Verigo Global
//CMMC 2.0
US DoD MandateLevel 1–3

CMMC 2.0, your path to eligibility.

The Department of Defense now requires verified cybersecurity across its supply chain. Verigo takes defense contractors from scoping and gap assessment to a certification-ready program — and through the C3PAO assessment itself.

At a glance
Authority
US Department of Defense
Protects
FCI & CUI
Levels
1 Foundational · 2 Advanced · 3 Expert
Typical timeline
6–12 months to certified
300K+DIB contractors in scope
Nov 2026Level 2 assessments phase in
~600Certified assessors available
110NIST 800-171 controls at Level 2
Why CMMC exists

The DoD is replacing “trust us” with “show us.”

For years, defense contractors self-attested that they safeguarded sensitive government data. Repeated breaches across the supply chain proved self-attestation was not enough. CMMC makes verified cybersecurity a condition of doing business with the Department of Defense.

The mandate protects two kinds of government information: Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). If your contracts touch either, a CMMC requirement will appear in them — and at the required level, no certification means no eligibility to win or keep the award.

Now codified in federal rule and phasing into DoD contracts, CMMC applies across every tier of the Defense Industrial Base — from primes to the smallest subcontractor.

Phase-in has begun

Why waiting is the expensive option.

Level 2 third-party assessments phase in from November 2026. With roughly 300,000 contractors in scope and only a few hundred certified assessors available, assessment slots are scarce and remediation takes months. Certifying early protects your eligibility — and opens work competitors cannot yet bid on.

FCI

Federal Contract Information — information provided for or generated under a contract, not intended for public release.

CUI

Controlled Unclassified Information — sensitive government information that requires safeguarding under federal law and policy.

The three levels

Three levels. Rising assurance.

CMMC 2.0 scales the required rigor to the sensitivity of the information you handle. Your contracts determine which level you must reach.

Level 1

Foundational

17 practicesProtects FCI

Basic safeguarding of Federal Contract Information — access control, identification, media handling, and physical protection. The entry tier for contractors that handle FCI but not CUI.

How it’s assessed
Annual self-assessment & affirmation
Most common
Level 2

Advanced

110 controlsProtects CUI

Full protection of Controlled Unclassified Information, implementing all 110 NIST SP 800-171 controls across 14 domains. This is the level most of the defense supply chain will need to certify to.

How it’s assessed
C3PAO assessment every 3 years (self-assessment for select programs)
Level 3

Expert

110 + enhancedProtects CUI (priority)

The 110 NIST SP 800-171 controls plus a subset of enhanced NIST SP 800-172 requirements, defending the highest-priority programs against advanced persistent threats.

How it’s assessed
Government (DIBCAC) assessment
Coverage

The 14 control domains of NIST SP 800-171.

Level 2 implements all 110 controls across these fourteen families — the same control set that underpins most US federal compliance. We assess and remediate every domain.

Access Control
Awareness & Training
Audit & Accountability
Configuration Management
Identification & Authentication
Incident Response
Maintenance
Media Protection
Personnel Security
Physical Protection
Risk Assessment
Security Assessment
System & Communications
System & Information Integrity
The roadmap to certification

From scoping to certified.

A clear, sequenced path to certification — with the remediation phase that, for most contractors, carries the weight. Durations are indicative for a mid-market environment.

2–3 wks
Scope & level
Map FCI and CUI flows; confirm the level your contracts require.
3–5 wks
Gap assessment
Measure your environment against every required practice and control.
3–9 mo
Remediate
Implement controls, write policies, and stand up the CUI enclave.
2–4 wks
SSP & POA&M
Document the System Security Plan and Plan of Action & Milestones.
2–4 wks
Score & rehearse
Submit your SPRS score and run a full mock assessment.
4–8 wks
Assess & certify
C3PAO (or DIBCAC) assessment, findings closure, and certification.
Seeking certification

If you’re pursuing CMMC, start here.

Certification is won or lost in the decisions you make before remediation begins. Get scope and level right, and the path is direct and predictable. Get them wrong, and cost and timeline balloon. These are the three things to get right first.

Confirm what data you handle

Whether your contracts involve Federal Contract Information, Controlled Unclassified Information, or both decides your required level. Get this wrong and you either over-invest or fail to qualify.

Define — and shrink — your scope

A tightly bounded CUI enclave is the single biggest lever on cost and timeline. We help you isolate where CUI lives so the assessment covers what it must and nothing more.

Assess honestly, then remediate

A candid gap assessment against NIST SP 800-171 is worth more than an optimistic one. We score every control, prioritize by risk, and close gaps before an assessor ever sees them.

Outputs

What you walk away with.

Every CMMC engagement produces the concrete artifacts an assessor expects — and a program that keeps generating them long after certification.

System Security Plan (SSP)

The authoritative document describing your environment, scope, and how each required control is implemented — the backbone of any CMMC assessment.

Plan of Action & Milestones

A tracked, dated plan for closing any control not yet fully met, with owners and target dates an assessor can review.

SPRS score & submission

Your NIST SP 800-171 self-assessment score, calculated and submitted to the Supplier Performance Risk System as the rules require.

Evidence package

Policies, procedures, configurations, and artifacts mapped control-by-control — organized so the assessment runs on prepared evidence, not a scramble.

Mock assessment results

A full pre-assessment run by a reviewer independent of your implementation team, with an exception log and corrective actions before the real assessment.

Certification & coordination

Coordination with your authorized C3PAO (or DIBCAC for Level 3) through assessment, findings closure, and the certification itself.

CMMC questions

Good to know before we start.

Questions on scope, levels, or the C3PAO assessment? A senior practitioner will walk you through it.

If your organization is part of the Department of Defense supply chain and handles Federal Contract Information or Controlled Unclassified Information — as a prime or at any subcontractor tier — a CMMC requirement will appear in your contracts. Roughly 300,000 companies across the Defense Industrial Base are in scope. If you are unsure whether you handle CUI, that determination is the first thing we help you make.

Eligibility is on the line

Get certification-ready before the assessment slots run out.

Tell us what you build and which contracts you hold. We'll confirm your level, scope your environment, and lay out a fixed-price path to a certification-ready program — and through the assessment itself.