CMMC field guide · Keepgrade

CMMC levels are a scope decision before they are a score.

A practical guide for small defense primes and subcontractors navigating FCI, CUI, enclaves, practice depth, and the difference between being ready for an assessment and receiving a formal CMMC outcome.

01 · Start with scope

CMMC is a contract- and information-scope model.

The first question is not “How big are we?” It is “What information are we handling, where does it move, and which contract requirement applies?” Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) create different starting points, while the systems and services around them determine the assessment boundary.

Treat the boundary as an engineering decision. Identify the people, devices, applications, facilities, and external providers that can touch in-scope information, then document what is intentionally outside it. A clean boundary makes the level conversation more honest and the eventual evidence review more useful.

A useful first inventory
  • What information is in the contract scope?
  • Which systems, people, and providers touch it?
  • What boundary can we defend with evidence?

02 · Status snapshot · July 13, 2026

The rollout timing is under review—not erased.

The current DoD CIO status page says Phase II requirements were immediately suspended. Phase I self-assessment requirements remain, and during the review the Department is enforcing NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments.

For small contractors, that means routine later rollout and Level 3 timing are on hold while the review continues. It does not mean CMMC or Level 3 was abolished: the applicable contract clause, solicitation, subcontract flow-down, and any solicitation-specific direction remain the source of truth.

Class Deviation 2025-O0006 should be read narrowly. It paused use of DFARS 252.204-7021 in new solicitations and contracts until the final rule took effect or the deviation was rescinded; it was not a blanket cancellation of Level 3. The final DFARS CMMC rule took effect on November 10, 2025, so this dated DoD suspension/review language is the better timing reference.

Use the clause in front of you
Treat this as a dated program-status explainer, not a promise of a future Level 3 date or a substitute for contract review.

03 · NIST transition

Build a bridge from the Rev. 2 obligation to Rev. 3 planning.

NIST finalized SP 800-171 Rev. 3 on May 14, 2024, superseding the Rev. 2 publication. The current DoD status snapshot still identifies the 110 Rev. 2 requirements, so contractors should preserve evidence against the contract’s applicable basis while preparing for what comes next.

Current basis
Protect the evidence you need now
Follow the contract and preserve Rev. 2 evidence for current CMMC or DFARS obligations. Do not let future planning erase today’s traceability.
Forward plan
Crosswalk before you claim equivalence
Use Rev. 2-to-Rev. 3 crosswalk and traceability work to identify changed scope, language, and evidence needs. The revisions are not automatically equivalent.
Go deeper
Compare the frameworks

See how CMMC’s contract-defined assessment path relates to NIST SP 800-171.

Read the Rev. 3 explainer

04 · The three levels

Each level adds depth, evidence, and consequence.

Use the cards below as orientation, not as a substitute for reading the applicable solicitation, contract clauses, and current program materials.

Level 1

Foundational

17 practices

The FCI-oriented starting point: establish basic safeguarding in the systems and people that touch federal contract information.

Scope depth
FCI and the assets, people, facilities, and services that handle it. The boundary should be explicit enough for an honest self-assessment.
Control depth
17 foundational safeguarding practices covering the basic protections expected for FCI.
Environment design
A small, understandable environment with clear ownership, basic access discipline, and documented boundaries around contract information.
Assessment type
Level 1 is generally an annual self-assessment and self-attestation path, subject to the solicitation and contract requirements.
Keepgrade readiness
Use Keepgrade to map the starting boundary, surface gaps, and organize the evidence your team should assemble before self-assessment.
Not certification
A Keepgrade score or readiness review is not the government self-attestation and does not establish contract eligibility.
Level 2

Advanced

110 practices

The CUI-centered baseline: prove that a controlled environment can protect sensitive information through repeatable, evidenced practice.

Scope depth
CUI and every in-scope asset, user, facility, and external service that stores, processes, or transmits it. Boundary discipline is central.
Control depth
110 practices aligned to the CMMC Level 2 and NIST SP 800-171 taxonomy, with evidence and implementation depth beyond a policy-only check.
Environment design
A documented system boundary supported by asset inventory, data-flow understanding, access controls, policies, procedures, and an accurate System Security Plan.
Assessment type
The contract determines whether an annual self-assessment or a triennial C3PAO-led assessment applies. Where certification is required, the C3PAO leads the formal assessment; do not infer the path from company size.
Keepgrade readiness
Use Keepgrade to structure a gap map, evidence review, SSP and POA&M drafting workflow, and the work your team needs to complete before an applicable assessment.
Not certification
A readiness score, SSP draft, POA&M draft, or assessor listing is not a C3PAO assessment, attestation, certification, or authorization.
Level 3

Expert

24 advanced practices

The highest-consequence CUI environment: extend the Level 2 baseline with deeper protections for advanced persistent threats and mission-critical work.

