Defense contractors are grappling with new compliance challenges as the Cybersecurity Maturity Model Certification (CMMC) moves from a proposed framework to a contractual requirement. With the final rule published on September 10, 2025, certification clauses are now appearing in solicitations. Compliance managers are asking critical questions about how to meet these requirements.
Do We Need a C3PAO Assessment, or Can We Self-Assess?
Your need for a C3PAO assessment depends on your CMMC level and contract phase.
For handling only Federal Contract Information (FCI), CMMC Level 1 allows for annual self-assessment. If you're dealing with Controlled Unclassified Information (CUI), CMMC Level 2 requires a C3PAO assessment every three years.
Timing is crucial. The Department of Defense (DoD) is implementing CMMC in phases. As of November 10, 2025 (Phase 1), contracts may require Level 1 or Level 2 self-assessment. By November 10, 2026 (Phase 2), contracts will start requiring C3PAO Level 2 assessments. By November 10, 2028 (Phase 4), all applicable contracts will require CMMC compliance.
If your contract specifies "Level 2 certification required," you must engage a C3PAO. Self-assessment won't suffice.
What's the Biggest Scoping Mistake Organizations Make?
Many teams mistakenly assume they need to include their entire IT environment in the CMMC scope. This "all-in" approach can increase assessment burdens, compliance costs, and risk exposure by maintaining 110 NIST SP 800-171 controls across unnecessary infrastructure.
Proper scoping should be based on actual CUI and FCI data flows, enforced through segmentation and access controls. Start with CUI flow mapping: identify where CUI enters, moves, and exits your environment. Build your scope from this reality, not from convenience.
If you can't clearly justify why a system is in scope, reassess your scoping strategy.
How Long Does the C3PAO Assessment Take?
The assessment involves four phases, with the timeline depending on your readiness at Phase 1.
Phase 1 (Planning) includes documentation review, scope validation, and completion of the Pre-Assessment Form for entry into the Enterprise Mission Assurance Support Service (eMASS). If your System Security Plan (SSP) and procedures align with NIST SP 800-171, this phase moves quickly. Otherwise, expect delays.
Phase 2 (Conditional Assessment) involves interviews, observations, and evidence inspection across all 110 controls. This phase concludes with a MET, NOT MET, or N/A determination for each control.
Phase 3 (Reporting) includes quality assurance reviews, the Out-Brief Meeting, and eMASS upload to publish results. You'll receive a final, conditional, or no certificate based on your scores.
Phase 4 (Remediation and Final Assessment) applies if you receive a conditional or no certificate. You have 180 days to close your Plan of Actions and Milestones (POA&M) and retest with the C3PAO.
Unprepared organizations often underestimate the time required. A readiness review before engaging the C3PAO can mitigate the risk of a "no status" outcome.
What If We Get a Conditional Certificate?
A conditional certificate means you scored at least 80%, met all critical controls, but some controls remain NOT MET.
You have 180 days to address these gaps and close your POA&M. The C3PAO will retest the failed controls. If successful, you'll receive your final certificate. If not, you'll revert to no certificate status.
While not a failure, a conditional status can delay contract execution if your award depends on certification. Plan accordingly.
We're Already ISO/IEC 27001 Certified. Can We Map That Over?
ISO/IEC 27001 provides a solid foundation in risk-based control design, but CMMC is prescriptive. You can't map controls one-to-one.
CMMC Level 2 requires implementing all 110 NIST SP 800-171 controls. While ISO/IEC 27001 covers similar domains, specific requirements differ. For instance, CMMC includes explicit CUI marking and FIPS-validated cryptography mandates.
Your ISO/IEC 27001 program aids governance and documentation but doesn't eliminate the need for targeted CMMC gap remediation.
How Do We Maintain Compliance Between C3PAO Assessments?
C3PAO assessments occur every three years, but you must annually affirm compliance in the Supplier Performance Risk System (SPRS). This involves attesting that your controls remain effective.
To support this, conduct internal assessments annually, reevaluate controls after significant changes, perform reviews following incidents, and monitor for compliance drift.
Compliance drift can occur due to business priorities, infrastructure changes, or restructuring. Successful organizations integrate CMMC into operational governance rather than treating it as a one-time project.
Many engage independent advisors for annual reviews before submitting SPRS affirmations, ensuring accuracy.
What's the False Claims Act Risk if We Get This Wrong?
Falsely claiming CMMC compliance exposes you to the False Claims Act, leading to legal liability, penalties, and loss of future DoD contracts.
This risk is real. The DoD enforces compliance, and false claims tied to contract awards have serious consequences. Don't attest to compliance you haven't achieved, and ensure SPRS affirmations are based on accurate assessments.
If unsure about your compliance status, conduct an internal review before submission. Verification costs far less than a False Claims Act investigation.
Where Do You Go from Here?
If you're in Phase 1 and contracts require self-assessment, start with CUI flow mapping and scoping. If Phase 2 is near and you need a C3PAO assessment, engage advisory support early to validate readiness.
CMMC isn't going away, and the phased rollout increases pressure. By November 10, 2028, all applicable contracts will require compliance. Organizations treating this as an ongoing discipline will remain competitive for contracts in the future.



