CMMC Level 2 · for contractors who handle CUI

Handle CUI? Here's how to become CMMC certified — the whole path, and where you stand.

The DoD now requires contractors who handle CUI to prove they protect it. It's confusing, the clock is running — and almost nobody's done: only about 1 in 100 feel ready. So you're not behind. Here's the entire path in plain English, and a free scorecard that shows where you stand today, no commitment.

That's the whole path. Not sure where you are on it? The free scan drops a pin in an afternoon.

What is CMMC, and why now?

CMMC — Cybersecurity Maturity Model Certification — is how the Department of Defense makes sure its contractors actually protect the sensitive information they handle. If your company touches Controlled Unclassified Information (CUI) — the contract details, specs, and drawings the government marks as sensitive-but-unclassified — the DoD now wants independent proof you're securing it.

The rule that puts CMMC into contracts took effect November 10, 2025 and phases in over three years. As it rolls out, the short version becomes true: no certification, no contract.

The reassuring part: almost nobody is finished. Roughly 99% of the contractors who need it aren't certified yet — most are figuring it out right now, same as you.

Which level do you need?

There are three, and most companies that handle CUI land on Level 2.

Not sure which applies? It comes down to one question: does the information in your contracts get marked as CUI? If yes, plan for Level 2.

What does Level 2 actually require?

110 practices, across 14 families. In plain English, they ask you to have control over:

None of it is exotic. Most of it is good IT hygiene, written down and proven.

The steps — and why each one exists

  1. Scope it. Find exactly where CUI lives and flows. Why: you only have to protect what's in scope — getting this right shrinks the whole job.
  2. Score yourself (SPRS). Assess against the 110 and submit a score to the DoD's SPRS system. Why: the DoD requires a current score on file — it's your baseline.
  3. Write the SSP and POA&M. A System Security Plan documents how each control is met; a Plan of Action & Milestones lists the gaps and how you'll close them. Why: the assessor examines these first — no security plan, no assessment.
  4. Secure the gaps. Actually implement the missing controls — the technical settings and the policies. Why: a plan isn't security; the assessor checks the real system.
  5. Get assessed by a C3PAO. An authorized third party evaluates you. Why: for CUI you generally can't just attest to yourself — independent proof is the point.
  6. Certify. Pass and you're certified. Score at least 88 of 110 with only certain gaps remaining and you can earn a conditional status — with 180 days to close them. Miss one of the critical controls, though, and there's no shortcut.

How hard is this, honestly?

We won't pretend it's a weekend. The real picture:

The honest summary: it's real, it's finite, and the earlier you see your actual gaps, the smaller the surprise.

Where DenseDefense comes in

This is the part we made easy. Start by seeing exactly where you stand — for free, no sales call.

You don't have to commit to anything to find out where you are. See your starting line, then decide.