The Defense Industrial Base (DIB) has been a frequent target of highly sophisticated cyber adversaries, non-state actors, and hostile nation-state actors. The primary purpose of these attacks is to steal sensitive defense information and critical technologies being developed within the DIB. To address these risks and strengthen cybersecurity across the DIB, the Department of Defense (DoD) introduced Cybersecurity Maturity Model Certification (CMMC) 1.0 in 2020. Before CMMC, DoD contractors and subcontractors were responsible for self-assessing their compliance readiness with cybersecurity requirements. However, CMMC 1.0, on the other hand, required covered organizations to undergo independent assessments conducted by Certified Third-Party Assessment Organizations (C3PAOs).
Based on the industry feedback, CMMC 2.0 was released in November 2021. The new framework decreased the number of maturity levels from five to three. Its requirements are closely aligned with current NIST cybersecurity requirements, streamlining compliance and improving cybersecurity responsibility throughout the DIB. CMMC 2.0 will be implemented in four phases, as per the details mentioned below. The final phase is expected to be implemented by Nov, 2028
What is CMMC?
CMMC is the Department of Defense's three-tiered cybersecurity framework for the United States’ Defense Industrial Base. The framework defines a process for cybersecurity measures to be implemented by contractors and subcontractors (nearly 300,000) working with the US DoD that process, store, or transmit sensitive Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
Contractors and subcontractors handling FCI or CUI may be required to achieve the applicable CMMC level as a condition of contract award. The Department of Defense will be implementing CMMC requirements through a four-phase rollout starting in November 2025:
- Phase 1: This is the Initial Implementation phase, which began on 10th Nov 2025. Covered organizations are required to have the applicable CMMC assessment status, including self-assessments or certifications, documented in accordance with DoD requirements.
- Phase 2: Starting on 10th Nov 2026, this phase introduces triennial Level 2 assessments conducted by C3PAOs for prioritized acquisitions, while select programs may continue to permit self-assessments every three years.
- Phase 3: The implementation of Level 3 is planned to begin on 10th Nov 2027. Some DoD contracts will require organizations to achieve CMMC Level 3 compliance. In addition to the C3PAO assessment, triennial Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) assessments are also carried out at this level, due to the highly sensitive nature of the covered information.
- Phase 4: The target of this phase is Full Implementation of CMMC for all DoD contracts, beginning from Nov 10, 2028.

Image: CMMC 2.0 Implementation Phases
Image Source: https://dodcio.defense.gov/cmmc/About/
The Three Levels of CMMC 2.0:
The updated CMMC 2.0 framework consists of three levels instead of the five as required by CMMC 1.0. These levels are designed to protect different types of information based on their level of sensitivity.
|
Level
|
Model
|
Assessment
|
|
Level 1 - Foundational
|
15 Requirements aligned with FAR (Federal Acquisition Regulation) 52.204-21
|
Annual self-Assessment & Affirmation
|
|
Level 2 - Advanced
|
110 Requirements aligned with NIST 800-171 R2
|
Triennial Self-Assessment or C3PAO Assessment (depending on contract requirements) & Annual Affirmation
|
|
Level 3 - Expert
|
134 Requirements
110 aligned with NIST 800-171 R2
24 based on NIST SP 800-172
|
Triennial Government Assessment
|
Media Sanitization Requirements in CMMC 2.0:
For organizations operating within the Defense Industrial Base, implementing secure media disposal practices is an important part of protecting FCI and CUI throughout the information lifecycle and supporting CMMC requirements. In CMMC 2.0, Media sanitization requirements are primarily addressed within Media Protection and Maintenance controls, with additional controls supporting the protection of systems containing sensitive information. These controls require secure sanitization of FCI or CUI from the storage media before disposal, reuse, reassignment, or off-site servicing:
LEVEL 1 CMMC 2.0 MEDIA SANITIZATION REQUIREMENTS:
- Media Protection [MP.L1-3.8.3]
“Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.”
Media Disposal requirement as per section 3.8.3 applies to all system media, digital and non-digital, subject to disposal or reuse. Organizations must sanitize or destroy information system media containing FCI before disposal or release for reuse. Media may include HDDs, SSDs, removable storage devices, backup media, optical media, mobile storage devices, and physical records containing FCI.
LEVEL 2 CMMC 2.0 MEDIA SANITIZATION REQUIREMENTS:
- Maintenance [MA.L2-3.7.3]
“Ensure equipment removed for off-site maintenance is sanitized of any CUI.”
Equipment Sanitization: Under section 3.7.3, contractors must ensure that organizational systems and storage devices containing CUI are properly sanitized before they are removed from organizational facilities for maintenance, repair, replacement, warranty service, refurbishment, or other off-site servicing activities. Prior to the equipment being transferred outside organizational control, contractors must ensure that CUI stored on the system has been appropriately sanitized or otherwise protected in accordance with organizational security procedures.
LEVEL 3 CMMC 2.0 MEDIA SANITIZATION REQUIREMENTS:
Organizations that are seeking Level 3 certification are obliged to comply with all applicable Level 1 and Level 2 requirements. This includes media sanitization controls related to media disposal, reuse, and off-site maintenance. While CMMC Level 3 introduces additional cybersecurity requirements based on NIST SP 800-172 to protect highly sensitive information, it does not add any new media sanitization requirements. Organizations that are seeking Level 3 certification are just required to comply with Level 2 media sanitization controls.
How to Meet CMMC 2.0 Media Sanitization Requirements?
CMMC requires media to be securely sanitized before disposal, or when they will be reused, reassigned, or sent off-site for maintenance. As CMMC requirements are gradually implemented into DoD contracts, covered businesses should develop documented and auditable media sanitization processes in accordance with recognized standards such as NIST SP 800-88 Rev 2. In addition to implementing technical controls, organizations must maintain evidence demonstrating that media sanitization activities are performed consistently and in accordance with documented procedures. During an assessment for CMMC, the C3PAOs may review organizational policies, procedures, and records of sanitization to determine whether applicable media sanitization requirements have been implemented effectively.
Software like BitRaser helps organizations support these media disposal requirements set by CMMC 2.0 by securely sanitizing storage media in accordance with NIST SP 800-88 and IEEE 2883 guidelines and generating tamper-proof erasure certificates and audit-ready reports.