All Frameworks

Compliance Framework

CMMC 2.0 — DoD Cybersecurity Certification

The Department of Defense's tiered cybersecurity standard. If you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) for a DoD program, you need to be on the path to certification — now.

3 Maturity Levels
110 Controls (Level 2)
C3PAO Assessment

Why CMMC matters right now

CMMC 2.0 is being phased into Department of Defense contracts beginning in 2025, with full implementation by 2028. Contracting officers are already inserting CMMC clauses into solicitations, and prime contractors are flowing the requirement down to every tier of the supply chain.

The bottom line: if you do not have a credible path to CMMC Level 2 in 2026, you will lose contracts in 2027. Lead times for C3PAO assessments are growing, and remediation work routinely takes 6–12 months.

The three CMMC 2.0 levels

Level 1 — Foundational

15 practices

Basic safeguarding from FAR 52.204-21. Covers fundamentals like access control, identification, and physical security.

Audience

Contractors handling FCI only

Assessment

Annual self-assessment

Level 2 — Advanced

110 practices

Full alignment with NIST SP 800-171 Rev 2. This is where the vast majority of the defense industrial base will land.

Audience

Contractors handling CUI

Assessment

Triennial C3PAO assessment (or self-assessment for non-critical CUI)

Level 3 — Expert

110+ enhanced practices

Adds enhanced requirements from NIST SP 800-172 to defend against advanced persistent threats.

Audience

Contractors on the highest-priority programs

Assessment

Government-led assessment by DIBCAC

What CMMC actually costs

Real-world ranges including readiness work, remediation, tooling uplift, and the C3PAO assessment itself. Assumes a single enclave with sensible scope reduction.

Org SizeLevel 1Level 2Notes
Small (1–25 employees)$5K – $15K$25K – $75KOften single-enclave scope
Mid (26–100 employees)$10K – $25K$60K – $150KMost common engagement size
Large (100+ employees)$20K+$120K – $400K+Multi-enclave, multi-site complexity

Costs vary widely based on existing security maturity, scope, and the chosen enclave strategy. Companies handling CUI in their general corporate environment routinely pay 5–10x more than those who isolate CUI properly.

A realistic timeline

Compressed plans exist, but expect the full path to certification to take 9–18 months from kickoff for a typical mid-sized contractor.

Months 1–2
Scoping, asset inventory, CUI flow mapping, enclave decision
Months 2–4
Gap assessment against all 110 NIST 800-171 controls
Months 3–8
Remediation, tooling deployment, policy development, SSP authoring
Months 7–10
POA&M closure, evidence collection, internal pre-assessment
Months 9–12
C3PAO scheduling, mock assessment, final readiness review
Months 12–18
Formal C3PAO assessment and certification

How Phaethon Security helps

We run fixed-fee CMMC readiness engagements for defense contractors from 10 to 500+ employees. Practitioner-led, no offshore hand-offs, and we hand the program back to you when we're done.

  • Scoping workshop and CUI flow analysis
  • Gap assessment against all 110 controls
  • SSP and POA&M development
  • Remediation roadmap with realistic budgets
  • Pre-assessment with a CMMC RP
  • C3PAO selection and project management
Request a CMMC Readiness Call

Frequently asked questions

Related frameworks