CMMC 2.0 Pillar Guide · Updated August 2026 · Pillar #8

CMMC 2.0 Practical Guide for 2026
Levels, NIST 800-171, DFARS 7012, and the C3PAO Path

A working walkthrough of the DoD Cybersecurity Maturity Model Certification (CMMC 2.0) — the three Maturity Levels (Level 1 FCI baseline + Level 2 CUI / NIST SP 800-171 Rev 2 + Level 3 DIB-priority / NIST SP 800-172), the 17-practice Level 1 baseline, the 110-control Level 2 control family set, the DFARS 252.204-7012 / SPRS self-assessment pathway, the C3PAO third-party assessment ladder, and the 2026 readiness roadmap for DoD primes and subcontractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).

Maintained by ComplianceStack · 2026-08-07 · Citation-ready (Dublin Core & citation_* meta)

On this page

  1. §1 CMMC 2.0 Overview — 32 CFR Part 170, the three Maturity Levels, and the Defense Industrial Base
  2. §2 The Three Maturity Levels — Level 1 FCI, Level 2 CUI, Level 3 DIB Priority
  3. §3 Scope and Controls — the 17-Practice Level 1 Baseline and the 110-Control Level 2 Set
  4. §4 Audit / Readiness Mechanics — Self, Self-Assessed, C3PAO, and DIBCAO Assessment Ladders
  5. §5 DFARS 7012, SPRS Scoring, and the Contract-Award Eligibility Linkage
  6. §6 Ready-in-90-Days Gap Checklist for a CMMC Level 2 C3PAO Assessment
  7. §7 2026 Readiness Roadmap for DoD Primes / Subcontractors / Hybrid Contractors
  8. §8 Pair this guide with the ComplianceStack CMMC 2.0 Tools
  9. §8a Framework Crosswalk — CMMC 2.0 Level 2 Control Families ↔ NIST SP 800-171 Rev 2 ↔ NIST CSF 2.0
  10. §9 Frequently Asked Questions

§1 CMMC 2.0 Overview — 32 CFR Part 170, the three Maturity Levels, and the Defense Industrial Base

CMMC 2.0 is the Department of Defense's certification scheme for defense industrial base (DIB) contractors. Formalized as a final rule at 32 CFR Part 170 effective October 15, 2024, CMMC 2.0 supersedes the prior CMMC 1.0 model (2020) and aligns tightly with the NIST cybersecurity controls already in DFARS 252.204-7012 (DFARS 7012). CMMC 2.0 applies to any prime contractor or subcontractor that handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) in performance of a DoD contract.

The CMMC 2.0 model organizes contractor cybersecurity obligations under three Maturity Levels, each tied to the sensitivity of the information handled. Level 1 — Foundational covers FCI (information provided by or generated for the Government under contract not intended for public release) and requires 17 safeguarding practices from FAR 52.204-21 with an annual self-assessment and affirmation in SPRS. Level 2 — Advanced covers CUI and requires the 110-control set in NIST SP 800-171 Rev 2, with either a triennial self-assessment (Level 2 self) or a C3PAO-led third-party assessment (Level 2 third-party), depending on the DoD program's contractual requirement. Level 3 — Expert covers CUI for DoD-priority programs and adds selected NIST SP 800-172 enhanced-security requirements; the assessment is government-led by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAO). ComplianceStack maps each DoD contract solicitation to the applicable CMMC Level via the contract CMMC requirement line, and pairs every Level 2 / Level 3 contractor with the appropriate SPRS scoring roadmap.

The rule-making lineage matters: CMMC 2.0 is the second iteration of a DoD program that began in 2019 with the interim DFARS rule, was finalized as CMMC 1.0 in 2020 (with five Maturity Levels and process maturity requirements), and was substantially restructured in 2021 around NIST SP 800-171 alignment. The October 2024 32 CFR Part 170 rule finalized the CMMC 2.0 framework. DoD contract solicitations began including CMMC requirements in Q4 2025; full phased rollout extends through Q4 2027 (Level 1 in Q4 2025, Level 2 third-party in Q2 2026, Level 3 DIBCAO in Q4 2026, all CMMC requirements self-asserted by prime contracts at Q4 2027). ComplianceStack tracks the rollout calendar with a CMMC contract-conditions checklist that flags any solicitation with a CMMC requirement line that exceeds the contractor's certified level.

CMMC 2.0 is not a "framework" in the closed-list sense — it is a conformance assessment scheme layered over NIST SP 800-171 Rev 2 (Level 2) and NIST SP 800-172 (Level 3). The controls live in the underlying NIST publications; CMMC adds the assessment mechanism, the SPRS scoring pipeline, the C3PAO accreditation structure, the Conditional / Final designation state for Level 2 third-party assessments, and the contractual-cyber-maturity linkage. The DIB contractor must implement NIST SP 800-171 controls across the CUI enclave boundary; the CMMC assessment confirms the implementation matches the published control implementation evidence.

§2 The Three Maturity Levels — Level 1 FCI, Level 2 CUI, Level 3 DIB Priority

CMMC 2.0 organizes contractor cybersecurity obligations under three Maturity Levels tied to the type of Federal information handled. ComplianceStack tracks the 32 CFR Part 170 model as the single effective baseline for DoD contract solicitations dated October 15, 2024 or later.

