CMMC 2.0 Is Now Law
The Department of Defense's Cybersecurity Maturity Model Certification (CMMC) 2.0 Final Rule was published in October 2024 and became effective in December 2024. This means the 300,000+ organizations in the Defense Industrial Base (DIB) that handle Controlled Unclassified Information (CUI) are now on the clock to achieve certification.
The Three Levels
Level 1 — Foundational: 17 practices aligned with FAR 52.204-21 (basic safeguarding of federal information). Annual self-assessment.
Level 2 — Advanced: 110 practices aligned with NIST SP 800-171. Required for contractors handling CUI on DoD contracts. Annual self-assessment for most; triennial third-party assessment (C3PAO) for critical programs.
Level 3 — Expert: 110+ practices based on NIST SP 800-172. For contractors supporting the highest-priority programs. Government-led assessments.
The Most Common Gaps
Based on our assessment work across dozens of contractors, the most common Level 2 gaps we see are:
- AC (Access Control) — insufficient multi-factor authentication and least-privilege implementation
- AU (Audit and Accountability) — log retention and centralized logging gaps
- SC (System and Communications Protection) — unencrypted data in transit and insufficient network segmentation
- SI (System and Information Integrity) — irregular vulnerability scanning and missing anti-malware on all endpoints
Your Action Plan
SYNCXELL recommends starting with a gap assessment against NIST SP 800-171 controls, developing a System Security Plan (SSP) and POA&M for identified gaps, then executing a remediation roadmap prioritized by control family risk.
Have questions about this topic?
Our compliance and engineering team is ready to help.
Discuss this topic with our experts