CMMC readiness you can prove.
CMMC turns 800-171 from a self-attestation into a verified requirement for defense contracts. TruOps helps you know your score, close your gaps, and show your evidence.
Mappings are typed exact, partial, or inferred, each with a citation.
The Cybersecurity Maturity Model Certification (CMMC) 2.0 is the U.S. Department of Defense program that verifies contractors protect Federal Contract Information and Controlled Unclassified Information. It has three levels: Level 1 (15 basic requirements, annual self-assessment), Level 2 (the 110 requirements of NIST SP 800-171 Rev. 2, self-assessed or certified by a C3PAO), and Level 3 (Level 2 plus selected SP 800-172 requirements, assessed by the government).
- A solicitation now states a CMMC level and you cannot show evidence per requirement
- You have an SPRS score and no POA&M that would survive a C3PAO
- You need to flow requirements to subcontractors
- Program owner
- U.S. Department of Defense
- Level 1
- 15 requirements · annual self-assessment
- Level 2
- 110 requirements (800-171 Rev. 2) · self or C3PAO
- Level 3
- Level 2 + SP 800-172 · government assessment
The three levels
| Level | Protects | Requirements | Assessment |
|---|---|---|---|
| Level 1 | Federal Contract Information | 15, from FAR 52.204-21 | Annual self-assessment |
| Level 2 | Controlled Unclassified Information | 110, from NIST SP 800-171 Rev. 2 | Self-assessment or C3PAO certification, every 3 years |
| Level 3 | CUI in high-priority programs | Level 2 plus selected SP 800-172 requirements | Government assessment (DIBCAC) |
The actual challenge
CMMC turns 800-171 from a self-attestation into a verified contract condition. Assessors will ask for objective evidence for each requirement, not a narrative.
- Level 2 is 110 requirements; "we have a policy" is not evidence.
- Limited POA&Ms have a 180-day clock.
- The CUI boundary is unclear, so the scope of the assessment keeps moving.
Bring one real document. Watch the program get set up from it.
What you are probably using today
Almost nobody starts CMMC 2.0 from zero. You already have a program somewhere. TruOps is built to take that over, not make you start again.
| What you use now | Where it breaks | With TruOps |
|---|---|---|
| Spreadsheets, shared drives, and email | The program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter. | Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period. |
| SOC 2 automation tools | They are strong at certification: automated tests, a broad framework library, and often a trust center. Maturity scoring, custom frameworks, and deep risk or vendor work can sit outside that model. | Keep the automation. Run any framework as the anchor, map the rest with partials shown as partial, and run vendor and risk on the same engine. Upload the policies and reports you already have. |
| Enterprise GRC suites | They can model almost anything. That flexibility usually comes through implementation partners and administrators, so a change can become a project. | AI reads your existing documents and sets up the program. The first assessment opens pre-filled from them, with sources. Changes are a request in plain language, not a project. |
Timeline
The CMMC program rule (32 CFR Part 170) took effect in December 2024, and the DFARS rule that places CMMC requirements into contracts began a phased rollout on 10 November 2025 (Phase 1: Level 1 and Level 2 self-assessments with annual SPRS affirmations). On 13 July 2026 the Department paused the move to Phase 2, which would have made C3PAO certification a standard Level 2 contract requirement from 10 November 2026, pending a program review. As of September 2026, third-party assessment requirements remain suspended and self-assessment is the primary path. The pause changed who verifies the work, not the work: DFARS 252.204-7012 and the 110 requirements of NIST SP 800-171 still apply. Limited plans of action and milestones are allowed at Levels 2 and 3, with items to be closed within 180 days. Check each solicitation for the level it requires.
How TruOps helps with CMMC
Pick CMMC as your anchor, or map it to the framework you already run. TruOps keeps CMMC's own structure, down to the individual requirement, and shows coverage per requirement as satisfied, partial, or open, with the evidence behind each.
Upload what you have (prior reports, policies, spreadsheets) and TruOps pre-fills your CMMC assessment with cited answers. Connected tools keep technical controls current on the schedule you set, and failed checks become findings with a recommended fix.
TruOps runs Level 1 and Level 2 assessments on the same engine as the rest of your program, so your CMMC evidence also counts toward NIST SP 800-171 and 800-53 work.
If this is your situation
Bring your 800-171 self-assessment and system inventory. TruOps prepares Level 1 and Level 2 on the same engine; a C3PAO still issues the certification.
How TruOps helps
- Anchor or map
- Run CMMC as your spine or map it to another framework; work counts once.
- Pre-filled assessment
- Your CMMC assessment opens with the answers your evidence supports already filled, each cited.
- Honest coverage
- Partial coverage is reported as partial, with the remaining requirements listed.
- Continuous monitoring
- Technical controls checked against your tools hourly to quarterly.
- Findings with fixes
- Failed checks become grouped findings with a recommended action.
- Audit-ready snapshots
- Results saved as of their date, with the evidence trail attached.
Questions
What are the CMMC 2.0 levels?
Level 1 (Foundational, 15 requirements), Level 2 (Advanced, the 110 requirements of NIST SP 800-171 Rev. 2), and Level 3 (Expert, Level 2 plus selected NIST SP 800-172 requirements).
When does CMMC apply?
Phase 1 of the DFARS rollout began on 10 November 2025 with self-assessments and SPRS affirmations. The planned November 2026 move to Phase 2 (C3PAO certification) was paused on 13 July 2026 pending a program review; the underlying NIST SP 800-171 requirements still apply. Contracts state the level required; check each solicitation.
Does the Phase 2 pause mean we can wait?
No. The pause affects who verifies, not what is required. Self-assessments must still be supportable requirement by requirement, a senior official still affirms them, and a C3PAO requirement can return when the review concludes. A program built on cited evidence is ready for either path.
Can TruOps certify me for CMMC?
No. Level 2 certification is performed by an authorized C3PAO and Level 3 by the government. TruOps prepares you and organizes your evidence.
Are POA&Ms allowed under CMMC?
Limited POA&Ms are allowed at Levels 2 and 3 for certain requirements, and must be closed out within 180 days.
Do we have to rip out the tools we already use?
No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.
Can we bring our existing assessments, control lists, and vendor files?
Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.
Does TruOps replace our auditor, QSA, or certification body?
No. Only a licensed auditor, QSA, C3PAO, or accredited certification body can issue the opinion. TruOps gets the evidence current, cited, and dated so fieldwork is a review, not an archaeology project.
Related
Know your score, close your gaps, show your evidence.
→FrameworksNIST SP 800-171Protecting Controlled Unclassified Information in nonfederal systems.
→LearnPOA&MPlans of action and milestones, explained.
→IndustriesGovernment contractorsCMMC, NIST SP 800-171, and SPRS, with evidence assessors accept.
→See it run on your own data.
Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.