Foundational
Protects FCI — Federal Contract Information. The basic safeguarding baseline for information not intended for public release.
- Controls17
- Assessmentannual self
- Affirmed inSPRS
CMMC 2.0 left the rulemaking queue on November 10, 2025, when the 48 CFR acquisition rule took effect and DFARS 252.204-7021 began flowing into new DoD solicitations. From November 10, 2026, a Level 2 certification from a C3PAO is required at award for work involving CUI. Atom gets you assessment-ready before your prime asks — and keeps you there afterward.
The Cybersecurity Maturity Model Certification program verifies that a contractor has actually implemented the safeguards it has long been contractually obligated to have. DFARS 252.204-7012 has required implementation of NIST SP 800-171 and 72-hour incident reporting via DIBNet for years. What changed in November 2025 is enforcement: the government now checks, at a defined assurance level, before it awards.
A February 1, 2026 restructuring tied to the broader FAR overhaul deleted DFARS 252.204-7019 and renumbered 252.204-7020 to 252.240-7997. The two clauses that carry the weight — 7012 and 7021 — remain unchanged and in full effect.
Your level is set by the data your contracts touch and named in the solicitation. Most of the Defense Industrial Base lands at Level 2. Read the data type first — the control count and assessment method follow from it.
Protects FCI — Federal Contract Information. The basic safeguarding baseline for information not intended for public release.
Protects CUI — Controlled Unclassified Information. This is where the majority of primes and subs handling technical data sit.
Protects CUI against advanced persistent threats on the highest-priority programs. Builds on Level 2.
The same distinction, in a single view: what each level protects, how many controls it measures, who assesses it, and how often.
| Attribute | Level 1 | Level 2 | Level 3 |
|---|---|---|---|
| Protects FCI | ✓ | ✓ | ✓ |
| Protects CUI | — | ✓ | ✓ |
| Control count | 17 | 110 | 110 + 800-172 |
| Assessment | Self | C3PAO | Government |
| Frequency | Annual | Every 3 yrs | Every 3 yrs |
DoD is phasing CMMC in rather than switching it on all at once. Each phase raises what a contracting officer must require at award. The safe read: work backward from the phase that lands on your contract type, then add the months a real remediation takes.
Level 1 or Level 2 self-assessment required at award. DoD may include Level 2 certification at its discretion on selected acquisitions.
Level 2 third-party certification by a C3PAO required at award for contracts involving CUI. This is the deadline most of the DIB is racing.
Level 2 certification extends to option exercises, not just new awards. Level 3 requirements are introduced at award on the highest-priority programs.
CMMC requirements apply across all applicable DoD contracts. The ramp is complete.
We are not a C3PAO and we do not issue the certification. What we do is the work that makes the certification pass: define the boundary, close the gaps, write the evidence, and operate the controls so they hold between assessments.
We map where CUI is created, stored, and transmitted and draw the assessment boundary tightly around it. A smaller, well-defined enclave is fewer controls to prove.
DFARS 252.204-7012
We score you against all 110 requirements and give you an honest SPRS number — not an aspirational one. You know exactly where you stand before a prime or an assessor does.
NIST SP 800-171
We author the System Security Plan that describes how each control is met and a Plan of Action & Milestones that tracks the ones that aren't — with owners and dates an assessor will accept.
NIST SP 800-171
We close the gaps for real — access control, MFA, logging, media protection, incident response — using the managed stack we operate, and we generate the artifacts that prove each one.
DFARS 252.204-7021
We run a mock assessment against the same objectives your C3PAO will use, tighten the evidence package, and stand beside you through the official assessment. We prepare; the C3PAO certifies.
DFARS 252.204-7021
Certification is a point in time; compliance is continuous. Our managed SOC and vCISO reviews keep the controls operating, file your annual affirmation, and flag when a CUI change must be reported.
SPRS affirmations
The data. Level 1 protects Federal Contract Information against 17 controls with an annual self-assessment. Level 2 protects CUI against all 110 NIST SP 800-171 controls and, for prioritized acquisitions, requires a C3PAO third-party assessment on a three-year cycle. If your contract touches CUI, you are almost certainly Level 2.
A Plan of Action & Milestones: the documented list of controls you have not yet fully met, each with a remediation owner and a target date. A limited set of controls may be POA&M-eligible with a closeout window; the highest-weighted requirements must be met outright. It is the difference between an honest plan and a failed assessment.
Yes, when the requirement flows down. If a prime hands you FCI or CUI to do the work, the applicable CMMC level flows to you through the contract. Subs are a common weak link, and primes increasingly ask for your SPRS score before they place the work. “We’re just a sub” is not an exemption.
For a Level 2 environment starting from a low SPRS score, plan on several months of real remediation before a credible C3PAO assessment — longer if a compliant enclave has to be stood up and CUI migrated. Standing infrastructure up, closing controls, and building an evidence package that survives scrutiny is not a two-week project. Start against the phase that lands on your contract.
Request a readiness assessment. We’ll scope your CUI boundary, score you against all 110 NIST SP 800-171 controls, and hand you a prioritized, dated path to the level your contracts require.
Request a Readiness Assessment →