How to Prepare for CMMC: A Contractor's Guide
Published July 5, 2026
To prepare for CMMC, you confirm which level your contracts require, map where Federal Contract Information and Controlled Unclassified Information live in your business, assess your systems against the NIST SP 800-171 requirements, close the gaps, and assemble the documentation an assessor expects before your assessment is due. The work is real but it is finite, and the businesses that start early treat it as a project with a plan rather than a scramble against a deadline. This guide lays out the path in plain English, for the defense contractor or supplier who knows CMMC is coming and wants to get ahead of it. One thing up front: a partner can prepare you, but only an authorized assessor certifies you, and we are clear about that difference throughout.
What CMMC is, and what changed
CMMC, the Cybersecurity Maturity Model Certification, is the Department of Defense's program for verifying that companies in its supply chain actually protect sensitive government information. The key word is verifying. For years, contractors self-attested to meeting security requirements. CMMC adds assessment and, for most handling sensitive data, third-party certification, so the security is checked rather than just promised.
If you read older articles, ignore anything describing five levels or 130 practices. That was the original 2020 model. The current program, sometimes called CMMC 2.0, has three levels, and it became real regulation recently: the program rule took effect in December 2024, and the acquisition rule that puts CMMC into actual contracts took effect in November 2025, starting a phased rollout. As of 2026 we are in the early phases, which is exactly the window to get ready in.
Step one: find your level
Your required CMMC level is not something you choose. It is set by the type of government information you handle, and it will be written into your contracts. Here is the plain-English version:
| Level | Protects | Requirements | How it is assessed |
|---|---|---|---|
| Level 1 | Federal Contract Information (FCI) | 15 basic safeguards | Annual self-assessment |
| Level 2 | Controlled Unclassified Information (CUI) | The 110 requirements of NIST SP 800-171 | Self-assessment or C3PAO certification every three years, depending on the contract |
| Level 3 | CUI, highest priority programs | Level 2 plus a subset of NIST SP 800-172 | Government-led assessment |
The FCI versus CUI distinction drives everything. Federal Contract Information is basic non-public information tied to a contract. Controlled Unclassified Information is more sensitive and carries specific handling rules. If you only ever touch FCI, you are likely a Level 1 business with a manageable path. The moment CUI enters, you are at Level 2 and the 110 requirements of NIST SP 800-171 apply. Most of the defense supply chain lands at Level 2.
Step two: scope where FCI and CUI live
Before you assess anything, you have to know where the protected information actually is: which systems store it, process it, or transmit it, and which people and services touch it. This scoping step is where readiness is won or lost, because it defines how big your compliance boundary is. A common and powerful move is to deliberately shrink that boundary, keeping CUI inside a defined enclave rather than letting it spread across your whole network. A smaller, well-defined scope is faster to secure, cheaper to maintain, and far easier to assess. Getting this wrong, and accidentally pulling your entire environment into scope, is the most expensive mistake in CMMC.
Step three: assess against NIST 800-171 and score it
For Level 2, readiness means measuring your environment against the 110 requirements in NIST SP 800-171. This is where CMMC connects to the broader NIST world we cover in our guide to the NIST Cybersecurity Framework: the framework is voluntary guidance for any business, while 800-171 is the specific, contractual requirement set for protecting CUI, and it is the technical heart of CMMC Level 2.
The assessment produces a score, and here is a fact many contractors miss: you very likely need to be doing this already. Even ahead of full CMMC enforcement, defense contractors are expected to have a current NIST SP 800-171 self-assessment score posted in the government's Supplier Performance Risk System, or SPRS, to be considered for many awards. Contracting officers check SPRS before they award. So the 800-171 assessment is not a future CMMC task, it is a present-day expectation you can act on now.
Step four: understand what can and cannot wait
CMMC allows a Plan of Action and Milestones, a POA&M, for some gaps, meaning you can achieve a conditional status while you finish specific items. But the rules are strict, and knowing them shapes your priorities:
- To earn a conditional status, you must already meet the large majority of requirements. Falling short on too many means no conditional status at all.
- Certain high-value requirements can never sit on a POA&M. Your system security plan itself, key access controls, and certain physical protections have to be fully in place, not planned.
- Anything on a POA&M has to be closed out within 180 days, or the conditional status expires.