Level 1 · Foundational
FCI safeguarding
17 practices from FAR 52.204-21. Annual self-assessment. Affirmation of compliance posted to SPRS. Eligible for any DoD contract handling only FCI.
Level 2 · Advanced
CUI safeguarding
110 controls from NIST SP 800-171 Rev 2 (14 control families). Triennial self-assessment scoring OR C3PAO third-party assessment (Conditional or Final). Required for any DoD contract involving CUI.
Level 3 · Expert
Enhanced CUI safeguarding
NIST SP 800-171 Rev 2 + selected NIST SP 800-172 enhanced-security requirements (typically 24-30 practices). Government-led DIBCAO assessment.

Level 1 — Federal Contract Information (FCI) safeguarding

Level 1 covers FCI — information provided by or generated for the Government under contract not intended for public release. FCI is the lower-tier information class (per FAR 2.101 and DFARS 252.204-7012); CUI is the higher-tier class and is separately addressed at Level 2. Level 1 requires the 17 safeguarding practices enumerated in FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems. Level 1 also requires an annual self-assessment by the contractor against the 17 practices and an affirmation of compliance posted to SPRS via the Contracting Officer. Level 1 does not require a C3PAO third-party assessment; the entire Level 1 path is self-attested.

Level 2 — Controlled Unclassified Information (CUI) safeguarding

Level 2 covers CUI. CUI is unclassified information that requires safeguarding or dissemination controls pursuant to federal law, regulation, or government-wide policy (per 32 CFR Part 2002). CUI includes things like export-controlled technical drawings, controlled technical information, NIST 800-171-protectable defense articles, and a wide range of program-specific DoD information categories. Level 2 requires the 110 controls in NIST SP 800-171 Rev 2 (the DoD Assessment Methodology explicitly maps each CMMC Level 2 practice to its NIST 800-171 Rev 2 control identifier; CMMC practice AC.L2-3.1.1 maps to 3.1.1, AT.L2-3.2.1 maps to 3.2.1, etc.). Level 2 requires either a triennial self-assessment (Level 2 self) for select DoD programs, or a C3PAO third-party assessment (Level 2 third-party) that yields a Conditional or Final CMMC Level 2 designation. ComplianceStack notes that the C3PAO-led Level 2 third-party assessment is required for any prime contract handling CUI in non-priority program scope; the conditional / final POA&M closeout cycle is the canonical remediation pathway.

Level 3 — Enhanced CUI safeguarding for DIB-priority programs

Level 3 covers a subset of CUI in DoD-priority programs. Level 3 adds selected NIST SP 800-172 enhanced-security requirements (typically 24-30 practices) covering advanced persistent threat (APT) protection, enhanced personnel security, and emerging-technology protection. Level 3 is functionally the CUI protection set applicable to DIB-priority programs (select missile programs, naval nuclear propulsion programs, space programs, and other DoD-priority acquisition pathways). Level 3 requires a government-led DIBCAO assessment; the DIBCAO assessment is scheduled only after a current CMMC Level 2 Final designation is in place. ComplianceStack notes that Level 3 requirement lines are sparse in the published contract vehicles but expanding per the 2024-2027 phased rollout. ComplianceStack provides a free CMMC Phase 2 Readiness Analyzer at /free-cmmc-readiness-analyzer — contractor-tier-aware scoring with applicable Phase 2 deadlines and shareable results for DoD contracting offices. Run it before scheduling a C3PAO assessment or refreshing your SPRS posting.

§3 Scope and Controls — the 17-Practice Level 1 Baseline and the 110-Control Level 2 Set

CMMC 2.0 scope is defined by the categorical boundary between FCI and CUI data flows, and the control set is fixed by the underlying NIST publications. Below the level-of-applicability decision, every CMMC contractor must implement a defined set of practices; CMMC assessments then verify conformance. ComplianceStack's CMMC readiness analyzer scores every Level 1 practice and every Level 2 control family.

Level 1 — the 17 FAR 52.204-21 practices

FAR 52.204-21 enumerates 17 safeguarding practices that any contractor that receives, processes, stores, or transmits FCI must implement. The practices are: (1) limit system access to authorized users; (2) limit system access to the types of transactions and functions that authorized users are permitted to execute; (3) verify and control/limit connections to and use of external information systems; (4) control information posted or processed on publicly accessible information systems; (5) identify and authenticate the identities of those users, processes, or devices that access the contractor's information system; (6) limit physical access to the contractor's information system, equipment, and the respective operating environment to authorized individuals; (7) protect and monitor physical access points; (8) escort visitors and monitor visitor activity; (9) establish and maintain physical protection of the contractor's information system, equipment, and operating environment; (10) create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity; (11) ensure that the actions of individual information system users can be uniquely traced to those users so they can be held accountable for their actions; (12) establish and maintain basic operational security (OPSEC) for the contractor's information system; (13) employ sufficient malware protection to detect, quarantine, and eradicate malicious software; (14) update malicious code protection mechanisms when new releases are available; (15) establish and enforce security configuration settings for information technology products employed in organizational information systems; (16) periodically assess and manage risk to information systems; (17) protect the confidentiality of FCI. ComplianceStack maps each of the 17 practices to its operational evidence category (system access control list, badge access log, audit log retention policy, malware scan results, etc.).

