CMMC starts outside IT. Free webinar June 30 @ 12PM ET. Register Now →

CMMC Final Rule: What Defense Contractors Need to Know Now

The CMMC final rule is here, and defense contractors can no longer afford to treat cybersecurity compliance as a future concern.

During Alluvionic’s webinar, CMMC Final Rule Discussion, cybersecurity and compliance experts explained what the rule means, how it will affect contracts, and what organizations across the defense industry should do now.

The discussion was led by Elizabeth Huy, who oversees Commercial Services at Alluvionic and featured insights from Bobby Padilla, Alluvionic’s Information Security Director and Cyber AB Certified CMMC Professional and Dustin Dabbs, Alluvionic Compliance Analyst.

Together, the panel explained the history behind CMMC, the difference between the 32 CFR and 48 CFR rules, key Level 1 and Level 2 requirements, and the practical steps contractors should take to prepare for assessment.

CMMC Is Final, But It Is Not New

One of the biggest takeaways from the webinar was that CMMC may now be final, but the underlying requirements have been building for years.

The panel reviewed the long history of Department of Defense (DoD) cybersecurity efforts, including DFARS 252.204-7012, NIST SP 800-171, CMMC 1.0, CMMC 2.0, the Joint Surveillance Program, and the final rule process.

Many contractors have already been required to protect Federal Contract Information, known as FCI, and Controlled Unclassified Information, known as CUI, through existing FAR and DFARS clauses. CMMC adds a formal assessment and certification structure to verify that those protections are properly implemented.

What CMMC Is Designed to Do

Bobby explained that CMMC is a pre-award assessment methodology. Its purpose is to determine whether a defense contractor or subcontractor has implemented the cybersecurity protections needed to safeguard sensitive government information.

That matters because certification may become a condition for winning or supporting certain DoD contracts.

For subcontractors, this is especially important. CMMC does not only apply to prime contractors. If CUI is flowed down to a subcontractor, that subcontractor may also need to meet the applicable CMMC requirements.

Understanding the CMMC Levels

The panel reviewed the three CMMC levels and what each one requires.

CMMC Level 1 focuses on protecting Federal Contract Information. It includes 15 basic safeguarding requirements aligned with FAR 52.204-21.

CMMC Level 2 focuses on protecting Controlled Unclassified Information. It includes 110 security requirements based on NIST SP 800-171 Revision 2.

CMMC Level 3 applies to a much smaller group of contractors and includes Level 2 requirements plus additional requirements from NIST SP 800-172.

For most defense contractors, Level 1 or Level 2 will be the primary focus. However, Bobby clarified that Level 2 is more detailed than simply meeting 110 controls. Those controls include 320 assessment objectives, which means organizations must be prepared to show how each requirement is met and documented.

32 CFR Defines CMMC. 48 CFR Enforces It Through Contracts

Elizabeth explained that 32 CFR is the CMMC rule itself. It defines the program, the requirements, and how CMMC will work.

The panel also explained that 48 CFR is tied to the contract language that will enforce CMMC by placing requirements into DoD solicitations and contracts.

In other words, 32 CFR explains the program. 48 CFR brings the requirement into the contracting process.

The panel also discussed the phased rollout. During the early phases, the DoD may begin including CMMC requirements in certain solicitations and contracts. Over time, those requirements are expected to expand across applicable DoD contracts, including option periods.

For contractors, the message was clear: do not wait until CMMC appears in a contract to begin preparing.

Key Clarifications from the Final Rule

The final rule answered several important questions for contractors, especially around POA&Ms, cloud providers, managed service providers, subcontractors, and virtual desktop infrastructure.

Dustin explained that some Plans of Action and Milestones, known as POA&Ms, may be allowed for certain unmet requirements. However, not every gap can be placed on a POA&M. Organizations still need to meet the minimum score threshold, and some requirements must be fully met at the time of assessment. If an allowable item is placed on a POA&M, the organization has 180 days to remediate it.

The panel also discussed cloud service providers. If a cloud service provider stores, processes, or transmits CUI, it must meet FedRAMP Moderate baseline equivalency requirements.

