• Skip to primary navigation
  • Skip to main content
Dean Dorton – CPAs and Advisors
  • Services
        • Audit & Assurance
          • Audits, Reviews & Compilations
          • ESG Programs & Reporting
          • Internal Audit
          • International Financial Reporting
          • Lease Accounting Managed Services
          • Peer Review Services
          • SOC Reporting
        • Family Office
        • Consulting & Advisory
          • Business Valuation Services
          • Forensic Accounting
          • Fractional CFO
          • Litigation Support
          • Matrimonial Dissolution
          • Merger & Acquisition
          • SEC Services
          • Succession Planning
          • Transaction Advisory Services
          • Whistleblower Hotline
        • Outsourced Accounting
        • Private Wealth
        • Healthcare Consulting
          • Finance
          • Health Systems Operational Transformation
          • Medical Billing and Credentialing
          • Risk Management & Compliance
          • Strategic Growth for Private Practices
          • Strategy and Strategy Implementation
          • Technology & Data Analytics
        • Tax
          • Business Tax
          • Cost Segregation Studies
          • Credits and Incentives
          • Estates and Trusts
          • Individual Tax
          • International Tax
          • SEC Provision and Compliance
          • State and Local Tax
        • Technology & Cybersecurity
          • Accounting Software
          • Cybersecurity
            • Cybersecurity Assessments
            • Cybersecurity Scorecard Assessment
            • Security Awareness Training
            • Virtual Information Security Office
          • Data Analytics & AI
          • IT Audit & Compliance
            • Cybersecurity Maturity Model Certification (CMMC)
            • Data Privacy Laws
            • SOC Reporting
          • IT Infrastructure & Cloud Solutions
            • Automation
            • Backup and Disaster Recovery
            • Cloud Strategy
            • Data Center
            • Enterprise Network
            • Network Security
            • Phone and Video Conferencing
            • User Identity Management Solutions
            • Webex
          • Managed IT Services
  • Industries
        • Construction
        • Distilleries and Craft Breweries
        • Energy and Natural Resources
        • Equine
        • Financial Institutions
        • Government
        • Healthcare
        • Higher Education
        • Life Sciences
        • Manufacturing and Distribution
        • Nonprofit
        • Real Estate
  • Insights
    • Articles
    • Guides
    • Case Studies
  • Events
  • Company
        • News
        • Our Team
        • Experiences
        • Careers
          • College Students
          • Experienced Professionals
        • Locations
        • Lexington, KY

          250 West Main Street
          Suite 1400
          Lexington, KY 40507
          859-255-2341

        • Louisville, KY

          435 North Whittington Parkway
          Suite 400
          Louisville, KY 40222
          502-589-6050

        • Louisville, KY

          700 North Hurstbourne Parkway
          Suite 115
          Louisville, KY 40222
          502-589-6050

        • Ft. Wright, KY

          810 Wright’s Summit Parkway
          Suite 300
          Fort Wright, KY 41011
          859-331-3300

        • Cincinnati, OH

          312 Walnut Street
          Suite 3330
          Cincinnati, OH 45202
          859-331-3300

        • Blue Ash, OH

          9987 Carver Rd
          Suite 120
          Blue Ash, OH 45242
          513-891-5911

        • West Chester, OH

          9025 Centre Pointe Drive
          Suite 310
          West Chester, OH 45069
          513-985-6240

        • Indianapolis, IN

          5975 Castle Crk Pkwy Dr N
          Suite 400
          Indianapolis, IN 46250
          317-469-0169

        • Raleigh, NC

          4130 Parklake Avenue
          Suite 400
          Raleigh, NC 27612
          919-782-9265

  • Contact Us

CMMC

Article 02.16.2022 Dean Dorton

The dust is still settling on the new CMMC release, officially called CMMC 2.0, and like any new CMMC related announcements we all have questions. Below are answers to some of the easiest, and fortunately the most important questions from a practical perceptive.

Before jumping into the questions, here is a comparison chart between CMMC 1.0 and 2.0.

