CMMC 2.0 — Gap Analysis
Cybersecurity Maturity Model Certification 2.0 — DoD Contractor ComplianceAbout CMMC 2.0
CMMC 2.0 is the US Department of Defense Cybersecurity Maturity Model Certification programme, finalised October 2024 and rolling into contracts through 2025–2028. CMMC 2.0 has three levels: Level 1 (Foundational, 17 basic safeguards from FAR 52.204-21), Level 2 (Advanced, 110 practices aligned with NIST SP 800-171), and Level 3 (Expert, additional practices from NIST SP 800-172). Compliance is a mandatory contract requirement for any DoD supplier handling Federal Contract Information or Controlled Unclassified Information.
Issuing Body
US Department of Defense — Cyber-AB (CMMC Accreditation Body)
Edition
2024
Coverage
3 levels (Foundational, Advanced, Expert) built on NIST SP 800-171 (Level 2 — 110 practices) and NIST SP 800-172 (Level 3 — additional 35 practices).
Typical Users
US Department of Defense (DoD) contractors and the Defense Industrial Base (DIB) handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).
How to use this tool
1. Work through each clause. For each requirement, choose Compliant, Partial, Non-compliant, or leave as Not assessed.
2. Add notes against any requirement to record evidence, gaps, or corrective actions.
3. Click Save progress — data is stored locally in your browser, never uploaded.
4. Export the report as TXT, CSV, JSON or print to PDF for your audit file.
Note: This tool is a guided self-assessment. It does not replace a third-party audit and the authoritative version of the standard must be obtained from the issuing body.
ISO Xpert — Get in touch
UK-based consultancy specialising in management-system gap analysis, training and certification preparation across ISO, API, Halal, GFSI, ESG, cybersecurity and industry-specific standards.
Phone / WhatsApp
Office
71-75 Shelton Street, Covent Garden, London WC2H 9JQ, UK