Managed service providers were another major point of clarification. Dustin explained that MSP services fall within the contractor’s compliance boundary and may be assessed as part of the contractor’s environment. However, the MSP itself does not necessarily need to obtain its own separate CMMC certification.

That distinction matters for small businesses that rely heavily on outside IT support.

Documentation Is Critical to Assessment Readiness

A major theme throughout the webinar was documentation.

Bobby emphasized that CMMC is not just a technology project. It includes people, processes, and technology.

As Bobby explained, “You could have an unlimited IT budget, but that’s not going to get you to CMMC compliance.”

Organizations need documented policies, procedures, processes, and a detailed System Security Plan. That documentation should not simply summarize the 110 controls. It should address the assessment objectives tied to each control.

The panel also discussed the importance of shared responsibility matrices and customer responsibility matrices when cloud service providers or external service providers are part of the environment.

For assessors, documentation is evidence. If a company is doing the right thing but has not written it down, it may still struggle during assessment.

Common Gaps Contractors Should Address Early

The panel shared several common gaps they see when working with defense contractors.

One of the most common technical challenges is FIPS-validated encryption. Dustin noted that organizations often struggle to ensure CUI is encrypted at rest and in transit using FIPS-validated algorithms and modules.

Other common gaps include multifactor authentication, unclear CUI flow, weak documentation, and poorly defined compliance boundaries.

Bobby explained that some organizations do not have a clear view of where CUI moves across their environment. In some cases, CUI may be spread across networks, systems, and processes without a strong boundary.

That is why scoping is one of the most important early steps.

Scoping Can Help Reduce Cost and Complexity

For organizations just getting started, the panel recommended beginning with scope.

Understanding where FCI and CUI live, move, and are accessed can help contractors define which systems, people, and processes fall within the assessment boundary.

Bobby explained that reducing scope can help reduce cost and make the environment easier to manage. For some companies, that may mean creating a CUI enclave instead of placing the entire organization inside the CMMC boundary.

This can be especially helpful for businesses where only part of their work supports the defense industrial base.

CMMC Readiness Takes Time

CMMC Final Rule implementation timeline showing four phases: Level 1 and 2 self-assessments, Level 2 assessments for new contracts, Level 2 and 3 certification periods, and full implementation after 36 months. The panel also addressed a common question: how long does CMMC readiness take?

Bobby shared that many small businesses should expect a 12- to 18-month remediation effort, depending on their starting point.

That timeline reflects more than technical implementation. Most organizations have internal stakeholders who are also managing full-time jobs. Even with outside support, CMMC requires internal commitment, coordination, documentation, training, and organizational change.

Bobby also emphasized the importance of minimizing disruption. The goal is not to replace every system at once. The goal is to implement the right controls in a way that supports compliance while allowing the business to continue operating.

What Contractors Should Do Next

The webinar closed with practical advice from the panel.

Dustin encouraged organizations to begin documentation now and prepare for C3PAO scheduling delays.

The panel noted that organizations ready for third-party assessment can use certification to demonstrate competitiveness in future bids. For others, a rigorous self-assessment is the first step toward becoming certified.

Bobby summarized the urgency clearly: “The rule is real. It’s final and it’s official.”

For defense contractors and subcontractors, the next steps are clear:

Understand which FAR and DFARS clauses apply to your organization.

Identify where FCI and CUI exist in your environment.

Define your compliance boundary.

Assess your current controls against CMMC requirements.

Document your policies, procedures, processes, and System Security Plan.

Build a remediation plan for any gaps.

Begin evaluating C3PAOs as you get closer to readiness.

The companies that begin now will be better positioned when CMMC requirements appear in contracts, when primes begin asking harder questions, or when assessment timelines become more competitive.

Watch the Full Webinar Replay

CMMC is no longer a future concern. The final rule is here, and defense contractors need a clear plan to move from awareness to action.

Watch the full webinar replay to hear the complete discussion from Alluvionic’s CMMC experts and learn how your organization can prepare for the next stage of CMMC implementation.

Watch the webinar replay and start building your path to CMMC readiness today.

Contact Us

Read From Our Blog

DOWNLOAD OUR PROJECT ASSURANCE® CHECKLIST

Fill out the form below to access our checklist that will ensure your project's success!