Level 2 — the 110 NIST SP 800-171 Rev 2 controls

Level 2 is the 110-control set from NIST SP 800-171 Rev 2 (February 2020; revision 3 finalized May 2024). The controls are organized under 14 control families. AC — Access Control (22 controls, CUI asset access enforcement); AT — Awareness and Training (3 controls); AU — Audit and Accountability (9 controls); CM — Configuration Management (9 controls); IA — Identification and Authentication (11 controls); IR — Incident Response (3 controls); MA — Maintenance (6 controls); MP — Media Protection (9 controls); PE — Physical and Environmental Protection (6 controls); PL — Planning (2 controls); PS — Personnel Security (8 controls); RA — Risk Assessment (3 controls); SA — System and Services Acquisition (5 controls); SC — System and Communications Protection (16 controls); SI — System and Information Integrity (7 controls). Each control includes a basic security requirement and (where applicable) one or more derived security requirements. ComplianceStack notes that NIST 800-171 Rev 3 introduces a refactored organization with a planned-organizational structure; the DoD CMMC L2 mapping will be updated when the DoD Assessment Methodology is updated to track Rev 3.

Enclave boundary and the CUI asset inventory

CMMC 2.0 enforces a boundary-protection principle: the CUI enclave is the network boundary inside which all 110 NIST 800-171 controls must be enforced. Boundary devices — firewalls, intrusion detection systems, encryption gateways, identity-aware proxies — carry the SC family requirements (SC-7 boundary protection, SC-8 transmission confidentiality and integrity, SC-13 cryptographic protection). The CUI asset inventory (CM-8, IA-2, IA-3, IA-5) defines the population of devices that must be in scope for the audit trail, the vulnerability management cadence, the configuration management baseline, and the change-management ticketing flow. ComplianceStack pairs the CUI enclave inventory with the ComplianceStack CUI Asset Discovery tool that scans Windows / macOS / Linux endpoints, identifies FCI and CUI handling, and produces the Level 2 system security plan (SSP) inventory list.

§4 Audit / Readiness Mechanics — Self, Self-Assessed, C3PAO, and DIBCAO Assessment Ladders

CMMC 2.0 has four assessment paths. The path depends on the contractor's Maturity Level (1 / 2 / 3) and, for Level 2, the DoD program's contractual CMMC requirement line. ComplianceStack's assessment-type selector maps every contract solicitation to its applicable path and pairs each contractor with the documentation expectations of the selected path.

Assessment path Level Who audits Frequency Output
Self-assessment Level 1 (FCI) Contractor Annual SPRS affirmation
Self-assessed Level 2 (CUI) — select programs Contractor (scored against NIST 800-171 via DoD Assessment Methodology) Triennial SPRS NIST 800-171 score (-203 to +110)
C3PAO third-party Level 2 (CUI) — standard programs Authorized C3PAO (Cyber AB accredited) Triennial Conditional or Final CMMC L2 designation
DIBCAO assessment Level 3 (DIB priority) DoD Defense Industrial Base Cybersecurity Assessment Center (DIBCAO) Triennial Final CMMC L3 designation (requires prior L2 Final)

Level 1 self-assessment path

Level 1 is the lightest assessment path. The contractor self-assesses against the 17 FAR 52.204-21 practices annually, retains the self-assessment results, and provides an affirmation of compliance in SPRS. The affirmation is a Senior Official's affirmation — typically a C-suite officer (CISO, COO, GM) signature attesting that the contractor's assessment accurately reflects the state of the information system. ComplianceStack pairs the Level 1 self-assessment with the ComplianceStack Level 1 Self-Assessment Workflow, which scores the 17 practices, generates the affirmation template, and submits to SPRS.

Level 2 self-assessed (SPRS scoring) path

For some DoD programs, the contractual CMMC requirement line is "CMMC L2 Self" rather than "CMMC L2 Third-Party." In that case, the contractor self-assesses against all 110 NIST SP 800-171 Rev 2 controls triennially, scoring each control on the -203 to +110 scale per the DoD Assessment Methodology, and submits the consolidated SPRS score to the DoD (sprs.csd.disa.mil). The SPRS score is the lowest single-control score assigned, not a sum — one control with a -50 assessment drags the overall SPRS score down to -50. ComplianceStack pairs the SPRS submission with an in-tool scoring engine that runs the DoD Assessment Methodology against every control and assigns the conservative (-203 floor) for any control with documented gaps. The ComplianceStack SPRS scoring engine generates the SPRS submission package and the supporting evidence catalog.

Level 2 C3PAO third-party assessment path

For most DoD programs, the contractual CMMC requirement line is "CMMC L2 Third-Party" with an active C3PAO assessment. The contractor hires an authorized C3PAO (Cyber AB accredited) to conduct the assessment. The C3PAO audits the contractor against all 110 NIST 800-171 Rev 2 controls using the DoD Assessment Methodology, drafts an assessment report, and submits to the Cyber AB. The Cyber AB reviews and either issues a Conditional CMMC Level 2 (90-day POA&M remediation window for specified gaps) or Final CMMC Level 2 (3-year triennial cycle). Conditional CMMC Level 2 designations carry 90 days to close specified POA&M items before Final designation; non-closure in 90 days invalidates the Conditional designation. ComplianceStack pairs the C3PAO assessment with a pre-audit readiness pass that shadows the C3PAO methodology, identifies controls at risk of POA&M designation, and produces a POA&M closeout plan. Typical C3PAO assessment cost for a mid-size contractor (200-1,000 employees): $30K-$100K+ for a CMMC Level 2 third-party assessment; the cost band widens for larger organizations or organizations with broad multi-enclave scope.

Level 3 DIBCAO assessment path

Level 3 is government-led DIBCAO assessment, applicable only to select DoD-priority programs. The DIBCAO assessment is scheduled only after a valid CMMC Level 2 Final designation. The Level 3 assessment adds the selected NIST SP 800-172 enhanced-security requirements (typically 24-30 practices). ComplianceStack notes that the Level 3 requirement set is small in 2024-2025 contract solicitations but is expected to expand through the 2026 phased rollout.

