CMMC
The Department of Defense certification requirement now flowing down through defense contracts.
What it is
CMMC verifies implementation of NIST SP 800-171 controls by contractors handling controlled unclassified information. Level 1 covers federal contract information and is self-assessed; Level 2 covers CUI across 110 controls and generally requires assessment by an authorized C3PAO; Level 3 adds requirements assessed by the government. Contract clauses determine which level applies, and the requirement flows down to subcontractors.
Who typically needs it
- Defense manufacturers and suppliers with CUI in scope under DFARS clauses
- Subcontractors receiving flow-down requirements from a prime
- Companies with an SPRS score submitted years ago that no longer reflects reality
- Organizations bidding on contracts with a CMMC requirement in the solicitation
- Automotive-adjacent defense suppliers who also carry a TISAX obligation
What the engagement looks like
Framewise partners with an authorized C3PAO for the formal Level 2 assessment. We handle readiness, implementation, and audit preparation; the assessment itself is performed by the C3PAO, and we do not hold C3PAO status. Keeping those roles separate is a requirement of the program, not a preference.
Common failure modes
- A CUI boundary drawn around the whole company rather than the enclave that handles it
- An SPRS score self-reported optimistically and never revisited
- MSP responsibilities assumed rather than documented in a Shared Responsibility Matrix
- POA&M items left open past the allowed closeout window
Price range
Programs typically run between $54,000 and $66,000 for the Level 2 Build phase, plus third-party assessment costs paid directly to the C3PAO.
Talk to us about your CMMC.
Thirty minutes on the calendar, an honest read on where you stand, and a plain answer on what your next framework actually takes.