Aller au contenu
Mise en œuvre
19 min de lecture

90 Day ISO First CMMC Roadmap for U.S. Contractors

support@ismscalculator.com|

Contract team comparing ISO and CMMC readiness

CMMC and ISO 27001 overlap substantially, but ISO 27001 does not replace CMMC for DoD contracts. CMMC is a mandatory U.S. Department of Defense certification tied to procurement, while ISO 27001 is a voluntary, risk-based standard for building an information security management system. Use ISO as your foundation, then map and close the CMMC-specific gaps before you bid.


TL;DR:

  • Organizations with ISO 27001 can leverage the extensive overlap with CMMC Level 2, but they still need to address specific technical mandates like MFA and cryptography.
  • CMMC Level 2 requires formalized artifacts such as a detailed System Security Plan and Plan of Action, which ISO certification does not automatically provide.
  • Building a CUI boundary and implementing tailored operational controls are critical gaps to close beyond the basic ISO governance, especially for high-risk DoD programs.
  • Assessment methods differ: ISO involves an independent certification process every three years, while CMMC relies on self or third-party audits with ongoing surveillance.
  • Starting with ISO prior to CMMC readiness reduces costs and resource duplication, but contractors must still prepare for CMMC’s prescriptive technical controls and documentation requirements.

Ismscalculator
Estimate Your ISO 27001 Effort
Build a tailored estimate using your company size, industry, and security maturity before committing resources to your ISO 27001 foundation.
Estimate your effort

Table of Contents

What CMMC Covers and Who Needs It

CMMC exists because the Department of Defense needed a way to verify that contractors actually protect two categories of sensitive information: Federal Contract Information (FCI), which is data not intended for public release that you generate or receive while performing a government contract, and Controlled Unclassified Information (CUI), which carries stricter handling rules under federal law. Without a certification requirement, the DoD had no reliable way to confirm that subcontractors deep in the supply chain were following through on security promises made in self-attestations.

The program has three levels, and where you land depends on what kind of information passes through your systems.

  • Level 1 covers basic safeguarding of FCI and requires an annual self-assessment against a short set of practices.
  • Level 2 applies to contractors handling CUI and aligns to NIST SP 800-171 Rev 2, a 110-practice catalog covering access control, incident response, and system monitoring.
  • Level 3 is reserved for the highest-risk programs and layers in selected practices from NIST SP 800-172 on top of everything in Level 2.

Award eligibility runs through the Supplier Performance Risk System (SPRS), where contracting officers check your CMMC status before making an award, and through a CMMC Unique Identifier (UID) tied to your assessment record. Acquisition rules require contracting officers to verify this status before an offeror can win a contract that specifies a CMMC level.

As of this writing, the DoD CIO suspended the Phase 2 transition to mandatory third-party (C3PAO) Level 2 assessments, limiting allowable designations to Level 1 Self and Level 2 Self during a 60-day review. Existing DFARS safeguarding clauses remain in force regardless, so contractors should still keep self-assessments, system security plans, and plans of action current rather than waiting out the pause.

What ISO 27001 Certification Actually Verifies

ISO/IEC 27001:2022 is a management system standard, not a fixed checklist. It asks you to build an Information Security Management System (ISMS): a structured, risk-based program for identifying threats to your information assets, deciding how to treat them, and proving the treatment is working over time. The heart of the standard is the risk assessment, which feeds a Statement of Applicability (SoA), a document that lists every control from Annex A and states whether you have applied it, and why. Annex A itself is a catalog of 93 controls across themes like access control, cryptography, and supplier relationships, but it is a reference list, not a mandate: you justify each inclusion or exclusion based on your own risk picture.

Certification runs through an accredited, independent certification body in a two-stage process.

  • Stage 1 is a documentation review, where the auditor checks that your ISMS scope, policies, and risk assessment are complete enough to audit.
  • Stage 2 is the implementation audit, where the auditor tests whether your controls actually operate as documented.
  • Certified organizations then undergo annual surveillance audits and a full recertification every three years.

What ISO 27001 certification demonstrates to a customer or partner is that your security program is deliberately managed and independently verified. What it does not do is automatically satisfy a DoD procurement clause. The standard has no concept of FCI or CUI, no mandated cryptography standard, and no government reporting timeline, so a certificate alone tells a contracting officer nothing about CMMC readiness. An ISO 27001 certification checklist walks through the full sequence if you are scoping this for the first time, and a Statement of Applicability guide covers how the SoA gets built.

How ISO 27001 Controls Map to CMMC Level 2

The practical question for most compliance teams is not whether the two frameworks overlap, but how much work an existing ISO 27001 program actually saves against CMMC Level 2. Mapping datasets that track the two side by side show the overlap is substantial.

A control-mapping dataset lists most of the controls as shared between ISO 27001 and CMMC Level 2, with only a few unique to ISO 27001 and none unique to CMMC Level 2, with only a handful of ISO-only items and no CMMC-only items in that particular comparison. That means an organization with a mature ISMS is already addressing the large majority of the practices NIST SP 800-171 requires, at least at the policy and process level.

The overlap is clearest in a few domains:

Access control. Both frameworks require you to limit system access to authorized users and enforce least privilege. ISO Annex A control 5.15 and the related access management clauses largely satisfy the intent of the CMMC access control family, but CMMC assessors want to see the access control policy tied to specific technical evidence, account review logs, and role definitions documented in a System Security Plan format, not just referenced in an ISMS policy binder.

Incident response. ISO 27001 requires a documented incident management process under Annex A clause 5.24 through 5.28. CMMC Level 2 expects the same process, but adds a government reporting obligation: specific DoD incident reporting timelines that ISO has no equivalent for.