§5 DFARS 7012, SPRS Scoring, and the Contract-Award Eligibility Linkage

DFARS 252.204-7012 (DFARS 7012) is the flow-down clause that operationalizes CMMC requirements across the entire Defense Industrial Base supply chain. The clause requires every DoD contractor and subcontractor at every tier to — at minimum — safeguard Covered Defense Information (CDI) per NIST SP 800-171, report cyber incidents through DIBNet within 72 hours, and submit a NIST 800-171 self-assessment score to SPRS. The CMMC 2.0 certification scheme layers assessment on top of this baseline.

DFARS 7012 flow-down is required in every subcontract at every tier where CDI will be received or generated. Failing to flow DFARS 7012 down creates contractor liability under the False Claims Act (31 USC §3729) — the most-cited violation pattern in DCAA audits. ComplianceStack pairs the flow-down requirement with the ComplianceStack Subcontractor Flow-Down Inventory, which maps every tier-1 to tier-N subcontractor against its applicable CMMC Level. SPRS scoring is on a -203 to +110 scale; -203 is the floor (a control rated as "absent"), 0 is the median under the DoD Assessment Methodology, +110 is the ceiling (a control fully implemented). An SPRS score of +110 reflects a perfect implementation; 88 is the median for organizations under conditional CMMC L2 review; a score below 0 reflects material weakness across multiple control families.

SPRS is the contract-award eligibility gate. DoD acquisition officers rely on SPRS for source selection decisions. An SPRS score below 0 typically disqualifies a contractor from a CMMC-required solicitation. ComplianceStack pairs the SPRS scoring pathway with a contract-award eligibility estimator that scores every active DoD solicitation against the contractor's most recent SPRS score. The estimator outputs a per-solicitation eligibility flag, the required CMMC level (1 / 2 / 3), the assessment path (Self / Self-Assessed / C3PAO / DIBCAO), and the SPRS score gap if applicable.

§6 Ready-in-90-Days Gap Checklist for a CMMC Level 2 C3PAO Assessment

ComplianceStack packages the CMMC 2.0 readiness program as a 14-family, 90-day gap checklist that maps every NIST SP 800-171 Rev 2 control into a sequenced remediation backlog, calibrated for the upcoming C3PAO Level 2 third-party assessment. The 90-day program is the baseline ramp before the SPRS final submission and the C3PAO's Conditional / Final designation issuance.

Day 0–14 — AC (Access Control) + IA (Identification and Authentication)

Day 15–30 — AU (Audit and Accountability) + SI (System and Information Integrity) + CM (Configuration Management)

Day 31–45 — SC (System and Communications Protection) + MP (Media Protection) + PE (Physical and Environmental Protection)

Day 46–60 — PL (Planning) + PS (Personnel Security) + RA (Risk Assessment) + AT (Awareness and Training) + SA (System and Services Acquisition)

Day 61–90 — IR (Incident Response) + MA (Maintenance) + CUI Boundary Hardening + SPRS Submission

§7 2026 Readiness Roadmap for DoD Primes / Subcontractors / Hybrid Contractors

ComplianceStack tracks three sector-specific 2026 CMMC readiness roadmaps. The roadmaps share a NIST SP 800-171 / DFARS 7012 baseline but diverge on the assessment path, the CUI enclave structure, and the contract-award eligibility timing.

Pattern 1 — DoD prime contractor with CUI on DIB-priority programs (Level 2 C3PAO + Level 3 DIBCAO)

The recommended pathway is C3PAO third-party assessment for Level 2 Final followed by Level 3 government DIBCAO assessment for any DoD-priority program scope. The 90-day program covers all 110 NIST SP 800-171 Rev 2 controls plus the selected NIST SP 800-172 enhanced-security requirements (typically 24-30 Level 3 practices); the 90-day program also covers the Supply Chain Risk Management family (NIST SR-1 / SR-3) and the incident response family aligned to DIBNet reporting. SPRS final submission target: +110. Contract-award eligibility: full CMMC L2 Final + L3 Final designation. ComplianceStack pairs the prime contractor pattern with the CUI enclave boundary discovery + the supply-chain flow-down inventory mapping every tier-1 to tier-3 subcontractor back to its CMMC Level. Typical C3PAO cost: $50,000-$100,000+ for a mid-size prime contractor; 501+ employee prime contractors commonly exceed $150,000 for the C3PAO engagement.

Pattern 2 — Subcontractor with FCI-only scope at Level 1

The recommended pathway is the annual Level 1 self-assessment against the 17 FAR 52.204-21 practices with affirmation of compliance posted to SPRS. The 90-day program covers the 17 practice areas (basic safeguarding of FCI, MFA on FCI-bearing systems, physical access, malware protection, patch management, account management). ComplianceStack pairs the Level 1 subcontractor pattern with the DFARS 7012 flow-down inventory mapping every tier above + every tier below. Contract-award eligibility: FCI-bearing DoD subcontract work where the prime's CUI enclave is tightly scoped and the FCI operations remain separate.

