Phase 1 Active — Phase 2 Mandatory Nov 2026

CMMC compliance,
finally clear.

The free, independent resource for defense contractors navigating CMMC certification. Learn the requirements, assess your readiness, and find verified compliance partners — all in one place.

220,000+
Defense contractors affected
~1%
Fully audit-ready today
Nov 2026
Mandatory C3PAO assessments begin
6–12 mo
Typical time to reach compliance

What is CMMC?

The Cybersecurity Maturity Model Certification is a DoD program that requires defense contractors to prove their cybersecurity practices meet specific standards before they can win or keep contracts. It's now law — and enforcement has begun.

L1
Foundational
17 controls · FCI

Basic safeguarding of Federal Contract Information. 17 practices focused on fundamental cyber hygiene like access control, identification, media protection, physical protection, system integrity, and communications protection.

FAR 52.204-21
L2
Advanced
110 controls · CUI

Comprehensive protection of Controlled Unclassified Information across 14 control families and 320 assessment objectives. This is where most defense contractors need to be.

NIST SP 800-171 Rev 2
L3
Expert
134 controls · CUI+

Enhanced protections against Advanced Persistent Threats (APTs). Adds 24 controls on top of Level 2 for the most sensitive programs. Government-led assessment by DIBCAC.

NIST SP 800-172

Implementation Timeline

CMMC enforcement is phased in over three years. Here's what's happening and when.

Nov 10, 2025Phase 1← We are here
Self-Assessments Begin

Level 1 and Level 2 self-assessments required in select contracts. DoD may also require C3PAO certifications at its discretion.

Nov 10, 2026Phase 2
C3PAO Audits Mandatory

Third-party C3PAO certifications become mandatory for Level 2 contracts. Level 3 DIBCAC assessments may begin.

Nov 10, 2027Phase 3
Level 3 Enforcement

Level 3 DIBCAC assessments required for applicable contracts. Full enforcement across all three levels.

Nov 10, 2028Phase 4
Full Implementation

CMMC requirements included in all applicable DoD contracts. Complete rollout across the Defense Industrial Base.

Not sure where you stand?

Take the free readiness check — 8 questions, 3 minutes, instant gap analysis.

📚

CMMC Academy

Free courses on every CMMC level and control family. Plain-English explainers with real examples.

Start Learning
🤝

Find a Partner

Searchable directory of verified MSPs, C3PAOs, and consultants. Filter by state, specialty, and level.

Browse Directory
📋

Resource Library

Free templates, checklists, and guides — SSPs, POA&Ms, scoping tools, and more.

Get Resources