Frequently asked questions
Twenty of the most common questions from contractors evaluating CMMC paths and CMMC consultants. If yours isn't here, email consulting@praedyn.com.
01. What is CMMC and who needs it?
The Cybersecurity Maturity Model Certification (CMMC) is the DoD's framework for verifying that defense contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Any organization that holds an active DoD contract or subcontract — including manufacturers, engineering firms, R&D contractors, IT service providers, professional services, and many primes' supply chain partners — eventually needs a CMMC certification at Level 1, 2, or 3 depending on what kind of information their contracts involve.
02. What's the difference between Levels 1, 2, and 3?
Level 1 (Foundational) protects FCI and requires 17 practices from FAR 52.240-93. Self-assessed annually. Level 2 (Advanced) protects CUI and requires all 110 controls from NIST SP 800-171 Rev. 2. Assessed by an independent C3PAO every three years. Level 3 (Expert) sits on top of Final Level 2 certification and adds 24 enhanced requirements from NIST SP 800-172. Assessed by DCMA DIBCAC. Roughly speaking: L1 is for contractors who handle only contract paperwork and similar non-sensitive information, L2 is for contractors who handle CUI, L3 is for contractors handling CUI under high-priority programs where the DoD has explicitly flagged additional protection requirements.
03. When does CMMC enforcement actually start?
CMMC entered Phase 1 on November 10, 2025, with self-assessed Level 1 and Level 2 requirements appearing in new DoD contracts at the contracting officer's discretion. Phase 2 starts November 10, 2026, when C3PAO-assessed Level 2 becomes a mandatory inclusion in covered contracts. Phase 3 follows in late 2027 with Level 3 enforcement, and Phase 4 in 2028 with full deployment across the contract base. The practical implication: if your contracts involve CUI and you want to bid on anything coming out after November 2026, you need a path to assessed Level 2 now.
04. How long does CMMC certification take?
Realistic end-to-end timelines for Level 2 vary by starting posture. A contractor starting from a clean self-assessment with existing documentation might reach assessed Level 2 in 6-9 months. A contractor starting from cold — no SSP, no controls implemented, no CUI scoping done — should plan 12-18 months. Add 4-8 months on top for the L3 overlay on contractors who need it. The actual C3PAO assessment itself is usually a 2-3 week engagement; everything before that is the implementation and documentation work.
05. What's the difference between Microsoft 365 GCC, GCC High, and Commercial?
Commercial Microsoft 365 is the standard tenant — not authorized for CUI. GCC (Government Community Cloud) is FedRAMP Moderate authorized and acceptable for non-export-controlled CUI. GCC High is FedRAMP High / DoD IL4-IL5 authorized and required for export-controlled CUI (ITAR / EAR) and DFARS 7012-covered information. The decision is mostly driven by the kind of CUI you handle: if you have any ITAR or export-controlled information, GCC High is mandatory. If you have only non-export-controlled CUI, GCC is usually sufficient and substantially cheaper. We walk this decision in detail during the readiness engagement.
06. Do I need GCC High to handle CUI?
Not always. GCC High is required for ITAR-controlled, EAR-controlled, and certain other categories of export-controlled CUI. For non-export-controlled CUI (much of what flows through standard DoD contracts), GCC is acceptable. Many small contractors over-provision into GCC High when GCC would have met their requirements at lower cost. This is one of the most common scoping mistakes we see, and one of the most valuable scoping wins early in an engagement.
07. What is the SPRS score and how is it calculated?
The Supplier Performance Risk System (SPRS) score is a single number ranging from -203 to 110 that represents your compliance with NIST SP 800-171 Rev. 2. You start at 110 (full compliance), and each control you don't fully implement deducts a point value (1, 3, or 5 points depending on the control's weight). The DoD Assessment Methodology v1.2.1 defines the scoring. Contractors are required to post a current SPRS score in the SPRS system for many DoD contracts under DFARS 252.204-7012. A score of 88 or above qualifies for Conditional Level 2 status; below 88 generally requires remediation before assessment.
08. What's a POA&M and how does it interact with conditional Level 2?
A Plan of Action and Milestones (POA&M) documents control gaps you have not yet closed, with specific remediation steps, owners, and target closure dates. Under CMMC conditional Level 2 status, contractors with SPRS scores at or above 88 can be conditionally certified with open POA&M items, as long as those items are closed within 180 days of the assessment. After 180 days, unresolved POA&M items void the conditional status. Final Level 2 status requires all POA&M items closed and a perfect score against the assessed scope.
09. Can I use my MSP for CMMC compliance?
Your MSP can be a meaningful part of your CMMC posture if they have the right capabilities and a documented relationship with you. The critical factor is whether the MSP itself meets CMMC requirements — under the new External Service Provider rules in 32 CFR Part 170, MSPs handling CUI on your behalf must themselves be assessed at the applicable CMMC level. Many MSPs are not. Praedyn engagements include MSP-readiness review as part of scoping, and we can help you evaluate whether your current MSP fits the CMMC model or whether you need to add a CMMC-compliant managed service to the stack.
