The CMMC Acquisition Rule took effect November 10, 2025. Certification is required for award on applicable contracts, with no grace period. See the phase-in schedule →

CMMC Certification

Certification Readiness for the
Defense Industrial Base.

CMMC requirements are appearing in DoD solicitations now. GiaMetrics® supports contractors from initial gap assessment through control implementation, documentation, and readiness for a C3PAO assessment, delivered by Cyber AB credentialed practitioners.

Governance is the foundation. Assurance is the proof.

What CMMC Requires, and Why It Is Urgent Now

The Cybersecurity Maturity Model Certification program verifies that defense contractors have implemented the security requirements needed to protect Federal Contract Information and Controlled Unclassified Information. It replaces self-attestation with verified assessment for most work involving CUI.

For most contractors the practical question is not whether to pursue certification. It is how much work stands between the current state and a defensible assessment, how long that work takes, and whether the assessment scope has been drawn correctly.

Scoping deserves particular attention. Organizations routinely bring far more of their environment into the assessment boundary than their contracts require, which multiplies both implementation cost and the ongoing maintenance burden for the full three-year certificate period.

GiaMetrics practitioners hold Cyber AB credentials as Registered Practitioner and Certified CMMC Professional.

Four Things to Know

  • Protects CUI and FCI. The requirement follows the information, not the organization.
  • Mandatory for award. Certification is a condition of eligibility, not a differentiator.
  • Flows down to subcontractors. Primes are responsible for ensuring subs comply.
  • Annual affirmation required. The certificate runs three years; the obligation is continuous.

Which Level Applies to You

Your required level is specified in your DoD contract and depends on the sensitivity of the information your systems handle.

Level 1

Foundational

For organizations handling Federal Contract Information only

17 Practices Self-Assessment FAR 52.204-21
  • Basic cyber hygiene across six domains
  • Annual self-assessment and affirmation in SPRS
  • No third-party assessor required
  • Access control, identification, media and physical protection, system integrity
Level 2 · Most Common

Advanced

For organizations handling Controlled Unclassified Information

110 Practices C3PAO Required NIST SP 800-171
  • Full alignment with NIST SP 800-171 Rev. 2, 110 requirements across 320 assessment objectives
  • Third-party C3PAO assessment required for most CUI contracts
  • System Security Plan and POA&M documentation required
  • POA&Ms permitted for certain non-compliant items
  • Certificate valid three years, annual affirmation required
Level 3

Expert

For the most critical national security programs

110+ Practices DIBCAC Assessment NIST SP 800-172
  • Builds on Level 2 with additional NIST SP 800-172 requirements
  • Government-led assessments conducted by DIBCAC
  • Targets advanced persistent threat defense
  • Continuous monitoring and proactive threat hunting required

The Four-Phase Phase-In

Requirements roll out across DoD contracts in four phases through 2028. Where your contracts fall in this schedule determines your urgency.

1
November 10, 2025 to November 9, 2026

Enforcement Begins

CMMC requirements now appear in applicable new DoD contracts. Level 1 and Level 2 self-assessments are required on applicable solicitations. A valid certification is required for award, and there is no grace period.

Active Now
2
November 10, 2026 to November 9, 2027

C3PAO Assessments Required

DoD solicitations and contracts may require Level 2 certificates issued by Certified Third-Party Assessment Organizations for CUI-sensitive work. Begin C3PAO preparation at least six months ahead.

Approaching
3
November 10, 2027 to November 9, 2028

Level 3 Enters Scope

Higher-sensitivity programs may require Level 2 C3PAO assessments or Level 3 government-led DIBCAC assessments. Contractors on critical programs should anticipate Level 3 requirements.

4
November 10, 2028 onward

Full Mandatory Compliance

CMMC requirements apply across all applicable DoD contracts, including options exercised on existing awards. No further phase-in remains.

CMMC Support Services

Engagements are scoped to where you actually are, whether that is a first look at the requirement or final preparation before an assessment window.

