Quick answer
CMMC 2.0 (Cybersecurity Maturity Model Certification) is the US Department of Defense's program for verifying that contractors and subcontractors protect sensitive federal information. It has three levels: Level 1 (basic safeguarding of federal contract information, self-assessed), Level 2 (protecting controlled unclassified information with the 110 controls of NIST 800-171, third-party or self-assessed depending on the contract), and Level 3 (enhanced requirements for the most sensitive programs). If DoD work is in your revenue, directly or as a sub, CMMC requirements arrive in your contracts.
The supply chain is the point
CMMC's defining feature is flow-down: primes must ensure their subcontractors meet the required level, who must ensure theirs do, all the way down. A machining shop, a logistics SaaS, or a staffing firm three tiers from the prime can find CMMC Level 2 in their contract terms because CUI touches their systems. The parallel to NIS 2's supply chain effect in Europe is exact: the regulation reaches you through your customers.
What each level demands
- Level 1: 17 basic practices (access control, media handling, physical protection), annually self-assessed with an executive affirmation.
- Level 2: the full NIST 800-171 control set, with a formal assessment by a certified third-party assessment organization (C3PAO) for most contracts handling CUI. This is where most of the supply chain lands, and where the work is.
- Level 3: NIST 800-172 enhancements on top, government-assessed, for a small set of critical programs.
The affirmation requirement carries personal weight: executives certify compliance status, and false claims expose the company under the False Claims Act. Scores also post to the DoD's supplier system, visible to contracting officers.
Getting realistic about readiness
Most small and mid-size defense suppliers discover a substantial gap when they first assess against 800-171: scoping CUI flows, MFA and encryption everywhere CUI lives, logging, incident response capability. The path is a gap assessment, a remediation plan with a plan of action, and evidence discipline for the assessment; see running CMMC on OptiTech.

Get a personalized walkthrough of automated compliance for your team. No commitment required.