Compliance Framework
CMMC 2.0 — DoD Cybersecurity Certification
The Department of Defense's tiered cybersecurity standard. If you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) for a DoD program, you need to be on the path to certification — now.
Why CMMC matters right now
CMMC 2.0 is being phased into Department of Defense contracts beginning in 2025, with full implementation by 2028. Contracting officers are already inserting CMMC clauses into solicitations, and prime contractors are flowing the requirement down to every tier of the supply chain.
The bottom line: if you do not have a credible path to CMMC Level 2 in 2026, you will lose contracts in 2027. Lead times for C3PAO assessments are growing, and remediation work routinely takes 6–12 months.
The three CMMC 2.0 levels
Level 1 — Foundational
Basic safeguarding from FAR 52.204-21. Covers fundamentals like access control, identification, and physical security.
Audience
Contractors handling FCI only
Assessment
Annual self-assessment
Level 2 — Advanced
Full alignment with NIST SP 800-171 Rev 2. This is where the vast majority of the defense industrial base will land.
Audience
Contractors handling CUI
Assessment
Triennial C3PAO assessment (or self-assessment for non-critical CUI)
Level 3 — Expert
Adds enhanced requirements from NIST SP 800-172 to defend against advanced persistent threats.
Audience
Contractors on the highest-priority programs
Assessment
Government-led assessment by DIBCAC
What CMMC actually costs
Real-world ranges including readiness work, remediation, tooling uplift, and the C3PAO assessment itself. Assumes a single enclave with sensible scope reduction.
| Org Size | Level 1 | Level 2 | Notes |
|---|---|---|---|
| Small (1–25 employees) | $5K – $15K | $25K – $75K | Often single-enclave scope |
| Mid (26–100 employees) | $10K – $25K | $60K – $150K | Most common engagement size |
| Large (100+ employees) | $20K+ | $120K – $400K+ | Multi-enclave, multi-site complexity |
Costs vary widely based on existing security maturity, scope, and the chosen enclave strategy. Companies handling CUI in their general corporate environment routinely pay 5–10x more than those who isolate CUI properly.
A realistic timeline
Compressed plans exist, but expect the full path to certification to take 9–18 months from kickoff for a typical mid-sized contractor.
How Phaethon Security helps
We run fixed-fee CMMC readiness engagements for defense contractors from 10 to 500+ employees. Practitioner-led, no offshore hand-offs, and we hand the program back to you when we're done.
- Scoping workshop and CUI flow analysis
- Gap assessment against all 110 controls
- SSP and POA&M development
- Remediation roadmap with realistic budgets
- Pre-assessment with a CMMC RP
- C3PAO selection and project management