CMMC Resources
Learn how to prepare for the Cybersecurity Maturity Model Certification (CMMC) 2.0 Requirements with our comprehensive library of resources, white papers, and web

A Detailed Explanation of DFARS, NIST SP 800-171, & CMMC 2.0, with Key Timelines
The Defense Federal Acquisition Regulation Supplement (DFARS) serves as the foundational regulatory framework that necessitates both CMMC and NIST compliance throughout the Defense Industrial Base (DIB). The DFARS cybersecurity clauses specifically address national defense concerns related to the Department of Defense's acquisition processes. A key clause within DFARS, 252.204-7012, mandates that contractors handling Controlled Unclassified Information (CUI) must adhere to the security controls outlined in NIST Special Publication (SP) 800-171 Rev. 2. This particular clause requires contractors to implement the comprehensive security requirements detailed in NIST SP 800-171 Rev 2. on their information systems that process, store, or transmit CUI, provided these systems are not operated on behalf of the U.S. government. (NOTE: DFARS 252.204-7012 still remains tied to NIST 800-171 Rev. 2 because of a standing DoD class deviation – despite Rev. 3 being published.)
NIST Special Publication (SP) 800-171 provides a detailed catalog of 110 security controls, organized across 14 distinct control domains, specifically designed to protect the confidentiality, integrity, and availability of CUI in nonfederal systems and organizations. These controls encompass a wide array of security best practices, including stringent access control mechanisms, robust incident response procedures, and comprehensive measures for system and communications protection.
Building upon the foundation of DFARS and NIST SP 800-171, the Department of Defense (DoD) developed the Cybersecurity Maturity Model Certification (CMMC) program. The primary objective of CMMC is to enhance the overall cybersecurity posture of the DIB and to ensure that all defense contractors and subcontractors effectively comply with the existing information protection requirements for both Federal Contract Information (FCI) and CUI. CMMC achieves this by introducing a mandatory certification element to the existing cybersecurity compliance framework established by NIST SP 800-171.
CMMC 2.0 represents a streamlined approach with three distinct tiered levels, replacing the previous version which had five levels. The Imprimis i2ACT Assessment and Compliance Tool was designed to accommodate all three levels of CMMC compliance, including a detailed intake architecture for managing all cybersecurity practices and controls at each CMMC Level. The i2ACT also includes a number of productivity features for users of the software which include suggested remediation actions and a document management framework allowing for effective management of all evidence and documentation. In addition, the i2ACT serves as an educational tool as the user learns about the regulations during the assessment process.

The Three Levels of CMMC
- Level 1: "Foundational" - Focuses on basic cyber hygiene practices and incorporates 17 fundamental security controls derived from Federal Acquisition Regulation (FAR) clause 52.204-21. This level is designed for organizations that handle Federal Contract Information (FCI). Compliance at Level 1 can be achieved through an annual self-assessment.
- Level 2: "Advanced" - Aligns directly with the 110 security requirements outlined in NIST SP 800-171 Rev. 2 and is intended for organizations that manage Controlled Unclassified Information (CUI). For most organizations seeking Level 2 certification, compliance will necessitate a triennial third-party assessment conducted by an accredited Certified Third-Party Assessor Organization (C3PAO), along with annual affirmations of continued compliance.
- Level 3: "Expert" - Represents the most stringent level of cybersecurity maturity. It builds upon the requirements of both NIST SP 800-171 Rev. 2 and NIST SP 800-172 and is intended for contractors handling particularly sensitive CUI related to critical defense programs. Achieving Level 3 certification will require government-led assessments.
