Federal Contractor Readiness Guide

How to Prepare for CMMC

Prepare for Cybersecurity Maturity Model Certification (CMMC) by scoping environments handling Federal Contract Information or Controlled Unclassified Information and aligning controls before reporting in SPRS when required.

Cybersecurity & Compliance

What it is

CMMC is the DoD framework for assessing contractor implementation of cybersecurity practices. Level 1 self-assessments and higher-level assessments are documented and, where required, reported through SPRS.

Who needs it

Defense contractors whose solicitations or contracts include CMMC or DFARS 252.204-7012/7019/7020 cybersecurity clauses.

Prerequisites

  • Inventory of systems that store or process FCI or CUI
  • NIST SP 800-171 or CMMC Level 1 practices implemented as required by contract
  • PIEE SPRS access for reporting when clauses require SPRS entry

Step-by-step process

  1. 1. Determine required CMMC level from contract documents

    Read solicitation and contract clauses to identify the required CMMC level and assessment type (self-assessment, C3PAO, etc.) using official DoD CMMC guidance.

    Official reference: https://dodcio.defense.gov/CMMC/

  2. 2. Scope systems and build a System Security Plan

    Document in-scope systems, boundaries, and control implementation consistent with NIST SP 800-171 or CMMC Level 1 practices as applicable.

    Official reference: https://www.nist.gov/publications/protecting-controlled-unclassified-information-nonfederal-systems-and-organizations

  3. 3. Perform required self-assessment or engage assessors

    Complete the assessment type specified in your contract. Higher levels may require certified third-party assessment organizations when rulemaking requires them.

    Official reference: https://dodcio.defense.gov/CMMC/

  4. 4. Report CMMC status in SPRS when directed

    Use PIEE → SPRS → Cyber Reports to enter Level 1 self-assessments or other CMMC data per the SPRS CMMC quick entry guide.

    Official reference: https://www.sprs.csd.disa.mil/

Information and documents you need

  • CMMC level required by contract
  • SSP and assessment artifacts
  • CAGE codes in SAM hierarchy
  • System Security Plan
  • Assessment evidence retained per DoD instructions

Cost

Government reporting through SPRS has no vendor fee described in SPRS materials; third-party assessment costs depend on assessor arrangements and are not set by a single federal fee schedule.

Typical processing time

Processing time varies; the official source does not publish a guaranteed completion timeframe.

Common mistakes

  • Assuming SPRS entry replaces control implementation
  • Mixing corporate IT with in-scope CUI environments without boundaries
  • Missing annual affirmation requirements for Level 1 self-assessments in SPRS

What happens after approval / completion

Maintain controls, refresh assessments before expiration, and update SPRS so contracting officers see current CMMC status during awards.

Official sources

Related acronyms

Related guides

Related federal market intelligence

Last reviewed / updated: September 20, 2026