Skip to main content
Power Up Boston
Cybersecurity controls for a defense contractor

CMMC Compliance for Massachusetts Businesses

The Department of Defense now requires Cybersecurity Maturity Model Certification (CMMC) in its contracts, and the requirement flows down to subcontractors. If your Massachusetts business handles Federal Contract Information or Controlled Unclassified Information, you will need to show a CMMC Level 1 or Level 2 result to keep bidding. We prepare South Shore and Greater Boston suppliers for the assessment and run the technical controls afterward.

CMMC 2.0 Levels and Assessment Types

CMMC 2.0 replaced the original five-level model with three levels. The level you need is set by the contract, based on whether you handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). The program requirements are published at 32 CFR Part 170.

Level 1

Foundational

15 requirements (FAR 52.204-21)

Annual self-assessment + affirmation in SPRS

Basic safeguarding of Federal Contract Information (FCI): limit access to authorized users, identify and authenticate users, sanitize media, control physical access, protect network boundaries, patch flaws, and run malware protection.

Level 2

Advanced

110 requirements (NIST SP 800-171 Rev. 2)

Triennial self-assessment or C3PAO certification, per contract, plus annual affirmation

Full protection of Controlled Unclassified Information (CUI) across 14 control families including access control, audit and accountability, configuration management, incident response, and system and communications protection.

Level 3

Expert

Level 2 + 24 requirements (NIST SP 800-172)

Government-led assessment by DIBCAC after a Level 2 certification

Enhanced protection against advanced persistent threats for the most sensitive programs. Rarely applicable to small suppliers.

Terminology note: the 15 FAR 52.204-21 requirements were presented as 17 practices in earlier CMMC documentation because the physical-access item was split into three. The current program rule and assessment guides count 15. The scope of what you must do is the same.

The 15 Level 1 Requirements by Domain

Level 1 is where most small Massachusetts suppliers start. Every requirement comes from paragraph (b)(1) of FAR 52.204-21, “Basic Safeguarding of Covered Contractor Information Systems,” grouped here by the six CMMC domains they map to.

Access Control (AC)

FAR (b)(1)(i)–(iv)

Limit system access to authorized users; limit access to permitted transactions and functions; verify and control connections to external systems; control information posted on publicly accessible systems.

Identification & Authentication (IA)

FAR (b)(1)(v)–(vi)

Identify users, processes, and devices; authenticate them before allowing access.

Media Protection (MP)

FAR (b)(1)(vii)

Sanitize or destroy media containing FCI before disposal or reuse.

Physical Protection (PE)

FAR (b)(1)(viii)–(ix)

Limit physical access to authorized individuals; escort visitors, keep physical access logs, and control keys, badges, and other access devices.

System & Communications Protection (SC)

FAR (b)(1)(x)–(xi)

Monitor and protect communications at external and key internal boundaries; separate publicly accessible components from the internal network.

System & Information Integrity (SI)

FAR (b)(1)(xii)–(xv)

Identify and correct flaws in a timely manner; provide malware protection; keep it updated; scan systems periodically and scan external files in real time.

Want the full checklist?

Our CMMC Level 1 checklist for Massachusetts small businesses lists all 15 requirements one by one, with what an assessor expects to see for each and how to document it for your self-assessment.

What Level 2 Adds

If your contracts involve CUI, such as technical drawings, specifications, test data, or export-controlled information, Level 2 applies. It is the full set of 110 requirements in NIST SP 800-171 Revision 2, the same standard contractors have been required to self-attest to under DFARS 252.204-7012 since 2017. CMMC adds verification: for most CUI contracts a C3PAO certification assessment, and for a smaller set a self-assessment, each with a three-year cycle and annual affirmations by a senior company official.

The areas that most often trip up small manufacturers are multi-factor authentication for every network and privileged account, audit logging that is actually retained and reviewed, encryption of CUI at rest and in transit using FIPS-validated cryptography, a written and tested incident response plan, and configuration baselines for workstations and shop-floor systems. Under the program rule, a limited number of requirements may remain on a Plan of Action and Milestones for up to 180 days after a conditional assessment; the rest must be fully implemented at assessment time.

The Phased Rollout

Two rules make CMMC real. The program rule at 32 CFR Part 170 became effective December 16, 2024. The acquisition rule that inserts CMMC into DoD solicitations and contracts, DFARS 252.204-7021, became effective November 10, 2025. From that date DoD began a phased implementation over roughly three years: early phases rely on Level 1 and Level 2 self-assessments, later phases require Level 2 certification assessments and then Level 3, with the requirement applying to all applicable solicitations at full implementation.

