What Is CMMC 2.0?
The Cybersecurity Maturity Model Certification (CMMC) is a Department of Defense program requiring contractors and subcontractors in the Defense Industrial Base (DIB) to demonstrate cybersecurity compliance before receiving contracts involving Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). CMMC 2.0, which took effect in late 2024, defines three levels of certification:
- Level 1 (Foundational): 17 basic practices protecting FCI. Annual self-assessment. No penetration testing required.
- Level 2 (Advanced): 110 practices from NIST SP 800-171 for CUI. Third-party assessment every three years, annual self-affirmation. Penetration testing not explicitly required but often identified as a practice to implement.
- Level 3 (Expert): 110+ practices from NIST SP 800-172 for the most sensitive CUI. Government-led assessments. Penetration-type testing is effectively required through the comprehensive control set.
The October 2026 Deadline
Full CMMC 2.0 implementation takes effect for DoD contracts in October 2026. From that point, contractors must demonstrate the appropriate certification level before contract award. Contracts already in place will require compliance on a rolling basis as they renew. Organizations that have not begun their compliance journey face real risk of being locked out of DoD contracting.
How Penetration Testing Applies to CMMC
For Level 2, NIST SP 800-171 includes control CA-8, which requires penetration testing be conducted periodically and upon significant changes. While Level 2 assessments focus primarily on documentation and implementation evidence, CMMC assessors are trained to verify that security controls actually work, not just that policies exist on paper. Network penetration testing provides the most defensible evidence that access controls, segmentation, and detection capabilities are functioning as claimed.
For Level 3, the comprehensive NIST SP 800-172 control set includes more advanced requirements around adversary simulation, red team exercises, and continuous monitoring that effectively require penetration-type assessments.
The Flow-Down Problem
CMMC requirements flow down the supply chain. If a prime contractor is subject to CMMC Level 2, any subcontractor that handles CUI on their behalf is also subject to Level 2. Many small and mid-size defense suppliers are discovering that their prime contractor relationships require CMMC compliance they did not anticipate. This is driving significant demand for independent security testing among companies that have never conducted formal pentesting before.
CMMC 2.0 Levels at a Glance
| Level | Basis | Assessment | Testing |
|---|---|---|---|
| Level 1 | 17 practices (FCI) | Annual self-assessment | Not required |
| Level 2 | 110 practices (NIST 800-171) | Third-party (C3PAO), typically every 3 years | CA-8 periodic testing |
| Level 3 | NIST 800-172 controls (CUI) | Government-led (DIBCAC) | Adversary simulation |
How to Prepare Before Your Assessment
The contractors who pass cleanly treat the formal assessment as the finish line, not the starting point. Begin with a gap assessment against NIST SP 800-171, record honest scores and a plan of action and milestones for anything not yet met, then use penetration testing to prove that access controls, segmentation, and monitoring actually work rather than merely existing in policy. That evidence is exactly what a CMMC assessor is trained to verify. See our guide to preparing for a compliance penetration test for the practical steps.
Frequently Asked Questions
Does CMMC require penetration testing?
CMMC does not name penetration testing as a standalone control, but Level 2 and Level 3 build on NIST SP 800-171 and 800-172, whose security assessment and continuous monitoring requirements are best satisfied with periodic penetration testing. Most defense contractors test annually to demonstrate their controls work in practice.
What is the CMMC deadline defense contractors need to plan for?
CMMC requirements are phasing into Department of Defense contracts, with Level 2 assessment obligations reaching many contractors through 2026. Organizations that handle Controlled Unclassified Information should validate their controls now, because remediation and a formal assessment both take time.
What is the CMMC flow-down problem?
Prime contractors must ensure subcontractors that handle Controlled Unclassified Information meet the same CMMC level. That flow-down means a small subcontractor can hold up a prime's award. Testing and documenting your controls early keeps you eligible for defense work rather than a compliance risk to your primes.
Working toward CMMC compliance?
Grid32 provides network and application penetration testing that supports CMMC Level 2 and Level 3 evidence requirements. Don't wait until 2026.
Get a Quote →