Gap Assessment & Readiness Review

A control-by-control evaluation against NIST SP 800-171, with a current SPRS score, an honest picture of what stands between you and a defensible assessment, and a realistic time estimate.

CUI Scoping & Enclave Design

Organizations routinely bring far more of their environment into assessment scope than the contract requires. Scoping decisions made early determine both implementation cost and the ongoing maintenance burden.

SSP & POA&M Development

A System Security Plan that an assessor can actually follow, and a POA&M with real owners and real dates rather than placeholders that will not survive examination.

Control Implementation & Remediation

Prioritized remediation that distinguishes blocking gaps from manageable ones, sequenced against your contract timeline rather than against the control catalog order.

C3PAO Assessment Support

Preparation and support through the formal assessment, delivered by practitioners holding Cyber AB Registered Practitioner and Certified CMMC Professional credentials.

Continuous Compliance & Annual Affirmation

Certification is valid for three years but requires annual affirmation. Control state and evidence are maintained through the FutureFeed platform rather than reconstructed each cycle.

The Proof

A Score You Can Defend and Evidence You Can Show

Certification is an evidence exercise. Through the FutureFeed platform, control state, SPRS scoring, and supporting artifacts are maintained continuously rather than reconstructed under deadline before an assessment window opens.

SPRSLive scoring, always current
SSPGenerated from actual control state
POA&MTracked with owners and dates
AssessmentEvidence ready on request

What the Formal Assessment Looks Like

From first contact with a C3PAO through certificate issuance, with defined milestones at each phase.

Pre-Assessment

Confirm Scope: Entities, CAGE Codes & ESPs

The C3PAO verifies the legal entities to be assessed, collects CAGE codes, and determines whether External Service Providers fall within scope. Your assessment unique identifier is established.

Pre-Assessment

Frame the Assessment

Logistics, schedule, personnel, evidence accessibility, and the formal CMMC Assessment Scope are agreed. On-site versus virtual format is determined and confirmed with your SSP in hand.

Pre-Assessment

Resolve Conflicts of Interest

C3PAOs must comply with ISO/IEC 17020:2012 impartiality requirements. A Lead CCA is proposed and approved. Conflicts are disclosed, documented, and mitigated before the assessment proceeds.

Pre-Assessment

Execute Contractual Agreement & NDA

A formal written agreement including a mutual Non-Disclosure Agreement is executed between the C3PAO and your organization. The DoD and the Cyber AB are not parties to this contract.

Assessment

Phase 1: Pre-Assessment

The C3PAO evaluates whether your organization has sufficiently prepared, reviewing SSP completeness, documentation readiness, and control implementation status. The Pre-Assessment Information Form is submitted to eMASS.

Assessment

Phase 2: Assessment Conformity

The core evaluation. All 110 NIST SP 800-171 requirements are assessed across depth and coverage objectives through interviews, document reviews, and direct observation, following 32 CFR 170.17 and NIST SP 800-171A.

Assessment

Phase 3: Report Assessment Results

Findings are documented and delivered. Results are uploaded to eMASS and flow to SPRS, where contracting officers verify status before award.

Closeout

Phase 4: Issue Certificate & Close POA&Ms

The certificate is issued with a three-year validity. Any POA&M items eligible for deferral must be closed within 180 days, and annual affirmation obligations begin.

Where Organizations Get Stuck

Most CMMC efforts do not fail on technical controls. They fail on structural questions that were never answered: who owns this system, what is actually in scope, where did this evidence come from, and who accepted this risk.

This is why we approach certification as an application of a governance foundation rather than as a standalone documentation project. Organizations that establish ownership, boundaries, and evidence structurally find that the assessment becomes a mapping exercise against work already done.

It also means the work does not have to be repeated. The same foundation supports RMF and FedRAMP obligations that may follow.