Practically, this means prime contractors are already asking their Massachusetts suppliers for SPRS scores and CMMC status. Because a Level 2 certification depends on assessor availability, and remediation takes time, starting before a contract requires it is the only way to avoid being disqualified from a bid.

This page summarizes public DoD regulations for general information and is not legal or contracting advice. Confirm requirements against your specific solicitation and the current DoD CIO CMMC guidance.

Our CMMC Readiness Process

1

Scope & Gap Assessment

We identify where FCI and CUI actually live, define the assessment boundary as tightly as possible, and score your environment against every applicable requirement.

2

Remediation Plan

You get a prioritized, written plan of the gaps to close, what each one involves, and the order that gets you to a passing self-assessment or certification fastest.

3

Implementation

We deploy the technical controls: multi-factor authentication, endpoint protection, patch management, encryption, logging, network segmentation, and secure backups.

4

Documentation & Evidence

We assemble the System Security Plan (SSP), Plan of Action and Milestones (POA&M) where permitted, policies, and the evidence an assessor will ask for, and help you record results in SPRS.

Why a Local Provider

Power Up Boston has served 1,622+ businesses over 17+ years from Plymouth, MA (as of September 2026). CMMC controls touch physical things, such as who can walk into the shop, which machines sit on the CUI network, and how visitor logs are kept, and we handle those on-site alongside the managed IT, cybersecurity, and access control work.

Related Compliance

CMMC Compliance FAQ

What is CMMC?

The Cybersecurity Maturity Model Certification (CMMC) is the U.S. Department of Defense program that verifies defense contractors and subcontractors are protecting Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The CMMC program rule is codified at 32 CFR Part 170 and is applied to contracts through a DFARS clause. CMMC 2.0 has three levels.

Does my Massachusetts business need CMMC?

If you hold, or want to bid on, a DoD contract or subcontract that involves FCI or CUI, the CMMC level required will be stated in the solicitation and flow down to subcontractors. Many South Shore and Route 3 corridor machine shops, electronics suppliers, engineering firms, and specialty manufacturers are in scope even several tiers below the prime contractor. Contracts limited to commercially available off-the-shelf (COTS) items are excluded.

What is the difference between CMMC Level 1 and Level 2?

Level 1 covers FCI and consists of the 15 basic safeguarding requirements in FAR 52.204-21 (older CMMC guides counted them as 17 practices). It is met with an annual self-assessment and affirmation. Level 2 covers CUI and consists of the 110 security requirements in NIST SP 800-171 Revision 2. Depending on the contract, Level 2 is verified by either a self-assessment or a certification assessment by a CMMC Third-Party Assessment Organization (C3PAO), each valid for three years with annual affirmations.

What is CMMC Level 3?

Level 3 applies to the most sensitive CUI programs. It requires a Level 2 certification assessment first, then 24 additional requirements drawn from NIST SP 800-172, assessed by the DoD's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). Very few small businesses will need Level 3.

When does CMMC become mandatory?

The 32 CFR Part 170 program rule took effect December 16, 2024, and the DFARS acquisition rule that puts CMMC requirements into contracts took effect November 10, 2025. DoD is phasing requirements into new solicitations over roughly three years, beginning with self-assessments and adding third-party certification requirements in later phases. Check your current solicitations and the DoD CIO's CMMC pages for the exact phase your contracts fall under.

How long does it take to get CMMC ready?

It depends on your starting point, how much of your environment touches FCI or CUI, and how many of the requirements you already meet. Shrinking the scope, for example by isolating CUI to a defined set of systems, is usually the biggest time saver. We give you a written gap list and a realistic timeline after the assessment rather than a generic number.

Can Power Up Boston perform our CMMC assessment?

We prepare your environment, implement the technical controls, and assemble the System Security Plan and evidence. We are not a C3PAO, so a Level 2 certification assessment is performed by an authorized C3PAO listed by the Cyber AB. For Level 1 and Level 2 self-assessments, we help you complete and document the assessment and record the result and affirmation in SPRS.

Ready to Start Your CMMC Readiness?

Free gap assessment for Massachusetts defense suppliers. We'll show you exactly which of the requirements you already meet and what it takes to close the rest.

Trusted since 2009 · 5-star rated on Google · On-site support across Plymouth, South Shore, Cape Cod & Greater Boston