Skip to content
Capability/Compliance Frameworks

CMMC

Cybersecurity Maturity Model Certification for defense contractors

01 / Overview

The Cybersecurity Maturity Model Certification establishes cybersecurity requirements for defense contractors handling Controlled Unclassified Information. Thalorin provides comprehensive CMMC support from initial assessment through certification, with continuous compliance monitoring that maintains certification readiness.

CMMC stopped being a planning exercise on 10 November 2025, when the 48 CFR acquisition rule took effect and DFARS 252.204-7021 became a clause that can appear in a live solicitation. The question for a defense contractor is no longer whether CMMC applies but which phase of the rollout catches which contract vehicle, and whether the certification you hold matches the level the clause names.

The programme phases in over 36 months. Phase 1 opened with Level 1 and Level 2 self-assessment appearing in applicable solicitations, with the Department retaining discretion to require a C3PAO assessment earlier. Phase 2, from 10 November 2026, brings Level 2 third-party certification into applicable solicitations as a matter of course. A contractor reading only the current phase will be late for the next one.

The practical trap is scope. CMMC assessments are scoped to the environment that stores, processes, or transmits Controlled Unclassified Information, and most organisations discover during assessment that this boundary is wider than the one they documented — a file share, a helpdesk tool, a subcontractor's portal. Scope drift is the most common reason an assessment that was expected to pass does not.

Thalorin treats the CUI boundary as the primary object rather than the control list. Assets are classified against the boundary, evidence is bound to the asset that produced it, and a change that widens the boundary raises the affected controls rather than silently invalidating an assessment nobody re-ran.

02 / Challenges

Framework compliance requires sustained effort

Phase timing against contract vehicles

Phase 1 permits self-assessment for many Level 2 awards; Phase 2 from November 2026 pushes those same awards to C3PAO certification. Programmes planning against today's phase are planning against the wrong one.

CUI boundary scope drift

Assessment scope follows CUI, not the org chart. Enclaves expand through ordinary operational decisions — a new collaboration tool, a support contract — and the documented boundary stops matching the real one.

C3PAO capacity and lead time

There are far fewer authorised C3PAOs than there are organisations requiring Level 2 certification. Assessment slots are booked well ahead, so a failed assessment costs a queue position, not just a remediation cycle.

Flow-down to subcontractors

Primes must flow CMMC requirements down, and a supplier that cannot certify at the required level becomes a sourcing problem. Verifying supplier status is now part of managing the bid, not the contract.

03 / Capabilities

How Thalorin helps

CMMC 2.0NIST 800-171DFARS

CMMC 2.0 level assessment

Assess against the 110 NIST SP 800-171 Rev 2 requirements the Department currently scores, with each requirement bound to the assets in the CUI boundary that satisfy it.

Practice implementation guidance

Work each practice down to its assessment objectives, so implementation is judged the way a C3PAO judges it rather than at the level of the practice statement.

Gap analysis and remediation

Track POA&M items against the closeout clock, since a conditional certification converts to final only when the plan is closed within the permitted window, with each item bound to the requirement it closes.

Certification preparation

Generate and version the System Security Plan from the same control state the assessment reads, so the SSP cannot drift from the environment it describes.

Continuous compliance monitoring

Model the boundary explicitly — in scope, out of scope, specialised asset, contractor risk managed asset — and maintain the SPRS submission trail, including the score basis and the date, so the figure the Department sees is reproducible from evidence.

Supply chain CMMC management

Carry supplier certification status alongside your own, so flow-down obligations are visible before award rather than at audit.

Questions

CMMC: common questions

When does CMMC actually apply to my contract?

The 48 CFR rule took effect 10 November 2025, which allows DFARS 252.204-7021 to appear in solicitations. Whether it appears in yours depends on the rollout phase and whether the contract involves Federal Contract Information or Controlled Unclassified Information. From 10 November 2026, Phase 2 brings Level 2 C3PAO certification into applicable solicitations as standard. Full implementation runs 36 months from the effective date.

Can I still self-assess at Level 2?

During Phase 1, many Level 2 requirements can be met by self-assessment, and the Department retains discretion to require a C3PAO assessment earlier on specific acquisitions. That latitude narrows in Phase 2. Planning a Level 2 posture on the assumption that self-assessment remains available through 2027 is the most common timing error we see.

Is CMMC assessed against NIST 800-171 Rev 2 or Rev 3?

Rev 2, as of August 2026. NIST published Rev 3 in May 2024, but the Department has not completed the rulemaking to adopt it for CMMC assessment, SPRS scoring, or DFARS 7012. Rev 3 reorganises the requirements from 110 to 97, so adoption will require a fresh self-assessment and a new SPRS score rather than a mapping exercise.

What happens if I fail a C3PAO assessment?

Depending on the findings, you may receive a conditional certification with a POA&M that must be closed inside the permitted window, or no certification at all. The operational cost is usually the calendar: C3PAO capacity is limited, so re-assessment means re-entering a queue, and an award that required certification will not wait.

Do subcontractors need their own certification?

Requirements flow down, and the level required depends on what the subcontractor handles. A supplier touching only Federal Contract Information faces a lower bar than one processing CUI. Primes are increasingly verifying supplier status during sourcing, because discovering a supplier cannot certify after award is a schedule problem with no clean remedy.

Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.

05 / Get Started

Talk to us about CMMC.

See how one evidence artifact satisfies CMMC requirements alongside every other framework you carry.