Pattern 3 — Hybrid contractor handling both FCI and CUI across separate enclaves

The recommended pattern recognizes that a single contractor can run different enclaves at different CMMC Levels. The CUI enclave is hardened to Level 2 + select Level 3 controls; the FCI operations rest at Level 1; the network boundary between the CUI enclave and the FCI operations must enforce isolation (NIST SC-7 boundary protection + SC-8 transmission confidentiality + SC-32 system partitioning) so that the CUI enclave cannot leak FCI-bearing data into the FCI network boundary. The compliance-pulse assessment scores the systems in each enclave separately; the SSP and POA&M cover each enclave scope. ComplianceStack pairs the hybrid pattern with a dual-enclave inventory + enclave-isolated audit-trail scoping.

§8 Pair this guide with the ComplianceStack CMMC 2.0 Tools

Four ComplianceStack tools pair directly with this pillar guide. The free CMMC compliance pulse is the lightweight Level / SPRS scoring diagnostic (under 60 seconds, no signup, no email required); the 90-day roadmap deliverable converts the 110-control gap backlog into a sequenced plan; the free-compliance-assessment covers CMMC 2.0 alongside HIPAA / SOX / GDPR / OSHA / PCI-DSS / NIST CSF 2.0 for multi-scope DIB contractors; and ComplianceStack pricing covers audit-ready deliverables from free gap-mapping to paid 90-day roadmap reports.

CMMC 2.0 Compliance Pulse (Free)

Run the ComplianceStack free CMMC 2.0 compliance pulse at /cmmc-compliance-pulse. Under 60 seconds, no email or signup required. Instant CMMC readiness score (Level-applicability-aware), SPRS scoring readiness, CUI enclave boundary integrity, DFARS 7012 flow-down completeness, plus the most-cited CMMC Level 2 deficiency categories surfaced (missing MFA enforcement under AC.L2-3.1.1, missing SPRS submission under DFARS 7012, missing documented SSP under PL.L2-3.2.1, missing POA&M under CA.L2-3.5.1, missing incident-response DIBNet reporting alignment to IR.L2-3.6.2), and the top three remediation actions ranked by likelihood times impact — with assessment-path recommendation (Self / Self-Assessed / C3PAO / DIBCAO) and a 90-day checklist timeline.

Run the Free CMMC 2.0 Assessment →

Multi-Framework CMMC + HIPAA + SOX Coverage

The ComplianceStack free compliance assessment at /free-compliance-assessment scores CMMC 2.0 alongside NIST 800-171 + HIPAA / SOX / GDPR / OSHA / PCI-DSS / SEC / FINRA in a single multi-question instrument. Useful for any DIB contractor whose compliance scope spans defense contracts (CMMC 2.0 / NIST 800-171 / DFARS 7012) and adjacent regulated industry compliance (HIPAA for healthcare adjacency, SOX for SEC-reporting-company adjacency, GDPR for European-bound CUI scope). Output: every-framework risk score and a cross-framework remediation map keyed to the contract-award eligibility signal.

Open the Multi-Framework Assessment →

90-Day Readiness Roadmap

The ComplianceStack 90-Day Roadmap at /90-day-roadmap converts the CMMC 2.0 110-control gap backlog into a sequenced implementation plan. Output: a 90-day delivery plan covering AC + IA + AU + SI + CM + SC + MP + PE + PL + PS + RA + AT + IR + MA, with named owners, evidence-package expectations, the SPRS scoring submission timeline, and the C3PAO assessment engagement window for the Level 2 third-party path. ComplianceStack delivers this in 3-5 business days.

Build the 90-Day Roadmap →

ComplianceStack Pricing & Audit-Ready Deliverables

Upgrade from the free assessment to a ComplianceStack audit-ready report ($49-$149), remediation action plan ($79), or 90-day roadmap ($299) for documented output that satisfies the CMMC / NIST 800-171 / DFARS 7012 cross-reference evidence-format expectation and is defensible at any C3PAO Level 2 third-party engagement. The ComplianceStack SSP and POA&M artifacts are the closing-package deliverable for the readiness program.

View Pricing →

§8a Framework Crosswalk — CMMC 2.0 Level 2 Control Families ↔ NIST SP 800-171 Rev 2 ↔ NIST CSF 2.0

ComplianceStack pairs every CMMC 2.0 Level 2 practice with its NIST SP 800-171 Rev 2 control family and its NIST CSF 2.0 Function / Category / Subcategory counterpart — covering the new Govern (GV) Function plus Identify (ID), Protect (PR), Detect (DE), Respond (RS), and Recover (RC). Use this crosswalk to map a finished CMMC Level 2 evidence package to a NIST CSF 2.0 Current-vs-Target Profile without re-papering controls, and to demonstrate continued CSF 2.0 alignment to enterprise buyers who request both attestations.

