For anyone selling to the Department of Defense, cybersecurity compliance has moved from “nice to have” to “no compliance, no award.” The framework is CMMC (Cybersecurity Maturity Model Certification), built on the security controls in NIST SP 800-171. If your pipeline includes DoD work, this is a topic you cannot defer. This guide is a plain-English starting point.

Why this exists

DoD contractors handle sensitive-but-unclassified government information on their own systems. Two categories drive the requirements:

  • FCI (Federal Contract Information) — information provided by or generated for the government under a contract, not intended for public release.
  • CUI (Controlled Unclassified Information) — information the government requires to be safeguarded (e.g., controlled technical information, export-controlled data).

Handling CUI triggers the meaningful obligations. DFARS clause 252.204-7012 already requires contractors handling CUI to protect it per NIST 800-171 and report cyber incidents.

NIST SP 800-171

NIST SP 800-171 is the control catalog — a set of security requirements (across families like access control, incident response, configuration management, and more) for protecting CUI on non-federal systems. CMMC assesses whether you actually meet them.

CMMC levels

CMMC sorts requirements into levels based on the sensitivity of the information you handle:

  • Level 1 (Foundational) — basic safeguarding for FCI; a defined set of practices, self-assessed.
  • Level 2 (Advanced) — aligned to the full NIST 800-171 control set for CUI; many contracts will require a third-party assessment (C3PAO).
  • Level 3 (Expert) — for the highest-sensitivity programs; adds controls from NIST 800-172 and government-led assessment.

The exact level you need is set by the contract, based on the information involved.

Figure — the CMMC certification levels
Level 1 · Foundational · FCI · self-assessedLevel 2 · Advanced · CUI · C3PAOLevel 3 · Experthigher sensitivity ↑

The SPRS score, SSP, and POA&M

  • SPRS score — DoD requires many contractors to post a self-assessment score (against the 800-171 controls) in the Supplier Performance Risk System. A current score is increasingly a condition of award.
  • System Security Plan (SSP) — documents how you meet each control. This is the backbone artifact; start it early.
  • POA&M (Plan of Action & Milestones) — documents gaps and your dated plan to close them.

How to start

  1. Determine whether you handle FCI, CUI, or neither — this drives everything.
  2. Scope the systems that touch that information.
  3. Assess against NIST 800-171 and write your SSP.
  4. Post an honest SPRS score and maintain a POA&M for gaps.
  5. Budget the remediation; compliance is a cost of doing DoD business, not a one-time checkbox.

How PursuitAI helps

PursuitAI’s Regulatory Radar tracks DFARS and cybersecurity rule changes (a fast-moving area of 48 CFR) so a new or revised requirement doesn’t first reach you as a surprise clause in a solicitation — giving you lead time to prepare before it gates an award.

A word of caution

CMMC requirements and timelines are evolving through rulemaking, and the specific level and clauses are contract-dependent. This is an orientation, not compliance advice — confirm current requirements against the governing rules and work with a qualified cybersecurity/compliance professional (and a C3PAO where an assessment is required).