ITAR-controlled technical data is treated as Controlled Unclassified Information under federal rules, so ITAR and CMMC compliance travel together: if your company handles that data on a Department of Defense contract, you need to meet Cybersecurity Maturity Model Certification requirements at Level 2 or higher, on top of everything ITAR already demands. The two regimes come from different agencies with different jobs. ITAR governs who may access defense technology. CMMC governs how contractors protect the digital systems that hold it. They land on the same companies, and they now gate the same contracts.
Why ITAR Data Pulls You Into CMMC
The International Traffic in Arms Regulations, at 22 CFR Parts 120–130, control the export and temporary import of defense articles and services listed on the United States Munitions List. The Department of State’s Directorate of Defense Trade Controls administers the program under the Arms Export Control Act.1U.S. Department of State Directorate of Defense Trade Controls. Understand The ITAR Technical data is defined at 22 CFR 120.33 as information required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modification of defense articles: blueprints, engineering drawings, test procedures, and manufacturing documentation.2eCFR. 22 CFR 120.33 Technical Data
The link to CMMC runs through the CUI framework. The National Archives CUI Registry places ITAR-controlled information in the “Export Controlled” category, which qualifies it as Controlled Unclassified Information.3National Archives. CUI Category: Export Controlled Once data carries that designation, DFARS clause 252.204-7012 requires contractors to implement the NIST SP 800-171 security controls as the minimum standard for adequate security.4eCFR. 48 CFR 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting CMMC, codified at 32 CFR Part 170, adds independent verification to that existing obligation. The government no longer takes contractors at their word that the controls are in place.5eCFR. 32 CFR Part 170 Cybersecurity Maturity Model Certification (CMMC) Program
Which CMMC Level Applies
Most ITAR-regulated contractors handling CUI on DoD contracts will need CMMC Level 2, which maps directly to the 110 security controls in NIST SP 800-171 Revision 2. The contracting officer specifies both the level and the assessment type in the contract through DFARS clause 252.204-7021, choosing among Level 1 (Self), Level 2 (Self), Level 2 (C3PAO), and Level 3 (DIBCAC).6eCFR. 48 CFR 252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Program A Level 2 self-assessment lets your organization evaluate its own systems. A Level 2 C3PAO assessment requires a formal audit by an accredited third-party organization.
Level 3 applies to contractors on the most sensitive programs, where state-sponsored threat actors are a heightened concern. It layers additional controls from NIST SP 800-172 on top of a completed Level 2 C3PAO certification, and only the Defense Contract Management Agency’s DIBCAC team can conduct the assessment.7U.S. Department of Defense Chief Information Officer. CMMC Assessment Guide Level 3 You cannot pursue Level 3 until you hold Final Level 2 (C3PAO) status. For most ITAR contractors outside those top-tier programs, Level 2 is the operative requirement.
When It Hits Your Contracts
CMMC is rolling into contracts across a four-phase timetable that began November 10, 2025.
- Phase 1 (November 2025 to November 2026): contracting officers have discretion to include Level 1 or Level 2 self-assessment requirements in new solicitations and contracts. C3PAO third-party assessments can appear but are not yet mandatory across the board.
- Phase 2 (November 2026 to November 2027): Level 2 C3PAO certification requirements begin appearing in applicable new contracts. Level 3 DIBCAC assessments start appearing for higher-sensitivity programs.
- Phase 3 (November 2027 to November 2028): C3PAO requirements spread more broadly across the DoD contract base, including task orders and indefinite-delivery contracts.
- Phase 4 (November 2028 onward): full implementation. All applicable DoD contracts requiring contractors to handle Federal Contract Information or CUI must include the appropriate CMMC level as a condition of award.8U.S. Department of Defense CIO. About CMMC
If you are reading this in 2026, you are in the transition. Self-assessments are already appearing in contracts, and C3PAO certification requirements will start showing up in solicitations by the end of the year. Waiting until Phase 4 to get compliant costs you contract eligibility in the meantime.
Scoping the Environment That Has to Be Secured
Not every computer in your building has to meet all 110 controls. Only systems that process, store, or transmit CUI do. The CMMC Level 2 Scoping Guide sorts assets into five categories that decide what falls inside or outside your assessment boundary.9U.S. Department of Defense Chief Information Officer. CMMC Scoping Guide Level 2
- CUI Assets: systems that directly handle CUI. Assessed against all Level 2 security requirements.
