CMMC compliance and readiness advisory.
Lightbridge Cloud is an independent CMMC compliance readiness advisor for defense contractors preparing for the Cybersecurity Maturity Model Certification. We guide CMMC 2.0 scoping across Levels 1, 2, and 3, NIST 800-171 gap assessment, Level 2 C3PAO assessment preparation, and Level 3 DIBCAC readiness, without acting as a certifying body or a vendor reseller.
Lightbridge Cloud explains the three CMMC 2.0 levels.
CMMC 2.0 organizes requirements into three levels. The applicable level and assessment type depend on what the specific DoD solicitation, contract, or flowdown requirement designates. Lightbridge Cloud helps defense contractors determine which level applies to a given contract and what evidence each one demands.
Level 1: Foundational
When designated by an applicable DoD solicitation, contract, or flowdown, Level 1 covers Federal Contract Information (FCI). It is based on the basic safeguarding practices in FAR 52.204-21, not NIST SP 800-171. Verified through annual self-assessment and affirmation under the current CMMC 2.0 model.
Level 2: Advanced
When designated by an applicable DoD solicitation, contract, or flowdown, Level 2 protects Controlled Unclassified Information (CUI) using the 110 security requirements of NIST SP 800-171 Revision 2. As of this page's August 30, 2026 date, CMMC implementation is paused in Phase 1; Phase I self-assessment requirements remain in force, and current DoD guidance indicates that only Level 1 and Level 2 self-assessments may currently be required. Verify the applicable assessment requirement if the implementation status or contract terms change.
Level 3: Expert
When designated by an applicable DoD solicitation, contract, or flowdown, Level 3 is for DoD's most critical programs and technologies based on enumerated risk factors in 32 CFR 170.5. It adds selected requirements drawn from NIST SP 800-172 on top of the Level 2 baseline. The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) performs the Level 3 assessment, not a C3PAO, only after Final Level 2 (C3PAO) status covering the Level 3 scope has been achieved; that status is a mandatory prerequisite.
Lightbridge Cloud aligns CMMC Level 2 to NIST 800-171 Rev. 2.
CMMC Level 2 is built directly on the 110 security requirements of NIST SP 800-171 Revision 2, the standard for protecting Controlled Unclassified Information in nonfederal systems. Lightbridge Cloud assesses your environment against each requirement and its assessment objectives, then translates the gaps into a remediation plan that an authorized C3PAO can verify.
This work connects to the broader regulatory picture. For the contractual safeguarding and incident-reporting obligations, see our guide to DFARS and NIST 800-171. To understand what counts as protected data in the first place, see our explainer on Controlled Unclassified Information. Clause specifics evolve, so confirm them against acquisition.gov and the NIST publication itself.
The Lightbridge Cloud CMMC readiness path.
Lightbridge Cloud runs CMMC readiness as a structured program, from scoping through the maintenance cadence that keeps a posture defensible between assessment cycles. We prepare contractors for assessment; we do not perform the certifying assessment.
Scoping and CUI Identification
Lightbridge Cloud maps your information flows to determine where FCI and CUI live, who touches them, and which systems fall inside the assessment boundary. Accurate scoping reduces the control footprint before any remediation begins.
Gap Assessment Against NIST 800-171 Rev. 2
We assess your environment against the 110 NIST SP 800-171 Revision 2 requirements that underpin CMMC Level 2, documenting each as met, partially met, or not met, with evidence references aligned to assessment objectives.
System Security Plan and POA&M
Lightbridge Cloud helps you author a System Security Plan (SSP) and, where permitted, a Plan of Action and Milestones (POA&M) that withstand external scrutiny. The SSP supports assessment evidence; a POA&M documents deficiencies and remediation milestones, is prohibited at Level 1, and is only a limited route to Conditional, not Final, Level 2 or Level 3 status.
Remediation and Architecture
We design the enclave, identity, logging, and encryption architecture that closes gaps, including FIPS-validated cryptography and access controls. Vendor selection stays vendor-neutral and fit-driven.
Assessment Readiness
Lightbridge Cloud runs a mock assessment against the published assessment objectives so you enter the applicable assessment path with evidence organized and findings already closed, including preparation for the applicable Level 2 assessment path or, for Level 3, the mandatory Final Level 2 (C3PAO) status covering the Level 3 scope as a prerequisite followed by DIBCAC review. We are an independent readiness advisor, not the certifying body.
Continuous Compliance
CMMC posture decays without maintenance. We establish the monitoring, evidence collection, and annual affirmation cadence that keeps your environment ready between assessment cycles.
Lightbridge Cloud delivers independent, vendor-neutral CMMC advisory.
Lightbridge Cloud accepts no vendor kickbacks and carries no reseller quotas. CMMC tooling, enclave platform, and security-stack recommendations are driven by control coverage and fit, not by commission. Where a defense contractor relies on a managed cloud platform such as AWS GovCloud or Microsoft Azure Government, we advise on configuration and control mapping without an obligation to favor any single offering. NIST SP 800-171 Revision 2 requirement 3.13.11 / CMMC SC.L2-3.13.11 specifically requires FIPS-validated cryptography when it is used to protect the confidentiality of CUI, not just a strong algorithm; see our guide on FIPS 140-2 and 140-3 validated cryptography for what to verify.
CMMC scope often reaches finance, project, and ERP systems where Controlled Unclassified Information flows, and defense contractors face separate accounting-system expectations under DCAA oversight. For that accounting-system angle, Lightbridge ERP maintains a guide to DCAA-compliant accounting.
