Principle Security Principle Security.

Defense supply chain

Which CMMC 2.0 level do you need?

For manufacturers and suppliers in the defense supply chain: a quick read on which CMMC 2.0 level you likely need and how far your current controls are from it. Directional — your contracts and CUI flow-down govern.

6 questions ~2 minutes No signup Runs in your browser

CMMC cost is won or lost in scoping. This gives you a fast read on your likely level and the size of the gap before an assessor sets it for you.

1
Do your DoD contracts (or flow-downs from primes) involve FCI or CUI?
2
Have you scoped where FCI/CUI actually lives in your systems?
3
Have you assessed against the 110 NIST 800-171 controls?
4
Is the environment handling CUI separated from your general/office IT?
5
Do you have a current SPRS score submitted?
6
Do you have security expertise (internal or external) driving this?

Why this matters

Scope decides the cost — before a single control does

The biggest lever in CMMC isn't which tools you buy; it's how much of your environment is in scope. A tightly scoped enclave that isolates CUI can shrink a Level 2 assessment from your whole company to a handful of systems, cutting cost and timeline dramatically. Get scoping wrong and everything is in scope. That's why the first work is always defining where FCI and CUI live, not buying software.

110
NIST 800-171 controls behind CMMC Level 2
Level 2 maps to NIST SP 800-171; Level 1 is a lighter FCI-only tier.

How this is scored

Six weighted questions on the factors that set your CMMC level and effort: whether you handle FCI or CUI, whether you've scoped where it lives, your NIST 800-171 assessment status, environment separation, SPRS submission, and dedicated expertise. Each scores 0–3; the total maps to a readiness band. This is directional — your contract flow-downs and a certified assessor govern the real requirement.

Questions

How do I know if I handle CUI or just FCI?

Check your contract flow-downs (DFARS 252.204-7012 points to CUI). FCI is federal contract information generated or received under a contract; CUI is controlled unclassified information with specific handling rules. CUI generally means Level 2; FCI-only generally means Level 1.

What is an enclave and why does it matter?

An enclave is a separated environment where CUI is stored and processed, isolated from your general/office IT. It dramatically reduces CMMC scope — often the single biggest cost saver — because only the enclave, not your whole company, is assessed.

What's an SPRS score?

A self-assessment score against NIST 800-171, submitted to the DoD Supplier Performance Risk System. A current SPRS score is effectively table stakes for contracts involving CUI.

Facing a CMMC requirement?

We scope where CUI lives, run the NIST 800-171 gap assessment, and build the SSP and POA&M an assessor will ask for.