CMMC FAQ
Frequently asked questions about CMMC compliance, certification, and assessment preparation.
What is CMMC?
The Cybersecurity Maturity Model Certification (CMMC) is a DoD framework that requires defense contractors to demonstrate cybersecurity practices at specific maturity levels. CMMC Level 2 aligns with NIST SP 800-171 and covers 110 security practices across 14 domains.
Who needs CMMC certification?
Any organization in the Defense Industrial Base (DIB) that handles Controlled Unclassified Information (CUI) or Federal Contract Information (FCI) needs CMMC certification. This includes prime contractors, subcontractors, and suppliers at any tier.
When is the CMMC compliance deadline?
CMMC Phase 1 enforcement began in late 2025. Phase 2, which requires third-party assessments for Level 2, takes effect in November 2026. Organizations typically need 6-12 months to prepare, making immediate action critical.
What is the difference between CMMC Level 1 and Level 2?
Level 1 covers 17 basic safeguarding practices for Federal Contract Information (FCI) with annual self-assessment. Level 2 covers 110 practices from NIST 800-171 for Controlled Unclassified Information (CUI) and requires a third-party assessment by a C3PAO.
How long does a CMMC assessment take?
A typical CMMC Level 2 assessment takes 1-2 weeks of active assessment time, depending on organization size and scope. However, preparation — including gap remediation, evidence collection, and policy development — typically takes 6-12 months.
What is a C3PAO?
A CMMC Third-Party Assessment Organization (C3PAO) is an authorized body that conducts CMMC Level 2 and Level 3 assessments. C3PAOs are accredited by the Cyber AB (formerly CMMC-AB) and employ certified assessors.
What does a CMMC assessment simulator do?
A CMMC assessment simulator lets you practice the assessment experience before facing a real C3PAO. You can role-play as either an assessor (conducting interviews, requesting evidence, scoring practices) or an auditee (responding to questions, presenting evidence, defending your security posture).
How does the Cubelet CMMC Simulator work?
The Cubelet CMMC Simulator covers all 110 Level 2 practices across 14 domains. Each practice is a "Cubelet" — a knowledge atom with six faces (WHAT, WHY, HOW, WHERE, WHEN, APPLY) explored across five mastery levels. AI coaching adapts to your knowledge gaps and provides targeted guidance.
What is CUI and how does it relate to CMMC?
Controlled Unclassified Information (CUI) is information that requires safeguarding per government regulations but is not classified. CMMC Level 2 is specifically designed to protect CUI in non-federal systems. If your contracts involve CUI, you need Level 2 certification.
Can I use MCP tools for CMMC training?
Yes. The Cubelet CMMC Simulator runs as an MCP (Model Context Protocol) server, meaning it works inside AI assistants like Claude Desktop and ChatGPT. This "in the flow of work" approach lets you practice compliance training without leaving your existing AI workflow.
Ready to start preparing?
Practice all 110 CMMC Level 2 practices with AI-guided coaching.