The interconnected controls for CMMC

For contractors in the Defense Industrial Base, CMMC isn't optional anymore. Phase 1 enforcement has been active since November 2025, with self-assessments now required as a condition of contract award. Phase 2 arrives in November 2026, when mandatory third-party C3PAO audits kick in for Level 2 contracts involving Controlled Unclassified Information (CUI). Most defense contractors that handle CUI will need Level 2 certification, making it the most common compliance target by a wide margin.

But knowing the deadlines is the easy part. The hard part is figuring out where to start, what evidence assessors actually want to see, and which gaps are most likely to derail your assessment. When contractors fail their first C3PAO assessment, it's rarely because they lack the right tools. They fail because they can't prove their controls are operating consistently, or because they treated all 110 controls as equally urgent and ended up with shallow implementation across the board.

Most articles to CMMC controls give you a flat list and call it a day. That approach treats every domain the same, which is exactly the mistake that derails first-time assessments. Assessors don't weigh every control equally. Some domains carry more weight, fail more often, and demand more evidence than others. A smarter starting point is understanding where the actual risk lives.

By the end of this article, you'll know which CMMC domains carry the most weight in an audit, which controls fail most often and why, what evidence assessors expect for each one, and how to sequence your remediation work for the strongest possible chance of passing your first assessment.

What are CMMC controls?

CMMC controls are the specific cybersecurity practices that the Department of Defense requires contractors to implement and verify as part of the Cybersecurity Maturity Model Certification program. The DoD officially calls them "practices" and "security requirements," but the industry universally refers to them as "controls." They're the same thing, and we'll use "controls" throughout this guide because that's what most practitioners say and what you're likely searching for.

CMMC didn't invent new cybersecurity requirements. It took existing standards and added a verification layer. Level 1 controls come directly from FAR 52.204-21, which covers basic safeguarding of Federal Contract Information (FCI). The final rule (32 CFR Part 170) codifies 15 security requirements for Level 1. If you've seen older DoD materials referencing 17 practices, that's because the 15 FAR requirements map to 17 NIST SP 800-171 requirements, and earlier CMMC 2.0 guidance used that higher number before the DoD consolidated them in the final rule. Level 2 controls map one to one with the 110 security requirements in NIST SP 800-171 Revision 2. Level 3 adds 24 enhanced requirements from NIST SP 800-172, targeting advanced persistent threats. Each level is cumulative, meaning Level 3 includes everything from Level 2, which includes everything from Level 1.

One detail worth noting early. CMMC assesses against NIST SP 800-171 Revision 2, not Revision 3 (which NIST published in May 2024). That distinction matters when you're mapping your existing security program to CMMC requirements. If you've already been implementing 800-171 Rev. 2 controls since the DFARS 252.204-7012 clause took effect in 2017, you're not starting from scratch. You're starting from wherever your implementation actually stands, which is what the assessment will verify.

That's the core shift CMMC represents. These CMMC compliance requirements have technically been mandatory for years. What's new is that someone will now check whether you've actually done the work. Self-attestation is being replaced by scored assessments, third-party audits, and real consequences for gaps.

CMMC control areas at a glance

All CMMC controls are grouped into 14 security domains, each representing a distinct category of cybersecurity capability. These domains originate from the NIST SP 800-171 control families, which themselves trace back to FIPS 200 security areas. Every one of the 110 Level 2 controls falls within one of these domains. Not all domains carry equal weight during an assessment. Here's what each one covers and why it matters: 

1. Access control (AC)

With 22 controls, this is the largest and most scrutinized domain. It governs who can access your systems, what they're permitted to do, and how CUI flows between networks. Controls include enforcing least privilege, separating duties, controlling remote access sessions, and restricting access to CUI based on job responsibilities. Assessors spend more time here than in any other domain.

2. Awareness and training (AT)

This domain covers three controls and ensures that everyone in your organization understands their security responsibilities. Controls require role-based cybersecurity training, regular updates on emerging threats, and documented proof that staff completed it. It's a small domain, but missing training records are an easy way to lose points.

3. Audit and accountability (AU)

AU includes nine controls governing logging, protecting audit records, and reviewing those logs for signs of unauthorized activity. You'll need centralized logging (typically through a SIEM), procedures for regular log review, and documented evidence that your team acts on findings. This domain establishes individual user traceability across all CUI systems.

4. Configuration management (CM)

With nine controls, CM focuses on establishing and maintaining secure baseline configurations for your systems, software, and network devices. Controls cover change management processes, restricting unauthorized software, and maintaining current system inventories. Assessors will check that your documented baselines match your actual configurations.

5. Identification and authentication (IA)

This domain contains 11 controls that verify the identity of users, devices, and processes before granting system access. Controls include multi-factor authentication, password complexity requirements, and session management. IA is heavily evidence-driven, and assessors will test whether your authentication policies match what's actually enforced in your environment.

6. Incident response (IR)

IR covers just three controls, but don't let the small number fool you. This domain addresses how your organization prepares for, detects, and recovers from security incidents. You'll need a documented incident response plan with defined roles, responsibilities, and communication protocols. Having a plan on paper isn't enough. Assessors want evidence that you've tested it, including training records showing staff have rehearsed their roles.

7. Maintenance (MA)

This domain includes six controls addressing timely system maintenance and the control of maintenance tools and unauthorized personnel. Controls require that you perform maintenance on schedule, log all maintenance activity, and supervise any maintenance personnel who lack authorized access. Remote maintenance sessions must also be monitored and controlled.

8. Media protection (MP)

MP contains nine controls that protect information stored on both digital and physical media. Controls cover marking, storing, transporting, and sanitizing media that contains CUI. Before you dispose of or repurpose any media, you must sanitize it using approved methods. This domain also applies to paper records.

9. Personnel security (PS)

The smallest domain with only two controls, PS ensures that CUI is protected during personnel actions like terminations and transfers. Controls require screening individuals before granting access to CUI systems and revoking that access promptly when someone leaves or changes roles.

