CMMC
What the requirement says, before anybody sells you anything.
Five separate pages on this site previously covered overlapping ground. This is the one page, and it links to the entries that go further.
For an adjacent operational perspective, the article explains the topic in a practical workplace context.
For an independent reference point, see 32 CFR Part 170.
The levels
Three levels
The level that applies is set by your contract. Most suppliers handling controlled unclassified information are at the second, which rests on the security requirements in the relevant NIST publication and is assessed by a third party for most contracts.
The certification programme documentation and the NIST publication it draws its controls from, both published by the issuing bodies.
Which level applies to a given contract is stated in that contract.
What it takes
The work is evidence, not intent
Most suppliers already do much of what the standard asks. What they cannot do is show it: no record of who authorised a transfer, no log from the machine, no document describing the boundary.
An assessment tests what you can demonstrate. That is the project, and it is longer than the technical work.
Timelines
What we will not promise
A duration before seeing your environment.
No fixed certification timeline is stated. Duration depends on scope, remediation, evidence history and assessor availability.
Not advice
This page is a description, not advice
Which level applies, what your boundary should be and whether a control is satisfied are questions for a qualified assessor with sight of your environment.