Sentrix

Framework · CMMC 2.0

CMMC 2.0: required to keep and win DoD contracts

US DoD Cybersecurity Maturity Model Certification: three levels, 110 NIST SP 800-171 practices at Level 2, triennial C3PAO assessment and SPRS score tracking.

CMMC 2.0 (Cybersecurity Maturity Model Certification) is the US Department of Defense (DoD) certification program for contractors and subcontractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Since late 2024, the DoD has been phasing its requirements into new contracts: at Level 2, certification must be demonstrated through a third-party assessment, not self-attestation alone.

Key facts

  • 3 levels: CMMC 2.0 simplified the original five-level model.
  • 110: Level 2 practices, derived from NIST SP 800-171.
  • Every 3 years: Level 2 assessment by a Certified Third-Party Assessor Organization (C3PAO), with annual affirmation.
  • SPRS: the Supplier Performance Risk System score, which DoD contracting officers can review before award.

What CMMC 2.0 requires

Level 1 applies to Federal Contract Information and allows annual self-attestation. Level 2, aligned to NIST SP 800-171, applies to CUI and requires triennial C3PAO assessment.

  1. Level 1: foundational practices for FCI, annual self-attestation by a senior official
  2. Level 2: 110 practices (NIST SP 800-171), C3PAO assessment every 3 years and annual affirmation
  3. Level 3: 24 additional practices from NIST SP 800-172, government-led assessment
  4. System Security Plan (SSP): system boundary, control descriptions, implementation status, responsible parties
  5. Plan of Action and Milestones (POA&M): for every open practice gap
  6. CUI scope: knowing where CUI lives and which environments are in scope for assessment

What Sentrix provides for CMMC

800-171 control mapping

All 110 Level 2 practices mapped directly to their NIST SP 800-171 counterparts. Continuous evidence collection means your assessment package is complete before your C3PAO schedules the first call.

SPRS score tracking

Your SPRS score is calculated continuously based on your current control implementation status. Sentrix tracks your score over time and alerts you when changes affect it.

System Security Plan

The SSP is required for CMMC assessment. Sentrix generates your SSP from your actual control implementations: system boundary, control descriptions, implementation status, and responsible parties all populated automatically.

POA&M management

Every open practice gap gets a Plan of Action and Milestones entry. Track owners, scheduled completion dates, and evidence of closure, in the format your C3PAO expects to review.

CUI data flow mapping

CMMC requires you to know where CUI lives. Sentrix maps CUI data flows from your cloud and on-premise systems and identifies which environments are in scope for assessment.

Crosswalks

  • CPCSC: Canadian defence suppliers pursuing both CMMC and CPCSC manage both from one program; the two frameworks share substantial overlap, with no formal equivalence.
  • NIST SP 800-53: 800-171 derives from 800-53; Sentrix shows which 800-53 controls satisfy CMMC practices.
  • NIST CSF 2.0: practices are mapped to the CSF functions.

Further reading

The Sentrix CPCSC guide includes a detailed CPCSC vs CMMC comparison for suppliers who also supply National Defence Canada.

See your CMMC Level 2 readiness and SPRS score.

Contact us

Frequently asked questions

What is required for CMMC Level 2 certification?
CMMC 2.0 Level 2 requires implementing 110 security practices aligned to NIST SP 800-171, then passing a triennial assessment by a Certified Third-Party Assessor Organization (C3PAO), with annual affirmation in between. It applies to any contractor or subcontractor handling Controlled Unclassified Information (CUI). A System Security Plan and a Plan of Action and Milestones are required for the assessment.
How is CMMC 2.0 different from NIST SP 800-171?
NIST SP 800-171 is the technical control baseline. CMMC 2.0 Level 2 requires implementing all 110 of those same practices, but adds a formal third-party assessment and certification layer on top. Since the 2024 enforcement rollout, self-attestation alone is no longer sufficient for most Level 2 contracts.
How does CMMC compare to Canada's CPCSC?
CMMC and CPCSC both trace back to NIST SP 800-171 at their higher tiers and share substantial control overlap, but there is no formal equivalence between them: a CMMC certification does not automatically satisfy CPCSC requirements or vice versa. Suppliers in both the US and Canadian defence supply chains manage both from a single Sentrix program instead of maintaining separate evidence sets.

Let's talk about your compliance program.

Last updated: 2026-09-17