10. Physical protection (PE)

PE includes six controls that limit physical access to your systems, equipment, and the environments where they operate. Controls include escorting visitors, maintaining physical access logs, and managing physical access devices like keys and badges. If you have on-premises infrastructure that touches CUI, this domain applies directly.

11. Risk assessment (RA)

RA contains three controls requiring you to periodically assess risks to your operations, assets, and people. Controls include conducting vulnerability scans and remediating vulnerabilities based on risk. Assessors will look for evidence that your risk assessments are current and that findings translate into action.

12. Security assessment (CA)

With four controls, CA deals with testing and evaluating your security controls to determine whether they're working as intended. Controls require periodic assessments, a plan of action for addressing deficiencies, and ongoing monitoring of your security posture. This domain is essentially about proving that you're checking your own work.

13. System and communications protection (SC)

SC is the second-largest domain with 16 controls and the one most commonly associated with Conditional certification status. Controls require you to monitor and protect communications at system boundaries, encrypt CUI in transit and at rest using FIPS-validated methods, and separate publicly accessible system components from internal networks. 

14. System and information integrity (SI)

SI includes seven controls focused on identifying system flaws, detecting malicious content, and monitoring system security alerts. Controls require timely patching, antivirus protection, email protections, and ongoing system monitoring. Assessors will check that you're not just running scans but acting on findings in a timely and documented manner.

{{cta_withimage27="/cta-blocks"}} | CMMC compliance checklist

CMMC certification levels and corresponding practices

There are three CMMC levels, as outlined in the following table:

Certification level Target audience Certificate validity
Level 1: Foundational Organizations in the Defense Supply Chain that handle Federal Contract Information (FCI) 1 year (with an accompanying compliance affirmation)
Level 2: Advanced Organizations within the Defense Supply Chain with access to FCI and Controlled Unclassified Information (CUI) 3 years (with annual compliance affirmations)
Level 3: Expert Organizations within the Defense Supply Chain with access to FCI and critical CUI 3 years (with annual compliance affirmations)

Each certification level encompasses different security practices that correspond to an organization’s role in the DoD supply chain and the criticality of shared information. Below, we’ll clarify the practices corresponding to each level.

CMMC Level 1 controls

CMMC Level 1 is the base-level certification program designed to establish basic cybersecurity practices for DoD contractors and subcontractors. As such, it only includes six out of the 14 CMMC control domains and has 15 specific practices in total.

The following table outlines the Level 1 domains with example practices:

CMMC Level 1 control domain Example practices
Access Control
  • Authorized Access Control
  • Transaction & Function Control
  • External Connections
Identification & Authentication
  • Identification (of information system users, processes, and devices)
  • Authentication (of the identified users, processes, and devices)
Media Protection
  • Media Disposal
Physical Protection
  • Limit Physical Access
  • Escort Visitors
  • Manage Physical Access
System and communications protection
  • Boundary Protection
  • Public-Access System Separation
System and information integrity
  • Flaw Remediation
  • Malicious Code Protection
  • System & File Scanning

To obtain a Level 1 certificate, you need to self-assess your IT infrastructure against these practices. The self-assessment encompasses various activities, such as:

  • Access reviews
  • Authentication policy reviews
  • Staff interviews

During the assessment, you'll need to collect and review the CMMC documentation that demonstrates compliance, such as:

  • Policy, procedure, and process documents
  • Security plans and planning documents
  • Training materials
  • Network, system, and data flow diagrams

After completing the self-assessment, you should enter the results into the Supplier Performance Risk System (SPRS). You must meet all of the applicable CMMC practices and affirm the implementation of the in-scope practices to get certified.

Your certificate will be valid for one year, after which you’ll need to repeat the entire self-assessment process. Alongside the results, you’ll have to provide annual compliance affirmations to maintain the certificate.

{{cta_withimage22="/cta-blocks"}}  | The audit ready checklist

CMMC Level 2 controls

CMMC Level 2 addresses the security of sensitive CUI, so it’s not surprising that it encompasses a much broader range of practices and processes. It’s built around 110 practices derived from NIST SP 800-171 R2, which are split across all 14 domains.

The following table outlines some of the key domains not included in Level 1 certification alongside example practices:

CMMC Level 2 control domain Example practices
Audit & Accountability
  • System Audit
  • User Accountability
  • Reduction & Reporting
Configuration Management
  • System Baselining
  • Security Impact Analysis
  • Application Execution Policy
Incident Response
  • Incident Reporting
  • Incident Handling
  • Incident Response Testing
Maintenance
  • System Maintenance Control
  • Media Inspection
  • Nonlocal Maintenance
Security Assessment
  • Security Control Assessment
  • Operational Plan of Action
  • Security Control Monitoring

Depending on the specific information your organization can access, process, and share, you can choose between two Level 2 assessment types:

  1. A self-assessment for organizations that do not handle highly sensitive CUI
  2. A Certified Third-Party Assessor Organization (C3PAO) assessment for organizations handling prioritized CUI

Whichever option you choose, your certificate will be valid for three years, but you still need annual compliance affirmations. This doesn’t mean both assessments are equally valuable, though—a C3PAO assessment is typically considered a superior option due to the increased security assurance it provides.

Unlike Level 1 certification, Level 2 doesn’t require immediate adherence to all the in-scope practices. If you meet at least 80 percent (88/110 practices) but still have gaps, you can apply for a Conditional Certificate. 

To do so, you must accompany your assessment results with a Plan of Action & Milestones (POA&M)—a document that outlines how the gaps will be remediated. You have 180 days to remediate all gaps, after which you’ll receive the Final Certificate.

At this point, it’s crucial to track remediation against specified timelines. This helps you properly prioritize gap remediation activities and ensure accountability for fixing these gaps.

CMMC Level 3 controls

CMMC Level 3 certification builds on Level 2, which means you must first implement all 110 NIST SP 800-171 R2 practices before upgrading to Level 3.

This level focuses on securing sensitive, high-value information—specifically CUI—and helps protect against advanced cybersecurity threats. Achieving Level 3 demonstrates your organization's maturity in cybersecurity practices, which builds trust and helps position your company as a reliable partner.

