Defense

What CMMC Actually Requires — and When It Starts Costing You Contracts

Founders & Ventures Alliance · July 2026 · 8 min read

What CMMC Actually Requires — and When It Starts Costing You Contracts

CMMC became a contract requirement in November 2025. What the three levels mean, which one applies to you, what the phased rollout does to your pipeline, and what it costs to get ready.

For a decade, defense cybersecurity requirements were something a supplier could largely self-attest to and move on. That ended on November 10, 2025, when the 48 CFR final rule took effect and CMMC became a clause that appears in contracts.

The change is not that the security requirements are new — most trace back to NIST SP 800-171, which has been in DFARS since 2017. The change is that they are now gating. An award can hinge on holding the right certification at the right level on the day of award.

Founders selling into defense tend to encounter this in one of two ways. Either they plan for it, or they lose a bid and find out why afterward.

The three levels, and which one is yours

CMMC sorts contractors by the sensitivity of the information they handle, not by company size or revenue.

Level 1 — Federal Contract Information (FCI). Information generated for or provided under a contract that is not intended for public release. Basic safeguarding. Satisfied by annual self-assessment.

Level 2 — Controlled Unclassified Information (CUI). The level most defense suppliers land on. Built on the NIST SP 800-171 control set. Depending on the sensitivity of the CUI and the contract, this is either a self-assessment or a third-party assessment conducted by a C3PAO.

Level 3 — the most sensitive CUI and critical-infrastructure-adjacent work. Highest bar, government-led assessment, a small fraction of the supplier base.

The practical question is rarely "which level do I want." It is "what information will this contract actually put in my systems." Handle CUI and you are at Level 2, whatever the size of the award.

The phase-in is the part founders miss

The rollout is staged across roughly three years rather than switching on at once.

Phase 1 began with the rule on November 10, 2025: Level 1 self-assessments for FCI contracts, Level 2 self-assessments for less sensitive CUI, and Level 2 third-party certification on select contracts at the department's discretion.

Phases 2 through 4 tighten from there — Phase 2 pushing Level 2 third-party certification broadly, Phase 3 introducing Level 3, and Phase 4 applying the requirement across all new and renewing contracts. Specific dates for those phases have not been fixed.

Two things follow from that structure, and they are the ones worth planning around.

"At the department's discretion" is doing a lot of work. Third-party certification can appear on a contract before the phase that formally requires it. A supplier reading the timeline as a deadline can be surprised by a solicitation that asks for certification early.

Renewals count. Phase 4 reaches existing relationships, not only new ones. A supplier with comfortable recurring work has a date on that revenue whether or not they are bidding on anything new.

What this does to a fundraise

For a venture selling into defense, CMMC is not only a compliance line item. It shows up in diligence in three places.

Pipeline quality. A pipeline full of opportunities you cannot legally win at your current certification level is not a pipeline. Investors who know the sector will ask which of those contracts require what.

Time to revenue. Third-party assessment is not instant. Readiness work, remediation, scheduling and the assessment itself take real calendar time, and the assessor ecosystem is finite. A company that starts when it wins the bid has already lost the quarter.

Prime relationships. Primes flow requirements down. A supplier who cannot demonstrate readiness becomes a risk in someone else's supply chain, and that conversation happens without you in the room.

What to actually do

Scope first, controls second. The most expensive CMMC mistake is assessing your entire company when only part of it touches CUI. A deliberately narrow enclave — a defined set of systems where the controlled information lives — reduces scope, cost and time. Architecture decisions here outweigh tooling decisions.

Know your score. Under existing DFARS requirements, contractors handling CUI have been expected to post a NIST SP 800-171 self-assessment score. If you do not know yours, that is the first hour of work, not the last.

Write the plan down. Gaps with a documented remediation plan and a date are a different conversation than gaps discovered during an assessment.

Budget honestly. Costs vary widely with scope, existing maturity and whether you need a third-party assessment. Anyone quoting a single number without seeing your environment is selling something.

The strategic read

It is tempting to treat this as pure cost. For a small supplier it is also a moat.

Certification is a fixed cost that lands hardest on the smallest players, and a meaningful number of them will not do the work. Companies that do become materially easier to buy from — for the department and for the primes carrying flow-down risk. In a market where procurement friction is the real barrier to entry, being the supplier who is already cleared to receive the information is a durable advantage.

The suppliers who move early are not just avoiding a penalty. They are shrinking the field.


The DFARS clause governing this requirement is 252.204-7021, published at Acquisition.gov. This briefing explains the framework in general terms and is not legal or compliance advice; requirements are contract-specific and you should confirm your obligations against the solicitation in front of you.

Source and original author: Acquisition.gov (DFARS 252.204-7021)

In person

Come see the Alliance in person

Members meet at our summits, fireside chats and coffee chats — smaller rooms than the name suggests, and the conversations are the point. Founders can also enter our next pitch session.

Tell us what interests you and we will send details on the next one.

Summit calendarFireside chatsPitch sessionsThe Alliance Dispatch

What interests you

← All briefings

Dispatch

Get new briefings first

Subscribers receive each briefing before it is published publicly.

One dispatch per week. No spam, no lists sold, unsubscribe anytime.

All payments made in the preview are in test mode. Read more