For years, the Department of Defense (DoD) operated on a “trust but verify” model: though, in practice, there was a lot more trusting than verifying. Contractors were expected to follow cybersecurity best practices, often self-attesting that their systems were secure.
Those days are over.
The Cybersecurity Maturity Model Certification (CMMC) represents a seismic shift in how the DoD handles the Defense Industrial Base (DIB). If you want to keep your contracts: or bid on new ones: understanding CMMC isn’t just a technical hurdle; it’s a business necessity.
At Lunarline, a wholly owned subsidiary of Motorola Solutions and a listed C3PAO, we see the confusion this framework causes every day. This guide is your “Level 0” starting point to understand what CMMC is, why it exists, and how it impacts your bottom line.
What exactly is CMMC?
At its core, CMMC is a unified standard for implementing cybersecurity across the defense industrial base. It’s designed to protect two specific types of data:
- Federal Contract Information (FCI): Information provided by or generated for the government under a contract that is not intended for public release.
- Controlled Unclassified Information (CUI): Information the government creates or possesses, or that an entity creates or possesses for or on behalf of the government, that requires safeguarding or dissemination controls.
CMMC isn’t a new set of rules created out of thin air. It primarily maps back to NIST SP 800-171, a document that has been around for years. The difference now is that “saying” you do it is no longer enough. You have to prove it.
The Legal Foundation: Why Now?
You might be wondering why the DoD suddenly decided to get strict. The answer lies in the massive amounts of intellectual property and sensitive data being exfiltrated by adversaries.
The legal teeth behind CMMC come from the Defense Federal Acquisition Regulation Supplement (DFARS). Specifically, DFARS 252.204-7012 has long required contractors to provide “adequate security” for CUI. However, compliance was inconsistent.
CMMC 2.0 was introduced to:
- Streamline the requirements.
- Increase accountability through third-party assessments.
- Ensure that every link in the supply chain: from the massive prime contractors to the smallest “mom and pop” machine shops: is secure.

The Three Levels of CMMC 2.0
CMMC 2.0 simplified the previous version into three tiers. Most companies will fall into Level 1 or Level 2.
Level 1: Foundational
This level is for companies that only handle Federal Contract Information (FCI). It consists of 15 basic safeguarding requirements found in FAR 52.204-21.
- Assessment: Annual self-assessment and an annual affirmation from a senior company official.
Level 2: Advanced
If you handle Controlled Unclassified Information (CUI), you will likely need to meet Level 2. This level aligns exactly with the 110 security constants in NIST SP 800-171.
- Assessment: This is the critical shift. For most contracts involving CUI, you cannot “grade your own homework.” You will need a C3PAO (Certified Third-Party Assessment Organization) like Lunarline to conduct an independent audit every three years.
Level 3: Expert
This is reserved for the highest-priority programs. It involves more than 110 practices based on NIST SP 800-171 and a subset of NIST SP 800-172.
- Assessment: Government-led assessments (typically by the DIBCAC) every three years.
Why Your Contract Depends on It
The “Certification” part of CMMC is the ultimate gatekeeper. In the very near future, you will see a CMMC requirement listed in Department of Defense RFPs (Requests for Proposals).
If the RFP requires CMMC Level 2 and you haven’t achieved that certification, you are ineligible for the award. It’s that simple. There are no “points for effort.” You either have the certification, or you don’t.
Furthermore, these requirements “flow down.” If a prime contractor is bidding on a project that requires Level 2, they cannot hire subcontractors who do not meet the necessary CMMC level. This means even if you don’t deal with the DoD directly, your partners will soon be asking for your certification status.
The Role of a C3PAO
A C3PAO: like Lunarline: is an organization authorized by the Cyber AB (The CMMC Accreditation Body) to conduct CMMC assessments.
Because we are a subsidiary of Motorola Solutions, we bring a unique perspective of global security standards to the C3PAO process. Our job is to verify that your System Security Plan (SSP) isn’t just a document in a drawer, but a lived reality within your IT environment.
When we step in for a Level 2 assessment, we are looking for evidence. We want to see that your multi-factor authentication is active, your logs are being reviewed, and your employees are trained. We are the bridge between your current security posture and your ability to win government work.
5 Steps to Start Your CMMC Journey
Don’t wait for a “deadline” to start. CMMC compliance can take months (sometimes over a year) to achieve if you are starting from scratch. Here is how to begin:
- Identify Your Data: Do you handle CUI or just FCI? Look at your current contracts and talk to your contracting officers. If you don’t know what data you have, you can’t protect it.
- Read NIST SP 800-171: This is your roadmap. Familiarize yourself with the 110 controls. This is the “test” you will eventually be taking.
- Perform a Gap Analysis: Compare your current environment to the NIST standards. Where are you failing? Do you lack encrypted email? Is your physical security lacking? Identify the holes now.
- Score Yourself in SPRS: The DoD currently requires contractors to upload their self-assessment score into the Supplier Performance Risk System (SPRS). If you haven’t done this, you are already behind on current DFARS requirements.
- Build Your System Security Plan (SSP): This is the most important document in your compliance journey. It describes how you meet every single control. If it isn’t in the SSP, for the purposes of an audit, it doesn’t exist.

The Bottom Line: Compliance is Competitive Advantage
It’s easy to look at CMMC as another layer of “government red tape.” However, the companies that embrace it early are finding a significant competitive advantage.
As the DoD narrows the pool of “safe” contractors, those with a Level 2 certification from a C3PAO will be the first in line for major awards. They are seen as lower risk and higher value.
At Lunarline, we believe that security shouldn’t be a barrier to doing business: it should be the foundation of it. By securing the Defense Industrial Base, we aren’t just checking boxes; we are protecting the men and women in uniform and the technology that keeps them safe.
Ready to Learn More?
CMMC is a marathon, not a sprint. Whether you are a small business trying to navigate Level 1 or a mid-tier contractor preparing for a Level 2 assessment with a C3PAO, the time to act is now.
Understanding the laws, the standards, and the assessment process is your first step toward long-term success in the federal marketplace.
For more information on CMMC assessments and readiness, visit the CyberAB marketplace to find authorized C3PAOs like Lunarline.