CMMC Compliance for MSPs: 7 Steps + Checklist

CMMC compliance will be mandatory for MSPs and MSSPs working with DoD contracts. Here’s a quick guide and checklist to getting certified before the deadline.

Sep 2, 2026
7 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

If your company serves the US Department of Defense (DoD) or organizations within the Defense Industrial Base (DIB), you’ve probably come across the Cybersecurity Maturity Model Certification (CMMC), commonly referred to as CMMC 2.0.

CMMC is more than the latest compliance buzz. It’s a US government framework designed to strengthen cybersecurity across the defense supply chain and protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

CMMC implementation officially began on November 10, 2025, with Phase I focused primarily on applicable Level 1 and Level 2 self-assessment requirements. However, in July 2026, the DoD suspended the planned transition to Phase II and is conducting a broader 60-day review of the program through mid-September. Phase I requirements remain in effect during the review. 

For MSPs and MSSPs supporting DoD contractors, CMMC is already an important consideration. Your requirements will depend on your role, the information you handle, whether your services fall within a customer’s CMMC assessment scope, and the requirements specified in the applicable contract or subcontract.

How to become CMMC compliant as an MSP

If your organization is looking to navigate the path to CMMC compliance, follow the seven steps outlined below to meet the requirements and secure your place in the US defense supply chain.

1. Determine your required CMMC level and assessment type

Start by reviewing the type of information your organization handles and the CMMC requirements included in your DoD contract or subcontract. 

Organizations handling FCI may be subject to Level 1 requirements, while organizations handling CUI may need Level 2. Depending on the contract, Level 2 may require either a self-assessment or an assessment by a CMMC Third-Party Assessment Organization (C3PAO).

2. Define your CMMC assessment scope

Determine which parts of your environment fall within the CMMC assessment scope. This could include the enterprise, organization, unit, program enclave, systems, personnel, facilities, or external services involved in processing, storing, transmitting, or protecting FCI or CUI. 

MSPs should pay particular attention to the systems and services that support customers’ CUI environments and, where possible, limit the scope to reduce compliance complexity.

Advertisement

3. Build your SSP and assess NIST SP 800-171 requirements

Develop a System Security Plan (SSP) and assess your environment against the security requirements for your CMMC level. For Level 2, this includes the 110 security requirements derived from NIST SP 800-171 Revision 2. 

Use the results to identify where your existing information security processes meet CMMC requirements and where improvements are needed.

4. Remediate gaps and create a POA&M where permitted

Based on the results of your assessment, identify and correct gaps in your information security processes. Where permitted, create a Plan of Action and Milestones (POA&M) identifying outstanding requirements, remediation actions, and target completion dates. Keep in mind that POA&Ms are not permitted for Level 1 and are subject to restrictions and remediation deadlines for Level 2.

A preliminary gap or readiness assessment is optional but may help identify issues before a formal CMMC assessment. Organizations can work with a qualified CMMC consultant, Registered Practitioner Organization (RPO), or C3PAO to evaluate readiness and address identified gaps. However, if a C3PAO provides preparatory, advisory, or consulting services to your organization, that C3PAO cannot participate in your Level 2 certification assessment for three years.

5. Submit self-assessment results and affirm compliance

Organizations required to complete a CMMC self-assessment must submit the applicable assessment information through the DoD’s Supplier Performance Risk System (SPRS). CMMC also requires a senior company official to affirm continuing compliance with the applicable security requirements. Make sure assessment records and affirmations remain up to date as required.

6. Complete a C3PAO assessment if your contract requires one

If your contract requires a Level 2 C3PAO assessment, use the Cyber AB Marketplace to identify an authorized or accredited CMMC Third-Party Assessment Organization (C3PAO) and schedule your assessment.

During the assessment, the C3PAO will review objective evidence to determine whether your organization meets the applicable CMMC requirements. This can include reviewing documentation and artifacts, interviewing personnel, and testing or examining security practices. Any eligible deficiencies may need to be addressed through the CMMC POA&M process before final status can be achieved.

Advertisement

7. Maintain your CMMC status and annual affirmations

After successfully completing the assessment process for your organization, make sure you maintain the CMMC status required by your contract. 

CMMC is not a one-time compliance exercise: organizations must continue to meet applicable security requirements, complete required affirmations, maintain supporting documentation, and undergo reassessment when required.

For organizations completing a Level 2 C3PAO assessment, successful completion results in a Certificate of CMMC Status that is generally valid for three years, subject to continuing compliance and annual affirmation requirements.

