Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

CMMC Compliance for Universities: A Guide for Research Institutions

A guide for research administrators on how CMMC 2.0 applies to universities, research institutes, UARCs, and FFRDCs that handle DoD-funded controlled unclassified information (CUI) — levels, scoping, assessment paths, and the phased rollout.

The Cybersecurity Maturity Model Certification (CMMC) program is a Department of Defense (DoD) requirement that verifies contractors and subcontractors are actually implementing the cybersecurity controls they claim to have in place before they can hold DoD contracts involving sensitive information. It is not limited to traditional defense contractors. Any university, research institute, Federally Funded Research and Development Center (FFRDC), or University Affiliated Research Center (UARC) that receives, generates, or transmits Controlled Unclassified Information (CUI) under a DoD-funded contract or subaward is potentially in scope. This guide explains what CMMC 2.0 actually requires, why it reaches into university research offices and IT departments rather than just prime defense contractors, and what a research administrator needs to know to scope the problem correctly.

What CMMC 2.0 Is

CMMC is a certification framework layered on top of cybersecurity requirements that have applied to DoD contractors since 2017. Under DFARS clause 252.204-7012, any contractor handling CUI has long been required to implement the 110 security requirements in NIST SP 800-171 and to self-attest to that compliance. CMMC’s purpose is to replace unverified self-attestation with an actual assessment — self-conducted, third-party, or government-led, depending on the sensitivity of the information and the contract — so DoD can have confidence that a contractor’s claimed security posture is real before CUI is shared with them.

The CMMC Program was finalized in two stages: the program rule itself, codified at 32 CFR Part 170, was published in the Federal Register on October 15, 2024 and took effect December 16, 2024, establishing the certification levels and assessment mechanics. A second rule then had to amend the acquisition regulations that actually insert CMMC into contracts — that rule, covering 48 CFR Parts 204, 212, 217, and 252, was published September 10, 2025 and became effective November 10, 2025. It added the contract clause DFARS 252.204-7021 (requiring an offeror to have a current CMMC status at the required level before award) and the solicitation provision 252.204-7025. From that date, DoD began inserting these requirements into new solicitations and contracts, phased in over roughly three years.

Why CMMC Reaches Universities, Not Just Defense Contractors

CMMC applies wherever the contract does, and DoD-funded research contracts and subcontracts are contracts. A university does not need to think of itself as “a defense contractor” for CMMC to apply — it needs to ask whether any DoD-funded award, prime or sub-tier, flows CUI to a specific lab, center, or program. Points where this commonly happens on a campus include:

  • Direct DoD contracts or grants (Army, Navy, Air Force, DARPA, Missile Defense Agency, and similar) where the statement of work or a data requirement specifies CUI categories such as export-controlled technical data, controlled technical information, or certain unclassified but sensitive program information.
  • Subcontracts under a defense prime, where the flow-down of DFARS 252.204-7012/7021 into the subaward brings the same CUI-handling obligations onto the university lab performing the work.
  • University Affiliated Research Centers (UARCs) and DoD-sponsored FFRDCs, which are explicitly within CMMC’s intended scope because of their direct, ongoing DoD sponsorship.

Crucially, CMMC does not automatically apply to a university’s entire IT environment. It applies to the specific program, lab, or system boundary that actually touches CUI under the relevant contract — see scoping below.

The Three CMMC Levels — and Which One a Research Program Is Likely To Need

CMMC 2.0 has three levels, each keyed to the sensitivity of the information a contract involves:

  • Level 1 (Foundational) — applies where a contract involves only Federal Contract Information (FCI), not CUI. Requires the 15 basic safeguarding requirements from FAR 52.204-21. Annual self-assessment.
  • Level 2 (Advanced) — applies where a contract involves CUI. Requires implementing all 110 security requirements of NIST SP 800-171. Depending on the contract, this is verified by either self-assessment or a third-party assessment performed by a Certified Third-Party Assessment Organization (C3PAO), reassessed on a triennial cycle with annual affirmation in between.
  • Level 3 (Expert) — reserved for the highest-priority programs, layering 24 additional requirements from NIST SP 800-172 on top of the 110 from SP 800-171 (134 total). Assessed by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), a DoD entity, not a commercial C3PAO.

