CMMC 2.0 is no longer a future requirement you can plan around. DoD is actively writing it into solicitations as a condition of award, and the phase-in schedule means more of your pipeline will require it every quarter. An SDVOSB set-aside does not exempt you. If the solicitation requires a CMMC level and you do not hold it, you are not eligible to be awarded the contract, regardless of your veteran-owned status or your technical score.

What CMMC 2.0 Actually Is

The Cybersecurity Maturity Model Certification is DoD’s framework for verifying that contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) at a level appropriate to the sensitivity of what they handle. It replaced the honor-system self-attestation model with a tiered system that, depending on level, requires third-party verification.

It applies to prime contractors and subcontractors alike. If you are a sub on a DoD contract and you touch CUI, your prime’s compliance does not cover you. You need your own certification at the level the flow-down requires.

The Three Levels

Level 1 covers FCI only, requires 17 basic safeguarding practices, and is verified by annual self-assessment. No third party required.

Level 2covers CUI, aligns to the 110 controls in NIST SP 800-171, and requires either self-assessment or third-party assessment depending on the sensitivity of the information involved — the solicitation will specify which.

Level 3 covers CUI associated with the highest priority DoD programs, adds a subset of NIST SP 800-172 controls on top of Level 2, and always requires government-led assessment. Very few SDVOSB firms will need Level 3.

Who Needs What Level

The level is not your choice. It is set by the contracting officer based on the type of information the contract involves, and it appears in the solicitation and in your contract’s DFARS clauses. Read the CUI designation and any DD Form 254 carefully — this is where the actual requirement lives, not in marketing language about “cybersecurity requirements.”

If you have never held a DoD contract that handled CUI, you are most likely looking at Level 1 or Level 2 self-assessment. If your current contracts already require you to comply with DFARS 252.204-7012, you are already supposed to be at the NIST SP 800-171 baseline that Level 2 formalizes and verifies.

Why FCI vs. CUI Is the Question That Actually Matters

Federal Contract Information is information provided by or generated for the government under contract that is not intended for public release — it is common and low-sensitivity. Controlled Unclassified Information is government-created or government-owned information that requires safeguarding under law, regulation, or policy — think technical data, export-controlled material, or program-specific sensitive information.

Most of what a first-time DoD contractor handles is FCI. The jump to CUI is what triggers the much heavier Level 2 requirement. Before you assume you need Level 2, confirm with your contracting officer whether the specific work actually involves CUI or only FCI. Firms routinely over-invest in Level 2 compliance for contracts that only required Level 1.

The Assessment Process

For self-assessment levels, you conduct your own evaluation against the required control set, document your System Security Plan (SSP), and submit your score to the Supplier Performance Risk System (SPRS). This is not optional paperwork — contracting officers check SPRS before award.

For third-party assessment, you engage a CMMC Third-Party Assessment Organization (C3PAO) that has itself been certified by the Cyber-AB. The C3PAO conducts a formal assessment against the required control set and issues certification if you pass. Expect the assessment itself to take several weeks once your environment is ready, and expect the C3PAO to require evidence, not just documentation — policies without corresponding technical controls will fail.

Timeline and Cost

Budget six to twelve months from a standing start to Level 2 certification if you have not previously implemented NIST SP 800-171 controls. Gap remediation — closing the difference between where your IT environment sits today and where the 110 controls require it to be — is almost always the long pole, not the assessment itself.

Cost varies widely based on your existing IT maturity, but plan for consulting or managed security provider fees for gap assessment and remediation, the cost of any new tooling required (endpoint detection, logging, access controls), and the C3PAO assessment fee itself if you need Level 2 third-party certification. Firms that wait until a specific solicitation requires it are almost always too late to bid it.

What Happens If You Are Not Certified When the Solicitation Drops

You are not eligible for award. CMMC status at the required level is increasingly a go/no-go gate, checked before technical and price evaluation even begins. A perfect proposal on an opportunity you cannot legally be awarded is wasted proposal hours. Build CMMC status into your go/no-go screening the same way you screen for NAICS eligibility and size standard.

How to Start

Determine whether your current and target contracts involve CUI or only FCI. Conduct a gap assessment against the applicable control set, even informally, to understand your starting position. Build your SSP and a Plan of Action and Milestones (POA&M) that documents how and when you will close identified gaps. Submit your self-assessment score to SPRS once your controls are in place, or engage a C3PAO if the required level demands third-party assessment.

CMMC and Your SDVOSB Set-Aside Are Independent Requirements

This is the mistake that catches experienced firms off guard: your SDVOSB certification and your CMMC status are evaluated separately, at different points in the process, against different criteria. A valid SDVOSB certification does not substitute for CMMC compliance, and CMMC compliance does not substitute for SDVOSB eligibility. Both gates have to clear independently before you can be awarded a DoD contract that requires them. If your contracts also involve ITAR-controlled technology, note that ITAR compliance runs as a third independent requirement alongside CMMC.

Bottom Line

CMMC is shifting from a future requirement to a present one across an increasing share of DoD solicitations. The firms that treat it as a strategic prerequisite — assessed, budgeted, and started well before a specific bid requires it — keep their full pipeline open. The firms that wait find their pipeline quietly shrinking as more solicitations they would otherwise be competitive on include a certification requirement they cannot meet in time.