In addition to 110 NIST 800-171 practices, Level 3 requires 24 more practices from NIST SP 800-172 (Feb 2021), which focuses on advanced threat protection. These additional practices are essential for strengthening your organization's defenses against sophisticated attacks, further improving your cybersecurity maturity.

The following table outlines some of the Level 3 control areas and their corresponding practices:

CMMC Level 3 control domain Example practices
Awareness and Training
  • Advanced Threat Awareness
  • Practical Training Exercises
Configuration management
  • Authoritative Repository
  • Automated Detection & Remediation
  • Automated Inventory
Incident Response
  • Security Operations Center
  • Cyber Incident Response Team
Risk Assessment
  • Threat-Informed Risk Assessment
  • Advanced Risk Identification
  • Supply Chain Risk Response
Security Assessment
  • Penetration Testing

The Level 3 assessment is government-led and conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), which is responsible for overseeing the certification process for contractors in the defense sector. It encompasses various practices related to automation and extensive risk assessments, which makes it potentially resource-intensive.

The good news is that the Conditional Certificate is available for Level 3 under the same conditions as for Level 2. If your initial assessment reveals at least 80 percent compliance, you can submit a POA&M to receive an additional 180 days to implement the remaining practices.

As per the DoD’s official resources, your Level 3 (and Level 2) certification will lapse if you fail to affirm compliance annually. This means that even though the certificate lasts for three years, you’ll need to self-assess your security practices, policies, and procedures at least once a year to ensure ongoing adherence to CMMC practices.

{{cta_withimage27="/cta-blocks"}} | CMMC compliance checklist

Common challenges of CMMC certification

Pursuing CMMC certification can be laborious and time-consuming, especially if you're looking to obtain a Level 2 or Level 3 certificate. The related assessments are extensive and examine nearly every aspect of your security infrastructure, presenting notable challenges such as:

  • Scoping: Outlining a precise CMMC scope can be challenging, especially for organizations with complex IT infrastructures. You must identify where you store, process, and transmit FCI or CUI—including systems, applications, users, and data flows. Focusing resources on securing these critical areas is essential for reducing risk exposure and ensuring compliance efficiency.
  • Extensive documentation: You’ll need to gather comprehensive documentation to provide evidence of implementation of CMMC practices and affirm compliance confidently. You must outline precisely how you’ve met each practice and keep records updated as your organization evolves.
  • Resource constraints: SMBs may face greater challenges in implementing CMMC compared to larger organizations, mainly due to limited internal resources and inefficient workflows. Some practices require dedicated teams, which many SMBs lack, making it difficult to allocate the necessary time and expertise.
  • Disruption of daily activities: Self-assessments and third-party assessments necessary for CMMC certification can place significant pressure on IT and compliance teams. The same goes for other departments involved in the certification process, which might struggle to balance everyday tasks with compliance practices. You’ll also need to conduct targeted training on FCI and CUI handling to ensure organization-wide CMMC implementation, which adds to the time and effort you’ll spend on compliance.

The easiest and most cost-effective way to avoid these challenges is to adopt a compliance automation solution. The right platform should automate tedious tasks like evidence collection and provide clear guidance on implementation to remove guesswork.

Which controls fail most often and how to prioritize

Knowing what the 110 controls require is one thing. Knowing where to start is another. Not all controls carry equal assessment risk, and not all domains produce the same volume of failures. If you're building a remediation plan or starting your CMMC journey from scratch, sequencing your work around the highest-risk areas will give you the best return on your compliance investment.

This isn't about skipping controls. Every one of the 110 must be MET for full certification. But tackling the domains with the highest failure rates and deepest assessor scrutiny first reduces the chance of a failed assessment and gives you the strongest possible foundation to build on.

Here's a three-tier prioritization framework based on assessment failure data and practitioner insights.

Tier 1: Address immediately

Access Control (AC) and System and Communications Protection (SC) should be at the top of your remediation plan. AC has the most controls (22) and ranks among the domains with the most assessment objectives. Assessors spend more time here than anywhere else, and gaps in access management are directly tied to real-world breach paths. If your least-privilege enforcement, remote access controls, or CUI flow restrictions aren't documented and verifiable, you'll lose points fast.

SC is one of the most common sources of Conditional certification status, and the primary culprit is FIPS-validated encryption. Many organizations encrypt CUI at rest but not in transit, or they use encryption methods that aren't FIPS 140-2 validated. Partial implementation fails the control entirely. Across C3PAO assessments, inadequate FIPS encryption is one of the most frequently cited findings. If you address nothing else first, get your encryption right.

Tier 2: Address early

Audit and Accountability (AU), Identification and Authentication (IA), and Incident Response (IR) are your next priorities. AU requires centralized logging, typically through a SIEM, along with regular log review procedures and documented evidence that your team acts on findings. Assessors will ask to see specific logs and the actions taken in response to anomalies. If you're collecting logs but never reviewing them, that's a gap.

IA is heavily evidence-driven. Assessors will test whether your multi-factor authentication, password policies, and session management controls match what's actually enforced in your environment. Policies that describe one thing while your systems enforce another will result in a NOT MET finding.

IR is a small domain with only three controls, but it punches above its weight in assessments. An incident response plan that's never been tested is a frequent failure. Assessors want dated evidence of tabletop exercises, training records showing staff rehearsed their roles, and documentation of how your organization handled actual or simulated incidents. If your IR plan is sitting in a folder untouched since the day it was written, that's not going to pass.

Tier 3: Address systematically

Configuration Management (CM), Risk Assessment (RA), Security Assessment (CA), and the remaining domains are less likely to be the single point of failure that blocks your certification. But each one must still be MET, and gaps in these areas can quietly erode your score. CM in particular requires that your documented baselines match your actual system configurations, something assessors will verify through direct testing. RA and CA require evidence that you're periodically assessing your own security posture and acting on what you find.

The evidence assessors expect for each control

Implementing a control and proving that it's operating are two different things. Many organizations discover this the hard way during their first C3PAO assessment. You can have every technical safeguard in place, but if you can't produce the evidence to back it up, assessors will mark the control as NOT MET.

