Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

CMMC 2.0 (Cybersecurity Maturity Model Certification)

In today’s world of wireless networks, we should configure our network security to the latest so that no one can penetrate our network. Users should use WPA3 to improve the authentication and encryption while making the connection easier. WPA3-SAE (Simultaneous Authentication of Equals) replaced the WPA2-PSK authentication process. WPA3-SAE uses a 128-bit encryption key and Forward secrecy protocol to resist offline dictionary attacks while improving key exchange security without any additional complexity. On the other hand, WPA2-Enterprise is replaced by WPA3-Enterprise, which uses a 192-bit encryption key and a 48-bit initialization vector as requested by sensitive organizations

CMMC 2.0 (Cybersecurity Maturity Model Certification) is a U.S. Department of Defense certification framework, with three levels aligned to NIST SP 800-171 and 800-172, requiring defense contractors to independently verify the cryptographic and cybersecurity controls protecting Federal Contract Information and Controlled Unclassified Information.

CMMC 2.0 requires defense contractors to certify at one of three levels based on the sensitivity of information they handle. The DFARS acquisition rule took effect November 10, 2025, phasing CMMC requirements into DoD contracts, with cryptography-related controls, including FIPS-validated encryption and key protection, central to satisfying NIST SP 800-171’s requirements at Level 2.

Key Takeaways

  • CMMC 2.0’s three levels are Level 1 (Foundational, 15 practices, self-assessed, for FCI), Level 2 (aligned to NIST SP 800-171, for CUI, third-party assessed), and Level 3 (adds 24 enhanced NIST SP 800-172 controls for advanced persistent threat defense).
  • The DFARS acquisition rule (32 CFR Part 170 and DFARS 252.204-7021) took effect November 10, 2025, beginning a phased rollout through full implementation on November 10, 2028.
  • Level 2 certification requires a third-party assessment (C3PAO), lands as a contract requirement starting November 10, 2026 for most contractors handling CUI.
  • NIST SP 800-171’s cryptographic controls, including requiring FIPS-validated encryption for CUI at rest and in transit, are among the most technically demanding requirements at Level 2.
  • CBOM (Cryptography Bill of Materials) tooling maps directly to CMMC’s cryptographic control requirements, since demonstrating exactly which algorithms and key lengths protect CUI is central to passing an assessment.

What Are the CMMC 2.0 Phased Rollout Dates?

PhaseDateRequirement
Phase 1November 10, 2025Level 1 and Level 2 self-assessments in applicable contracts
Phase 2November 10, 2026Third-party Level 2 (C3PAO) certification required for most CUI contracts
Phase 3November 10, 2027Level 3 assessment requirements begin
Phase 4November 10, 2028Full implementation across all applicable DoD contracts

What Cryptographic Controls Does CMMC 2.0 Require?

CMMC 2.0’s Level 2 requirements align directly with NIST SP 800-171, which includes control families covering encryption of Controlled Unclassified Information both at rest and in transit, typically requiring FIPS-validated cryptographic modules. Level 3 adds enhanced requirements from NIST SP 800-172, aimed at defending against Advanced Persistent Threats, which raises the bar further on key management and cryptographic assurance for contractors handling the most sensitive information.

How Does a Cryptography Bill of Materials (CBOM) Support CMMC Compliance?

A core challenge in a CMMC assessment is demonstrating, concretely, which cryptographic algorithms, key lengths, and modules protect CUI across an organization’s systems, rather than asserting compliance in general terms. A CBOM provides that concrete inventory: an auditable record of every cryptographic asset in use, which maps directly onto the evidence a C3PAO assessor expects to see when verifying NIST SP 800-171’s encryption-related controls.

CBOM Secure

Gain complete visibility with continuous cryptographic discovery, automated inventory, and data-driven PQC remediation.

What Should Defense Contractors Do to Prepare for Their CMMC Assessment?

  1. Determine the required CMMC level based on whether your contracts involve FCI (Level 1) or CUI (Level 2 or above).
  2. Build a cryptographic inventory (CBOM) covering every system that stores, processes, or transmits CUI.
  3. Confirm cryptographic modules protecting CUI are FIPS-validated, addressing gaps ahead of a third-party assessment.
  4. Document a Plan of Action and Milestones (POA&M) for any outstanding gaps, and remediate within the required window to achieve final CMMC status.
  5. Schedule a C3PAO assessment well ahead of your contract’s applicable phase deadline, since assessor availability is limited during peak certification periods.

How Encryption Consulting Helps

How Encryption Consulting HelpsCBOM Secure builds the cryptographic inventory a CMMC assessment requires, mapping every algorithm and key to the specific NIST SP 800-171 and 800-172 controls it satisfies, while Compliance Advisory Services guide contractors through the full certification process. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.

Frequently Asked Questions

When does CMMC 2.0 become a contract requirement?

The DFARS acquisition rule took effect November 10, 2025, beginning Phase 1 with Level 1 and Level 2 self-assessment requirements. Level 2 third-party certification becomes required for most CUI-handling contracts starting November 10, 2026.

What is the difference between CMMC Level 1 and Level 2?

Level 1 (Foundational) covers 15 basic practices for contractors handling Federal Contract Information (FCI), verified by annual self-assessment. Level 2 aligns fully with NIST SP 800-171 for contractors handling Controlled Unclassified Information (CUI), and generally requires third-party (C3PAO) certification.

Does CMMC require FIPS-validated encryption?

NIST SP 800-171, which CMMC Level 2 aligns with, requires encryption controls for CUI that typically call for FIPS-validated cryptographic modules. Contractors should confirm their specific implementation meets current FIPS 140-3 validation status ahead of an assessment.

What is a CBOM and why does it matter for CMMC?

A Cryptography Bill of Materials (CBOM) is an inventory of every cryptographic algorithm, key, and module in use across an organization’s systems. It matters for CMMC because assessors need concrete evidence of which cryptography protects CUI, and a CBOM provides that evidence directly.

Build the Cryptographic Evidence Your CMMC Assessment Needs

Take the next step CBOM Secure builds the cryptographic inventory your CMMC Level 2 or Level 3 assessment requires, and Compliance Advisory Services guide you through certification. Discover your cryptography with CBOM Secure.