CMMC

  • Who it's for

    US Department of Defense (DoD) supply-chain contractors and subcontractors.

  • Problems we solve

    Uncertainty about the required level, difficulty scoping CUI/FCI, and gaps against NIST SP 800-171.

  • Benefits

    Meet each CMMC level to keep bidding and contract eligibility; IngSafe partners with a US-based RPO to improve pass rates.

CMMC overview

In early 2020 the US DoD announced the Cybersecurity Maturity Model Certification (CMMC), requiring all contractors and subcontractors to comply. After a 2021 pilot, CMMC 1.0 was found too onerous — especially for SMEs — so DoD revised it to CMMC 2.0 in November 2021, streamlining to three levels and aligning with NIST standards.

CMMC 2.0 establishes three progressively mature levels by information type:

  • Level 1 (Foundational): for contractors with Federal Contract Information (FCI, 聯邦合約資訊); information needs protection but is not critical to national security.
  • Level 2 (Advanced): for contractors with Controlled Unclassified Information (CUI, 受控非機密資訊); aligned with NIST SP 800-171.
  • Level 3 (Expert): for the highest-priority programs with CUI; uses selected NIST SP 800-172 controls.

Framework

CMMC 2.0 has three key characteristics: a tiered model (cybersecurity standards applied by information type and sensitivity, with flow-down to subcontractors); assessment requirements (allowing DoD to verify implementation); and implementation through contracts (certain contractors must reach a specified level as a condition of award).

Assessment

Level 1 and part of Level 2 require an annual self-assessment with senior-executive affirmation, submitted to the Supplier Performance Risk System (SPRS). Contractors handling information critical to national security (part of Level 2) require third-party assessment by an authorized C3PAO; Level 3 requires government-led assessment.

Current status

CMMC-related rules are now in force: the program rule (32 CFR Part 170) took effect in December 2024, and the acquisition rule (48 CFR / DFARS) on 10 November 2025, with a four-phase rollout expected to fully apply across DoD procurement by 2028. Achieving CMMC conformance is therefore essential for DoD contractors and subcontractors, and requires early planning, implementation and investment.

Why IngSafe

US certification bodies do not currently open RPO/RP services to consultants outside the US; IngSafe partners with a US consulting firm to provide approved, effective services. We communicate smoothly with the US side, clients can join discussions, and we work primarily in English documentation (translated to Chinese after review) to avoid execution issues. Choosing an experienced advisor is essential — IngSafe can be your strong support in improving your chance of passing.

Interested in adoption and consulting? Contact us and a specialist will assist you.