TL;DR: CMMC now determines defense supply chain eligibility by tying compliance to contract-bound evidence, data sensitivity, and assessed control effectiveness rather than self-attestation, according to Cyberhaven. The shift makes visibility, documentation, and continuous enforcement core governance issues for IAM, access control, and audit readiness.
At a glance
What this is: CMMC is a DoD framework that ties defense contractor eligibility to demonstrated cybersecurity controls, with the article emphasizing evidence-based compliance and Level 2 readiness.
Why it matters: It matters because IAM, access control, and data governance teams must prove controls work continuously across FCI and CUI environments, not just on paper.
👉 Read Cyberhaven's complete guide to CMMC compliance and Level 2 readiness
Context
CMMC moves defense supply chain security from self-attestation to assessed evidence, which changes how organizations must prove control effectiveness. For security leaders, the key problem is not just passing an audit, but showing that access, monitoring, and data protection controls operate consistently across the environment.
The identity angle is direct: CMMC readiness depends on knowing who can access controlled data, which accounts are privileged, and whether those access paths are governed well enough to withstand assessment. That makes CMMC a governance problem as much as a compliance one.
Key questions
Q: What breaks when CMMC is treated as a documentation exercise instead of an operating control model?
A: When CMMC is treated as paperwork, organisations usually discover that their controls are inconsistent, their evidence is stale, and their access governance cannot support what the assessment asks for. The biggest failure is assuming policy equals implementation. Assessors look for proof that controls work in normal operations, which means access, logging, and data protection must be continuously evidenced.
Q: Why does CMMC place so much weight on data classification and access mapping?
A: Because the required level and assessment path depend on whether an organisation handles FCI or CUI, not on its size or industry. If teams cannot map where the data lives and who can reach it, they cannot scope the control environment accurately. That makes classification and entitlement visibility foundational, not administrative.
Q: What do organisations get wrong about CMMC Level 2 readiness?
A: The most common mistake is treating readiness as a document review instead of an operating-state problem. Policies, plans, and diagrams matter, but the assessment tests whether controls work in practice and whether evidence supports that claim. Teams that ignore live access patterns, logging, and remediation discipline usually discover their gaps too late.
Q: Who is accountable when a contractor cannot prove CMMC identity controls?
A: The contractor remains accountable, because CMMC shifts eligibility from self-reporting to third-party assessment. If identity controls are incomplete, poorly documented, or not aligned to the target maturity level, the organisation can lose the ability to bid at the contract level it is pursuing.
Technical breakdown
How CMMC ties compliance to evidence
CMMC is built around demonstrated implementation, not policy intent. In practice, that means assessors look for operating controls, supporting documentation, and repeatable evidence that security measures function during normal business operations. For Level 2, the standard aligns closely to NIST SP 800-171, so organisations must show that access control, authentication, logging, and protection measures are both defined and enforced. Temporary fixes rarely survive assessment because the model is designed to test sustainability, not just configuration snapshots.
Practical implication: build evidence collection into daily operations so controls can be shown, not assembled, at assessment time.
Why data sensitivity drives the CMMC level
CMMC does not assign requirements by company size or industry label. It assigns them by the type of information handled, especially Federal Contract Information and Controlled Unclassified Information. That distinction matters because the sensitivity of the data determines the required level, the assessment path, and the evidence standard. This is why data discovery, access mapping, and entitlement review become foundational. If you cannot locate CUI reliably, you cannot scope the control environment accurately, and assessment readiness remains uncertain.
Practical implication: establish authoritative data classification and access mapping before you attempt to scope CMMC controls.
What continuous compliance means for identity and access controls
CMMC pushes organisations away from one-time remediation and toward continuous control operation. That has direct consequences for IAM and PAM because assessor confidence depends on whether access is limited, monitored, and justified over time. Credential compromise, standing privilege, and weak identity governance all undermine the evidence model, because a control that is rarely reviewed is hard to defend as consistently effective. The compliance burden therefore overlaps with identity governance, not just technical security.
Practical implication: treat access reviews, privileged account governance, and monitoring as continuous control evidence rather than periodic compliance tasks.
Threat narrative
Attacker objective: The objective is to reach sensitive defense data or trusted contractor environments with access that is broad enough to create operational and contractual impact.
- Entry occurs when defense supply chain organisations expose poorly scoped access to FCI or CUI across systems, users, and third-party providers.
- Escalation follows when standing privilege, weak identity governance, or incomplete access review expands the blast radius of a compromise.
- Impact appears when the organisation cannot prove control effectiveness, delaying contract eligibility, remediation, or assessment approval.
NHI Mgmt Group analysis
CMMC is increasingly an identity governance problem disguised as a compliance framework. The article treats certification as evidence of operational security, which is correct, but the control reality is that access paths, privileged accounts, and data scoping determine whether evidence can be trusted. For IAM and PAM teams, the issue is not only whether controls exist, but whether they are continuously provable under assessment conditions.
