Resources - eBooks & On-Demand Webinars - Field Effect

CMMC, the Final Rule, and What it Means for Your Business

Written by Field Effect | Apr 30, 2025 7:03:50 PM

Recorded live on December 11, 2024.

What CMMC means for your business

The Cybersecurity Maturity Model Certification (CMMC) final rule is here, and for businesses in or supporting the defense supply chain, the clock is running. In this webinar, Matt Lewis, Chief Security Officer at Field Effect, breaks down what CMMC is, what changed in the final rule, how to prepare for an audit, and what role Field Effect plays in helping defense companies and their MSPs get there.

What CMMC is and why it exists

CMMC is a Department of Defense initiative to strengthen the cybersecurity of the defense industrial base (DIB). It exists for two reasons.

The first is intellectual property protection. The widely cited example is the Chinese Z10 helicopter, which bears a striking resemblance to the US Apache and is believed to have been reverse-engineered from stolen plans. CMMC is designed to prevent that kind of theft by ensuring that the companies holding sensitive defense information are actually protecting it.

The second reason is supply chain availability. A small defense contractor producing a critical component that goes offline for three months because of a ransomware attack creates a ripple effect across the entire supply chain. CMMC addresses that too.

The three levels of certification

Level 1 applies to companies handling Federal Contract Information (FCI). FCI is not classified or particularly sensitive, but the DoD has determined it still warrants protection. A janitorial company with a contract at a military base is a good example: they hold no weapon systems data, but they do hold FCI. Level 1 requires an annual self-assessment against 15 basic cybersecurity controls, with results uploaded to the DoD's supplier performance risk system (SPRS).

Level 2 applies to companies handling Controlled Unclassified Information (CUI), which covers things like the specifications and plans for weapon systems that flow through the supply chain. It requires implementation of all 110 controls in the NIST 800-171 framework. Most Level 2 certifications will require a third-party assessment.

Level 3 is for the most sensitive programs, particularly those with exposure to nation-state threats. If your company is involved in cutting-edge weapons development, Level 3 may apply.

A brief history

CMMC's roots go back to 2016, when the DFARS 252.204-7012 memo first made contractors accountable for safeguarding CUI and implementing the NIST 800-171 controls. It also introduced a 72-hour cyber incident reporting requirement. What it lacked was any enforcement mechanism.

CMMC was the answer to that gap. A version 1.0 came close to release in 2021 before the Biden administration paused it, deciding it was too complex and had too many levels. Version 2.0 was rebuilt from that feedback, and the final rule (32 CFR) was published in October. As of the recording of this webinar, the rule was taking effect the following Monday.

Key terminology

The DoD loves acronyms. A few to know:

  • DIB (Defense Industrial Base): the full ecosystem of companies supporting the DoD. Best estimates put it at over 60,000 companies and 1.1 million employees. DoD contract spending alone totaled $440 billion in the most recent year and represents roughly 1.6% of US GDP. Many MSPs serving small and medium-sized businesses have at least one DIB company in their client base.

  • OSA/OSC (Organization Seeking Assessment / Certification): the CMMC term for any DIB company pursuing CMMC certification at any level.

  • CUI (Controlled Unclassified Information): the weapon system plans, specifications, and related data that flow through the supply chain. This is the primary thing CMMC is designed to protect.

  • ESP (External Service Provider): any external person, technology, or facility that an OSA uses for IT or cybersecurity. MSPs are the most common example. Field Effect, as an MDR provider, is also an ESP under CMMC.

  • SPA (Security Protection Asset): any asset providing security functions for the OSA's assessment scope. This includes MDR providers, SIEM systems, security cameras, and badge readers. If a service company sits behind an SPA, it is also an ESP.

  • SPD (Security Protection Data): data stored or processed by a security protection asset. This includes configuration data, log files, vulnerability data for in-scope assets, and passwords used to access in-scope systems. It is not CUI, but it is still within the audit scope.

  • C3PAO (CMMC Third-Party Assessment Organization): the private sector auditors certified to perform independent CMMC assessments. There are currently around 60 to 70 authorized C3PAOs.

What changed in the final rule

The phased rollout

The good news is that CMMC rolls out over three years. Year one focuses on Level 1 self-assessments and eligible Level 2 self-assessments. The full implementation, where all new DoD contracts require a stated CMMC level at signing, hits in December 2027.

