What the requirement actually says · 1.1

What the three levels are, and which applies

The level is set by your contract, not by your size. Most suppliers handling controlled unclassified information are at the second.

For an independent reference point, see CMMC resources and documentation.

The levels

Three levels, and most suppliers are at the second

The certification programme defines levels by the sensitivity of the information a contract involves and by how the supplier's compliance is verified.

Level 1 covers federal contract information and rests on a small set of basic safeguarding requirements, verified by annual self-assessment.

Level 2 covers controlled unclassified information and rests on the security requirements in the relevant NIST publication. Verification is by third-party assessment for most contracts and by self-assessment for a subset.

Level 3 covers the highest-priority programmes, adds requirements from a further NIST publication, and is assessed by the government rather than by a commercial body.

The level that applies to you is determined by the contract, not by your size or your preference.

Where it comes from

The requirement is not new; the verification is

The obligation to protect controlled unclassified information was already carried by a defence acquisition clause requiring compliance with the NIST requirements and self-attestation of that compliance.

What certification changed is the verification: from an assertion to an assessment, with eligibility for award attached.

This matters when somebody tells you the requirement arrived recently. In substance it did not. What arrived was somebody checking.

Rests on

The defence acquisition regulation clause on safeguarding covered defense information, and the NIST publication on protecting controlled unclassified information in nonfederal systems. Both are published in full.

The distinction between the underlying obligation and its verification is visible in the dates of those two documents.

The controls

What the standard actually contains

Requirements grouped into families covering access control, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.

They are written for an information system. Applying them to a machine tool is the work, and the entry on legacy equipment in the next part is about what that involves.

The gap

Self-assessment and reality

Suppliers have been self-attesting for years, and the scores submitted have on average been considerably more optimistic than what assessments subsequently found. That gap is the reason the programme exists.

It is not usually dishonesty. It is that a requirement reads as met when nobody has tried to produce the evidence for it, and producing evidence is where most of the effort turns out to be.

What to do first

Three things, in order

Read your contract. The clause names what applies. Suppliers frequently plan against a level their contracts do not require, in both directions.

Define the boundary. Which systems handle covered information. A narrower boundary is cheaper to assess and harder to defend; a wider one is the reverse. The entry on scoping treats this properly.

Find out what you can evidence. Not what you do: what you can show an assessor twelve months from now. The two are different and the difference is the project.

Not advice

What this page is not

It is a description of a published programme. Which level applies to your contracts, what your boundary should be, and whether any particular control is satisfied are questions for a qualified assessor with sight of your environment.

Where this site describes a requirement it names the document the requirement comes from, so that you can read the source rather than trusting a vendor's summary of it. That includes ours.

The subset

When the second level is self-assessed

Not every contract at the second level requires a third-party assessment. A subset is permitted to self-assess, and which contracts fall into it is determined by the acquiring agency rather than by the supplier.

The practical consequence is that a supplier can be at the second level and never see an assessor, and can also be at the second level and be assessed within the year. Planning on the first and receiving the second is the expensive version of this mistake.

Flow-down

The requirement travels down the chain

A prime contractor with an obligation passes it to subcontractors who handle the same information. A supplier three tiers down can therefore acquire a requirement from a contract it never read, communicated in a purchase order clause.

If you supply into defence at any depth, the question is not whether this applies to you but which of your customers will ask first, and asking them is better than waiting.

Common misreadings

Four things suppliers get wrong about the levels

That size determines the level. It does not. A twelve-person shop handling covered information is at the same level as a large prime handling the same information.

That a certificate covers the company. It covers a defined boundary. Work performed outside that boundary is not covered by it, which is why the scoping decision matters more than the technology decision.

That certification is permanent. It has a validity period and requires annual affirmation in between.

That preparing is mostly buying. The documentation, the boundary definition and the evidence collection are the bulk of the work, and no purchase removes them.

What good preparation looks like

Twelve months, roughly

A quarter establishing the boundary and the gap. A quarter implementing what is missing. A quarter producing evidence and running an internal check against the requirements. A quarter waiting for and undergoing an assessment, because assessor availability is a real constraint rather than a scheduling detail.

That shape is common and it is not a promise. Yours will differ with the state of your documentation and the size of your boundary, which is why this site declines to quote a duration before seeing an environment.

Where to read the source

Both documents are public

The programme documentation and the NIST publication behind it are published in full by the issuing bodies and are free. Anybody selling you a summary, including this page, is standing between you and a document you can read yourself.

Read the control families relevant to your environment before the first vendor conversation. It takes an afternoon and it changes what you are able to ask.

Also

Elsewhere in what the requirement actually says