DoD Cybersecurity Regulations Summary
32 CFR Part 170 – CMMC Program (Program Rule)
-
- Finalized October 15, 2024; currently up to date as of March 6, 2026
- Establishes CMMC as the DoD’s cybersecurity assessment and certification program
- Requires contractors to meet one of three CMMC levels
- Level 1: Basic safeguarding (aligned to FAR 52.204-21)
- Level 2: Based on NIST SP 800-171 Rev 2 - (self or third-party)
- Level 3: Includes selected NIST SP 800-72 requirements (DIBCAC-led assessments)
- CMMC uses standards from FAR 52.20421, NIST SP 800171 Rev. 2, and NIST SP 800172
48 CFR Final Rule – DFARS 252.204-7021
-
- Final CMMC Rule published September 10, 2025 – effective November 10, 2025
- Officially embeds CMMC requirements into DoD contracts under 48 CFR
- Requires contracting officers to insert CMMC clauses into new DoD solicitations and contracts starting November 10, 2025
- Three-year phased rollout (2025-2028) – by 2028 CMMC required in all applicable contracts
- Adds DFARS 252.204-7021 (Compliance Clause) and 252.204-7025 (Notice Clause)
- Requires valid CMMC certification for contract award
- Clarifies assessment validity periods (i.e., Level 1 valid for 1 year, Levels 2/3 valid for 3)
- Annual affirmation in SPRS
- Subcontractor compliance at the same level
DFARS 252.204-7012 – Safeguarding Covered Defense Information
-
- Requires NIST SP 800-171 Rev 2 implementation
- Cyber incident reporting within 72 hours
- Flow down requirements to subcontractors
- Required FedRAMP Moderate cloud services
- Requires a System Security Plan (SSP) and Plan of Action & Milestones (POA&M)
- Key context: DFARS 7012 remains tied to NIST 800-171 Rev 2 because of a standing DoD class deviation (despite Rev. 3 being published)
DFARS 252.204-7019 & 7020 – NIST SP 800-171 Assessments
-
- 7019: Requires self-assessment every 3 years; score posted in SPRS
- 7020: Allows DoD to conduct Medium or High assessments
- Will continue to be mandatory for contract eligibility
- Enforcement pressure increased significantly in 2025/2026 due to DoJ’s Civil Cyber-Fraud Initiative (FCA)
FAR 52.204-21 – Basic Safeguarding of FCI
-
- Applies to contractors handling Federal Contract Information (FCI)
- Requires implementation of 15 basic cybersecurity controls
- Forms the basis for CMMC Level 1
- Annual Self-assessment
- Effective: Since 2016
NIST SP 800-171 & SP 800-172
-
- Technical foundation for protecting CUI in non-federal systems
- SP 800-171: 110 controls for protecting CUI
- SP 800-172: 24 enhanced controls for advanced threats – basis for CMMC Level 3
- Required for CMMC Level 2 and Level 3
- Self-assessment but must be documented and available for DoD review
- Must be documented in a System Security Plan (SSP) and POA&M
- NIST 800-171 Rev 2 remains official baseline because of a standing DoD class deviation (despite Rev 3 being published)
DoDI 5200.48 – CUI Program
-
- Defines DoD rules for identifying, marking, and protecting CUI
- Contractors must follow DoD CUI handling procedures
- 2026 DoD found widespread errors in CUI marking and misuse of dissemination controls
- Supports DFARS 7012 and CMMC compliance
DoDI 5000.90 – Cybersecurity in Acquisition
-
- Guides acquisition officials on integrating cybersecurity into program lifecycles
- Requires cybersecurity planning and risk management throughout acquisition phases
Executive Order 14028 – Improving the Nation’s Cybersecurity
-
- Federal-wide directive to modernize cybersecurity
- Mandates Zero Trust Architecture, secure cloud adoption, and software supply chain security
- Requires incident reporting and endpoint detection
- Signed: May 2021; implementation ongoing
GSA CUI Framework Summary
Major Expansion of CUI Requirements Beyond DoD
-
- GSA launched new CUI security framework Jan 5, 2026
- Requires NIST SP 800171 Rev. 3 as baseline (DoD still uses Rev. 2)
- Imposes:
- 1hour cyber incident reporting
- Required flow-down to subcontractors
- Formal documentation + independent assessments
- Signals federal-wide shift toward mandatory CUI control
CMMC Resources & Documentation (From the US Department of Defense)
CMMC Resources & Documentation (External Sources)
Additional Resources:
Imprimis Inc. is committed to "Turning Technology Into Capability" for your company... No matter your size or sector, we meet you where you are, and take you where you need to be.
Ready to explore how we can support your assessment and compliance journey? CONTACT US to start the conversation now! 