🛡️ CMMC & NIST 800-171
For defense contractors: CMMC Level 2, NIST SP 800-171, GCC High, timelines and cost.
What is CUI?
Controlled Unclassified Information (CUI) is information the government creates or possesses, or that a contractor creates for the government, that a law, regulation or government-wide policy requires to be safeguarded, but that is not classified. For defense contractors, holding CUI is what triggers DFARS 252.204-7012, the 110 requirements of NIST SP 800-171 Rev 2 and CMMC Level 2.
What does DFARS 252.204-7012 require?
DFARS 252.204-7012 requires defense contractors that handle covered defense information to implement NIST SP 800-171 Rev 2, use only cloud providers meeting FedRAMP Moderate-equivalent requirements, report cyber incidents to DoD within 72 hours, preserve affected system images for at least 90 days and flow the clause down to subcontractors. It remains fully in effect during the CMMC Phase 2 suspension.
What are an SSP and a POA&M for CMMC?
A System Security Plan (SSP) describes your CUI system's boundary, environment, connections and how each NIST SP 800-171 Rev 2 requirement is implemented. A Plan of Action and Milestones (POA&M) lists requirements not yet met, with tasks, resources and completion dates. Under CMMC Level 2 the SSP itself can never be placed on a POA&M, and POA&M items must close within 180 days.
What are the CMMC Level 1 requirements?
CMMC Level 1 requires the 15 basic safeguarding requirements of FAR 52.204-21 on every contractor system that holds Federal Contract Information (FCI). Every requirement must be fully met, no POA&M is allowed, and you must self-assess annually, post the result in SPRS and have a senior official affirm compliance. Level 1 (Self) remains an allowed designation under the July 2026 Phase 2 suspension.
What is the difference between Microsoft GCC and GCC High?
Microsoft 365 GCC is a government community cloud for federal, state, local and tribal agencies and contractors handling government data, with FedRAMP High authorization. GCC High is a separate environment designed to DoD Impact Level 4 controls for the Defense Industrial Base and contractors holding DoD CUI or ITAR data. Defense contractors with CUI usually choose GCC High because Microsoft documents its DFARS 7012 support there.
What is CMMC Level 2?
CMMC Level 2 is the Department of Defense cybersecurity tier for contractors that handle Controlled Unclassified Information (CUI). It requires the 110 security requirements of NIST SP 800-171 Revision 2, verified by self-assessment or by an authorized third-party assessor (C3PAO). Since a July 13, 2026 memo suspended Phase 2, new DoD solicitations may only call for the self-assessment version.
How long does it take to get CMMC Level 2 compliant?
CMMC Level 2 takes as long as it takes your company to implement and evidence all 110 NIST SP 800-171 Rev 2 requirements, and DoD publishes no fixed duration. Companies with a documented SSP and mature Microsoft 365 controls move far faster than those starting from scratch or migrating CUI to a new environment. The rule's fixed clocks are 180-day POA&M closeout and three-year validity.
How much does CMMC Level 2 cost?
DoD's regulatory cost analysis in the 32 CFR Part 170 final rule estimates, for a small entity over three years, $37,196 for a Level 2 self-assessment and $104,670 for a Level 2 C3PAO certification assessment, including annual affirmations. Those figures assume the 110 requirements are already implemented. Remediation, tooling and any GCC High migration are separate and usually the larger cost.
Is Microsoft GCC High required for CMMC?
No regulation names GCC High. CMMC Level 2 and DFARS 252.204-7012 require any cloud that holds CUI to be FedRAMP Moderate authorized or equivalent and to meet the clause's incident-reporting terms. For Microsoft 365, Microsoft documents those DFARS commitments for its U.S. Government clouds, which is why most defense contractors storing CUI in Microsoft 365 choose GCC High.
What is on a NIST SP 800-171 compliance checklist?
A NIST SP 800-171 checklist for CMMC Level 2 covers all 110 requirements of Revision 2 across 14 families, from access control to system integrity, plus the work around them: scoping where CUI lives, writing a System Security Plan, scoring with the DoD methodology, tracking gaps in a POA&M, posting to SPRS and annual affirmation. Use Rev 2, not Rev 3, for CMMC.
Can a managed service provider help with CMMC?
Yes. A managed service provider can implement and operate many of the 110 NIST SP 800-171 controls for you, from multifactor authentication to logging and patching. Under the CMMC rule, though, an MSP that handles your CUI or security data is part of your assessment scope, and your company, not the MSP, owns the SSP, the SPRS score and the senior-official affirmation.
CIO Support is an executive technology library published by LAN Service Group, Inc. — an IT management, cybersecurity, compliance and AI services firm in San Ramon, California, serving businesses since 1992.
Talk to LAN Service Group