CMMC is not optional for most of the defense industrial base. But knowing what the requirements are is only half the job. The other half is understanding that meeting them and being secure are two different things, and only one of them keeps your organization out of a breach report.
Sentinel Blue is an authorized C3PAO, credentialed by the CyberAB to perform CMMC assessments. We were one of the first CMMC Level 2-certified organizations in the country, and we hold our own DIBCAC High Assessment every three years to certify our implementation of NIST SP 800-171. We are not a software platform explaining CMMC from the outside. We assess it.
What Are CMMC Compliance Requirements?
CMMC, the Cybersecurity Maturity Model Certification, sets the cybersecurity baseline the Department of Defense requires for contractors and subcontractors handling federal information. It applies across the supply chain, not just to prime contractors.
The framework is organized into three levels. Each one corresponds to the sensitivity of the information your organization handles.
CMMC Levels at a Glance
| Level | Protects | Controls | Assessment Type |
|---|---|---|---|
| Level 1 | Federal Contract Information (FCI) | 17 foundational practices | Annual self-assessment |
| Level 2 | Controlled Unclassified Information (CUI) | 110 controls from NIST SP 800-171 | Third-party (C3PAO) assessment every three years, with annual affirmations |
| Level 3 | CUI for high-priority programs | Level 2 controls plus enhanced requirements from NIST SP 800-172 | Government-led assessment |
Who Has to Comply
If your organization holds a DoD contract or subcontract that includes the CMMC clause, compliance is a condition of award, not a recommendation. This applies to primes and subs alike. A prime contractor's certification does not cover its subcontractors. Every organization in the chain that touches FCI or CUI needs its own level of certification. If you're a subcontractor working under a prime, see our breakdown of CMMC services for prime contractors for how that flow-down obligation works in practice.
How CMMC Assessments Work
Level 1 organizations can self-assess and submit the results themselves. Level 2 organizations, in most cases, need a Certified Third-Party Assessment Organization to conduct the assessment and issue certification. That's a formal, CyberAB-authorized process. It's not a checklist you fill out and file.
A C3PAO reviews documented evidence, interviews personnel, and tests whether controls are actually implemented, not just written down. Results are reported to SPRS, where they inform contract award and eligibility decisions.
Compliance vs. Security: Why Meeting Requirements Isn't the Same as Being Secure
Tim Van Name breaks down this exact tension in the clip above. For more conversations like this, subscribe to Sentinel Blue on YouTube.
Here's the part most CMMC guides skip. Passing an assessment tells you controls existed and were documented on the day the assessor showed up. It does not tell you whether your organization is resistant to an actual attack six months later.
You can pass an assessment with real gaps in your security posture, and you can run a genuinely tight security program that still fails on documentation. Compliance and security overlap heavily, but they are not the same discipline, and treating them as interchangeable is where organizations get hurt.
Part of the problem is how compliance work often gets done. A lot of organizations approach it by producing hundreds of rows of a spreadsheet, mapping every control to every piece of evidence, one line at a time. That process is slow, labor-intensive, and it captures a fraction of what actually matters. In many cases, a focused set of well-chosen questions gets you to the same confidence level as that spreadsheet, faster, and leaves you time to spend on the security work that spreadsheet was supposed to represent in the first place.
Why the Gap Between Compliance and Security Exists
The gap isn't an accident. It comes from how the work is usually structured.
- Separate teams, separate incentives. One team builds and runs security. A different team checks whether the paperwork matches. When those two functions never talk to each other, compliance becomes a lagging report on security instead of a driver of it.
- Point-in-time assessment vs. ongoing risk. An assessment is a snapshot. Threats are not. A network that was compliant in January can have new vulnerabilities by March, and the certification won't reflect that.
- Standards move slower than threats. Frameworks get updated on a multi-year cycle. New versions of underlying standards can exist and still not be formally adopted into the certification requirement for years, which means organizations can be certifying against a standard that's already outdated by the time they finish the process. Our breakdown of what's changing under NIST 800-171 Rev 3 covers exactly this lag in more detail.
How to Close the Gap
The organizations that get this right stop treating compliance and security as sequential handoffs. They build them together from day one, so the systems and documentation that make you compliant are the same systems and documentation that make you secure. This is also what's really behind operational decay: environments that were compliant on assessment day slowly drifting out of alignment with actual security practice.
That's the model behind how Sentinel Blue builds CMMC environments, and it's the same approach behind our managed CMMC compliance program:
- Citadel stands up a CMMC Level 2-ready GovCloud environment in Microsoft GCC High, built around Azure infrastructure, access control, and continuous monitoring, not bolted-on documentation after the fact.
- Shield combines the full technology, governance, monitoring, and documentation stack into one integrated environment, purpose-built to get organizations assessment-ready in as little as 90 days.
- Radar, our C3PAO assessment arm, conducts the certification itself, following official CyberAB processes, separate from our managed security work.
The result is an environment where the controls that satisfy an assessor are the same controls actively defending your systems, not two separate efforts pulling in different directions. See how this played out for one client in our Navy contractor case study.
Get to CMMC Compliance Without Losing the Security Thread
Sentinel Blue has supported 20+ successful C3PAO assessments with perfect 110 scores. We know what it takes to build an environment that passes assessment and holds up after it.
Talk to Sentinel BlueWant more conversations like the one above? Subscribe to The Watchers on YouTube.
Frequently Asked Questions
Does CMMC certification mean my company is secure?
No. CMMC certification confirms that specific controls were in place and documented at the time of assessment. It does not guarantee ongoing protection against real-world threats, which requires continuous monitoring and response beyond what any point-in-time assessment can capture.
What is the difference between CMMC Level 1 and Level 2?
CMMC Level 1 covers 17 foundational cyber hygiene practices to protect Federal Contract Information and allows annual self-assessment. CMMC Level 2 requires 110 controls drawn from NIST SP 800-171 to protect Controlled Unclassified Information, and most organizations at this level require a third-party assessment from a C3PAO.
How often do CMMC and NIST standards get updated?
Updates happen on an irregular cycle. NIST has published newer revisions of its standards before the Department of Defense formally adopts them into the CMMC program, which means contractors can be certifying against an older version of a standard for years after a newer one exists.
How do I know if my organization needs CMMC Level 1 or Level 2?
It depends on the type of information you handle. Organizations that only process Federal Contract Information typically need Level 1. Organizations that handle Controlled Unclassified Information typically need Level 2, and the specific requirement is usually stated in the DoD solicitation or contract.