This is a joint effort between Schellman and risk3sixty. You can find the original post here.
The Cybersecurity Maturity Model Certification (CMMC) has officially shifted from proposed framework to an enforceable requirement for organizations supporting the U.S. Department of Defense (DoD).
With the Final Rule now in effect and contractual mandates accelerating, defense contractors and subcontractors can no longer treat CMMC as a future initiative.
To meet this newly enforceable compliance obligation, defense contractors are increasingly exploring what CMMC implementation requires, what certification entails, and how to maintain compliance once certified.
Through risk3sixty’s advisory services as a Registered Practitioner Organization (RPO) and Schellman’s assessment and certification expertise as a Certified Third-Party Assessment Organization (C3PAO), organizations can navigate the full CMMC journey with clarity.
In this guide, Andrew Parks, Manager, Advisory at risk3sixty, and Jay Molnar, Manager at Schellman, break down CMMC compliance from end to end, including key CMMC dates and milestones, certification assessment phases, and actionable best practices to help your organization prepare, implement, and sustain compliance with confidence.
CMMC is a framework created by the US Department of Defense (DoD) that includes a list of cyber security requirements you must implement if you’re handling federal contract information (FCI) or controlled unclassified information (CUI). CMMC applies to contractors and their supply chain, including subcontractors or the people those contractors are working with, that fulfils DoD contracts.
CMMC is important for DoD contract eligibility and customer trust. CMMC is contractually required for any organization doing business with the DoD that processes, stores, or transmits FCI or CUI.
As CMMC is a prescriptive framework, its Implementation improves security posture and reduces breach and ransomware risk. False CMMC compliance claims can trigger the False Claims Act, resulting in legal exposure, monetary liability, and loss of eligibility for future DoD contracts.
CMMC has been in development since 2019, and the standard’s implementation is evolving and ongoing as the DoD has begun their multi-year, phased rollout.
Key CMMC milestones and dates include:
Over the next several years, CMMC will start significantly impacting the industry and contract eligibility.
The CMMC certification assessment process follows four phases of formal activities:
It’s important to understand what’s involved in each phase as stakeholders often underestimate the amount of time and effort required to achieve full CMMC certification.
Achieving CMMC certification is a significant milestone, but maintaining compliance requires ongoing discipline.
Unlike many other frameworks that require annual third-party assessments, a C3PAO assessment occurs once every three years for CMMC. However, organizations must annually affirm their continued compliance in the SPRS (Supplier Performance Risk System), involving a formal attestation to the DoD that required controls remain implemented and effective.
To support annual attestation for maintaining CMMC compliance, organizations should:
Compliance drift is common across long certification cycles. Competing business priorities, infrastructure changes, or organizational restructuring can gradually move systems away from their originally certified scope. The most successful organizations build CMMC into operational governance, rather than treating it as a one-time initiative.
Many companies leverage independent advisory support to conduct annual internal reviews to provide the Authorized Official with confidence before submitting their SPRS affirmation.
Given the rigor of the CMMC certification process, proper preparation is critical. As an RPO, risk3sixty helps organizations design and operationalize their CMMC programs before formal assessment. Advisory services typically include:
One of the most critical focus areas is scoping because improper scoping — especially “all-in” approaches or convenience-based scope decisions — can dramatically increase assessment burden and risk. The most defensible scopes are:
Organizations that engage advisory support early often reduce assessment friction, avoid rework, and enter the C3PAO phase with greater clarity and confidence.
CMMC is technical, procedural, evidence-driven, and maturity-focused. When you partner with Schellman for your CMMC assessment, you can expect a structured, collaborative process built on deep program expertise and practical guidance.
Schellman was involved at the ground level in the development and rollout of CMMC. As the fifth authorized C3PAO, Schellman performed the first Joint Surveillance Voluntary Assessment alongside the DoD during the early instantiation of the program.
Our history expands beyond experience and provides insight into regulatory intent. Our assessors understand not just what the requirements say, but why they exist and how they are interpreted in practice.
In addition to formal certification assessments, Schellman offers:
This depth allows organizations to navigate certification with clarity and confidence.
Organizations that perform best during CMMC assessment work typically demonstrate:
Best practices to ensure a smoother assessment journey include:
CMMC is a high-stakes certification tied directly to contract eligibility. That pressure can create urgency, but success depends on thoughtful preparation.
By combining risk3sixty’s advisory expertise as an RPO with Schellman’s accredited C3PAO assessment capabilities, organizations can navigate the full CMMC lifecycle from readiness and remediation through certification and ongoing maintenance with a unified, coordinated approach.
CMMC is about building a defensible, sustainable security program aligned to how your organization operates and delivers value within the Defense Industrial Base. With the right preparation and partners, compliance becomes achievable and repeatable. Contact risk3sixty to discuss CMMC advisory services and Schellman to learn more about the certification assessment requirements and process today.
In the meantime, discover additional CMMC insights in these helpful resources:
Andrew specializes in Payment Card Industry (PCI) and CMMC compliance. He has served as a PCI Qualified Security Assessor (QSA) for more than five years and previously held the role of PCI Internal Security Assessor (ISA), bringing his total PCI experience to over a decade. More recently, Andrew has obtained the CMMC certification of Registered Practitioner (RP).Andrew leverages a strong technical background in his work as both a PCI QSA and CMMC advisor. He holds certifications in cloud technologies and Kubernetes (KCNA), enabling him to effectively support clients operating in complex technical environments to achieve and maintain compliance.
Jay is based in Washington, DC, where he focuses on the emerging CMMC program. Prior to joining Schellman in 2021, Jay served as a Senior with Ernst & Young’s Government Contract Services, specializing in NIST SP 800-171 and CMMC compliance. He played a lead role in piloting early DIBCAC High Confidence Assessments under the Joint Surveillance Voluntary Assessment (JSVA) program and continues to support the program as a lead assessor. Jay holds several key certifications, including CISSP, CISA, CMMC Lead CCA, and CCP.