CMMC assessors verify controls through three methods, and each one demands a different type of proof. They examine your documentation to confirm that policies, procedures, and your System Security Plan describe what you're doing. They interview your staff to verify that the people responsible for controls understand how they work and can explain them clearly. And they test your technical environment to confirm that configurations, access restrictions, and monitoring tools are functioning as documented. All three methods need to align. If your documentation says one thing, your staff says another, and your systems show a third, you have a problem.

The evidence itself falls into three categories. Documentation evidence includes your policies, procedures, System Security Plan (SSP), and Plan of Action and Milestones (POA&M). These must be finalized, version-controlled, and current. Drafts don't count. Assessors treat draft documents as unofficial and will not accept them as evidence of compliance. Configuration evidence includes screenshots, system exports, access control lists, and firewall rules that show your technical controls are configured correctly. Operational evidence is where many organizations fall short. This includes help desk tickets, log review records, training completion records, incident reports, and dated artifacts that prove your controls are running consistently over time, not just on the day of the assessment.

To make this tangible, consider what assessors expect in a few high-priority domains. For Access Control, an assessor may request a full list of accounts with administrative privileges, then pull a sample of recently terminated employees from your HR records. They'll cross-reference those lists against your system logs to verify that access was revoked promptly and completely. If there's a gap between the termination date and the access revocation date, that's a finding.

For Audit and Accountability, assessors will want to see your SIEM outputs, evidence that someone reviews those logs on a defined schedule, and documentation showing what actions were taken when the review surfaced anomalies. Collecting logs without reviewing them, or reviewing them without documenting the results, won't satisfy the assessment objectives.

For Incident Response, expect assessors to ask for your dated IR plan, records of tabletop exercises or simulated incidents, and training documentation proving that your staff know their roles during a security event. A plan written two years ago and never tested will not pass.

Two final points on evidence management. First, all assessment evidence should ideally be retained for six years. Second, organization matters more than you might think. If you can't locate evidence quickly during an assessment, assessors may conclude it doesn't exist. Build an evidence library organized by control ID so that every artifact is retrievable on demand. The time you spend organizing before the assessment will pay for itself many times over when assessors arrive.

How automation reduces the burden of implementing CMMC controls

Manually collecting evidence for 320 assessment objectives across 14 domains is where most compliance programs stall. Screenshots go stale within weeks. Logs pile up without anyone reviewing them. Documentation drifts from reality as systems change and staff rotate. By the time an assessment arrives, teams find themselves scrambling to reconstruct months of evidence they should have been collecting all along.

This is the problem compliance automation solves. Instead of relying on periodic, manual collection, automation platforms connect directly to your infrastructure, including your cloud environment, identity provider, endpoint management tools, and ticketing systems, and gather evidence continuously. Controls that require proof of ongoing operation, like log reviews, access revocations, and configuration baselines, generate that proof automatically as part of daily operations rather than as a special project before an audit.

Continuous monitoring is especially important for CMMC because compliance doesn't end at certification. Level 2 certification is valid for three years, but you must submit an annual executive affirmation confirming that your controls are still operating as assessed. If your evidence collection only happens in the weeks before an assessment, you'll have significant gaps during those affirmation periods. Automation keeps your evidence library current year-round, which makes both annual affirmations and triennial reassessments far less disruptive.

There's also a cross-framework benefit that many organizations overlook. If you already hold a SOC 2 or ISO 27001 certification, a meaningful number of your existing controls overlap with CMMC requirements. Automation platforms can map those overlapping controls across frameworks, eliminating duplicative work. Instead of implementing and documenting the same access control or logging practice separately for each framework, you maintain it once and satisfy multiple standards simultaneously.

Vanta, for example, offers a dedicated CMMC product with pre-mapped controls and guidance aligned to NIST SP 800-171 and 800-172. The platform runs over 1,400 automated tests across 400+ integrations, continuously collecting evidence and monitoring controls so you stay audit-ready between assessments. For smaller contractors without dedicated compliance teams automation can mean the difference between passing on the first attempt and burning through tens of thousands of dollars in rework after a failed assessment.

None of this replaces the need for strong security practices, good documentation habits, and knowledgeable staff who can explain your controls during an interview. But automation handles the repetitive, high-volume evidence collection that humans are worst at maintaining consistently. It lets your team focus on the work that requires judgment, like remediating gaps, training staff, and improving your security posture, rather than spending their time taking screenshots and organizing folders.

Implement CMMC controls with Vanta

Vanta’s CMMC compliance software offers clear prescriptive guidance and resources to help you implement the in-scope CMMC controls. It offers a dedicated CMMC solution equipped with numerous useful features, such as:

  • Out-of-the-box support for all certification levels
  • Automated evidence collection supported by 400+ integrations
  • Centralized tracking of CMMC practices
  • Continuous monitoring of CMMC practices using automated tests

“CMMC practices are largely sourced from NIST 800-171, so that’s the framework that significantly overlaps with CMMC. At Vanta, we have already done this work for our customers and cross-mapped these frameworks.”

Ethan Heller

Vanta also automatically cross-references your controls to avoid duplicative workflows.

While you can’t choose your Level 3 auditor, you can pick a reputable and helpful C3PAO for a Level 2 assessment as the prerequisite for Level 3 certification. To find the best option, you can tap into Vanta’s extensive partner network.

Schedule a custom demo to see Vanta in action.

{{cta_simple33="/cta-blocks"}} | CMMC product page

A note from Vanta: Vanta is not a law firm, and this article does not constitute or contain legal advice or create an attorney-client relationship. When determining your obligations and compliance with respect to relevant laws and regulations, you should consult a licensed attorney.

CMMC controls explained: A complete guide for DoD contractors

Written by
Vanta
Written by
Vanta
Reviewed by
Crystal Jackson
GRC Product SME

Looking to streamline the work for CMMC?

The interconnected controls for CMMC

For contractors in the Defense Industrial Base, CMMC isn't optional anymore. Phase 1 enforcement has been active since November 2025, with self-assessments now required as a condition of contract award. Phase 2 arrives in November 2026, when mandatory third-party C3PAO audits kick in for Level 2 contracts involving Controlled Unclassified Information (CUI). Most defense contractors that handle CUI will need Level 2 certification, making it the most common compliance target by a wide margin.

