically establish CMMC compliance.