CMMC 2.0 and the defence supply chain
What the levels mean, how it relates to NIST SP 800-171, and why the assessment is the easy part.
What it is for
The Cybersecurity Maturity Model Certification programme exists because self-attestation across a very large supply chain did not produce reliable protection of sensitive but unclassified information.
It applies to organisations in the US defence industrial base that handle federal contract information or controlled unclassified information, which reaches a long way past prime contractors.
The relationship to NIST SP 800-171
The important thing to understand is that CMMC is largely an assurance wrapper around an existing control set. The technical requirements come from NIST SP 800-171.
That is good news if you have done 800-171 work already: the control implementation transfers. What CMMC adds is the requirement to demonstrate it to someone else, to a defined standard, on a defined cadence.
The levels
The levels differ principally in how assurance is obtained rather than in inventing new controls at each step. Lower levels rely on self-assessment against a basic set; the middle level introduces assessment by an accredited third party against the 800-171 control set; the highest introduces government-led assessment for the most sensitive programmes.
Which level applies is driven by the information you handle under a given contract, which means a single organisation can face different levels for different work.
Why the assessment is the easy part
Organisations that struggle rarely fail on the controls. They fail on scope and evidence.
Scope, because controlled unclassified information has usually spread further than anyone documented: into engineering file shares, onto supplier portals, into email. Narrowing and enforcing an enclave is most of the work.
Evidence, because the assessment asks for demonstration over time rather than a snapshot. If your evidence is assembled for the assessment, it describes the week of the assessment.
If you also serve non-defence customers
Most manufacturers do, and each large customer arrives with its own security schedule. The efficient approach is one control set mapped to many obligations rather than a separate programme per customer.
CMMC in particular is a fast-moving programme; current status and applicability are verified for your entities during onboarding.
Questions, answered
We are a subcontractor. Does CMMC reach us?
Does ISO 27001 cover it?
Where this goes next
Want this applied to your estate?
Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.