---
title: How to prepare for CMMC
url: https://www.medius.com/blog/how-to-prepare-for-cmmc/
updated: 2025-03-04T03:43:43Z
---
[Back to Blog](https://www.medius.com/blog/)

                                Procurement

6.23.2020

# How to prepare for CMMC

The US Department of Defense is planning to implement ‘Cybersecurity Maturity Model Certification’ (CMMC) in 2020. The new framework comes as the Department of Defense (DoD) plan to push defense industrial base (DIB) organizations to improve their cybersecurity infrastructure and procedures.

In this blog post, we’ll discuss the details of the new legislation, what it means for you and show you how to prepare your organisation for its rollout planned later this year.

## What is the CMMC legislation?

The DoD has created new legislation to encourage a high standard of security when DIB firms distribute controlled unclassified information (CUI) within the supply chain; as breaches of confidential information pose risks to national security and cost the U.S. economy [$600 billion a year](https://landing.exostar.com/cmmc-v1-is-here-what-does-this-mean-for-nist-sp-800-171-and-members-of-the-defense-industrial-basehs_previewytjnwkso-26673392108?utm_campaign=CMMC%20PIM%20Webinar_PostEvent&amp;utm_content=120111198&amp;utm_medium=social&amp;utm_source=twitter&amp;hss_channel=tw-1469806519).

CMMC aims to create a unified standard or cybersecurity throughout this industry, outlining the security requirements to trade within the aerospace and defense sector.

The legislation will work on a tiering system with five levels of CMMC approval, certifying organizations with a rating from ‘basic cyber hygiene’ to ‘advanced’.

The five levels are comprised of 171 practices (technical capabilities) and five processes (employee and team procedures) that span 17 domains. This means that if a firm aims to reach a maximum CMMC certification, they must adhere to all practices and processes within tier one to five.

## What does this mean for NIST SP 800-171 contracts?

The [National Institute of Standards and Technology](https://www.nist.gov/) (NIST) special publication 800-171, governed the security capabilities of organizations which handle and share CUI documents.

Due to the large number of contracts listed within NIST SP 800-171, there will be a large crossover period where both CMMC and NIST SP 800-171 will coexist. Once these contracts have come to their conclusion, NIST SP 800-171 will be terminated, replaced by CMMC.

Whilst CMMC is being implemented for DIB organizations, you’re required to adhere to guidelines outlined within NIST SP 800-171 until the DoD retire that legislation when CMMC is fully adopted. So, any company that accesses and handles CUI, is still required to self-assess their cybersecurity capabilities - confirming that they meet all 110 security controls of NIST SP 800-171 or must have a [Plan of Actions and Milestones](https://nvd.nist.gov/800-53/Rev4/control/PM-4) (POA&M).

## How is CMMC different to NIST SP 800-171?

The key difference is that NIST SP 800-171requires firms to follow a number of security procedures mainly related to infrastructure, to achieve accreditations. CMMC however, will work on a tiering system with five ranking levels that aren’t just infrastructure requirements but practice and policy-related. CMMC will also require organizations to test their cybersecurity procedures and risk mitigation practices, recording how well they work, and to provide optimization plans.

## When is CMMC going to be implemented?

The DoD has announced that a elements of CMMC will be mandatory as early as June 2020 – and in certain requests for proposals (RFP) by September 2020.

Due to varying cybersecurity requirements for unique RFIs and RFPs, the CMMC tiering system allows you to specify to what tier contractors in your supply need to adhere to. Initially, the DoD is planning to roll out the first contracts with mandatory CMMC certification for those with low-security requirements.

## What do I need to do to get CMMC certification?

All CMMC accreditations will be conducted by independent third-party organizations, requiring your organisation to organize and conduct CMMC inspections themselves. Before these reviews take place you must specify which level of certification you need, based on the type of contracts you aim to deliver.

Here, we’ve detailed the top-level requirements for each of the CMMC rankings:

- **Level one (Basic Cyber Hygiene):**

Organizations operating with a level one certification perform security measures with an ad hoc manner - only using a predefined system that addresses the 17 practices that are required for the basic security safeguarding specified in [48 CFR 52.204.21](https://www.govinfo.gov/app/details/CFR-2016-title48-vol2/CFR-2016-title48-vol2-sec52-204-21).

- **Level two (Intermediate Cyber Hygiene):**

To achieve level two, organizations must have all of the infrastructure listed in tier one but will need to provide policy and documentation of their cybersecurity practices.

- **Level three (Good Cyber Hygiene):**

Level three certification is very similar to the previous level as it is still based around providing documentation of policies and practices surrounding cybersecurity in your organisation. However, you are required to show how employees and stakeholders intend to comply with CMMC. A plan must be prepared to outline how staff training is conducted, teaching criteria around your missions, goals, project plans, resourcing, required training, and involvement of stakeholders.