CMMC 2.0 Level 2 Family NIST SP 800-171 Rev 2 Section NIST CSF 2.0 Function / Category / Subcategory HIPAA Security Rule safeguard (45 CFR §164) SOC 2 Trust Services Criterion Primary-source citation
AC — Access Control §3.1.1–3.1.22 PR.AA-01 through PR.AA-05 + PR.AC-01/04/06 §164.312(a)(1) Access Control + §164.308(a)(3) Workforce Security CC6.1 + CC6.3 32 CFR Part 170 / NIST SP 800-171 Rev 2
AT — Awareness and Training §3.2.1–3.2.3 PR.AT-01 through PR.AT-05 §164.308(a)(5) Security Awareness & Training CC1.4 32 CFR Part 170 / NIST SP 800-171 Rev 2
AU — Audit and Accountability §3.3.1–3.3.9 DE.AE-02/03 + DE.CM-01 §164.312(b) Audit Controls + §164.308(a)(1)(ii)(D) Information System Activity Review CC7.1 + CC7.2 32 CFR Part 170 / NIST SP 800-171 Rev 2
CM — Configuration Management §3.4.1–3.4.9 PR.PS-01 + PR.DS-01 + ID.IM-01 §164.308(a)(8) Evaluation + §164.310(a)(1) Facility Access Controls CC8.1 + CC6.1 32 CFR Part 170 / NIST SP 800-171 Rev 2
IA — Identification and Authentication §3.5.1–3.5.11 PR.AA-01/03 §164.312(a)(2)(i) Unique User Identification + §164.312(d) Person/Entity Authentication CC6.1 32 CFR Part 170 / NIST SP 800-171 Rev 2
IR — Incident Response §3.6.1–3.6.3 RS.AN-01 + RS.RP-01 + RS.MI-01/02 §164.308(a)(6) Security Incident Procedures CC7.2 + CC7.3 + CC7.4 32 CFR Part 170 / NIST SP 800-171 Rev 2
MA — Maintenance §3.7.1–3.7.6 PR.MA-01/02 §164.310(a)(2)(iv) Facility Maintenance + §164.310(c) Device/Media Controls CC6.7 + CC7.2 32 CFR Part 170 / NIST SP 800-171 Rev 2
MP — Media Protection §3.8.1–3.8.9 PR.DS-01 + MP-6 sanitization §164.310(d)(1) Device & Media Controls CC6.7 + CC6.1 32 CFR Part 170 / NIST SP 800-171 Rev 2
PE — Physical and Environmental Protection §3.10.1–3.10.6 PR.AA-04 §164.310(a) Facility Access Controls CC6.4 + CC6.5 32 CFR Part 170 / NIST SP 800-171 Rev 2
PL — Planning §3.9.1–3.9.2 GV.PO-01 + ID.AM-01/-05 §164.308(a)(7) Contingency Plan CC1.1 + CC3.1 32 CFR Part 170 / NIST SP 800-171 Rev 2
PS — Personnel Security §3.9.1–3.9.2 PR.AT-01/04 §164.308(a)(3) Workforce Security + §164.308(a)(7)(ii)(D) Data Backup Plan (training-driven) CC1.2 + CC6.3 32 CFR Part 170 / NIST SP 800-171 Rev 2
RA — Risk Assessment §3.11.1–3.11.3 ID.RA-01 through ID.RA-05 + GV.RM-01 §164.308(a)(1)(ii)(A) Risk Analysis + §164.308(a)(8) Evaluation CC3.1 + CC3.2 32 CFR Part 170 / NIST SP 800-171 Rev 2
SA — System and Services Acquisition §3.13.1–3.13.5 PR.PS-06 + ID.SC §164.308(a)(4) Information Access Management + §164.314(b) Subcontractor BAA CC9.2 32 CFR Part 170 / NIST SP 800-171 Rev 2
SC — System and Communications Protection §3.13.1–3.13.16 PR.DS-01/02 + PR.PS-01 §164.312(e)(1) Transmission Security + §164.312(e)(2)(ii) Encryption CC6.6 + CC6.7 32 CFR Part 170 / NIST SP 800-171 Rev 2
SI — System and Information Integrity §3.14.1–3.14.7 DE.CM + RS.AN §164.308(a)(1)(ii)(D) Information System Activity Review + §164.312(a)(2)(i) Audit Controls CC7.1 + CC7.2 32 CFR Part 170 / NIST SP 800-171 Rev 2

Pair this crosswalk with the two other pillar references below. Each row can be lifted wholesale into a CMMC Level 2 evidence cell, an SPRS scoring cell, a NIST SP 800-171 Rev 2 control inventory row, a NIST CSF 2.0 Target Profile cell, or a HIPAA Security Rule §164 evidence map.

Open the NIST CSF 2.0 Pillar Guide

The ComplianceStack NIST CSF 2.0 pillar at /pillar/nist-csf walks the six Functions (Govern + Identify / Protect / Detect / Respond / Recover), the four Tiers (Partial → Adaptive), Current-vs-Target Profiles, Implementation Examples, and Informative References — the Function/Category side of every row above, plus the §8a crosswalk mapping NIST SP 800-53 Rev 5 ↔ §164.308-312 ↔ CMMC 2.0 AC/IA/SC family controls.

Open the NIST CSF 2.0 Pillar Guide →

Open the HIPAA Practical Guide

The ComplianceStack HIPAA pillar at /pillar/hipaa walks the Security Rule §164.308-312 safeguard table that anchors the HIPAA-adjacent healthcare DIB contractor program — Privacy Rule, Security Rule, Breach Notification, OCR §160.404 enforcement, the 90-day ComplianceStack roadmap, and the §6 crosswalk mapping §164 ↔ NIST SP 800-66 Rev 2 ↔ CMMC 2.0 AC / IA / AU family controls.

