CMMC Level 2 · for contractors who handle CUI

Handle CUI? Here's how to become CMMC certified — the whole path, and where you stand.

The DoD now requires contractors who handle CUI to prove they protect it. It's confusing, the clock is running — and almost nobody's done: only about 1 in 100 feel ready. So you're not behind. Here's the entire path in plain English, and a free scorecard that shows where you stand today, no commitment.

That's the whole path. Not sure where you are on it? The free scan drops a pin in an afternoon.

What is CMMC, and why now?

CMMC — Cybersecurity Maturity Model Certification — is how the Department of Defense confirms its contractors actually protect the sensitive information they handle. If your company touches Controlled Unclassified Information (CUI) — the contract details, specs, and drawings the government marks as sensitive-but-unclassified — DFARS 252.204-7012 already requires you to safeguard it by meeting the 110 security requirements of NIST SP 800-171.

Here is the part that carries teeth today: you self-assess against those 110, post a score to the DoD’s SPRS system, and a senior official personally affirms it. That affirmation is a signature to the federal government — and a score you cannot back up is False Claims Act exposure, not just a failed audit.

The reassuring part: almost nobody is finished. Roughly 99% of the contractors who need it are not there yet — most are working through it right now, same as you.

Which level do you need?

There are three, and most companies that handle CUI land on Level 2.

Not sure which applies? It comes down to one question: does the information in your contracts get marked as CUI? If yes, plan for Level 2.

Read this before you sign

You don’t just post your score — you sign it. And the False Claims Act is what you sign under.

Notice the word affirm back there. When you post your SPRS score, a senior official signs their name to it. To the government, that signature isn’t a formality — it’s a promise that the number is true.

If it isn’t — if a control is marked met that isn’t, and you knew, or looked the other way, or never actually checked — that’s not a paperwork slip. Under the False Claims Act, an inflated score tied to a federal contract can become a false claim. What that carries is steep:

None of this is hypothetical — a single cyber-fraud settlement has already reached $11.25 million. And the pause on third-party assessments doesn’t lower this risk. It raises it: with no assessor checking your work first, nobody catches an inflated score until the government does.

This is the whole reason ForteFide is built the way it is. It can’t make the False Claims Act go away — nothing can, and anyone who tells you otherwise is selling you a new problem. What it does is let you sign a number you can prove: all 110 controls checked against your real systems, with signed, tamper-evident evidence you can put in front of a skeptical reviewer, one control at a time. The honest score — and the receipts to back it.

General information, not legal advice — for how the False Claims Act applies to you, talk to qualified counsel. Sources: False Claims Act, 31 U.S.C. §§ 3729–3733; DFARS 252.204-7012; 32 CFR 170.24.

What does Level 2 actually require?

110 practices, across 14 families. In plain English, they ask you to have control over:

None of it is exotic. Most of it is good IT hygiene, written down and proven.

The steps — and why each one exists

  1. Scope it. Find exactly where CUI lives and flows. Why: you only have to protect what is in scope — getting this right shrinks the whole job.
  2. Write the SSP and POA&M. A System Security Plan documents how each of the 110 is met; a Plan of Action & Milestones lists the gaps and how you will close them. Why: the SSP is the basis of your score — no security plan, no complete assessment.
  3. Score yourself and submit (SPRS). Assess against the 110 and post the resulting score to the DoD’s SPRS system. Why: the DoD requires a current score on file — and it has to be one the SSP substantiates.
  4. Secure the gaps. Actually implement the missing controls — the technical settings and the policies. Why: a plan is not security; the score has to reflect the real system.
  5. Affirm it. A senior official affirms the SPRS score to the government. Why: that affirmation is a signature under False Claims Act liability — a false or inflated score is treble-damages territory, so the number has to be one you can prove.
  6. Reach the bar. Score at least 88 of 110 with only certain gaps remaining for a conditional status, with 180 days to close them; miss one of the critical controls and there is no shortcut. Re-assess as your systems change so the score on file stays true.

How hard is this, honestly?

We won’t pretend it’s a weekend. The real picture:

The honest summary: it’s real, it’s finite, and the earlier you see your actual gaps, the smaller the surprise.

Where DenseDefense comes in

This is the part we made easy. Start by seeing exactly where you stand — for free, no sales call.

You don't have to commit to anything to find out where you are. See your starting line, then decide.