Government Security
CMMC 2.0 Explained: Levels, Requirements and What It Means for Suppliers
CMMC 2.0 explained: the three levels, 110 NIST SP 800-171 requirements, SPRS scoring, POA&M rules and what it means for Australian suppliers.
CMMC 2.0 is the US Department of Defense’s program for verifying that its contractors protect sensitive information. It is now written into contracts, it flows down through the supply chain, and it reaches well beyond the United States. If your organisation supplies a US defense program, directly or through a prime contractor, CMMC is likely to land on your desk.
This guide explains how CMMC 2.0 works, what each level requires, how the scoring and conditional status rules work, and what Australian suppliers should do now.
What CMMC is and why it exists
CMMC stands for the Cybersecurity Maturity Model Certification. It exists because self-declared compliance with existing rules was not working: many contractors said they met the requirements without having implemented them.
The program is set out in 32 CFR Part 170, which took effect on 16 December 2024. The contract clause that makes it enforceable, DFARS 252.204-7021, began appearing in solicitations from 10 November 2025 under a phased rollout. You can read the rule and supporting guidance on the DoD CIO CMMC site.
CMMC protects two types of information:
- Federal Contract Information (FCI): information provided by or generated for the government under a contract that is not intended for public release.
- Controlled Unclassified Information (CUI): more sensitive information that law, regulation or policy requires to be safeguarded, such as technical drawings and specifications for defense systems.
The three CMMC 2.0 levels
Level 1 (Foundational)
For contractors that handle FCI only. It covers the 15 basic safeguarding requirements in FAR 52.204-21, such as limiting system access to authorised users, sanitising media before disposal and keeping malware protection up to date. Level 1 is an annual self-assessment with an affirmation in the Supplier Performance Risk System (SPRS). Every requirement must be met, and plans of action are not allowed.
Level 2 (Advanced)
For contractors that handle CUI. It covers all 110 requirements of NIST SP 800-171 Revision 2 across 14 families, from access control to system and information integrity. Depending on the contract, Level 2 is either a self-assessment or a certification assessment by an authorised C3PAO (a CMMC Third-Party Assessment Organization), repeated every three years with an annual affirmation.
Note the revision: NIST published SP 800-171 Revision 3 in May 2024, but the CMMC rule specifies Revision 2, so that is what Level 2 is assessed against.
Level 3 (Expert)
For the most sensitive programs. Level 3 builds on a Level 2 certification and adds 24 selected requirements from NIST SP 800-172, assessed by the government’s own assessors (DIBCAC). Most suppliers will never need it.
How Level 2 scoring works
Level 2 uses the DoD Assessment Methodology, now written into 32 CFR 170.24. You start with 110 points and subtract a value for each requirement that is NOT MET:
- 5 points for 44 high-impact requirements, such as multifactor authentication, incident response and malware protection
- 3 points for 14 requirements
- 1 point for the remaining 51
Two requirements allow partial credit: multifactor authentication (3.5.3) and FIPS-validated cryptography (3.13.11) lose 3 points instead of 5 when partly implemented. The System Security Plan (3.12.4) has no point value, because without an SSP an assessment cannot be completed. The lowest possible score is -203.
Conditional status and POA&Ms
You do not need a perfect score to be awarded work. Under 32 CFR 170.21 you can achieve conditional Level 2 status with a plan of action and milestones (POA&M) if:
- your score is at least 88 (80 percent of 110)
- no requirement on the POA&M is worth more than 1 point, except 3.13.11 where encryption is used but not FIPS-validated
- none of six specific requirements is NOT MET, including the System Security Plan and the physical access requirements for escorting visitors, keeping access logs and managing access devices
Every POA&M item must then be closed within 180 days, or the conditional status lapses.
What CMMC means for Australian suppliers
CMMC requirements flow down from US prime contractors to subcontractors, wherever those subcontractors are based. An Australian engineering firm, software house or manufacturer that handles FCI or CUI for a US defense program can expect to be asked for CMMC compliance, including work linked to AUKUS.
CMMC is separate from Australia’s Defence Industry Security Program (DISP), but the two overlap heavily. NIST SP 800-171 is derived from NIST SP 800-53, which maps closely to the Australian ISM. An organisation with a mature ISM or ISO 27001 program already has much of the evidence it needs. If you are building up from a lower base, my guide to Defence supply chain security is a good starting point.
How to prepare: a practical sequence
- Confirm the level. Check your contracts and solicitations for DFARS 252.204-7021 and the CMMC level required.
- Scope the environment. Identify where FCI and CUI live. A tightly scoped enclave can dramatically reduce the effort.
- Write the System Security Plan. It is a hard prerequisite.
- Self-assess against all 110 requirements. Be honest about partial implementations.
- Calculate your SPRS score and identify gaps that block conditional status.
- Fix the 5-point gaps first, then build a POA&M for the rest.
- Book a C3PAO early if you need certification. Assessor capacity is limited.
My free CMMC Level 2 checklist does steps 4 to 6 for you: it contains all 110 requirements word for word, calculates your SPRS score and flags gaps that cannot go on a POA&M.
Frequently asked questions
What is the difference between CMMC 1.0 and CMMC 2.0?
CMMC 2.0 simplified the original five-level model to three levels, aligned Level 2 directly with NIST SP 800-171, allowed self-assessment for some Level 2 contracts and introduced limited, time-bound POA&Ms.
Does CMMC apply to companies outside the United States?
Yes, if they handle FCI or CUI under a US defense contract or subcontract. The requirement flows down through the supply chain regardless of where the supplier is based.
What SPRS score do I need for CMMC Level 2?
A score of 110 gives final Level 2 status. A score of at least 88 with only POA&M-eligible gaps can give conditional status, provided every POA&M item is closed within 180 days.
Is CMMC Level 2 assessed against NIST SP 800-171 Revision 3?
No. NIST published Revision 3 in May 2024, but the CMMC program rule specifies Revision 2, so Level 2 assessments are performed against Revision 2.
Supplying a US defense program and unsure where you stand? Talk to my AI agent or download the free CMMC Level 2 checklist.