The practical takeaway: identify the requirements that cannot be deferred and do those first, well before your assessment. Leaving a "cannot POA&M" item unfinished is what turns an assessment into a failed one.
Step five: document, and know who certifies
CMMC runs on evidence. The centerpiece is your System Security Plan, the document that describes how you meet each requirement, backed by the policies, configurations, and records that prove the controls are real and running. Assessors do not take your word for it; they look for the artifacts. Building and maintaining that evidence, and keeping it current between assessments, is the ongoing part of readiness and exactly the kind of discipline a good compliance readiness partner sets up alongside your day-to-day security program.
Be clear on roles, because the market is full of muddy claims. Only an authorized third-party assessment organization, a C3PAO, can conduct a Level 2 certification assessment. Consultants, managed IT providers, and registered practitioners prepare you: they run the gap assessment, implement controls, write the documentation, and get you assessment-ready. They do not, and cannot, issue the certification. Anyone telling you they will certify you directly is misrepresenting how the program works. For what it is worth, we have already taken an organization through to CMMC readiness and the underlying 800-171 work, so this is ground we have walked, and we are just as clear there: we prepare you for the assessment, the C3PAO performs it.
Why 2026 is the year to move
The rollout is phased and the requirements ratchet up over time. In the current phase, some contracts already require a self-assessment as a condition of award. The next phase makes third-party certification a condition of award for Level 2 contracts, and after that the requirements keep expanding through 2028. Readiness for Level 2 is not a quick task; scoping, closing gaps, and building evidence realistically takes months. That gap between how long preparation takes and how soon certification becomes a condition of winning work is the whole argument for starting now. The contractors who wait until a specific solicitation demands certification will be doing months of work against a clock, while their competitors already hold the status.
Frequently asked questions
What are the three CMMC levels and which one do I need?
Level 1 covers 15 basic safeguards for Federal Contract Information and is self-assessed each year. Level 2 covers the 110 requirements of NIST SP 800-171 for Controlled Unclassified Information. Level 3 adds a subset of 800-172 and is government-assessed. Your required level is set by your contract, so the answer is in your contract language, not a guess.
Can we self-assess for CMMC Level 2, or do we need a C3PAO?
It depends on the contract. Some Level 2 contracts allow an annual self-assessment; most require a certification assessment by an authorized third party, a C3PAO, every three years. The specific contract tells you which. Plan for the C3PAO path unless your contract clearly says otherwise.
What is the difference between FCI and CUI?
Federal Contract Information is basic information provided by or generated for the government under a contract that is not meant for public release. Controlled Unclassified Information is more sensitive government information that requires safeguarding under specific rules. FCI maps to CMMC Level 1; CUI maps to Level 2.
When do CMMC requirements start appearing in contracts?
They already have. The rollout began in late 2025 and runs in phases. As of 2026, some contracts require a self-assessment as a condition of award, and the phase that makes third-party certification a condition of award for Level 2 contracts follows in stages after that. New requirements keep phasing in through 2028, so the safe assumption is that it is coming to your contracts soon if it has not already.
Do consultants or MSPs certify us for CMMC?
No. Only an authorized third-party assessor, a C3PAO, can conduct a certification assessment. Consultants, managed IT providers, and registered practitioners prepare you for that assessment, implement the controls, and assemble the evidence, but they do not issue the certification. Be cautious of anyone who claims to certify you directly.
What is SPRS and why does it matter?
SPRS is the government system where your assessment scores and affirmations are posted. Contracting officers check it before award. In fact, even ahead of full CMMC, defense contractors are already expected to have a current NIST SP 800-171 self-assessment score posted in SPRS to be considered for many awards, so it matters today, not just later.
Getting CMMC-ready on your terms, not the deadline's
Preparing for CMMC comes down to knowing your level, scoping the information you have to protect, meeting the 800-171 requirements behind it, and building the evidence an assessor will expect, ideally well before a contract makes it urgent. It is a project you can plan and control if you start with time to spare, and a scramble if you wait for a solicitation to force it. If you want to know exactly where you stand against your required level, Desert Lakes Solutions offers a no-pressure discovery call to walk through your scope, your likely gaps, and a realistic path to assessment-ready. Book a discovery call and we will give you the honest version, including where the real work is.