Lightbridge Cloud separates CMMC from FedRAMP.
CMMC governs how defense contractors protect federal information on their own systems. FedRAMP authorizes cloud service offerings sold to United States federal agencies. The two programs are frequently confused because both draw on NIST control families, but they have different authorities, scopes, and assessment paths. If your organization sells a cloud service to agencies rather than performing on defense contracts, see our FedRAMP readiness advisory.
Frequently asked questions.
What is CMMC and who needs it?
CMMC, the Cybersecurity Maturity Model Certification, is the United States Department of Defense framework for verifying that defense contractors and subcontractors protect sensitive federal information. Organizations in the Defense Industrial Base may be subject to CMMC when an applicable DoD solicitation, contract, or flowdown requirement says it applies. Handling Federal Contract Information or Controlled Unclassified Information alone does not impose a CMMC level or assessment type, so confirm the specific requirement against the official DoD CIO and acquisition.gov sources.
How many levels does CMMC 2.0 have?
CMMC 2.0 defines three levels, but the applicable level and assessment type are designated through the specific DoD solicitation, contract, or flowdown requirement. Level 1 (Foundational) is based on the basic safeguarding practices in FAR 52.204-21 and covers Federal Contract Information. Level 2 (Advanced) aligns to the 110 security requirements of NIST SP 800-171 Revision 2 and protects Controlled Unclassified Information. Level 3 (Expert) is for DoD's most critical programs and technologies based on enumerated risk factors in 32 CFR 170.5, adds selected requirements drawn from NIST SP 800-172, and is assessed by DCMA's DIBCAC, not a C3PAO, only after Final Level 2 (C3PAO) status covering the Level 3 scope has been achieved; that status is a mandatory prerequisite.
What is a C3PAO and does Lightbridge Cloud certify CMMC?
A C3PAO is a CMMC Third-Party Assessment Organization authorized to conduct CMMC Level 2 certification assessments. Lightbridge Cloud is an independent readiness advisor and does not issue CMMC certifications. An authorized C3PAO performs the Level 2 certifying assessment; DIBCAC performs the Level 3 assessment, not a C3PAO, but Final Level 2 (C3PAO) status covering the Level 3 scope is a mandatory prerequisite before that DIBCAC assessment. We prepare your organization so that assessment goes smoothly, and we stay vendor-neutral throughout.
How does CMMC relate to NIST 800-171 and DFARS?
CMMC Level 2 is built on the 110 security requirements in NIST SP 800-171 Revision 2. DFARS clause 252.204-7012 applies when included in a contract or subcontract involving covered defense information, rather than to every contractor that handles CUI. It requires safeguarding measures and reporting to DoD within 72 hours of discovery of a cyber incident affecting a covered contractor information system or the covered defense information residing therein, or affecting the contractor's ability to perform contract requirements designated as operationally critical support and identified in the contract, while DFARS 252.204-7019 and 252.204-7020 address the related assessment and access mechanisms. See our DFARS and NIST 800-171 guide at /guides/dfars-nist-800-171, and verify clause specifics against acquisition.gov.
How long does CMMC Level 2 readiness take?
Timelines vary with the size of your environment, the maturity of existing controls, and the scope of Controlled Unclassified Information you handle. Many organizations spend several months on scoping, remediation, and documentation before they are ready for a C3PAO assessment. Lightbridge Cloud begins with a gap assessment so the effort is sized to evidence, not guesswork.
What is the difference between CMMC readiness and FedRAMP?
CMMC governs how defense contractors protect federal information on their own systems. FedRAMP authorizes cloud service offerings sold to United States federal agencies. They are distinct programs with different scopes and authorities, though both draw on NIST control families. If you sell a cloud service to agencies, see our FedRAMP readiness page at /services/fedramp-readiness.
Does CMMC affect my accounting and ERP systems?
It can. If Controlled Unclassified Information flows through finance, project, or ERP systems, those systems may fall inside your assessment boundary. Defense contractors also face separate accounting-system expectations under DCAA oversight. For the accounting-system angle, Lightbridge ERP maintains a DCAA-compliant accounting guide at https://lightbridgeerp.com/guides/dcaa-compliant-accounting.
How does Lightbridge Cloud stay vendor-neutral on CMMC?
Lightbridge Cloud accepts no vendor kickbacks and carries no reseller quotas, so tooling and platform recommendations are driven by fit and control coverage, not commission. We advise on readiness across cloud platforms and security tools without an obligation to steer you toward any single vendor.
This page is general guidance, not legal, audit, or accounting advice. CMMC, DFARS, NIST, and related requirements change. Verify specifics against the official sources, including acquisition.gov, the DoD CIO and OUSD(A&S), NIST, the NARA CUI Registry, DCSA, and, for export controls such as ITAR and EAR, DDTC and BIS.
AWS, GovCloud, Microsoft, Azure, Deltek, Costpoint, and Unanet are trademarks of their respective owners. Lightbridge Cloud is independent and is not affiliated with, endorsed by, or a partner-tier reseller of these vendors.
Start your CMMC readiness assessment.
We scope your environment, assess it against NIST 800-171, and deliver a remediation roadmap for the applicable assessment path. For Level 3, Final Level 2 (C3PAO) status covering the Level 3 scope is a mandatory prerequisite before DIBCAC review.