10. Do I have to remediate everything before assessment?
No, but the scoring matters. Under conditional Level 2, you can be certified with open items in your POA&M, provided your SPRS score is at or above 88 and the open items are closed within 180 days post-assessment. Below 88, you need to remediate to the threshold before the assessor will issue conditional certification. Final Level 2 requires all POA&M items closed. The practical strategy for most contractors is to remediate everything that's high-point-value or risky, defer the genuinely-deferrable items into the POA&M for post-assessment closure, and time the assessment when SPRS is comfortably above 88.
11. What happens if I fail my CMMC assessment?
A C3PAO assessment that doesn't reach the required level results in no certification. You can re-attempt after remediating the gaps. The DoD has not published a hard cooldown between attempts, but the assessment itself isn't cheap, and the more common pattern is conditional Level 2 (with a POA&M) rather than outright failure. Our Mock Pre-Assessment service is designed specifically to surface the issues that would have caused a fail before the real assessor arrives, while there's still time to fix them.
12. How is Praedyn different from a C3PAO?
A C3PAO is an authorized assessor — they conduct the formal CMMC Level 2 assessment that produces certification. Praedyn is a consulting firm — we prepare you for that assessment but do not perform it. The Cyber AB and 32 CFR Part 170 require strict separation between consulting and assessment to preserve assessor independence. We work alongside any C3PAO of your choice and support you through their engagement, but we do not score your assessment.
13. Can Praedyn both prepare us AND assess us?
No. This is a regulatory requirement, not a choice. The Cyber AB explicitly prohibits a single firm from both consulting on CMMC preparation and performing the C3PAO assessment for the same client. Any firm that tells you otherwise is putting your certification at risk — assessments performed by entities with consulting relationships are subject to decertification.
14. What does engagement with Praedyn cost?
Pricing scales with the size of your environment, your target CMMC level, and the engagement type. Our published baseline for a Level 2 Readiness Assessment ranges from $35,000 for a micro contractor to $545,000+ for an enterprise. Full Implementation runs roughly 2.5x readiness pricing. Mock-only engagements run roughly 0.55x. Ongoing retainer engagements are priced monthly. The intake form provides a live estimate as you fill it in, and our pricing guide PDF documents the full model. All estimates are planning figures — final pricing is fixed in a signed SOW after a no-cost scoping conversation.
15. How long does a Praedyn engagement take?
Readiness Assessment: 6-10 weeks. Mock Pre-Assessment: 3-6 weeks. SSP and POA&M Authoring: 4-8 weeks. Full Implementation to Level 2: 6-12 months. L3 overlay adds another 4-8 months on top of L2. Retainer engagements run monthly with a 12-month minimum commitment. These are typical durations; we lock the actual timeline against your contract deadlines during scoping.
16. Do you work with companies in non-traditional industries?
Yes. Defense contracting cuts across more industries than people realize — manufacturing, R&D services, IT services, professional services, logistics, construction, energy, and critical infrastructure all have contractor populations with CMMC obligations. Praedyn's OT/ICS specialization makes us particularly well-suited for manufacturers and industrial control system environments where standard CMMC scoping falls short.
17. What if I don't have CUI yet but might soon?
Plan ahead. The most expensive CMMC engagements happen when contractors get a new contract requiring CUI handling and have 6 months to certify. The lead time on Level 2 implementation is real — environments take time to harden, documentation takes time to author, controls take time to bed in. If your pipeline includes contracts that will likely carry CUI requirements, start scoping now. A Readiness Assessment gives you a defensible budget figure for the implementation work without committing to the larger engagement until the contract lands.
18. How does NIST SP 800-171 Rev. 3 affect my planning?
NIST SP 800-171 Rev. 3 was published in May 2024 but has not yet been incorporated into the CMMC program. Current CMMC assessments still use Rev. 2 as the baseline. DoD has indicated Rev. 3 will phase in over future CMMC program updates, with a transition period for contractors. For 2026 planning, target Rev. 2. We track Rev. 3 readiness in our ongoing retainer engagements so existing clients are not caught flat-footed when the transition happens.
19. What's a CCP, CCA, RP, RPA, RPO?
These are Cyber AB / CAICO credentials. RP (Registered Practitioner) is the entry-level Cyber AB credential for individuals offering CMMC consulting. RPA (Registered Practitioner Advanced) is the more experienced tier. CCP (Certified CMMC Professional) is ISACA / CAICO's certification for CMMC consultants, more rigorous than RP. CCA (Certified CMMC Assessor) is the assessor credential held by individuals who perform formal C3PAO assessments. RPO (Registered Provider Organization) is the firm-level Cyber AB registration. Praedyn's credential roadmap is on the About page.
20. How do I get started with Praedyn?
Start with the intake form — it takes 10-15 minutes, shows you a live cost estimate as you fill it in, and gives us the scope information we need to prepare for our first conversation. After you submit, we follow up within one business day with a scoped proposal. If you would rather talk first, email consulting@praedyn.com and we will set up a 30-minute scoping call.
— Still have questions