Cybersecurity Maturity Model Certification Services (CMMC)

Deliver sound risk management practices, internal control systems and compliance frameworks.
The CyberAB - CyberAB Third-Party Assessment Organization (C3PAO) - 2025-01-31

Schneider Downs is an authorized C3PAO qualified to assess and certify CMMC certification for organizations conducting business with the Department of Defense’s (DoD) program.

What is CMMC?

To enhance the protection of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) within the supply chain, the U.S. Department of Defense (DoD) has worked with DoD stakeholders, university-affiliated research centers, federally funded centers and industry at large to develop version 2.0 of the CMMC, a process that measures the ability of organizations within the defense industrial base (DIB) sector to protect FCI and CUI.

CMMC 2.0 adds a certification element to verify implementation of cybersecurity requirements. Under the full program, DoD contractors storing CUI will need to be certified by a CMMC Third Party Assessment Organization (C3PAO) — though this third-party certification requirement (Phase II) is currently suspended pending DoD’s program review. See the update above for details.

CMMC is designed to provide the DoD assurance that a DIB contractor can adequately protect CUI at a level commensurate with the risk and account for flow down to subcontractors in a multitier supply chain. CMMC Level 1 and Level 2 self-assessment requirements continue to be phased into RFIs and RFPs. The third-party (C3PAO) certification requirement under Phase II, which would have expanded this mandate, is currently paused while DoD conducts its program review.

Ready to Get Started? Contact our team and let us know how we can help.

Download our comprehensive CMMC Guide for a detailed overview of CMMC, including a deep dive into the certificate framework, certification process, potential costs and best practices for preparing your organization.

CMMC FAQs

To help you navigate these requirements and prepare your organization for compliance, we have compiled answers to the most frequently asked questions about the CMMC framework, its impact on your business. For the full list of frequently asked questions, download our CMMC FAQ Guide

As of July 13, 2026, the Department of War (DoW) suspended CMMC Phase II — the requirement for many contractors to obtain a third-party assessment from a Certified Third-Party Assessment Organization (C3PAO) — which had been scheduled to take effect November 10, 2026. The suspension also pauses other pending and future CMMC implementation milestones.

A new CMMC Reform Task Force will conduct a 60-day, top-to-bottom review of the program, and DoW is soliciting industry feedback through a Request for Information (RFI), with responses due August 14, 2026.

Importantly, this pause does not eliminate contractors' underlying cybersecurity obligations. CMMC Phase I self-assessment requirements — Level 1 and Level 2 self-assessments and attestations under DFARS 252.204-7021 — remain firmly in place, as does the safeguarding and incident-reporting obligation under DFARS 252.204-7012. For active contracts that currently include Level 2 (C3PAO) or Level 3 requirements, DoW has directed that those requirements be removed at the next contract modification or option period.

Bottom line: if your organization only needs Level 1 or Level 2 self-assessment, keep moving forward — those obligations haven't changed. If your path required a formal C3PAO assessment, that specific requirement is on hold for now, and we recommend against making major changes to in-progress assessment plans until DoW issues further guidance.

Any system, network, or infrastructure that stores, processes, or transmits FCI or CUI is considered in scope for CMMC 2.0. This includes:

  • Internal IT networks that handle CUI.
  • Cloud environments where CUI is stored or processed (e.g., Microsoft GCC High, AWS GovCloud).
  • End-user devices (laptops, desktops, mobile devices) that access CUI.
  • Email and collaboration tools (if used for CUI communication).
  • Subcontractors handling CUI must also meet the appropriate CMMC level.

Organizations need to define and document the boundary of their CMMC in-scope environment to ensure compliance within their System Security Plan (SSP).

For defense contractors, the consequences could be severe. If you decide to not comply or are unable to comply with the CMMC requirements, you will no longer be able to bid on any DoD contracts that include the DFARS clause.

Note: as of the July 2026 CMMC Phase II suspension, this consequence currently applies most directly to Level 1 and Level 2 self-assessment obligations, which remain mandatory for applicable contracts. The formal third-party (C3PAO) certification requirement is paused pending DoD's program review, so contracts are not currently being enforced against that specific requirement — though this could change once the review concludes.

Each DoD Request for Proposal (RFP), Request for Quote (RFQ), or Request for Information (RFI) will specify the required CMMC level for that contract.

Contracts that require CMMC compliance will reference specific Defense Federal Acquisition Regulation Supplement (DFARS) clauses, such as:

  • DFARS 252.204-7012 (Cybersecurity Requirements)
  • DFARS 252.204-7019 (SPR System Submission)
  • DFARS 252.204-7020 (DIBCAC Assessment for Medium & High Risk)
  • DFARS 252.204-7021 (CMMC Certification Requirements)

Note: During the current CMMC Phase II suspension, DoD has directed contracting officers to remove Level 2 (C3PAO) and Level 3 assessment requirements from active solicitations and contracts. New RFPs may temporarily omit this language until the program review concludes.

If DFARS 252.204-7021 is included, the contract will specify the required CMMC level.

There is also the way to determine by the type of information that you will be handling with this contract:

  • If your company only handles Federal Contract Information (FCI) → CMMC Level 1 is required.
  • If your company handles Controlled Unclassified Information (CUI) → CMMC Level 2 or Level 3 may be required.
  • If your company works with high-value CUI for critical national security → CMMC Level 3 is required.

The CMMC framework is closely aligned with NIST standards, as compliance with CMMC requirements necessitates adherence to NIST guidelines. DoD contractors must either perform a self-assessment or undergo a third-party evaluation to verify compliance with the relevant NIST standards outlined in DFARS clause 252.204-7012. Under CMMC 2.0, Level 2 assessments are based on the security controls in NIST SP 800-171, while Level 3 assessments incorporate both NIST SP 800-171 and a subset of advanced protections from NIST SP 800-172.