But knowing the deadlines is the easy part. The hard part is figuring out where to start, what evidence assessors actually want to see, and which gaps are most likely to derail your assessment. When contractors fail their first C3PAO assessment, it's rarely because they lack the right tools. They fail because they can't prove their controls are operating consistently, or because they treated all 110 controls as equally urgent and ended up with shallow implementation across the board.

Most articles to CMMC controls give you a flat list and call it a day. That approach treats every domain the same, which is exactly the mistake that derails first-time assessments. Assessors don't weigh every control equally. Some domains carry more weight, fail more often, and demand more evidence than others. A smarter starting point is understanding where the actual risk lives.

By the end of this article, you'll know which CMMC domains carry the most weight in an audit, which controls fail most often and why, what evidence assessors expect for each one, and how to sequence your remediation work for the strongest possible chance of passing your first assessment.

What are CMMC controls?

CMMC controls are the specific cybersecurity practices that the Department of Defense requires contractors to implement and verify as part of the Cybersecurity Maturity Model Certification program. The DoD officially calls them "practices" and "security requirements," but the industry universally refers to them as "controls." They're the same thing, and we'll use "controls" throughout this guide because that's what most practitioners say and what you're likely searching for.

CMMC didn't invent new cybersecurity requirements. It took existing standards and added a verification layer. Level 1 controls come directly from FAR 52.204-21, which covers basic safeguarding of Federal Contract Information (FCI). The final rule (32 CFR Part 170) codifies 15 security requirements for Level 1. If you've seen older DoD materials referencing 17 practices, that's because the 15 FAR requirements map to 17 NIST SP 800-171 requirements, and earlier CMMC 2.0 guidance used that higher number before the DoD consolidated them in the final rule. Level 2 controls map one to one with the 110 security requirements in NIST SP 800-171 Revision 2. Level 3 adds 24 enhanced requirements from NIST SP 800-172, targeting advanced persistent threats. Each level is cumulative, meaning Level 3 includes everything from Level 2, which includes everything from Level 1.

One detail worth noting early. CMMC assesses against NIST SP 800-171 Revision 2, not Revision 3 (which NIST published in May 2024). That distinction matters when you're mapping your existing security program to CMMC requirements. If you've already been implementing 800-171 Rev. 2 controls since the DFARS 252.204-7012 clause took effect in 2017, you're not starting from scratch. You're starting from wherever your implementation actually stands, which is what the assessment will verify.

That's the core shift CMMC represents. These CMMC compliance requirements have technically been mandatory for years. What's new is that someone will now check whether you've actually done the work. Self-attestation is being replaced by scored assessments, third-party audits, and real consequences for gaps.

CMMC control areas at a glance

All CMMC controls are grouped into 14 security domains, each representing a distinct category of cybersecurity capability. These domains originate from the NIST SP 800-171 control families, which themselves trace back to FIPS 200 security areas. Every one of the 110 Level 2 controls falls within one of these domains. Not all domains carry equal weight during an assessment. Here's what each one covers and why it matters: 

1. Access control (AC)

With 22 controls, this is the largest and most scrutinized domain. It governs who can access your systems, what they're permitted to do, and how CUI flows between networks. Controls include enforcing least privilege, separating duties, controlling remote access sessions, and restricting access to CUI based on job responsibilities. Assessors spend more time here than in any other domain.

2. Awareness and training (AT)

This domain covers three controls and ensures that everyone in your organization understands their security responsibilities. Controls require role-based cybersecurity training, regular updates on emerging threats, and documented proof that staff completed it. It's a small domain, but missing training records are an easy way to lose points.

3. Audit and accountability (AU)

AU includes nine controls governing logging, protecting audit records, and reviewing those logs for signs of unauthorized activity. You'll need centralized logging (typically through a SIEM), procedures for regular log review, and documented evidence that your team acts on findings. This domain establishes individual user traceability across all CUI systems.

4. Configuration management (CM)

With nine controls, CM focuses on establishing and maintaining secure baseline configurations for your systems, software, and network devices. Controls cover change management processes, restricting unauthorized software, and maintaining current system inventories. Assessors will check that your documented baselines match your actual configurations.

5. Identification and authentication (IA)

This domain contains 11 controls that verify the identity of users, devices, and processes before granting system access. Controls include multi-factor authentication, password complexity requirements, and session management. IA is heavily evidence-driven, and assessors will test whether your authentication policies match what's actually enforced in your environment.

6. Incident response (IR)

IR covers just three controls, but don't let the small number fool you. This domain addresses how your organization prepares for, detects, and recovers from security incidents. You'll need a documented incident response plan with defined roles, responsibilities, and communication protocols. Having a plan on paper isn't enough. Assessors want evidence that you've tested it, including training records showing staff have rehearsed their roles.

7. Maintenance (MA)

This domain includes six controls addressing timely system maintenance and the control of maintenance tools and unauthorized personnel. Controls require that you perform maintenance on schedule, log all maintenance activity, and supervise any maintenance personnel who lack authorized access. Remote maintenance sessions must also be monitored and controlled.

8. Media protection (MP)

MP contains nine controls that protect information stored on both digital and physical media. Controls cover marking, storing, transporting, and sanitizing media that contains CUI. Before you dispose of or repurpose any media, you must sanitize it using approved methods. This domain also applies to paper records.

9. Personnel security (PS)

The smallest domain with only two controls, PS ensures that CUI is protected during personnel actions like terminations and transfers. Controls require screening individuals before granting access to CUI systems and revoking that access promptly when someone leaves or changes roles.

10. Physical protection (PE)

PE includes six controls that limit physical access to your systems, equipment, and the environments where they operate. Controls include escorting visitors, maintaining physical access logs, and managing physical access devices like keys and badges. If you have on-premises infrastructure that touches CUI, this domain applies directly.

11. Risk assessment (RA)

RA contains three controls requiring you to periodically assess risks to your operations, assets, and people. Controls include conducting vulnerability scans and remediating vulnerabilities based on risk. Assessors will look for evidence that your risk assessments are current and that findings translate into action.

