Back to Field Notes
International Standards/Field Note

CMMC 2.0 — What the Defense Supply Chain Actually Has to Do

CMMC 2.0's three levels map cleanly to FCI, CUI, and high-value CUI. Get scoping right and the rest of the program follows.

Author

Mark Velasquez

Principal Standards Architect

Published

January 10, 2026

Read

10 min

Share
AI-generated illustration of a banking data center
AI-generated illustration of a banking data center
Key Takeaways
  • 01Three levels: L1 = 17 FAR practices (annual self-assessment), L2 = 110 NIST 800-171 practices (triennial third-party for prioritized contracts), L3 = 110 + subset of 800-172 (triennial government).
  • 02The single most expensive mistake is over-scoping the assessment boundary. Define your CUI data flows, isolate them in an enclave, and exclude the rest of corporate IT from scope.
  • 03A 25,000-endpoint corporate estate can often reduce to a 200-endpoint CUI enclave. The audit cost difference is two orders of magnitude.
  • 04POAMs are allowed for a small subset of practices with a 180-day closure window. Do NOT architect a program that depends on POAMs as permanent compensating controls — the rule is explicit they are temporary.

The Cybersecurity Maturity Model Certification 2.0 program codifies what the defense industrial base has been navigating informally for years: a tiered, assessor-validated control set that scales with the sensitivity of the information you handle.

The three levels

  • 01Level 1 — Foundational. 17 practices from FAR 52.204-21. Annual self-assessment.
  • 02Level 2 — Advanced. 110 practices from NIST SP 800-171. Triennial third-party assessment for prioritized contracts; self-assessment otherwise.
  • 03Level 3 — Expert. 110 practices from 800-171 plus subset of 800-172. Triennial government assessment.

Scoping is the program

The single most expensive mistake is over-scoping the assessment boundary. Define your Controlled Unclassified Information (CUI) data flows, isolate them in a CUI enclave (often a separate cloud tenant or on-prem environment), and exclude the rest of corporate IT from the assessment scope.

An organization with a 25,000-endpoint estate can often get to a 200-endpoint enclave that holds CUI. The audit cost difference is two orders of magnitude.

POAMs are limited, not eliminated

CMMC 2.0 allows a Plan of Action and Milestones for a small subset of practices, with a 180-day closure window. Do not architect a program that depends on POAMs as permanent compensating controls — the rule is explicit that they are temporary.

#CMMC#DFARS#Federal

/WRITTEN_BY

Mark Velasquez

Principal Standards Architect · Alexa Cybersecurity