At this stage you also need to have all 110 control requirements of NIST SP 800-171, to achieve a level three certification. There are also 13 new practices adopted from various other security standards that are focused around:

- CUI data handling
- Auditing
- Risk assessments and risk mitigation
- Cyber threat response procedures

- **Level four (Proactive):**

The next level is focused on testing and practicing your procedures that you show in levels two and three; running mock scenarios to measure the effectiveness of your plans. Mediators will be examining whether all the correct actions are taken to communicate between the team and appropriate upper-level management.

- **Level five (Advanced/Progressive):**

Once you have passed all of the prior tests, level five will require your organization’s processes to be standardized throughout the company and regular efforts are committed to optimize your procedures. Level five also requires all the practices and infrastructural requirements listed within CMMC to be in place.

## Get prepared with eProcurement

Modern eProcurement technology has widely been out of the reach of Aerospace and Defense companies, because of the inability of these tools to meet government regulations and cybersecurity requirements. Through our close partnership with Exostar we’ve enhanced our eProcurement platform, creating a [secure eProcurement platform](https://www.medius.com/resources/esourcing-managed-events-v-platform/ "secure eProcurement platform") that’s in meets the stringent requirements of defense organizations.

The powerful functionality of web3 can help you to drive huge cost savings throughout the procurement lifecycle, but it’ll also help to centralize your purchasing activities required for CMMC certification.

If you’re conducting research to start your preparations for CMMC, be sure to get in touch with our industry experts who will give you clear guidance on how eProcurement can help. And if you have found this blog post useful, be sure to share it with your colleagues on [Twitter](https://twitter.com/mediusgroup) and [LinkedIn](https://www.linkedin.com/company/medius/).

#### Medius Financial Census 2026

87% of finance pros have ignored suspected fraud. That's just one finding. See what 2,386 finance leaders revealed about fraud, late payments, AI, and the profession's future.

[Get the report](https://www.medius.com/resources/guides-reports/medius-financial-census-2026/ "Medius Financial Census 2026")

#### Ardent Partners' State of AP in 2026

AI is changing what AP teams can do, and fast. Get leading analysts at Ardent Partners' take on where the industry is headed.

[Get the report](https://www.medius.com/resources/guides-reports/ardent-partners-state-of-ap/ "Ardent Partners State of AP")

#### Webinar: Preparing for agentic AI in AP

In this webinar with SSON, see how leading finance teams are moving from automation to autonomous AP, with real governance built in.

[Watch the webinar](https://www.medius.com/resources/events-and-webinars/through-trust-and-governance-sson/ "Through trust and governance SSON")

#### Discover accounts payable benchmarks

Learn the efficiency metrics that matter for AP teams and the benchmarks derived from thousands of Medius customers around the globe.

[Get the report](https://www.medius.com/resources/guides-reports/ap-benchmark-report/ "AP Benchmark Report")

#### Questions about AP automation?

Let's talk through it. A 30-minute conversation with a Medius expert costs you nothing and might save you a lot.

Book a consult

## Related Posts

[8.11.2026
Fraud & Risk
The best AP automation platforms for strengthening payment controls](https://www.medius.com/blog/the-best-ap-automation-platforms-for-strengthening-payment-controls/)

[8.3.2026
AP Automation
Improving freight invoice accuracy with AP automation](https://www.medius.com/blog/improving-freight-invoice-accuracy-with-ap-automation/)

[7.22.2026
AP Automation
How poor supplier data leads to duplicate payments](https://www.medius.com/blog/how-poor-supplier-data-leads-to-duplicate-payments/)

[7.21.2026
AP Automation
What AP automation features help prevent duplicate payments?](https://www.medius.com/blog/what-ap-automation-features-help-prevent-duplicate-payments/)

[7.21.2026
AP Automation
How AP teams can strengthen internal controls to prevent duplicate payments](https://www.medius.com/blog/how-ap-teams-can-strengthen-internal-controls-to-prevent-duplicate-payments/)

[7.17.2026
AP Automation
Why an approved invoice isn’t always ready to pay](https://www.medius.com/blog/why-an-approved-invoice-isn-t-always-ready-to-pay/)

[8.26.2026
Accounts Payable
Best AP automation software features](https://www.medius.com/blog/best-ap-automation-software-features/)

Previous

Next

[View All Posts](https://www.medius.com/blog/)

## Ready to transform your AP?

[Book a Demo](https://www.medius.com/book-a-demo/ "Book a Demo") [Contact Us](https://www.medius.com/contact-us/ "Contact Us")
