Skip to content

What Does CMMC 2.0 Require?

CMMC Compliance for DoD Contractors

What Is CMMC 2.0?

CMMC 2.0 is the DoD's method for requiring organizations in the DoD supply chain to protect FCI, CUI, and/or ITAR to the appropriate level determined.


Here are a few types of data requiring different levels from CMMC Level 1 to CMMC Level 3:
CMMC Level Graphic

This page is built as an overview of the following:

  • CMMC 1.0 To CMMC 2.0
  • Who Is Affected By CMMC 2.0?
  • The Three Levels of CMMC
  • When will CMMC 2.0 appear in contracts?
  • How Does The DIB Prepare For CMMC 2.0?
  • Microsoft 365 and CMMC 2.0
  • CMMC Industry Events 
  • CMMC 2.0 Timeline

From CMMC 1.0 to CMMC 2.0

Version 1.0

  • Level 1: 17 NIST 800-171 Requirements
  • Level 2: 72 Practices (65 NIST 800-171 Requirements PLUS 7 Other Practices)
  • Level 3: 130 Practices (110 NIST 800-171 Requirements PLUS 20 Other Practices)
  • Level 4: 156 Practices (110 NIST 800-171 Requirements  PLUS 46 Additional Practices)
  • Level 5: 171 Practices (110 NIST 800-171 Requirements PLUS 61 Additional Practices)

Version 2.0

  • Level 1: 17 Practices (with an annual self-assessment or self-attestation)
  • Level 2: 110 Practices (NIST SP 800-171 and third-party assessments for critical national security information. Annual self-assessment for select programs)
  • Level 3: 110+ Practices (NIST SP 800-172 and government-led assessments)
CMMC-1.0-Level-Model-img CMMC-2.0-Level-Model-img

*Important note about the change from 1.0 to 2.0* The underlying requirements in NIST SP 800-171 have not changed. These requirements still must be implemented. If a company handles and manages Controlled Unclassified Information (CUI), then CMMC 2.0 represents very little tangible change. 

Who Is Affected by CMMC?

The Defense Industrial Base

The release of CMMC 2.0 affects the following groups: 

According to the DoD, there will be around 300,000 aerospace and defense suppliers who need to meet CMMC 2.0 compliance.
  • Cut red tape for small- and medium-sized businesses
  • Set priorities for protecting DoD information
  • Reinforce cooperation between the DoD and industry in addressing evolving cyber threats.

What are the Levels of CMMC?



Level 1: 17 Practices and Self Assessment 

  • Classified as "Basic" by the DoD
  • Requires those who handle Federal Contractor Information (FCI) to meet Level 1
  • Contractors must self-attest that they have implemented the requirements

Level One consists of 17 basic cybersecurity practices. The requirement states that all federal contractors must implement these safeguard controls.

Level 2: NIST 800-171 and 3rd Party Assessments

One of the most significant changes from CMMC 1.0 Level 3, now CMMC 2.0 Level 2, relates to the fact that the 130 controls in 1.0 Level 3 now move to 110 controls for 2.0 Level 2.

You can keep reading a Q&A blog some of the details for 1.0 to 2.0 here.

guide to cmmc level 2

Level 3: NIST 800-172

CMMC Solutions

Summit 7 has served over 650 government contractors, manufacturers, and higher ed research facilities by helping them meet the requirements for DFARS 7012NIST 800-171, and CMMC compliance. Summit 7 offers a solution set for CMMC 2.0 Levels 1, 2, and 3.

When Will CMMC Appear In Contracts?

For information regarding the CMMC compliance deadline, see our post here: CMMC Compliance Deadline

The Key For Contractors

  • The DoD is claiming that costs, burdens, and barriers to entry are significantly reduced as a result of the changes in CMMC 2.0. However, accounting for these savings and reductions is done for the overall CMMC program, not for individual companies.
  • The allowance of POAMs, the removal of the "Delta 20" controls, and the removal of process maturity requirements are the basis for significant cost reductions. However, if an OSC's costs and burdens was a result of NIST SP 800-171, then these changes are not as helpful as the government is indicating.

Rulemaking is often triggered by direction from Congress. For example, much of the impetus for the CMMC interim rule was a result of the FY 2020 NDAA. Based on the statement that DoD will pursue rulemaking, here's what we know will be codified for CMMC 2.0 based on the two CFRS. The DoD has stated that they will pursue rulemaking in Title 48 and Title 32 of the Code of Federal Regulations.

What are the two CFRs that drive rulemaking?



How to Be CMMC Compliant

1) CMMC 2.0 Level 1: Contractors Handling FCI

  • If you haven't already done so, implement the 17 practices required for CMMC 1.0 and prepare to submit your annual self-assessment results. 
    • Not sure if you have Federal Contract Information (FCI)? Start here.

2) CMMC 2.0 Level 2: Contractors Handling CUI / ITAR Data

  • Implement NIST SP 800-171 if you have not already done so.
  • Prepare for third-party (C3PAO) or government-led assessments 


3) CMMC 2.0 Level 3: Contractors Handling CUI / ITAR Data / Secret / Top Secret Data

  • Since the CMMC 2.0 Levels are in aggregate you will need to implement the requirements for L1, L2, and L3
  • Implement the practices based on NIST SP 800-172
  • Prepare for Triannual government-led assessments of your environment(s)

Microsoft 365 and CMMC 2.0 Compliance

Many contractors in the DoD supply chain have already chosen to tackle federal compliance in the Microsoft Government Cloud. Examples of some of the applications contractors rely on are:


Do You Need Microsoft 365 GCC High For CMMC 2.0?

The short answer: No

The long answer: You likely need to choose GCC High for your overall compliance strategy.

GCC High is not required to meet CMMC 2.0 at any Level. However, Microsoft's official recommendation is for organizations planning or required to meet CMMC 2.0 Level 2 (formerly CMMC 1.0 Level 3) should deploy to Microsoft 365 GCC High. The Commercial and GCC versions of the platform can be configured to meet NIST 800-171, and the vast majority of CMMC's requirements with native security products/capabilities. CMMC 2.0 Level 2, for example, can be met in Commercial and GCC per the standards written to date.

What Is Microsoft 365 GCC High? Start here.

The graphic below represents the Microsoft Platform as it relates to relevant compliance frameworks such as CMMC, DFARS 7012, ITAR regulations.


There are several long-term concerns and considerations to assess, and these are highlighted in this guide to GCC vs GCC High.


CS2: CMMC Industry Days

CS2 Full Logo Black-1What Is CS2?

CS2, or The Cloud Security and Compliance Series, is an ongoing informational series for contractors in the Defense Industrial Base looking to meet federal compliance mandates. These hybrid events are specifically curated towards aerospace and defense contractors and those in higher education institutions looking for practical approaches to address security threats, invest in the culture of cybersecurity for their organization, and glean best practices for their cloud investments.

Areas of focus for CS2 events include, but are not limited to


Contact Us

More Resources