12. Security assessment (CA)

With four controls, CA deals with testing and evaluating your security controls to determine whether they're working as intended. Controls require periodic assessments, a plan of action for addressing deficiencies, and ongoing monitoring of your security posture. This domain is essentially about proving that you're checking your own work.

13. System and communications protection (SC)

SC is the second-largest domain with 16 controls and the one most commonly associated with Conditional certification status. Controls require you to monitor and protect communications at system boundaries, encrypt CUI in transit and at rest using FIPS-validated methods, and separate publicly accessible system components from internal networks. 

14. System and information integrity (SI)

SI includes seven controls focused on identifying system flaws, detecting malicious content, and monitoring system security alerts. Controls require timely patching, antivirus protection, email protections, and ongoing system monitoring. Assessors will check that you're not just running scans but acting on findings in a timely and documented manner.

{{cta_withimage27="/cta-blocks"}} | CMMC compliance checklist

CMMC certification levels and corresponding practices

There are three CMMC levels, as outlined in the following table:

Certification level Target audience Certificate validity
Level 1: Foundational Organizations in the Defense Supply Chain that handle Federal Contract Information (FCI) 1 year (with an accompanying compliance affirmation)
Level 2: Advanced Organizations within the Defense Supply Chain with access to FCI and Controlled Unclassified Information (CUI) 3 years (with annual compliance affirmations)
Level 3: Expert Organizations within the Defense Supply Chain with access to FCI and critical CUI 3 years (with annual compliance affirmations)

Each certification level encompasses different security practices that correspond to an organization’s role in the DoD supply chain and the criticality of shared information. Below, we’ll clarify the practices corresponding to each level.

CMMC Level 1 controls

CMMC Level 1 is the base-level certification program designed to establish basic cybersecurity practices for DoD contractors and subcontractors. As such, it only includes six out of the 14 CMMC control domains and has 15 specific practices in total.

The following table outlines the Level 1 domains with example practices:

CMMC Level 1 control domain Example practices
Access Control
  • Authorized Access Control
  • Transaction & Function Control
  • External Connections
Identification & Authentication
  • Identification (of information system users, processes, and devices)
  • Authentication (of the identified users, processes, and devices)
Media Protection
  • Media Disposal
Physical Protection
  • Limit Physical Access
  • Escort Visitors
  • Manage Physical Access
System and communications protection
  • Boundary Protection
  • Public-Access System Separation
System and information integrity
  • Flaw Remediation
  • Malicious Code Protection
  • System & File Scanning

To obtain a Level 1 certificate, you need to self-assess your IT infrastructure against these practices. The self-assessment encompasses various activities, such as:

  • Access reviews
  • Authentication policy reviews
  • Staff interviews

During the assessment, you'll need to collect and review the CMMC documentation that demonstrates compliance, such as:

  • Policy, procedure, and process documents
  • Security plans and planning documents
  • Training materials
  • Network, system, and data flow diagrams

After completing the self-assessment, you should enter the results into the Supplier Performance Risk System (SPRS). You must meet all of the applicable CMMC practices and affirm the implementation of the in-scope practices to get certified.

Your certificate will be valid for one year, after which you’ll need to repeat the entire self-assessment process. Alongside the results, you’ll have to provide annual compliance affirmations to maintain the certificate.

{{cta_withimage22="/cta-blocks"}}  | The audit ready checklist

CMMC Level 2 controls

CMMC Level 2 addresses the security of sensitive CUI, so it’s not surprising that it encompasses a much broader range of practices and processes. It’s built around 110 practices derived from NIST SP 800-171 R2, which are split across all 14 domains.

The following table outlines some of the key domains not included in Level 1 certification alongside example practices:

CMMC Level 2 control domain Example practices
Audit & Accountability
  • System Audit
  • User Accountability
  • Reduction & Reporting
Configuration Management
  • System Baselining
  • Security Impact Analysis
  • Application Execution Policy
Incident Response
  • Incident Reporting
  • Incident Handling
  • Incident Response Testing
Maintenance
  • System Maintenance Control
  • Media Inspection
  • Nonlocal Maintenance
Security Assessment
  • Security Control Assessment
  • Operational Plan of Action
  • Security Control Monitoring

Depending on the specific information your organization can access, process, and share, you can choose between two Level 2 assessment types:

  1. A self-assessment for organizations that do not handle highly sensitive CUI
  2. A Certified Third-Party Assessor Organization (C3PAO) assessment for organizations handling prioritized CUI

Whichever option you choose, your certificate will be valid for three years, but you still need annual compliance affirmations. This doesn’t mean both assessments are equally valuable, though—a C3PAO assessment is typically considered a superior option due to the increased security assurance it provides.

Unlike Level 1 certification, Level 2 doesn’t require immediate adherence to all the in-scope practices. If you meet at least 80 percent (88/110 practices) but still have gaps, you can apply for a Conditional Certificate. 

To do so, you must accompany your assessment results with a Plan of Action & Milestones (POA&M)—a document that outlines how the gaps will be remediated. You have 180 days to remediate all gaps, after which you’ll receive the Final Certificate.

At this point, it’s crucial to track remediation against specified timelines. This helps you properly prioritize gap remediation activities and ensure accountability for fixing these gaps.

CMMC Level 3 controls

CMMC Level 3 certification builds on Level 2, which means you must first implement all 110 NIST SP 800-171 R2 practices before upgrading to Level 3.

This level focuses on securing sensitive, high-value information—specifically CUI—and helps protect against advanced cybersecurity threats. Achieving Level 3 demonstrates your organization's maturity in cybersecurity practices, which builds trust and helps position your company as a reliable partner.

In addition to 110 NIST 800-171 practices, Level 3 requires 24 more practices from NIST SP 800-172 (Feb 2021), which focuses on advanced threat protection. These additional practices are essential for strengthening your organization's defenses against sophisticated attacks, further improving your cybersecurity maturity.

