Atom Cybersecurity — two practices, one standard
CMMC 2.0 • 48 CFR final rule • DFARS 252.204-7021

The clause is in the contract now.

CMMC 2.0 left the rulemaking queue on November 10, 2025, when the 48 CFR acquisition rule took effect and DFARS 252.204-7021 began flowing into new DoD solicitations. From November 10, 2026, a Level 2 certification from a C3PAO is required at award for work involving CUI. Atom gets you assessment-ready before your prime asks — and keeps you there afterward.

Where the program stands

CMMC is no longer a rule in progress. It's a term in the deal.

The Cybersecurity Maturity Model Certification program verifies that a contractor has actually implemented the safeguards it has long been contractually obligated to have. DFARS 252.204-7012 has required implementation of NIST SP 800-171 and 72-hour incident reporting via DIBNet for years. What changed in November 2025 is enforcement: the government now checks, at a defined assurance level, before it awards.

A February 1, 2026 restructuring tied to the broader FAR overhaul deleted DFARS 252.204-7019 and renumbered 252.204-7020 to 252.240-7997. The two clauses that carry the weight — 7012 and 7021 — remain unchanged and in full effect.

  • DFARS 252.204-7021 — the CMMC clause, inserted into applicable new DoD contracts and setting the required level.
  • DFARS 252.204-7012 — implement NIST SP 800-171; report cyber incidents within 72 hours via DIBNet; safeguard Covered Defense Information / CUI.
  • NIST SP 800-171 (Rev 2) — the 110 security requirements a Level 2 assessment measures against.
  • SPRS — where your self-assessment score and annual affirmations are recorded and where primes can see them.
Scope first

Which level do you need?

Your level is set by the data your contracts touch and named in the solicitation. Most of the Defense Industrial Base lands at Level 2. Read the data type first — the control count and assessment method follow from it.

Level 1

Foundational

Protects FCI — Federal Contract Information. The basic safeguarding baseline for information not intended for public release.

  • Controls17
  • Assessmentannual self
  • Affirmed inSPRS
Level 2 • most common

Advanced

Protects CUI — Controlled Unclassified Information. This is where the majority of primes and subs handling technical data sit.

  • Controls110 · 800-171 Rev 2
  • AssessmentC3PAO third-party
  • Cycle3-year
Level 3

Expert

Protects CUI against advanced persistent threats on the highest-priority programs. Builds on Level 2.

  • Adds800-172 subset
  • Assessed byGovernment · DIBCAC
  • BaselineLevel 2 first
Side by side

CMMC 2.0 at a glance

The same distinction, in a single view: what each level protects, how many controls it measures, who assesses it, and how often.

AttributeLevel 1Level 2Level 3
Protects FCI
Protects CUI
Control count17110110 + 800-172
AssessmentSelfC3PAOGovernment
FrequencyAnnualEvery 3 yrsEvery 3 yrs
The rollout

Four phases over three years. The bar rises on a schedule.

DoD is phasing CMMC in rather than switching it on all at once. Each phase raises what a contracting officer must require at award. The safe read: work backward from the phase that lands on your contract type, then add the months a real remediation takes.

Find your phase — book an assessment →

  • Phase 1 • Nov 10, 2025

    Self-assessment at award

    Level 1 or Level 2 self-assessment required at award. DoD may include Level 2 certification at its discretion on selected acquisitions.

  • Phase 2 • Nov 10, 2026

    Level 2 C3PAO certification

    Level 2 third-party certification by a C3PAO required at award for contracts involving CUI. This is the deadline most of the DIB is racing.

  • Phase 3 • Nov 10, 2027

    Option exercises & Level 3

    Level 2 certification extends to option exercises, not just new awards. Level 3 requirements are introduced at award on the highest-priority programs.

  • Phase 4 • Nov 10, 2028

    Full implementation

    CMMC requirements apply across all applicable DoD contracts. The ramp is complete.

The readiness path

How Atom gets you assessment-ready.

We are not a C3PAO and we do not issue the certification. What we do is the work that makes the certification pass: define the boundary, close the gaps, write the evidence, and operate the controls so they hold between assessments.

01

Scope the CUI boundary

We map where CUI is created, stored, and transmitted and draw the assessment boundary tightly around it. A smaller, well-defined enclave is fewer controls to prove.

DFARS 252.204-7012

02

Gap assessment & SPRS score

We score you against all 110 requirements and give you an honest SPRS number — not an aspirational one. You know exactly where you stand before a prime or an assessor does.

NIST SP 800-171

03

SSP & POA&M

We author the System Security Plan that describes how each control is met and a Plan of Action & Milestones that tracks the ones that aren't — with owners and dates an assessor will accept.

NIST SP 800-171

04

Remediate the 110 controls

We close the gaps for real — access control, MFA, logging, media protection, incident response — using the managed stack we operate, and we generate the artifacts that prove each one.

DFARS 252.204-7021

05

C3PAO-ready

We run a mock assessment against the same objectives your C3PAO will use, tighten the evidence package, and stand beside you through the official assessment. We prepare; the C3PAO certifies.

DFARS 252.204-7021

06

Sustain

Certification is a point in time; compliance is continuous. Our managed SOC and vCISO reviews keep the controls operating, file your annual affirmation, and flag when a CUI change must be reported.

SPRS affirmations

Straight answers

The questions we hear first.

What’s the difference between Level 1 and Level 2?

The data. Level 1 protects Federal Contract Information against 17 controls with an annual self-assessment. Level 2 protects CUI against all 110 NIST SP 800-171 controls and, for prioritized acquisitions, requires a C3PAO third-party assessment on a three-year cycle. If your contract touches CUI, you are almost certainly Level 2.

What is a POA&M?

A Plan of Action & Milestones: the documented list of controls you have not yet fully met, each with a remediation owner and a target date. A limited set of controls may be POA&M-eligible with a closeout window; the highest-weighted requirements must be met outright. It is the difference between an honest plan and a failed assessment.

Do subcontractors need CMMC?

Yes, when the requirement flows down. If a prime hands you FCI or CUI to do the work, the applicable CMMC level flows to you through the contract. Subs are a common weak link, and primes increasingly ask for your SPRS score before they place the work. “We’re just a sub” is not an exemption.

How long does readiness take?

For a Level 2 environment starting from a low SPRS score, plan on several months of real remediation before a credible C3PAO assessment — longer if a compliant enclave has to be stood up and CUI migrated. Standing infrastructure up, closing controls, and building an evidence package that survives scrutiny is not a two-week project. Start against the phase that lands on your contract.

Start with the facts

Know your SPRS score before Phase 2 arrives.

Request a readiness assessment. We’ll scope your CUI boundary, score you against all 110 NIST SP 800-171 controls, and hand you a prioritized, dated path to the level your contracts require.

Request a Readiness Assessment