- Security Protection Assets: systems that provide security functions to CUI assets, such as firewalls, SIEM platforms, or domain controllers. Assessed against the requirements relevant to the protections they provide.
- Specialized Assets: equipment that touches CUI but cannot be fully secured, including industrial IoT devices, operational technology, and government-furnished equipment. Documented in your System Security Plan and managed under risk-based policies rather than assessed against every control individually.
- Contractor Risk Managed Assets: systems that can but are not intended to process CUI, documented and managed under company policy.
- Out-of-Scope Assets: systems that never touch CUI and provide no security protections for systems that do. Outside the assessment entirely.
The practical move is the enclave strategy. Rather than pushing 110 controls across the entire corporate network, you build a logically isolated environment where all CUI processing happens. The 32 CFR Part 170 final rule allows different enclaves to be assessed at different CMMC levels, and a C3PAO assessment can cover a specific enclave rather than your whole enterprise.10U.S. Department of Defense Chief Information Officer. CMMC Assessment Guide Level 2 For ITAR contractors, that usually means isolating the engineering workstations and file shares that hold technical data from the rest of the business network. The controls still apply in full inside the enclave. You are just reducing the surface area you have to secure and maintain.
Cloud Services and Outsourced IT
If your organization uses cloud platforms or outsources IT functions, the compliance boundary follows the data. A cloud service provider that processes, stores, or transmits CUI must meet the FedRAMP Moderate baseline or an equivalent level of security, per DFARS 252.204-7012.11U.S. Department of Defense Chief Information Officer. FedRAMP Authorization and Equivalency Standard commercial platforms like ordinary Microsoft 365 or Google Workspace do not meet FedRAMP Moderate out of the box. Contractors typically need purpose-built offerings such as Microsoft GCC High or AWS GovCloud.
An external service provider that is not a cloud provider but still handles CUI, such as a managed IT provider with remote access to your systems, falls inside your assessment scope and is evaluated as part of your CMMC assessment.12U.S. Department of Defense Chief Information Officer. Technical Application of CMMC Requirements A managed security provider running a security operations center on your behalf has to appear in your asset inventory and network diagram and be assessed against the relevant CMMC requirements. If an outsourced technician holds admin credentials on equipment in your enclave, they are treated as equivalent to your own staff for scoping, which pulls their infrastructure into scope.
Documentation You Have to Produce
System Security Plan
The System Security Plan is the backbone of the readiness package. It inventories every piece of hardware and software within your assessment scope, describes your network architecture, and explains how you implement each of the 110 NIST SP 800-171 Rev 2 controls.13Department of Defense. NIST SP 800-171 DoD Assessment Methodology Building one is a collaboration between IT and export control staff. IT maps the technical implementation. Export control confirms that CUI boundaries align with the ITAR program. Every server, router, workstation, and firewall that touches ITAR data, or that protects a system that does, has to appear in the SSP’s asset inventory.
Data Flow Diagram
A data flow diagram traces every path ITAR-controlled technical data takes through your environment: where it enters, where it is stored, how it moves between systems, and where it exits to subcontractors or government agencies. Most scoping mistakes happen here. A missed workstation or an undocumented cloud backup can put you out of compliance with both ITAR and CMMC at once. If engineering staff email technical drawings to a subcontractor, that email system is in scope. If a laptop goes home with an engineer who accesses files remotely, that device and the connection path are in scope.
Plan of Action and Milestones
Gaps found during SSP development go into a Plan of Action and Milestones. A POA&M identifies each unmet control, assigns responsibility, and sets a timeline and budget for remediation. Under CMMC, a POA&M can earn a “Conditional” status, but only if your assessment score reaches at least 80% of the total possible points and none of the open controls are among the ones the rule designates as non-deferrable. Those non-deferrable controls include CUI encryption, external connection controls, visitor escort requirements, and the SSP itself.14eCFR. 32 CFR 170.21 Plan of Action and Milestones Requirements You then have 180 days from the Conditional status date to close everything through a POA&M closeout assessment. Miss the window and the Conditional status expires.
