What is CMMC?
The Cybersecurity Maturity Model Certification (CMMC) is the US Department of Defense's framework for verifying that contractors handling government data have implemented adequate cybersecurity. CMMC was finalized as DFARS 252.204-7021 in late 2024 and is now appearing in DoD contract solicitations on a phased rollout through 2028.
CMMC has three levels:
- Level 1 (Foundational): 17 controls. Protects Federal Contract Information (FCI). Annual self-assessment.
- Level 2 (Advanced): 110 controls (NIST SP 800-171). Protects Controlled Unclassified Information (CUI). Third-party assessment by a C3PAO.
- Level 3 (Expert): Adds 24 controls from NIST SP 800-172. Protects the highest-sensitivity CUI. Assessment by the DoD's DIBCAC team.
If your MSP touches a DoD prime or sub-tier contractor, you almost certainly need Level 2.
Why CMMC matters for MSPs
Three reasons CMMC is one of the highest-leverage frameworks an MSP can pursue:
- Mandatory, not nice-to-have. Without CMMC at the right level, you cannot service DoD-adjacent clients, period. Your DIB clients are contractually required to flow down requirements to you.
- Massive serviceable market. The Defense Industrial Base is roughly 300,000 contractors — most of them small or mid-sized, most needing MSP support to reach Level 2. The supply of CMMC-ready MSPs is far below demand.
- Premium pricing. Unlike commodity managed services, CMMC support carries 2–3x normal MSP rates because the certified provider pool is so small.
Which clients require CMMC
Any company in the Defense Industrial Base that handles FCI or CUI must meet CMMC. In practice, that means:
- Direct DoD contractors (primes)
- Sub-contractors at any tier under a DoD contract
- Manufacturing firms supplying DoD platforms (think aerospace, naval, ground vehicles)
- Engineering and consulting firms with DoD or DARPA contracts
- Software vendors with DoD use cases
- Logistics, supply chain, and professional services firms with DoD scope
If your client's contract has a DFARS clause referencing 252.204-7012, 7019, 7020, or 7021 — they need CMMC, and so do you.
Where CMMC applies
CMMC is a US Department of Defense requirement. It applies to any company — domestic or international — that handles US DoD contract data. Foreign subsidiaries of DIB primes, allied nation suppliers, and offshore service providers are all in scope when they touch CUI.
How CMMC helps MSPs win business
CMMC creates a procurement moat. Your DIB clients are contractually required to verify their MSP's CMMC level before granting access to in-scope systems. Once you're certified at Level 2, you're inside the moat — your competitors aren't.
We've seen MSPs displace incumbents purely on CMMC readiness, even when the incumbent was the lower-priced option. The math is simple: if the incumbent can't sign the DPA flow-down, they're out.
The MSP opportunity in CMMC services
Becoming CMMC-ready yourself is the entry ticket. The recurring revenue is in helping your DIB clients stay ready.
CMMC is not a one-and-done certification. The program requires continuous monitoring, annual self-attestation (Levels 1 and 2 self-assessed), and triannual third-party reassessment for Level 2. Plus the DoD will likely roll out higher-frequency requirements as the program matures.
MSPs that build a CMMC compliance practice for DIB SMBs are looking at $5k–25k MRR per client, depending on size and level. With Cyber Verify CaaS, you can deliver this without building the platform yourself.
How Cyber Verify accelerates CMMC
Cyber Verify gives MSPs a pre-built CMMC framework that takes most of the policy and evidence work off the table:
- Scoping templates that carve a defensible CUI enclave (often shrinking audit surface 60%+)
- All 110 SP 800-171 controls pre-mapped to UCS Practice Domains and policy templates
- System Security Plan (SSP) template at the depth C3PAOs expect
- Evidence library indexed by CMMC assessment objective
- C3PAO relationships in our partner network
- CORTEX scoring keeps you assessment-ready between recerts
The result: a typical MSP reaches CMMC Level 2 ready in 9–12 months instead of 18+, with materially less internal time burned.