Open the HIPAA Practical Guide →

§9 Frequently Asked Questions

What is CMMC 2.0 and which Maturity Level applies to a DoD contractor?
ComplianceStack tracks CMMC 2.0 (Cybersecurity Maturity Model Certification) as the DoD certification scheme formalized under 32 CFR Part 170, published October 15, 2024, that replaces the original CMMC 1.0 model. CMMC 2.0 organizes DoD contractor cybersecurity obligations under three Maturity Levels tied directly to the type of information handled. Level 1 (Foundational) covers Federal Contract Information (FCI) and requires the 17 safeguarding practices from FAR 52.204-21, plus an annual self-assessment and an affirmation of compliance in SPRS. Level 2 (Advanced) covers Controlled Unclassified Information (CUI) and tracks the 110-control set in NIST SP 800-171 Rev 2, plus a self-assessment scoring using the DoD Assessment Methodology on the -203 to +110 scale (target score of 88+ recommended for conditional / final CMMC L2). Level 3 (Expert) covers CUI in DoD-priority programs and adds selected NIST SP 800-172 controls (typically 24-30 practices); the assessment is government-led by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAO). ComplianceStack maps each DoD contract solicitation to the applicable CMMC Level via the contract CMMC requirement line, and pairs every Level 2/3 contractor with the ComplianceStack SPRS scoring roadmap.
How does DFARS 7012 flow-down work and what is SPRS scoring for CMMC 2.0?
ComplianceStack tracks DFARS 252.204-7012 (DFARS 7012) as the flow-down clause that obligates every DoD contractor (and subcontractor) to safeguard Covered Defense Information (CDI) per NIST SP 800-171, report cyber incidents to the DoD through DIBNet within 72 hours, and submit a NIST 800-171 self-assessment score to SPRS (sprs.csd.disa.mil). DFARS 7012 flow-down is required in every subcontract at every tier where CDI will be received or generated — the obligations pass down the supply chain unchanged. SPRS scoring is on a -203 to +110 scale; +110 reflects a perfect implementation across all 110 NIST 800-171 controls, 88 is the median for organizations under conditional CMMC L2 review, and a score below 0 reflects material weakness across multiple control families. Failing to flow DFARS 7012 down to a subcontractor creates contractor liability under the False Claims Act (31 USC §3729) — the most-cited violation pattern in DCAA audits. ComplianceStack pairs DFARS 7012 flow-down with the ComplianceStack Subcontractor Flow-Down Inventory that maps every tier-1 to tier-N subcontractor against its applicable CMMC Level.
What are the CMMC 2.0 assessment types and the C3PAO / DIBCAO ladder?
ComplianceStack tracks four CMMC 2.0 assessment types. (1) Level 1 self-assessment: an annual self-assessment by the contractor against the 17 FAR 52.204-21 practices, with affirmation of compliance posted to SPRS. All Level 1 contractors self-assess. (2) Level 2 self-assessment (a.k.a. self-assessed): a triennial self-assessment scoring all 110 NIST 800-171 Rev 2 controls using the DoD Assessment Methodology, with results posted to SPRS, for select DoD programs where Level 2 self-assessment is the contractual requirement. (3) Level 2 third-party C3PAO assessment: conducted by an authorized CMMC Third-Party Assessment Organization (C3PAO) accredited by the Cyber AB; the contractor receives either a Conditional or Final CMMC Level 2 designation (Conditional = 90-day POA&M remediation window for specific gaps; Final = 3-year triennial cycle); required for any DoD program requiring CMMC Level 2 Final at award. (4) Level 3 government DIBCAO assessment: conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAO) for select DoD priority programs; only awarded after a current CMMC Level 2 Final is in place; adds the NIST SP 800-172 enhanced-security requirement set. ComplianceStack pairs the assessment-type selector with the C3PAO / DIBCAO selection logic for any contract that crosses into Level 2 or Level 3 scope.
How does ComplianceStack build a 90-day CMMC gap-checklist ready for a Level 2 C3PAO assessment?
ComplianceStack packages the CMMC 2.0 readiness program as a 14-family, 90-day gap checklist calibrated for the upcoming C3PAO Level 2 third-party assessment. Day 0-14 covers AC + IA (Access Control + Identification and Authentication): MFA enforcement across all privileged and CUI-touching system access via CAC/PIV where applicable, SSO integration, RBAC review, quarterly access reviews with ticketed evidence, identification of CUI assets, and FIPS 140-3 / FIPS 140-2 validated cryptography via CMVP for every CUI data store. Day 15-30 covers AU + SI + CM (Audit + System and Information Integrity + Configuration Management): 12-month audit-log retention (NIST AU-4), vulnerability management cadence with CVSS-based prioritization, EDR-class endpoint malware protection on every CUI-bearing endpoint, CIS / STIG baseline configuration, and configuration drift monitoring. Day 31-45 covers SC + MP + PE (System and Communications Protection + Media Protection + Physical and Environmental Protection): FIPS-validated TLS 1.2+, FIPS-validated firewall at the CUI enclave boundary, NIST SP 800-88 Rev 1 media sanitization (Clear / Purge / Destroy), and physical access controls. Day 46-60 covers PL + PS + RA + AT + SA: documented system security plan (SSP, NIST PL-2), POA&M (NIST CA-5 / CMMC L2.5), risk register, personnel-security termination (PS-4), and CUI-specific awareness training. Day 61-90 covers IR + MA + CUI boundary hardening + SPRS submission: DIBNet-aligned 72-hour reporting procedure (NIST IR-4/-6/-8), tabletop drill with documented minutes, FIPS / enclave boundary hardening, and SPRS final submission with POA&M closeout for any Conditional POA&M gap.