The Assessment and What It Costs
For Level 2 C3PAO certification, you engage a CMMC Third-Party Assessment Organization authorized by the Cyber AB.15Cyber-AB. FAQ The process opens with a services contract during which the C3PAO reviews your SSP and supporting documentation. Pentagon cost estimates put a Level 2 certification assessment at roughly $105,000 for small entities and $118,000 for larger ones, covering the triennial assessment and two annual affirmation cycles. Self-assessments run around $37,000 to $49,000 over the same period, but they do not satisfy contracts that specify C3PAO certification.
The assessment team verifies that the controls described in the SSP actually function in daily operations. They check configurations, interview staff, and examine evidence that the policies are more than paper. Each of the 110 controls receives a MET, NOT MET, or NOT APPLICABLE determination, and the results are scored under the methodology in 32 CFR 170.24. The C3PAO uploads results into the CMMC instance of eMASS, which feeds the Supplier Performance Risk System.16eCFR. 32 CFR 170.17 CMMC Level 2 Certification Assessment and Affirmation Requirements SPRS is what contracting officers check when they verify that a bidder meets the CMMC requirement in a solicitation.17Supplier Performance Risk System. Supplier Performance Risk System The resulting CMMC status is valid for three years from the status date.8U.S. Department of Defense CIO. About CMMC
Annual Affirmation and Personal Liability
Keeping the status active requires a senior official, designated as the Affirming Official, to submit an annual affirmation in SPRS certifying that the organization continues to meet the applicable CMMC security requirements.18eCFR. 32 CFR 170.22 Affirmation The affirmation is required after every assessment, including POA&M closeout, and every year after that. A current affirmation is a prerequisite for contract award and option exercise under DFARS 252.204-7021.6eCFR. 48 CFR 252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Program
The affirmation is not a routine checkbox. It is a recurring certification that the organization has implemented and will maintain all applicable security controls. If that certification is false when made, or made with reckless disregard for its accuracy, it can trigger False Claims Act liability with treble damages and per-claim penalties. The Department of Justice has been actively pursuing cybersecurity-related False Claims Act cases, including settlements involving contractors that reported inaccurate assessment scores or failed to implement controls they claimed to have in place. Liability can reach parent companies and acquiring entities, which makes CMMC status a due diligence question in any defense sector transaction.
Subcontractors carry the same obligation. Under DFARS 252.204-7021, a prime must verify that every subcontractor holds a current CMMC status at the appropriate level before award, and each subcontractor’s Affirming Official has to submit its own annual affirmation.6eCFR. 48 CFR 252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Program
Penalties on Both Sides
ITAR and CMMC each have their own enforcement mechanisms, and a single failure can trigger both. Civil penalties for ITAR violations reach up to $1,200,000 per violation.19eCFR. 22 CFR Part 127 Violations and Penalties – Section 127.10 Civil Penalty Criminal penalties for willful violations carry fines up to $1,000,000 and imprisonment up to 20 years.20U.S. Department of State Directorate of Defense Trade Controls. DDTC Compliance Actions – Section: Penalties A cybersecurity failure that exposes ITAR-controlled technical data to an unauthorized foreign person is a potential ITAR violation and a CMMC compliance failure at the same time.
On the CMMC side, the primary enforcement lever is contract eligibility. Without a valid CMMC status and a current affirmation in SPRS, you cannot receive award on contracts that include DFARS 252.204-7021. The secondary lever is False Claims Act exposure on any contract where you certified compliance and were not actually compliant.
You also have to meet the 72-hour cyber incident reporting requirement under DFARS 252.204-7012. When you discover a cyber incident affecting covered defense information or your ability to perform operationally critical contract work, you have to report it to the DoD through the DIBNet portal within 72 hours.4eCFR. 48 CFR 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting A missed report compounds the legal exposure.
One Boundary: Fundamental Research
Research designated in writing by a contracting officer as “fundamental research” cannot involve CUI or controlled technology, which puts it outside CMMC entirely. Fundamental research covers basic and applied research at accredited institutions where results are ordinarily published and shared broadly, as opposed to proprietary or restricted work. A DoD contract for that kind of work should not carry the DFARS safeguarding clauses or CMMC requirements.
The exclusion disappears the moment the contract contains publication restrictions, dissemination controls, or access limitations. If the contracting officer will not confirm in writing that the work qualifies as fundamental research, assume it does not and plan for CMMC compliance accordingly. This distinction matters most for university-affiliated research operations that sit at the edge between open science and contract work involving ITAR-controlled technical data.