The following table outlines some of the Level 3 control areas and their corresponding practices:

CMMC Level 3 control domain Example practices
Awareness and Training
  • Advanced Threat Awareness
  • Practical Training Exercises
Configuration management
  • Authoritative Repository
  • Automated Detection & Remediation
  • Automated Inventory
Incident Response
  • Security Operations Center
  • Cyber Incident Response Team
Risk Assessment
  • Threat-Informed Risk Assessment
  • Advanced Risk Identification
  • Supply Chain Risk Response
Security Assessment
  • Penetration Testing

The Level 3 assessment is government-led and conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), which is responsible for overseeing the certification process for contractors in the defense sector. It encompasses various practices related to automation and extensive risk assessments, which makes it potentially resource-intensive.

The good news is that the Conditional Certificate is available for Level 3 under the same conditions as for Level 2. If your initial assessment reveals at least 80 percent compliance, you can submit a POA&M to receive an additional 180 days to implement the remaining practices.

As per the DoD’s official resources, your Level 3 (and Level 2) certification will lapse if you fail to affirm compliance annually. This means that even though the certificate lasts for three years, you’ll need to self-assess your security practices, policies, and procedures at least once a year to ensure ongoing adherence to CMMC practices.

{{cta_withimage27="/cta-blocks"}} | CMMC compliance checklist

Common challenges of CMMC certification

Pursuing CMMC certification can be laborious and time-consuming, especially if you're looking to obtain a Level 2 or Level 3 certificate. The related assessments are extensive and examine nearly every aspect of your security infrastructure, presenting notable challenges such as:

  • Scoping: Outlining a precise CMMC scope can be challenging, especially for organizations with complex IT infrastructures. You must identify where you store, process, and transmit FCI or CUI—including systems, applications, users, and data flows. Focusing resources on securing these critical areas is essential for reducing risk exposure and ensuring compliance efficiency.
  • Extensive documentation: You’ll need to gather comprehensive documentation to provide evidence of implementation of CMMC practices and affirm compliance confidently. You must outline precisely how you’ve met each practice and keep records updated as your organization evolves.
  • Resource constraints: SMBs may face greater challenges in implementing CMMC compared to larger organizations, mainly due to limited internal resources and inefficient workflows. Some practices require dedicated teams, which many SMBs lack, making it difficult to allocate the necessary time and expertise.
  • Disruption of daily activities: Self-assessments and third-party assessments necessary for CMMC certification can place significant pressure on IT and compliance teams. The same goes for other departments involved in the certification process, which might struggle to balance everyday tasks with compliance practices. You’ll also need to conduct targeted training on FCI and CUI handling to ensure organization-wide CMMC implementation, which adds to the time and effort you’ll spend on compliance.

The easiest and most cost-effective way to avoid these challenges is to adopt a compliance automation solution. The right platform should automate tedious tasks like evidence collection and provide clear guidance on implementation to remove guesswork.

Which controls fail most often and how to prioritize

Knowing what the 110 controls require is one thing. Knowing where to start is another. Not all controls carry equal assessment risk, and not all domains produce the same volume of failures. If you're building a remediation plan or starting your CMMC journey from scratch, sequencing your work around the highest-risk areas will give you the best return on your compliance investment.

This isn't about skipping controls. Every one of the 110 must be MET for full certification. But tackling the domains with the highest failure rates and deepest assessor scrutiny first reduces the chance of a failed assessment and gives you the strongest possible foundation to build on.

Here's a three-tier prioritization framework based on assessment failure data and practitioner insights.

Tier 1: Address immediately

Access Control (AC) and System and Communications Protection (SC) should be at the top of your remediation plan. AC has the most controls (22) and ranks among the domains with the most assessment objectives. Assessors spend more time here than anywhere else, and gaps in access management are directly tied to real-world breach paths. If your least-privilege enforcement, remote access controls, or CUI flow restrictions aren't documented and verifiable, you'll lose points fast.

SC is one of the most common sources of Conditional certification status, and the primary culprit is FIPS-validated encryption. Many organizations encrypt CUI at rest but not in transit, or they use encryption methods that aren't FIPS 140-2 validated. Partial implementation fails the control entirely. Across C3PAO assessments, inadequate FIPS encryption is one of the most frequently cited findings. If you address nothing else first, get your encryption right.

Tier 2: Address early

Audit and Accountability (AU), Identification and Authentication (IA), and Incident Response (IR) are your next priorities. AU requires centralized logging, typically through a SIEM, along with regular log review procedures and documented evidence that your team acts on findings. Assessors will ask to see specific logs and the actions taken in response to anomalies. If you're collecting logs but never reviewing them, that's a gap.

IA is heavily evidence-driven. Assessors will test whether your multi-factor authentication, password policies, and session management controls match what's actually enforced in your environment. Policies that describe one thing while your systems enforce another will result in a NOT MET finding.

IR is a small domain with only three controls, but it punches above its weight in assessments. An incident response plan that's never been tested is a frequent failure. Assessors want dated evidence of tabletop exercises, training records showing staff rehearsed their roles, and documentation of how your organization handled actual or simulated incidents. If your IR plan is sitting in a folder untouched since the day it was written, that's not going to pass.

Tier 3: Address systematically

Configuration Management (CM), Risk Assessment (RA), Security Assessment (CA), and the remaining domains are less likely to be the single point of failure that blocks your certification. But each one must still be MET, and gaps in these areas can quietly erode your score. CM in particular requires that your documented baselines match your actual system configurations, something assessors will verify through direct testing. RA and CA require evidence that you're periodically assessing your own security posture and acting on what you find.

The evidence assessors expect for each control

Implementing a control and proving that it's operating are two different things. Many organizations discover this the hard way during their first C3PAO assessment. You can have every technical safeguard in place, but if you can't produce the evidence to back it up, assessors will mark the control as NOT MET.

CMMC assessors verify controls through three methods, and each one demands a different type of proof. They examine your documentation to confirm that policies, procedures, and your System Security Plan describe what you're doing. They interview your staff to verify that the people responsible for controls understand how they work and can explain them clearly. And they test your technical environment to confirm that configurations, access restrictions, and monitoring tools are functioning as documented. All three methods need to align. If your documentation says one thing, your staff says another, and your systems show a third, you have a problem.