Levels of CMMC compliance

Keep in mind that CMMC has three levels, with the required level specified by the applicable DoD solicitation or contract based on the information systems and information involved:

  • Level 1 – Foundational: Applies to organizations that handle Federal Contract Information (FCI) and includes the 15 basic safeguarding requirements specified in FAR 52.204-21. Level 1 requires an annual self-assessment and annual affirmation of compliance.
  • Level 2 – Advanced: Applies to organizations that handle Controlled Unclassified Information (CUI) and incorporates the 110 security requirements from NIST SP 800-171 Revision 2. Depending on the applicable contract, organizations may be required to complete either a Level 2 self-assessment every three years or a Level 2 certification assessment conducted by an authorized or accredited C3PAO. Annual affirmations are also required.
  • Level 3 – Expert: Applies to organizations supporting DoD critical programs and high-value assets and builds upon Level 2 with 24 selected security requirements from the February 2021 version of NIST SP 800-172. Level 3 requires a government-led assessment by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) every three years, along with annual affirmations.

Although NIST SP 800-171 Revision 2 has been superseded by Revision 3 outside of CMMC, the current CMMC Level 2 requirements remain based on the 110 security requirements in Revision 2.

CMMC compliance checklist

This CMMC compliance checklist for MSPs covers 11 areas: determining your level, assigning ownership, limiting scope, documenting external providers, restricting CUI access, selecting compliant technology, building the SSP, managing POA&Ms, conducting assessments, remediating gaps, and completing required reporting.

Bottom line: Is CMMC compliance worth it for MSPs?

For MSPs seeking CMMC compliance, there’s a great deal to consider. Taking a proactive approach, understanding the specific requirements and scope involved, and investing in the necessary resources are all crucial areas your organization needs to address.

You also need to consider that the time and costs involved can vary considerably based on factors such as your required CMMC level and assessment type, organization size, assessment scope, existing cybersecurity posture, and the amount of remediation needed.

Advertisement

That said, investing in the compliance process can help your MSP remain eligible for applicable DoD contracting opportunities while strengthening its cybersecurity posture and reputation as a trusted partner in an increasingly regulated landscape.

Frequently asked questions (FAQs)

CMMC compliance is not necessarily a one-and-done process. Organizations subject to the program may need to maintain their required CMMC status, complete annual affirmations, and undergo future assessments depending on their required level and assessment type.

Here are some frequently asked questions about CMMC:

What is Cybersecurity Maturity Model Certification (CMMC)?

The Cybersecurity Maturity Model Certification (CMMC) is a DoD program designed to strengthen cybersecurity across the Defense Industrial Base (DIB) and help protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

CMMC builds on existing federal cybersecurity requirements and organizes them into three levels. Depending on the requirements specified in a DoD solicitation or contract, an organization may need to complete a self-assessment, a C3PAO assessment, or a government-led assessment.

Does an MSP need its own CMMC certification?

CMMC can apply to DoD contractors and subcontractors whose information systems process, store, or transmit FCI or CUI as part of contract performance. 

The required CMMC level and assessment type are determined by the applicable solicitation, contract, or subcontract. Requirements can also flow down the defense supply chain when FCI or CUI is shared with subcontractors and suppliers.

For MSPs and MSSPs, supporting a DoD contractor does not automatically mean the provider needs its own CMMC certification. 

MSPs should instead determine whether their services involve FCI or CUI, whether their systems fall within a customer’s CMMC assessment scope, and what requirements apply through the relevant contract or subcontract.

Advertisement

How much does CMMC compliance cost?

CMMC compliance costs vary considerably depending on your required level, assessment type, organization size, existing security posture, and remediation needs. According to PreVeil’s June 2026 analysis of DoD estimates and other compliance costs, organizations should consider the following ranges:

  • CMMC Level 1: Approximately $5,000-$15,000 for most small businesses completing the required self-assessment and implementing basic security controls.
  • CMMC Level 2: Approximately $75,000-$300,000+ when accounting for costs such as security tools, consulting, remediation, and a third-party assessment where required.
  • CMMC Level 3: Often $500,000+ due to the advanced security controls and infrastructure that may be required.

These ranges are estimates rather than fixed CMMC fees, and actual costs can vary significantly depending on an organization’s existing security environment and the work needed to meet the applicable requirements. 

Organizations should also account for ongoing expenses such as security tools and services, employee training, continuous monitoring, annual affirmations, and future reassessments.

How long does it take to become CMMC compliant?

There is no standard timeline for becoming CMMC compliant. How long the preparation takes will depend on factors such as your current cybersecurity posture, the required CMMC level and assessment type, assessment scope, documentation readiness, and the number and severity of security gaps to be addressed.

The current CMMC rollout also adds some uncertainty to planning. The DoD suspended the planned transition to Phase II in July 2026 and will conduct a broader 60-day review of the program until mid-September.

This article was originally written by Pamela Winikoff and published in February 2024. It was updated by Luis Millares in 2026 for freshness and accuracy.

Pamela Winikoff

Pamela Winikoff is an award-winning corporate communications and writing professional with extensive experience creating marketing, publicity, thought leadership, and other content that enhances public perception and accelerates business growth. She has also ghostwritten hundreds of articles for subject matter experts across numerous industries.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.