Federal Contractor Readiness Guide
How to Prepare for CMMC
Prepare for Cybersecurity Maturity Model Certification (CMMC) by scoping environments handling Federal Contract Information or Controlled Unclassified Information and aligning controls before reporting in SPRS when required.
What it is
CMMC is the DoD framework for assessing contractor implementation of cybersecurity practices. Level 1 self-assessments and higher-level assessments are documented and, where required, reported through SPRS.
Who needs it
Defense contractors whose solicitations or contracts include CMMC or DFARS 252.204-7012/7019/7020 cybersecurity clauses.
Prerequisites
- Inventory of systems that store or process FCI or CUI
- NIST SP 800-171 or CMMC Level 1 practices implemented as required by contract
- PIEE SPRS access for reporting when clauses require SPRS entry
Step-by-step process
- 1. Determine required CMMC level from contract documents
Read solicitation and contract clauses to identify the required CMMC level and assessment type (self-assessment, C3PAO, etc.) using official DoD CMMC guidance.
- 2. Scope systems and build a System Security Plan
Document in-scope systems, boundaries, and control implementation consistent with NIST SP 800-171 or CMMC Level 1 practices as applicable.
- 3. Perform required self-assessment or engage assessors
Complete the assessment type specified in your contract. Higher levels may require certified third-party assessment organizations when rulemaking requires them.
- 4. Report CMMC status in SPRS when directed
Use PIEE → SPRS → Cyber Reports to enter Level 1 self-assessments or other CMMC data per the SPRS CMMC quick entry guide.
Information and documents you need
- CMMC level required by contract
- SSP and assessment artifacts
- CAGE codes in SAM hierarchy
- System Security Plan
- Assessment evidence retained per DoD instructions
Cost
Government reporting through SPRS has no vendor fee described in SPRS materials; third-party assessment costs depend on assessor arrangements and are not set by a single federal fee schedule.
Typical processing time
Processing time varies; the official source does not publish a guaranteed completion timeframe.
Common mistakes
- Assuming SPRS entry replaces control implementation
- Mixing corporate IT with in-scope CUI environments without boundaries
- Missing annual affirmation requirements for Level 1 self-assessments in SPRS
What happens after approval / completion
Maintain controls, refresh assessments before expiration, and update SPRS so contracting officers see current CMMC status during awards.
Official sources
- DoD CIO — CMMC (primary)
- SPRS (supporting)