The bad news is that the DoD has the authority to add CMMC requirements to any contract at any point during those three years. And prime contractors can begin requiring sub-suppliers to demonstrate CMMC progress almost immediately. For many DIB companies, the three-year runway may be shorter in practice than it looks on paper.

Self-assessments

Level 1 and some Level 2 certifications can be handled through self-assessment, with scores uploaded to SPRS. That is the good news.

The bad news is that Level 1 only applies to FCI, meaning any company handling CUI needs at minimum a Level 2 certification. And Level 2 self-assessments are expected to be rare. The DoD assigns the required certification level by contract, and anything involving even moderately sensitive programs will likely require a third-party assessment.

External service providers

This is one of the most significant changes for MSPs. In an earlier version of the rules, there was serious concern that ESPs would be required to obtain CMMC certification at an equivalent level to their clients. If that had stood, it would have made implementation practically impossible for much of the DIB. The DoD listened to those concerns.

Under the final rule, ESPs do not require an equivalent level of certification. That said, they will still be drawn into audits to demonstrate how they help the company meet its CMMC requirements.

The difference in how an MSP handles things can have a significant impact on how deep that audit goes. The example given at a recent CyberAB CMMC town hall: if an MSP manages a client's firewall and stores the firewall passwords in a cloud-based password manager with MFA and restricted access, auditors should be satisfied fairly quickly. But if those passwords are stored in a password-protected Excel file on the MSP's internal network, auditors may want to see the MSP's access control policies, security controls, and logging for the machine where that file lives. Small implementation differences create very different audit footprints.

FedRAMP requirements

Another significant piece of good news for cybersecurity vendors: ESPs and SPAs that do not store, process, or transmit CUI in the cloud are not required to have FedRAMP Moderate authorization. This matters because some very good cybersecurity solutions do not carry FedRAMP certification. Without this carve-out, many DIB companies would have spent 2025 ripping out solid security tools and replacing them with a small set of expensive, FedRAMP-authorized alternatives.

One important caveat noted at the CMMC town hall: backup solutions are treated differently. Even if CUI backups are encrypted and the decryption key stays with the defense company, those backups still need to be stored in a FedRAMP Moderate-authorized environment.

Scoring

To pass a Level 2 audit, an OSA needs to achieve a score of 88 out of a possible 110 (80%). That sounds reasonable. The complexity is in how scoring actually works.

The 110 NIST 800-171 controls are not all worth one point. Forty-four controls are worth five points each, fourteen are worth three points each, and fifty-one are worth one point each. Your score is calculated by taking 110 and subtracting the point value of every control that is not fully met.

The more critical complication is that many controls are not eligible for a Plan of Action and Milestone (POAM). A POAM is essentially a remediation plan for a gap: you acknowledge the deficiency, commit to fixing it, and get a six-month window to resolve it before a closeout audit. But for controls that are not POAMable, a finding means you failed, full stop. You could have a near-perfect audit, get dinged on a single unmet control that is not POAMable, and have to start over from the beginning. A missing physical access log for a room where printed CUI is stored (control 3.10.4) is enough to trigger that outcome.

Almost all five-point and three-point controls (with narrow exceptions like FIPS encryption) are not POAMable. A significant portion of the one-point controls are also not POAMable. Understanding which controls fall into that category before an audit is essential.

Subjectivity

The final rule leaves meaningful room for interpretation, which cuts both ways. On the positive side, it gives MSPs and MDR providers flexibility in how they demonstrate that their services help an OSA meet NIST requirements, rather than prescribing a rigid checklist. On the negative side, different C3PAOs will interpret both the final rule and the NIST framework differently. For an MSP with many DIB clients using different auditors, that inconsistency can create a significant operational burden. Where possible, working with clients to select the same C3PAO reduces that risk.

How to prepare for a CMMC audit

  1. Understand your CUI flow. Before implementing controls, map exactly where CUI enters your organization, where it is stored (locally and in the cloud), where it leaves digital environments (printing, loading into manufacturing equipment), and who has access to it. A poorly scoped assessment leads to unnecessary cost and effort. The goal is to enclave your CUI environment from your general corporate network and make the certification scope as small as defensible.

  2. Select the right C3PAO. There are not many C3PAOs yet, and demand is expected to drive prices up as CMMC scales. Still, interview multiple organizations, get competitive quotes, and ask hard questions about how they interpret the subjective areas of the framework. You want an auditor who is willing to work with you, not one who is looking to make examples.