How does ComplianceStack build a 2026 CMMC readiness roadmap for DoD primes and subcontractors?
ComplianceStack builds three sector-specific 2026 CMMC readiness roadmaps. Pattern 1 — DoD prime contractor with CUI on DIB-priority programs (Level 2 C3PAO + Level 3 DIBCAO): C3PAO third-party assessment for Level 2 Final, followed by Level 3 DIBCAO assessment for any DoD-priority program scope; 90-day program covers all 110 NIST SP 800-171 Rev 2 controls plus the selected NIST SP 800-172 enhanced-security requirements; SPRS final submission target +110; C3PAO cost $50K-$100K+ for a mid-size prime contractor. Pattern 2 — Subcontractor with FCI-only scope at Level 1: annual self-assessment against the 17 FAR 52.204-21 practices with affirmation of compliance posted to SPRS; 90-day program covers the 17 practice areas (basic safeguarding of FCI, MFA, physical access, malware protection, patch management, account management); ComplianceStack pairs the Level 1 subcontractor pattern with the DFARS 7012 flow-down inventory. Pattern 3 — Hybrid contractor handling both FCI and CUI: the CUI enclave is hardened to Level 2 + select Level 3 controls; the FCI operations rest at Level 1; the network boundary between the CUI enclave and the FCI operations enforces isolation (NIST SC-7 boundary protection + SC-8 transmission confidentiality + SC-32 system partitioning); ComplianceStack pairs the hybrid pattern with a dual-enclave inventory.
How does ComplianceStack run a CMMC readiness assessment for a DoD contractor?
ComplianceStack runs a CMMC readiness assessment in two passes. First, the free ComplianceStack CMMC compliance pulse at compliancestack.ai/cmmc-compliance-pulse (no signup, no email required, results in under 60 seconds) scores your applicable Level, SPRS scoring readiness, CUI enclave boundary integrity, and DFARS 7012 flow-down completeness. The free CMMC pulse flags the most-cited Level 2 deficiency categories — missing MFA enforcement under AC.L2-3.1.1, missing SPRS submission under DFARS 7012, missing documented system security plan under PL.L2-3.2.1, missing POA&M under CA.L2-3.5.1, and missing incident-response DIBNet reporting alignment to IR.L2-3.6.2. Second, the ComplianceStack deep CMMC 2.0 assessment (multi-framework, runs CMMC 2.0 alongside NIST 800-171 + DFARS 7012 + NIST CSF 2.0 for span-of-control DIB contractors) produces a prioritized 14-family gap remediation backlog with Level-applicability selection (Level 1 / Level 2 / Level 3), assessment-path selection (Self / Self-Assessed / C3PAO / DIBCAO), 90-day C3PAO engagement timing, Conditional POA&M plan, and a Contract Award Eligibility Estimate. ComplianceStack pairs the deep assessment with a 90-day readiness roadmap deliverable and an SPRS scoring submission that satisfies Cyber AB C3PAO documentation expectations.
How do CMMC 2.0 Level 2 control families map to NIST SP 800-171 Rev 2 and NIST CSF 2.0 Functions?
ComplianceStack maintains a CMMC 2.0 Level 2 control-family crosswalk that pairs every CMMC 2.0 practice with its NIST SP 800-171 Rev 2 control family and its NIST CSF 2.0 Function/Category/Subcategory counterpart. AC (Access Control, 22 practices) maps to PR.AA-01 through PR.AA-05 + PR.AC-01/04/06 + NIST 800-171 §3.1.1-3.1.22; AT (Awareness and Training, 3 practices) maps to PR.AT-01 through PR.AT-05 + NIST 800-171 §3.2.1-3.2.3; AU (Audit and Accountability, 9 practices) maps to DE.AE-02/03 + DE.CM-01 + NIST 800-171 §3.3.1-3.3.9; CM (Configuration Management, 9 practices) maps to PR.PS-01 + PR.DS-01 + ID.IM-01 + NIST 800-171 §3.4.1-3.4.9; IA (Identification and Authentication, 11 practices) maps to PR.AA-01/03 + NIST 800-171 §3.5.1-3.5.11; IR (Incident Response, 7 practices) maps to RS.AN-01 + RS.RP-01 + RS.MI-01/02 + NIST 800-171 §3.6.1-3.6.3; MA (Maintenance, 6 practices) maps to PR.MA-01/02 + NIST 800-171 §3.7.1-3.7.6; MP (Media Protection, 9 practices) maps to PR.DS-01 + MP-6 sanitization + NIST 800-171 §3.8.1-3.8.9; PE (Physical and Environmental Protection, 6 practices) maps to PR.AA-04 + NIST 800-171 §3.10.1-3.10.6; PL (Planning, 2 practices) maps to GV.PO-01 + ID.AM-01/-05 + NIST 800-171 §3.9.1-3.9.2; PS (Personnel Security, 8 practices) maps to PR.AT-01/04 + NIST 800-171 §3.9.1-3.9.2; RA (Risk Assessment, 3 practices) maps to ID.RA-01 through ID.RA-05 + GV.RM-01 + NIST 800-171 §3.11.1-3.11.3; SA (System and Services Acquisition, 5 practices) maps to PR.PS-06 + ID.SC + NIST 800-171 §3.13.1-3.13.5; SC (System and Communications Protection, 16 practices) maps to PR.DS-01/02 + PR.PS-01 + NIST 800-171 §3.13.1-3.13.16; SI (System and Information Integrity, 7 practices) maps to DE.CM + RS.AN + NIST 800-171 §3.14.1-3.14.7. The crosswalk sources from 32 CFR Part 170 (October 15, 2024), NIST SP 800-171 Rev 2 (February 2020, with Rev 3 finalized May 2024), and the NIST CSF 2.0 Reference Tool (csfr.nist.gov). ComplianceStack pairs the crosswalk table with outbound pillar links to /pillar/nist-csf and /pillar/hipaa so a single AC.L2-3.1.1 evidence cell resolves to its PR.AA / PR.AC CSF 2.0 row and its §164.312(a) HIPAA Security Rule counterpart in the same deliverable.