"*" indicates required fields
The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense’s framework for verifying that contractors protect sensitive federal information. The program is codified at 32 CFR Part 170 and reaches defense contracts through DFARS clause 252.204-7021.
CMMC does not invent new security requirements — it verifies existing ones. Level 1 draws on the 15 basic safeguarding requirements in FAR clause 52.204-21. Level 2 draws on the 110 security requirements in NIST Special Publication 800-171 Revision 2. Level 3 adds a selected subset of the enhanced requirements in NIST SP 800-172.
NIST SP 800-171 reaches well beyond the defense sector. Organizations in energy, manufacturing, research, and healthcare increasingly adopt it — and cite it in their own agreements — as an established baseline for handling sensitive information shared between organizations.
CMMC applies to organizations in the Defense Industrial Base that process, store, or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) — prime contractors and subcontractors alike. The required level and assessment type are specified in the solicitation and flow down through the supply chain, so a subcontractor’s obligation depends on the information it actually handles rather than on its distance from the contracting agency.
NIST SP 800-171 applies more broadly. Federal civilian agencies, state governments, universities, and private companies routinely require conformance with it in agreements involving sensitive but unclassified information.
CUI is information that the government requires to be safeguarded or disseminated under controls, but which is not classified. Executive Order 13556 established the CUI Program in 2010 and designated the National Archives and Records Administration (NARA) as its Executive Agent.
NARA maintains the CUI Registry, which organizes roughly 80 categories of CUI into about 20 organizational index groupings — ranging from export-controlled technical data and critical infrastructure information to personally identifiable information and protected health information.
Two distinctions matter in practice. First, CUI is not the same as Federal Contract Information. FCI is information provided by or generated for the government under a contract and not intended for public release; FCI alone points to Level 1, while CUI points to Level 2 or above. Second, because the CUI definition is broad, many organizations outside the defense sector — energy production and distribution, for example — use NIST SP 800-171 to demonstrate that they handle sensitive information safely.
CMMC is a three-level model. The level your organization needs, and whether you may assess yourself or must be assessed by a third party, is determined by the contract and by the type of information you handle.
Defense contractors have long been required to protect sensitive information, but for years they attested to their own compliance and the government had limited means to verify it. CMMC was created to close that gap by tying verified cybersecurity practices to contract eligibility.
The program was first released in 2020 and restructured in 2021 to reduce the number of levels and align them directly with existing NIST standards rather than a separate maturity scale. It was then finalized through federal rulemaking: the program rule at 32 CFR Part 170, and the acquisition rule that added the CMMC requirement to the DFARS.
A CMMC status is the outcome of an assessment against a defined set of requirements, evaluated using the assessment objectives published in NIST SP 800-171A.
Assessment results are recorded in the Supplier Performance Risk System (SPRS), and a senior company official must submit an affirmation of continuing compliance there after each assessment and annually thereafter. Limited Plans of Action and Milestones are permitted at Levels 2 and 3 for certain requirements and must be closed within 180 days.
Start with the information, not the paperwork. Determine whether your environment handles FCI, CUI, or both, then define the boundary of the systems, people, and service providers that touch it. Scope drives everything downstream — cost, duration, and difficulty.
From there, the path is straightforward:
The Cyber AB accredits C3PAOs and certifies the individual assessors who staff them. It does not issue your CMMC status — that follows from the assessment itself and is reflected in SPRS.
Cost depends far more on your environment than on the assessment itself. The main drivers are:
The Department of Defense published cost estimates by level and organization size in the rulemaking record, but those are averages across the industrial base. A scoped estimate for your actual environment will tell you far more, and we are glad to walk through one.
A CMMC Third-Party Assessment Organization, or C3PAO, is a firm accredited to perform CMMC Level 2 certification assessments. C3PAOs are accredited by the Cyber AB against ISO/IEC 17020, and the assessors who staff their engagements hold individual certification.
A C3PAO is not the same as a FedRAMP 3PAO. The designations sound alike and the acronyms invite confusion, but accreditation as a FedRAMP 3PAO does not authorize a firm to perform CMMC assessments; the two programs have separate requirements and separate oversight.
Linford & Co LLP is proud to be an officially Authorized CMMC Third-Party Assessment Organization (C3PAO). Having successfully met all established requirements of the Cybersecurity Maturity Model Certification (CMMC) Program, our firm and certified Assessment Team are fully authorized by The Cyber AB to conduct CMMC Level 2 certification assessments.
Our highly-experienced auditors simplify complex NIST requirements while delivering thorough CMMC assessments in an efficient manner.
Demonstrate CMMC compliance and achieve certification by partnering with an authorized assessor firm that employs only experienced auditors with experience in DoD and government certifications.
Linford & Company tailors the audit process to meet the needs of our clients, and we leverage our own tools or our client’s chosen GRC platform to perform assessments.
Our auditors have worked with dozens of clients to help them navigate the complexities of assessments based on NIST requirements including NIST 800-53 and 800-171, the standards that CMMC compliance is based on.
Fill out the form and we’ll put you in touch with one of our experienced auditors. Your contact information stays with us and is only used to talk with you about your CMMC or NIST 800-171 audit — we do not sell or share your contact information with anyone.
"*" indicates required fields
We use cookies to optimize our website and our service.
"*" indicates required fields