Most university research programs that handle CUI under a DoD award will be scoped to Level 2 — the exact level is dictated by the contract, not chosen by the institution. A single university can simultaneously have some awards that involve only FCI (Level 1), some that involve CUI (Level 2), and no involvement at all in most of its non-DoD-funded research.

Scoping: Why This Is a Program-Level Problem, Not an Institution-Wide One

The most consequential decision a research institution makes in a CMMC engagement is how it draws the assessment boundary. DoD guidance and common practice both support scoping CMMC to the specific systems, networks, and personnel that actually process, store, or transmit CUI for the relevant contract — commonly implemented as a dedicated, segmented enclave (a separate network segment, sometimes cloud-hosted, with its own access controls, isolated from the general campus network) rather than an attempt to bring an entire university’s IT environment into compliance. Enclaving is the practical strategy most research-intensive institutions use to keep a manageable, auditable boundary instead of treating every campus system as in-scope. Getting this boundary wrong in either direction — too narrow, which misses in-scope CUI flows, or too broad, which multiplies cost and assessment burden for no security benefit — is the single most common reason a university CMMC effort stalls.

NIST SP 800-171 and the Underlying Controls

NIST SP 800-171 is the control catalog CMMC Level 2 assesses against — 110 requirements across 14 families (access control, incident response, media protection, system and communications protection, and so on) that were originally written for any non-federal system that processes CUI, independent of CMMC. CMMC did not create these requirements; DFARS 252.204-7012 already required them starting in 2017. What CMMC changes is verification: instead of a contractor’s own attestation, a Level 2 assessment produces a scored, time-stamped result that DoD (or a C3PAO) can rely on before award.

Assessment Paths: Self-Assessment, C3PAO, and DIBCAC

Which assessment path applies depends on level and, within Level 2, on the sensitivity DoD assigns to the specific program:

  • Level 1 — annual self-assessment, submitted by a senior company official through DoD’s Supplier Performance Risk System (SPRS).
  • Level 2, self-assessment track — for a defined subset of Level 2 programs, annual self-assessment with a senior official affirmation is sufficient.
  • Level 2, certification track — for most Level 2 programs, a triennial assessment performed by an accredited C3PAO, with an annual affirmation required in the intervening years.
  • Level 3 — a triennial government-led assessment performed by DIBCAC, on top of an already-passed Level 2 C3PAO certification, again with annual affirmation.

A university preparing for a C3PAO or DIBCAC assessment should expect the same evidentiary rigor common to any formal security audit: a current System Security Plan (SSP), a Plan of Action and Milestones (POA&M) for any unmet controls, and objective evidence (configuration exports, logs, policy documents) for each of the 110 (or 134) requirements — not just a completed checklist.

Implementation Timeline

DoD is phasing CMMC into new solicitations over roughly three years from the November 10, 2025 effective date of the acquisition rule, rather than requiring every current contractor to certify overnight. Early in the rollout, DoD contracting officers began including Level 1 and Level 2 self-assessment requirements in applicable new solicitations; third-party Level 2 certification and Level 3 requirements are being phased in over the following phases, with DoD’s stated intent to reach full applicability across relevant new contracts and task orders within 36 months of the effective date. Existing contracts are not retroactively reopened by the rule on day one — CMMC requirements are added as solicitations and contract actions occur, which means a university’s actual deadline is contract-specific: it depends on when the relevant award, option, or modification comes up, not on a single fixed calendar date. Research offices should treat “check every active and pending DoD award for a CMMC level requirement” as an ongoing compliance task, not a one-time project.