Evidence-first compliance: CMMC rewards organisations that can show control operation over time, not those that can assemble documentation after the fact. That creates a stronger alignment with continuous monitoring, access review, and entitlement governance. It also exposes the weakness of security programmes that still rely on periodic snapshots, because assessment-grade evidence has to reflect real operating conditions. Practitioners should assume the audit will test day-to-day control durability, not exception handling.
Data scoping is the real prerequisite to CMMC readiness. If teams cannot identify where FCI and CUI live, who can reach them, and which third parties sit inside that path, every downstream control becomes harder to validate. This is where CMMC intersects with identity verification, privileged access, and third-party governance in a way that goes beyond generic compliance language. The practical conclusion is simple: classify the data, map the access, then prove the controls.
Standing access is the hidden compliance risk CMMC surfaces. Many organisations think of certification as a documentation exercise, but persistent access entitlements are what undermine both security posture and assessment confidence. A programme with weak offboarding, broad service account permissions, or stale subcontractor access will struggle to demonstrate sustained control effectiveness. Security leaders should read CMMC as pressure to eliminate unmanaged privilege, not just complete a checklist.
Named concept: assessment-grade identity governance. This is the discipline of making access, privilege, and evidence verifiable enough to withstand contractual scrutiny. It matters because CMMC is not only asking whether security controls exist, but whether the organisation can prove who had access, why they had it, and whether that access remained appropriately constrained. For defence contractors, that is becoming a board-level governance requirement.
What this signals
Assessment-grade identity governance will become a useful operating concept for contractors that live under CMMC. The practical challenge is no longer whether controls exist in principle, but whether they can be shown to work when contract language, evidence collection, and entitlement review all intersect. That pushes IAM and PAM teams closer to compliance operations, especially where privileged accounts and third-party access touch CUI.
The next maturity step is to make access evidence continuous, not episodic. Organisations that still rely on quarterly review cycles or manual screenshots will struggle as CMMC expectations move deeper into procurement and renewal decisions. A tighter link between access governance, audit logging, and data scoping will reduce assessment friction and improve programme resilience.
For practitioners
- Map FCI and CUI to identity paths Identify where Federal Contract Information and Controlled Unclassified Information move, which accounts can reach them, and which systems store or process them. Tie the map to access paths, not just data labels, so scope decisions reflect real entitlement exposure.
- Convert access reviews into evidence workflows Turn periodic access reviews into recurring evidence-gathering processes that capture approvals, exceptions, revocations, and privileged access changes. Use the review output as assessment-ready proof that controls are functioning over time.
- Reduce standing privilege before assessment windows open Audit privileged accounts, service accounts, and subcontractor access for unnecessary persistence, then remove or constrain access that is not tied to a current contract need. Standing privilege is difficult to defend during an assessment and increases blast radius if compromised.
- Align third-party access with contract scope Review MSP, SaaS, and cloud-provider access where they store, process, or transmit CUI. Require evidence that their access and security posture support the required CMMC scope, rather than assuming vendor status alone is sufficient.
Key takeaways
- CMMC shifts defence supply chain security toward verifiable evidence, which makes access governance and data scoping core compliance tasks.
- The article reinforces that Level 2 readiness depends on sustained control operation, not last-minute documentation or assessment staging.
- The most material control gap is unmanaged access, especially where privileged, third-party, or hard-to-scope identities can reach CUI.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Access control and least privilege are central to CMMC readiness. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege underpins the identity and access controls described in the guide. |
| MITRE ATT&CK | TA0006 , Credential Access; TA0004 , Privilege Escalation | Credential compromise and privilege escalation are the identity risks that weaken CMMC evidence. |
| ISO/IEC 27001:2022 | A.5.15 | Access control governance aligns with the article's emphasis on enforced and documented controls. |
| CIS Controls v8 | CIS-5 , Account Management | Account lifecycle management is critical when proving control durability for CMMC. |
Use ATT&CK to test whether credential and privilege pathways could undermine assessment confidence.
Key terms
- CMMC: CMMC is a US Department of Defense cybersecurity certification model for contractors that handle controlled information. It uses maturity levels and control requirements to determine whether an organisation can bid on or support defence work, with identity controls playing a central role in readiness.
- Controlled Unclassified Information: Controlled Unclassified Information, or CUI, is sensitive federal information that must be protected according to defined handling rules outside federal systems. For practitioners, the key issue is not only storage security but also proving that every system, identity, and data path in scope preserves those rules.
- Assessment-grade identity governance: Assessment-grade identity governance is the discipline of making access, privilege, and identity evidence reliable enough to stand up in a formal security assessment. It requires accurate entitlement mapping, revocation discipline, and continuous proof that access is limited, justified, and monitored.
What's in the full article
Cyberhaven's full guide covers the operational detail this post intentionally leaves for the source:
- Step-by-step CMMC Level 1, Level 2, and Level 3 requirement breakdowns for contractors and subcontractors
- The 110 control mapping to NIST SP 800-171 for teams preparing formal Level 2 assessments
- Assessment-path guidance for self-assessment versus third-party validation across contract types
- Practical readiness checklist items covering evidence collection, monitoring, and policy documentation
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, identity lifecycle, secrets management, and workload identity. It is designed for practitioners who need to connect identity controls to broader security and compliance programmes.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org