  3. Get a gap assessment first. Before the real audit, have someone come in and evaluate your control implementation. Ideally, use the same C3PAO, and the same team, that will conduct the formal assessment. Given how much subjectivity is in the rules, you want the gap assessment to look and feel as close to the actual audit as possible.

  4. Prepare as if the stakes are high, because they are. Being audited is a skill. Build an internal playbook that covers every control: your evidence, your strong points, your weak spots, and how you plan to present each one. Keep answers to auditors direct and concise. Do not volunteer information beyond what is asked. And do not stress about audits running behind schedule: that responsibility sits with the C3PAO, and a time-pressed auditor often means fewer controls scrutinized at the back end.

Field Effect and CMMC

Field Effect MDR is classified as both an ESP and a security protection asset under CMMC. The customer responsibility matrix, available on the Field Effect trust center, outlines exactly which NIST 800-171 controls Field Effect helps satisfy and where the responsibility lies with the organization seeking certification.

Critically, CUI never leaves the client's audit boundary when using Field Effect MDR. Field Effect does not pull sensitive data back to its own infrastructure, and clients can verify that independently through the appliance if needed.

Field Effect is available to review system security plans, provide support during audits, and answer general CMMC questions. With SOC 2 and ISO 27001 already in place, the underlying framework work is similar enough to NIST 800-171 that pursuing formal CMMC certification is a likely future step, particularly as more DIB clients go through audits and ESPs get drawn into the process more frequently.

Q&A

Which source identifies which controls are POAMable?

The 32 CFR final rule. As a general rule, nearly all five-point and three-point controls are not POAMable, with the exception of FIPS encryption and possibly MFA. A number of one-point controls are also not POAMable. Looking up every control assigned five or three points in the NIST 800-171 framework is a good starting point. When you combine those two tiers, you are likely looking at roughly half or more of the 110 controls being non-POAMable.

If an MSP claims they can perform a CMMC gap analysis, how can a client validate their capabilities?

Ask detailed questions about the depth and structure of their assessment process. The most important thing to look for is whether the gap assessment will resemble the actual audit experience, not just a checklist review. Ideally, the organization doing the gap assessment should be the same one doing the formal audit, or at least using the same methodology, so that when game day comes the OSA has already been through the process once and knows what to expect.

How involved is the MSP in the audit versus the DIB company itself?

Significantly involved, in most cases. The depth of involvement depends on how embedded the MSP is in the client's IT environment, but for smaller DIB companies where an MSP handles most of the IT, the MSP is likely to be present for a large portion of the audit. ESPs can voluntarily obtain CMMC certification at the equivalent level, and for MSPs and MDR providers that get drawn into many audits, pursuing that certification may eventually become the most practical path forward.

Will Field Effect pursue CMMC certification?

Yes, that is the expectation. Field Effect does not want CMMC to be an obstacle to serving the defense industrial base. With SOC 2 and ISO 27001 already in place, the NIST 800-171 requirements are not dramatically different, and the customer responsibility matrix already makes clear how Field Effect MDR maps to those controls. The plan is to first gain experience being drawn into client audits before formalizing the certification.

When will CMMC requirements start appearing in contracts?

The DoD can add CMMC language to contracts at any point. Level 2 language is expected to appear in contracts roughly a year from the effective date, though some sources suggest April 2025 as an early milestone. Full implementation, where all new contracts require a stated CMMC level at signing, is December 2027. Any DIB company waiting for a formal deadline should be aware that their prime contractor could require proof of progress well before that.

Where can organizations find the full list of non-POAMable controls?

The 32 CFR final rule contains a full section on the scoring system and identifies which controls cannot be addressed through a POAM. The rule makes clear that for Level 2 certification, no control at the five-point or three-point level (with narrow exceptions) can be left open through a POAM. Looking up the controls in those two point categories in the NIST 800-171 framework gives a solid working list to prioritize.

When will CMMC move to NIST 800-171 Revision 3?

At least three years away, based on information shared at recent CyberAB town halls. CMMC 2.0 is currently tied to Revision 2 of the NIST 800-171 framework. Revision 3 was published in May and is considered an improvement on the prior version. When the eventual transition happens, it should be a positive development for organizations already working toward compliance.