The evidence itself falls into three categories. Documentation evidence includes your policies, procedures, System Security Plan (SSP), and Plan of Action and Milestones (POA&M). These must be finalized, version-controlled, and current. Drafts don't count. Assessors treat draft documents as unofficial and will not accept them as evidence of compliance. Configuration evidence includes screenshots, system exports, access control lists, and firewall rules that show your technical controls are configured correctly. Operational evidence is where many organizations fall short. This includes help desk tickets, log review records, training completion records, incident reports, and dated artifacts that prove your controls are running consistently over time, not just on the day of the assessment.

To make this tangible, consider what assessors expect in a few high-priority domains. For Access Control, an assessor may request a full list of accounts with administrative privileges, then pull a sample of recently terminated employees from your HR records. They'll cross-reference those lists against your system logs to verify that access was revoked promptly and completely. If there's a gap between the termination date and the access revocation date, that's a finding.

For Audit and Accountability, assessors will want to see your SIEM outputs, evidence that someone reviews those logs on a defined schedule, and documentation showing what actions were taken when the review surfaced anomalies. Collecting logs without reviewing them, or reviewing them without documenting the results, won't satisfy the assessment objectives.

For Incident Response, expect assessors to ask for your dated IR plan, records of tabletop exercises or simulated incidents, and training documentation proving that your staff know their roles during a security event. A plan written two years ago and never tested will not pass.

Two final points on evidence management. First, all assessment evidence should ideally be retained for six years. Second, organization matters more than you might think. If you can't locate evidence quickly during an assessment, assessors may conclude it doesn't exist. Build an evidence library organized by control ID so that every artifact is retrievable on demand. The time you spend organizing before the assessment will pay for itself many times over when assessors arrive.

How automation reduces the burden of implementing CMMC controls

Manually collecting evidence for 320 assessment objectives across 14 domains is where most compliance programs stall. Screenshots go stale within weeks. Logs pile up without anyone reviewing them. Documentation drifts from reality as systems change and staff rotate. By the time an assessment arrives, teams find themselves scrambling to reconstruct months of evidence they should have been collecting all along.

This is the problem compliance automation solves. Instead of relying on periodic, manual collection, automation platforms connect directly to your infrastructure, including your cloud environment, identity provider, endpoint management tools, and ticketing systems, and gather evidence continuously. Controls that require proof of ongoing operation, like log reviews, access revocations, and configuration baselines, generate that proof automatically as part of daily operations rather than as a special project before an audit.

Continuous monitoring is especially important for CMMC because compliance doesn't end at certification. Level 2 certification is valid for three years, but you must submit an annual executive affirmation confirming that your controls are still operating as assessed. If your evidence collection only happens in the weeks before an assessment, you'll have significant gaps during those affirmation periods. Automation keeps your evidence library current year-round, which makes both annual affirmations and triennial reassessments far less disruptive.

There's also a cross-framework benefit that many organizations overlook. If you already hold a SOC 2 or ISO 27001 certification, a meaningful number of your existing controls overlap with CMMC requirements. Automation platforms can map those overlapping controls across frameworks, eliminating duplicative work. Instead of implementing and documenting the same access control or logging practice separately for each framework, you maintain it once and satisfy multiple standards simultaneously.

Vanta, for example, offers a dedicated CMMC product with pre-mapped controls and guidance aligned to NIST SP 800-171 and 800-172. The platform runs over 1,400 automated tests across 400+ integrations, continuously collecting evidence and monitoring controls so you stay audit-ready between assessments. For smaller contractors without dedicated compliance teams automation can mean the difference between passing on the first attempt and burning through tens of thousands of dollars in rework after a failed assessment.

None of this replaces the need for strong security practices, good documentation habits, and knowledgeable staff who can explain your controls during an interview. But automation handles the repetitive, high-volume evidence collection that humans are worst at maintaining consistently. It lets your team focus on the work that requires judgment, like remediating gaps, training staff, and improving your security posture, rather than spending their time taking screenshots and organizing folders.

Implement CMMC controls with Vanta

Vanta’s CMMC compliance software offers clear prescriptive guidance and resources to help you implement the in-scope CMMC controls. It offers a dedicated CMMC solution equipped with numerous useful features, such as:

  • Out-of-the-box support for all certification levels
  • Automated evidence collection supported by 400+ integrations
  • Centralized tracking of CMMC practices
  • Continuous monitoring of CMMC practices using automated tests

“CMMC practices are largely sourced from NIST 800-171, so that’s the framework that significantly overlaps with CMMC. At Vanta, we have already done this work for our customers and cross-mapped these frameworks.”

Ethan Heller

Vanta also automatically cross-references your controls to avoid duplicative workflows.

While you can’t choose your Level 3 auditor, you can pick a reputable and helpful C3PAO for a Level 2 assessment as the prerequisite for Level 3 certification. To find the best option, you can tap into Vanta’s extensive partner network.

Schedule a custom demo to see Vanta in action.

{{cta_simple33="/cta-blocks"}} | CMMC product page

A note from Vanta: Vanta is not a law firm, and this article does not constitute or contain legal advice or create an attorney-client relationship. When determining your obligations and compliance with respect to relevant laws and regulations, you should consult a licensed attorney.

Get started with CMMC

Start your CMMC journey with these related resources.

What you need to know about CMMC—from our Director of Government Strategy & Affairs Morgan Kaplan

Vanta’s director of US government strategy and affairs shares how current and future contractors for the DoD can get CMMC certified.

What you need to know about CMMC—from our Director of Government Strategy & Affairs Morgan Kaplan
What you need to know about CMMC—from our Director of Government Strategy & Affairs Morgan Kaplan
CMMC Checklist cover image

CMMC Checklist

This checklist will guide you through the steps to take to get CMMC certified and how to successfully implement and maintain the certification.

CMMC Checklist
CMMC Checklist
The nst 800 - 1717 logo on a yellow background.

The ultimate guide to NIST 800-171

Jumpstart your NIST 800-171 compliance with Vanta's complete guide to this legally required security standard.

The ultimate guide to NIST 800-171
The ultimate guide to NIST 800-171