How CMMC Relates to Adjacent Research-Security Obligations

CMMC does not sit in isolation — universities managing federally sponsored research typically already have several adjacent compliance obligations, and it helps to keep them distinct:

  • NISPOM (32 CFR Part 117) governs classified information under a facility security clearance, a different and generally more stringent regime than CMMC’s CUI-focused requirements. See CASRAI’s guide to 32 CFR Part 117 (NISPOM) for universities with classified research for how the two compare.
  • Export control (ITAR/EAR) governs the transfer of controlled technical data and items to foreign persons or countries, and frequently overlaps with CUI in practice — export-controlled technical data is one of the CUI categories a DoD contract may specify. See CASRAI’s guide to export control (EAR/ITAR) and international research collaboration.
  • Institutional research security programs, required under NSPM-33 for larger federal research funding recipients, are a broader policy and disclosure framework (foreign talent programs, conflict-of-interest/commitment disclosure, cybersecurity awareness training). See CASRAI’s dictionary entries on research security policy and the JASON Report on research security for background on how that framework developed.
  • Fundamental research — publicly releasable, unrestricted basic research — is generally treated differently from controlled research under both export-control and CUI frameworks, but a project loses that treatment the moment it involves CUI or export-controlled data under contract, regardless of how the underlying science is otherwise characterized. Institutions should not assume “this is basic research” resolves a CMMC scoping question on its own; the contract terms and the actual information involved control the analysis.

Practical Steps for a Research Administration Office

  1. Inventory DoD-funded awards across the institution, including subawards under non-DoD primes and UARC/FFRDC arrangements, and flag any that reference DFARS 252.204-7012, 252.204-7021, CUI, or a required CMMC level.
  2. Identify where CUI actually flows for each flagged award — which PI, lab, server, and data path — rather than assuming an institution-wide answer.
  3. Scope a defined enclave around those systems in coordination with campus IT/information security, sized to the actual CUI footprint rather than the whole campus network.
  4. Gap-assess against NIST SP 800-171 for any Level 2 program, and build a System Security Plan and POA&M for unmet controls.
  5. Confirm the required assessment path (self-assessment vs. C3PAO vs. DIBCAC) directly against the contract language or with the contracting officer — do not assume a level.
  6. Track re-affirmation and reassessment cycles (annual affirmation, triennial reassessment) as an ongoing compliance calendar item, not a one-time certification event.

Frequently Asked Questions

Does CMMC apply to our university if we don’t hold a DoD contract directly?

It can. CMMC obligations flow down through subcontracts — if your institution performs work under a subaward from a defense prime, and that subaward involves CUI, the CMMC requirement in the prime contract typically flows down to your institution through the subcontract terms.

Is CMMC the same thing as NISPOM or a facility security clearance?

No. CMMC governs CUI on unclassified systems under DFARS-covered contracts. NISPOM (32 CFR Part 117) governs classified information and requires a facility security clearance — a separate, generally more demanding regime. An institution could need one, both, or neither, depending on what kinds of information its DoD-funded work actually involves.

Do we need to certify our entire university, or just the program that holds the DoD award?

Common practice — and the scoping principle behind CMMC assessments generally — is to certify the specific system boundary that actually processes, stores, or transmits CUI for the relevant contract, frequently implemented as a segmented enclave, not the institution’s entire IT environment.

What happens if a university can’t achieve the required CMMC level in time?

A contractor without the CMMC status level a solicitation requires is generally ineligible for award of that contract. For an already-active award, losing or failing to maintain the required status can put continued performance and funding at risk under the terms of that specific contract; a POA&M can address some but not all situations, and the details depend on contract language and the specific DoD component involved.

What’s the difference between the underlying security controls and CMMC itself?

The security controls — NIST SP 800-171’s 110 requirements for Level 2 — have applied to DoD contractors handling CUI since DFARS 252.204-7012 took effect in 2017. CMMC did not add new controls; it added a verification and assessment layer (self-assessment, C3PAO, or DIBCAC) to confirm those controls are actually implemented rather than only self-attested.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →