You need CMMC. Here's what that actually means.
If you do business with the U.S. Department of Defense and your contract has been updated to require CMMC, you have a deadline and a real risk of losing the work. This page explains, in plain English, what CMMC is, whether you need it, how long it takes, and what it costs.
If your contract has a DFARS 7012 clause and you handle CUI, yes.
- You handle CUI. If you've received any defense data the government has marked or treated as controlled (drawings, specs, plans, controlled research), you need Level 2.
- Your contract has a DFARS 252.204-7012 or 7021 clause. These are the clauses that trigger the CMMC obligation. Check any recent contract modification or new RFP.
- You only handle FCI, not CUI. Federal Contract Information without CUI = Level 1, which is a self-assessment. Easier path, but still mandatory. Level 1 with Garde1 is $150 a month →
If you don't get certified, you lose the work.
CMMC isn't a "nice to have." When a contract requires it, missing the deadline has direct, contractual consequences:
- Existing contracts at risk. If your contract was modified to require CMMC and you can't prove it, you may be in breach.
- Ineligible for new awards. You can't bid on DoD work that requires CMMC, and primes are already asking suppliers for their status.
- False Claims Act exposure. If you ever affirmed compliance you didn't have, that can carry penalties separate from the contract itself.
CMMC is the DoD's required security standard for anyone handling sensitive defense data.
CMMC stands for Cybersecurity Maturity Model Certification. It is the security framework the U.S. Department of Defense requires every contractor and subcontractor to be certified against if they handle Controlled Unclassified Information (CUI) — things like technical drawings, manufacturing specs, or controlled research that isn't classified but isn't public either.
CMMC has three levels. Level 1 is for companies that only handle Federal Contract Information (the day-to-day stuff, like procurement records). Level 2 — built on the 110 security requirements in NIST SP 800-171 — is what most defense contractors handling CUI need. Level 3 is reserved for the most sensitive programs.
Level 1 and Level 2 (Self) are self-assessments you post in SPRS. Level 2 (C3PAO) is run by an accredited firm called a C3PAO (Certified Third-Party Assessment Organization), which issues the certificate. While Phase 2 is suspended, new contracts can require only Level 1 or Level 2 (Self). Garde1 is not a C3PAO — we're the platform that gets you ready for one.
See it on your own environment. 30 minutes, no slides.
Bring a contract with the clause in it. We show you your gaps and a real timeline, or start a 14-day trial and see for yourself.
Common questions, direct answers.
What is CMMC?+
CMMC stands for Cybersecurity Maturity Model Certification. It is the U.S. Department of Defense's required security standard for any company that handles Controlled Unclassified Information (CUI) on behalf of the DoD. There are three levels. Most contractors that handle CUI need Level 2; companies with only FCI need Level 1.
Do I actually need CMMC?+
If you handle CUI, DFARS 252.204-7012 already requires the 110 NIST SP 800-171 requirements and a current SPRS score. DFARS 252.204-7021 adds a CMMC status as a condition of award; while Phase 2 is suspended, new contracts may require only Level 1 or Level 2 (Self). Companies that handle only FCI (Federal Contract Information) need Level 1.
What happens if I don't get certified?+
You lose the ability to hold or bid on DoD contracts that require CMMC. You may be in breach of existing contracts that have already been updated with the new clauses. There is also potential exposure under the False Claims Act if you affirmed compliance you did not have.
How long does CMMC certification take?+
It depends on your gaps. Garde1 shows you exactly where you stand in your first week, and the rest is fixing what it finds, much of which Garde1 can apply for you. The traditional consultant path typically runs 6–18 months because of manual evidence collection, document drafting, and back-and-forth with the assessor.
What does CMMC cost?+
Garde1 starts at $1,999 a month. The traditional route to Level 2 typically runs $50K–$200K all in. A C3PAO assessment, when required, is a separate cost set by the assessor; the DoD estimates $101,752 for a small business.
Is Garde1 a C3PAO?+
No. Garde1 prepares you for assessment and runs a mock assessment so you know where you stand. The official certification is issued by a separate, accredited C3PAO — Garde1 does not issue certifications.