See the GRC foundation →

  • Assessment scope defined far more broadly than the contract requires
  • CUI never formally identified or located across the environment
  • System Security Plan written once and never maintained
  • POA&M items with no named owner and no real date
  • Evidence assembled only in the weeks before assessment
  • Inherited controls from service providers never documented
  • Subcontractor flow-down clauses never updated
  • SPRS score stale or inconsistent with actual posture

Evidence Maintained, Not Reconstructed

GiaMetrics is a certified FutureFeed partner. FutureFeed is a FedRAMP High-authorized compliance platform running on AWS GovCloud, purpose-built for CMMC and NIST SP 800-171 evidence management.

Live SPRS ScoringKnow your score before a contracting officer does.

SSP & POA&M GenerationProduced from live control state.

CUI DiscoveryFind controlled information before an assessor does.

Annual AffirmationEvidence current when affirmation comes due.

110
NIST SP 800-171 requirements tracked continuously
320
Assessment objectives mapped to evidence
SPRS
Live scoring, submitted with confidence
Available as a managed service through GiaMetrics or as a standalone subscription · futurefeed.co

CMMC, Answered Directly

Is CMMC actually required right now?

Yes. The CMMC Acquisition Rule at 48 CFR became effective November 10, 2025. Contracting officers are now including CMMC requirements in applicable new DoD solicitations. Contractors without the required certification level are ineligible for award on those contracts, and there is no grace period.

How do I know which level I need?

Your required level is specified in the DoD contract or solicitation. As a general matter, handling only FCI with no CUI points to Level 1. Contracts involving CUI most commonly require Level 2. Level 3 applies to the most sensitive national security programs. We can review your contract vehicles and data flows to confirm which level applies.

What changed between CMMC 1.0 and what exists now?

The original model used five levels and required third-party assessment for all contractors. The current model streamlined this to three levels, aligned requirements with existing NIST standards, and introduced self-assessment for Level 1 and some Level 2 scenarios. What is now simply called CMMC is what is currently in effect.

Do requirements flow down to my subcontractors?

Yes. Any subcontractor that processes, stores, or transmits FCI or CUI covered by your prime contract must achieve the appropriate level. As the prime you are responsible for ensuring subcontractor compliance and must update subcontract templates with proper flow-down clauses.

What if we are not fully compliant yet?

Limited use of Plans of Action and Milestones is permitted for certain non-compliant items, but not all requirements are POA&M-eligible. Some must be fully implemented before certification. We help identify which gaps are blocking versus manageable, build a realistic POA&M, and prioritize remediation before your next opportunity closes.

How long does Level 2 certification take?

It varies substantially with your current posture. Organizations starting from a low SPRS score with incomplete documentation should budget six to eighteen months of preparation before engaging a C3PAO. The formal assessment itself takes several weeks to months depending on organization size. Starting early is strongly recommended, since assessor availability is constrained relative to the scale of the requirement.

What is SPRS and why does it matter?

The Supplier Performance Risk System is where certifications, self-assessment scores, and annual affirmations are tracked. Contracting officers verify CMMC status through SPRS before award. Inaccurate records affect contract eligibility, and misrepresentation may create False Claims Act exposure.

SDVOSB Certified SBA Service-Disabled Veteran-Owned Certified

Service-Disabled Veteran-Owned Small Business

GiaMetrics® is an SDVOSB verified through the U.S. Small Business Administration. Federal agencies and prime contractors can apply GiaMetrics work toward SDVOSB subcontracting goals under FAR Part 19.

Have a Project? Let’s Talk.

We work with organizations at every stage, from those addressing governance for the first time to those with mature programs facing a new requirement. Tell us about your situation and we will outline a clear path forward.

Phone(202) 381-7575
Emailservices@giametrics.com
Small Business StatusSDVOSB Certified · SBA Verified

Send Us a Message

Whether you are exploring your options or ready to start, we are here to help. All inquiries are confidential.

Your information is kept strictly confidential.

Thank you for your inquiry. We have received your message and will review the information provided. We look forward to connecting with you to discuss your needs and potential next steps.

Something went wrong. Please email us at services@giametrics.com