Schneider Downs is one of the first 55 Authorized C3PAOs accredited by the CMMC Accreditation Body and is currently one of only 54 Authorized C3PAOs in the nation.
 
Schneider Downs provides readiness and consulting services to help organizations prepare for evolving CMMC requirements and their CMMC assessment. Once you are ready for an assessment, Schneider Downs can connect you with partner C3PAOs to conduct the assessment.

The CMMC Model Framework

The CMMC model framework categorizes cybersecurity best practices at the highest level by domains.

Each domain is further segmented by a set of capabilities and achievements to ensure that cybersecurity objectives are met within each domain. Companies will further validate compliance with the required capabilities by demonstrating adherence to practices and processes that have been mapped across three maturity levels (explained below). Within this context, practices will measure the technical activities required to achieve compliance with a given capability requirement, while processes will measure the maturity of a organizations cybersecurity processes.

CMMC Model 2.0 Levels

The CMMC model has three defined levels, each with a set of supporting practices and processes, from Level 1 that addresses basic cyber hygiene to advanced and expert Levels 2 and 3. To meet a specific CMMC level, an organization must meet the practices and processes within that level and below. Levels are described as follows:

  • CMMC Level 1The “foundational” level of CMMC compliance requires all contractors that have FCI in their contracts to implement a set of 17 basic cybersecurity practices that are required by the Federal Acquisition Regulation (FAR) 52.204-21. Organizations that fall under level one may perform an annual self-assessment of the FAR 52.204-21 controls and report there score to the Department of Defense.
  • CMMC Level 2The “advanced” level of CMMC that requires contractors that handle CUI to implement the National Institute of Standards and Technology (NIST) 800-171 framework which includes 110 practices from 14 CMMC domains. If a contractor handles sensitive CUI, the Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 requires the contractor to be level 2 certified by having a CMMC Third Party Assessment Organization (C3PAO) perform an independent assessment to validate that the contractor has fully implemented the NIST 800-171 framework. This third-party (C3PAO) certification requirement is part of CMMC Phase II, which is currently suspended pending DoD’s program review (see update above). Level 2 self-assessment remains required in the interim.
  • CMMC Level 3The “expert” level of CMMC maturity that is required for contractors that work with critical DoD infrastructure. Organizations seeking level 3 certification will be required to comply with the NIST 800-172 framework. Level 3 contractors are also required to be accessed by the DoD directly as opposed to an independent C3PAO. Organizations will need to become certified for level 2 practices by a C3PAO prior to being assessed by the DoD for level 3. As with Level 2 third-party certification, this DoD-led Level 3 assessment process is affected by the current Phase II suspension.
CMMC Guide

CMMC: Cybersecurity Maturity Model Certification Guide

Download our comprehensive CMMC Guide for a detailed overview of CMMC, including a deep dive into the certificate framework, certification process, potential costs and best practices for preparing your organization.

CMMC Domains

The CMMC 2.0 model is cumulative and consists of 6 Level 1 domains and 8 additional domains for Level 2. Level 1domains originated from Federal Acquisition Regulation (FAR) 52.204.-21 and Level 2 originated from NIST SP 800-171. The domains are as follows:

Level 1:

  • Access Control (AC)
  • Identification and Authentication (IA)
  • Media Protection (MP)
  • Physical Protection (PE)
  • System and Communication (SC)
  • System and Information Integrity (SI)

Level 2 (Also contains all Level 1 Practices):

  • Awareness and Training (AT)
  • Audit and Accountability (AU)
  • Configuration Management (CM)
  • Incident Response (IR)
  • Maintenance (MA)
  • Personnel Security (PS)
  • Risk Assessment (RA)
  • Security Assessment (CA)

CMMC Timeline and Cost

The final CMMC rule was published and put into effect on December 16, 2024.

For contracts that require CMMC, you may be disqualified from participating if your organization is not certified. Given that, we expect future RFIs and RFPs will allow prime contractors subcontractors to work the cost of compliance into their bids.

Note: While the final CMMC rule took effect December 16, 2024, the next major milestone — Phase II’s third-party (C3PAO) certification requirement, originally set for November 10, 2026 — has been suspended as of July 13, 2026 pending a DoD program review expected to conclude within 60 days. We’ll update this timeline once DoD issues further guidance.

CMMC Assessments

Schneider Downs is currently one of the first 55 Authorized Certified Third-Party Assessor Organization (C3PAO) by the Defense Contract Management Agency’s (DCMA) Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). 

How Can Schneider Downs Help?

Schneider Downs is one of the first 55 authorized C3PAOs in the nation. We can help your organization prepare for and complete an official CMMC assessment once formal C3PAO assessments resume under the current program review — and in the meantime, we can support your Level 1 or Level 2 self-assessment and help you stay audit-ready. Schneider Downs is also able to help with a readiness consulting engagements to identify gaps within your controls and help remediate those gaps prior to your CMMC assessment. Organizations Seeking Certification (OSCs) should note that a single firm cannot perform both consulting and assessment service for a single client, per the CyberAB standards.

About Schneider Downs IT Risk Advisory 

Schneider Downs’ team of experienced risk advisory professionals focuses on collaborating with your organization to identify and effectively mitigate risks. Our goal is to understand not only the risks related to potential loss to the organization but to drive solutions that add value to your organization and advise on opportunities to ensure minimal disruption to your business.

To learn more, visit our dedicated IT Risk Advisory page.

Cybersecurity Maturity Model
Certification (CMMC)

Schneider Downs is one of the first 55 Authorized C3PAOs
and can handle your CMMC Certificaton.

View our additional IT Risk Advisory services and capabilities