Scope depth
The higher-consequence CUI environment defined by the contract, including the enclave boundary and the supporting services that can affect its security.
Control depth
The Level 2 baseline plus 24 advanced practices associated with NIST SP 800-172. The count does not replace implementation evidence or assessor judgment.
Environment design
An appropriately designed enclave or segmented environment with mature identity, monitoring, configuration, incident, recovery, and evidence practices.
Assessment type
Level 3 requires the government-led assessment and certification process defined by the CMMC program, including the DIBCAC path; readiness work is preparation, not the outcome.
Keepgrade readiness
Use Keepgrade to make the enclave boundary, advanced practice gaps, evidence lineage, and assessment package easier to inspect and improve.
Not certification
Keepgrade does not issue Level 3 certification, approve an enclave, or guarantee a favorable formal assessment result.

Framework relationship

Need the CMMC vs NIST 800-171 distinction?

See where the 110-practice overlap ends — and where CMMC adds the contract-defined assessment, evidence, and affirmation path.

Read the comparison

05 · Side-by-side

Same questions. Different level of proof.

Comparison of CMMC Levels 1, 2, and 3
DimensionLevel 1 · FoundationalLevel 2 · AdvancedLevel 3 · Expert
Scope depthFCI-oriented scopeCUI scope with boundary disciplineHigher-consequence CUI environment
Control depth17 foundational practices110 practices aligned to NIST SP 800-171Level 2 baseline plus 24 NIST SP 800-172-associated practices
Environment designSimple, owned, documented safeguarding environmentDefined boundary, asset and data-flow evidence, SSP disciplinePurpose-designed enclave or segmentation with mature evidence
Assessment typeAnnual self-assessment/self-attestation pathContract-defined self-assessment or C3PAO-led assessmentGovernment-led assessment and certification process
What Keepgrade readiness meansA starting boundary and prioritized gap planEvidence-led preparation for the applicable pathA structured view of enclave and advanced-practice readiness
What it does not constituteGovernment attestation or contract eligibilityC3PAO assessment, attestation, certification, or authorizationLevel 3 certification or a guaranteed formal result

06 · Typical remediation path

Move from contract language to defensible evidence.

CMMC remediation is not a one-time checklist. Small defense contractors make progress when they move through a clear sequence, keep the boundary stable, and validate their work against the assessment path the contract actually requires.

  1. 01

    Scope the contract and information

    Start with the solicitation, contract clauses, and the FCI or CUI your team actually handles. Identify the prime-contract and subcontract obligations that apply before choosing a target level.

  2. 02

    Define the system boundary

    Trace the people, devices, applications, facilities, and service providers that store, process, or transmit in-scope information. Document the intended enclave or segmented boundary and what sits outside it.

  3. 03

    Map gaps and evidence

    Compare the applicable practices with how work is performed today. Link each gap to the policies, procedures, configurations, records, and other evidence that can demonstrate implementation.

  4. 04

    Remediate and build the package

    Prioritize the work, assign owners, and track completion. Update the System Security Plan and, when permitted by the applicable path, document a POA&M with realistic milestones and risk treatment.

  5. 05

    Validate against the applicable path

    Run an honest readiness review, then prepare for the required Level 1 self-assessment, Level 2 C3PAO-led assessment when the contract requires it, or Level 3 government-led assessment and certification process.

07 · Readiness boundary

Preparation is valuable because it is not the outcome.

A score, gap map, SSP or POA&M draft, evidence review, or assessor-directory listing can make your next decision clearer. None of those artifacts, alone or together, certifies, attests, authorizes, or guarantees contract eligibility.

Keepgrade supports readiness work and helps teams prepare for the applicable path. Formal outcomes come from the authorized assessment or certification authority under the contract and current CMMC program requirements. This guide is educational, not legal advice.

The assessment workbench is an authenticated surface for teams working inside Keepgrade. The readiness score and gap analysis are preparation tools, not formal assessment results.

Keep the claim precise
“Ready to prepare” is not the same statement as “certified.” That distinction protects your team, your customers, and the integrity of the assessment process.

Keep moving

Put the explainer into a practical next step.

Choose the route that matches your current question: understand the framework, find people to help, review plans, or establish a baseline signal.

Frameworks

Compare CMMC with the other frameworks in Keepgrade before you choose a workstream.

Explore
Partners

Find specialist support for scoping, remediation, assessment preparation, and delivery.

Explore
Pricing

See the plans for organizing readiness work across a small contractor team.

Explore
Readiness score

Start with a free, readiness-only signal before you commit to a remediation plan.

Explore

08 · Questions teams ask

CMMC answers without the marketing fog.

Plain-language answers about CMMC levels, FCI and CUI scope, assessment routes, the current DoD status snapshot, and readiness boundaries.

Next step

Know your starting point before you buy the answer.

Run the free, readiness-only score to organize your first CMMC conversation and see which work deserves attention next.

Get your readiness score