CMMC 1.0

CMMC 2.0

Cyber Hygiene Levels

Certification Method Required

Cyber Hygiene Levels

Certification Method Required

Level 5 – Advanced

CMMC Third Party Assessor Organization (C3PAO) Certification

Level 3 – Expert

DoD Certification

Level 4 –  Proactive

Level 3 – Good

Level 2 – Advanced

C3PAO Certification

Level 2 – Intermediate

Self-Assessment

Level 1 – Basic

Level 1 – Foundational

Being proactive seemed like the right thing to do, did I waste time and money due to the regulations changing?

No, as long as you haven’t actually been certified as compliant. If you were confident of your CMMC 1.0 level then you know your CMMC 2.0 level. The requirements haven’t changed, just the level number. However, there are discussions on whether additional requirements will be added to levels, but it does not appear they will be reduced.

All the preparation prior to being certified is the same for CMMC 1.0 and CMMC 2.0. Any gap or readiness assessments, information gathering, and remediation are the same for both CMMC versions. The real difference is one may qualify for performing a self-assessment and not need a C3PAO to certify.

How do I know if a self-assessment will meet our organization’s CMMC requirements?

Like CMMC 1.0, the RFPs and contracts will dictate the requirements. Level 1 organizations can perform self-assessments. Level 2 organizations that are not touching information critical to national security will be able to perform self-assessments. For those Level 2 organizations touching information critical to national security, a C3PAO certification will be required.

Has CMMC 2.0 changed the timeline for compliance?

The timeline with CMMC 1.0 was never definitive. The CMMC 2.0 announcement in November 2021 provided a 9 to 24-month timeline to complete the rulemaking process. RFPs and contracts will have CMMC level requirements on them once the rulemaking process is finalized. There is an indication the DoD wants to create incentives for contractors to be ready sooner rather than later.

What does this mean going forward?

The good news is many organizations expecting to pay for a C3PAO certification will not be required to do so. Even If there is no time or resources to perform a self-assessment, utilizing a third party to assist with a self-assessment will be less expensive than going through the C3PAO certification process. There is less liability and risk involved with a self-assessment, which allows third parties to assist with the readiness assessment, remediation, and ongoing assessment support. It is now even easier to get help if your organization falls into the self-assessment requirement.

Explore other IT Audit and Compliance Services we offer.

Contact your Dean Dorton advisor or other professional advisor for more information.
If you don’t have an advisor, but would like to speak with us, send an email to:
insights@deandortonstg.wpenginepowered.com

Filed Under: Cybersecurity, IT Audit, Services, Technology Tagged With: CMMC, CMMC 2.0, CMMC 2.0 Release, CMMC Update, Cybersecurity Maturity Model Certification

Article 06.26.2020 Dean Dorton

Kevin Cornwell, Associate Director of Technology Consulting takes a deep dive into the Department of Defense (DoD)’s new enhancements to the protection of unclassified information within the supply chain for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). 

This webinar contains all the information your organization needs to get certified along with additional resources about the CMMC maturity levels.

Anyone who plays a technology role in their organization including (but not limited to):

  • CIOs/CTOs
  • VPs and Directors of Technology
  • Technology Managers
  • Office Managers

Resources:

  • CMMC Webinar Presentation Slides
  • CMMC Errata
  • CMMC Public Briefing
  • CMMC Appendices
  • Cybersecurity Maturity Model Certification
  • CMMC Model Excel File

Filed Under: Cybersecurity, Services, Technology Tagged With: CMMC, Cybersecurity, Cybersecurity Maturity Model Certification, Webinar

  • Services
    • Outsourced Accounting
    • Audit & Assurance
    • Tax
    • Consulting & Advisory
    • Technology & Cybersecurity
    • Family Office
    • Wealth Management
  • Industries
  • Company
  • Locations
  • Careers
  • Insights
  • Events
  • Contact Us
facebook Dean Dorton - CPAs And Advisors On Facebook twitter twitter linkedin Dean Dorton - CPAs And Advisors On LinkedIn youtube Dean Dorton - CPAs And Advisors On YouTube

The matters discussed on this website provide general information only. The information is neither tax nor legal advice. You should consult with a qualified professional advisor about your specific situation before undertaking any action.

© 2026 Dean Dorton Allen Ford, PLLC. All Rights Reserved