Privileged account management. Both frameworks expect tighter controls on administrative accounts. Where CMMC diverges is in mandating multifactor authentication for all privileged and remote access, a specific technical control that ISO’s risk-based approach might satisfy a different way depending on your risk assessment.

The practical move is to build a crosswalk early: list every NIST SP 800-171 practice, note which ISO Annex A control or ISMS process already covers it, and flag the practices with no ISO equivalent. That crosswalk becomes your gap list, and it keeps you from re-documenting policies you already have in a slightly different format just because two different auditors will eventually read them.

ISO and CMMC control crosswalk with gaps

Where CMMC Demands More Than ISO 27001 Requires

The overlap numbers are reassuring, but the remaining gap is where DoD contractors get tripped up, because CMMC is prescriptive in places where ISO deliberately leaves the decision to you. ISO 27001 is risk-based by design: if your risk assessment concludes that a control is unnecessary for your context, you document that and move on. CMMC does not offer that flexibility for its core technical requirements.

Three categories of gap show up consistently for ISO-certified organizations preparing for CMMC:

  1. Mandatory technical controls. CMMC requires multifactor authentication on all remote and privileged access, FIPS-validated cryptographic modules for protecting CUI, and often application whitelisting, regardless of what your risk assessment concludes. ISO might accept a compensating control; CMMC usually will not.
  2. Formal evidence artifacts. CMMC assessors expect a System Security Plan (SSP) built in a specific format that maps directly to the 110 NIST SP 800-171 practices, plus a Plan of Action and Milestones (POA&M) that tracks every open gap with a remediation date. ISO’s documentation requirements are real, but they do not follow this exact structure.
  3. Operational obligations unique to government work. CMMC requires a defined CUI boundary (a clear map of every system, network segment, and storage location where CUI lives or travels), specific DoD incident reporting timelines, and a continuous affirmation process where someone in your organization periodically attests that controls remain in place.

Pro Tip: Build your CUI boundary diagram before you touch the SSP template. Every other artifact, from the POA&M to the access control evidence, depends on knowing exactly which systems are in scope.

Log retention is a smaller but recurring gap too: ISO expects you to monitor and review logs as part of your ISMS, but CMMC assessors look for specific retention periods and integrity controls that many ISO programs have not formalized. None of this means the ISO work was wasted. It means the ISO program gave you the governance structure, and CMMC is asking you to bolt specific, auditable technical and procedural controls onto that structure.

Who Assesses You and When

The two frameworks use different assessment models, and knowing which applies to you changes your timeline and budget.

ISO 27001 certification is always performed by an accredited, independent certification body, following the Stage 1 and Stage 2 process described earlier, with surveillance audits in years one and two and recertification in year three. A guide to ISO 27001 audit stages lists sample records auditors typically request at each stage.

CMMC assessment depends on your required level. Level 1 and, currently, Level 2 can be completed as a self-assessment submitted to SPRS. Under the paused Phase 2 framework, third-party assessments for Level 2 are performed by Certified Third-Party Assessment Organizations (C3PAOs), while the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) handles government-led assessments for certain contracts.

  • Self-assessments are typically annual, tied to the continuous affirmation requirement.
  • Third-party CMMC certifications, once fully implemented, are expected to follow a three-year cycle similar to ISO.
  • Contracting officers verify your status through SPRS before award, and your CMMC UID becomes part of the contract record.
  • 32 CFR and acquisition.gov program rules govern exactly which clauses require which level, so solicitation language should always be checked rather than assumed.

Because the Phase 2 suspension changes what is currently enforceable, the safest practice is to treat DoD CIO memoranda and the acquisition.gov program text as your source of truth rather than secondhand summaries, since the rules have moved more than once in a short period.

A Six-Step Roadmap From ISO to CMMC Readiness

Once you know where the overlap sits and where the gaps are, the sequencing problem becomes manageable. Most organizations that already run an ISMS can follow a straightforward path.

  1. Scope the ISMS around the systems and data that matter most, including any that will eventually touch CUI.
  2. Run the risk assessment and build the SoA, documenting which Annex A controls you have applied and why.
  3. Map your ISO controls against NIST SP 800-171 Rev 2 practice by practice, flagging every gap rather than assuming coverage.
  4. Define the CUI boundary and draft the SSP, using the ISO risk assessment as a starting point but following the CMMC-specific format.
  5. Produce POA&M entries for every open gap, prioritized by how much they affect award eligibility, with MFA, FIPS-validated crypto, and logging usually at the top.
  6. Assemble procurement-ready evidence: the SSP, POA&M, access logs, and incident response records a C3PAO or contracting officer will want to see.

Organizations with a mature ISO program typically find that the bulk of their CMMC work is gap-closing rather than starting from scratch, since the governance, risk assessment, and documentation habits already exist. The items worth tackling first are the ones that gate award eligibility: MFA everywhere it is required, a working POA&M, a defined CUI boundary, and defensible logging.

Pro Tip: Run your gap list through a maturity assessment before you commit budget. Knowing where you sit across all four ISO/IEC 27001:2022 control themes tells you which remediation items are quick wins and which require new tooling.

This is the kind of planning our ISO 27001 Readiness Assessment and ISO 27001 Cost Calculator are built for: turning a gap list into a budget line and a defensible timeline you can hand to procurement. Our implementation timeline guide also helps set realistic expectations for how long each phase takes.

The Verdict: ISO First, CMMC Where Required

Pursue ISO 27001 for your organization’s overall security posture and commercial credibility, and pursue CMMC specifically when a DoD contract requires it, treating the ISO program as the base you build from rather than a substitute.

A practical 90-day plan looks like this: in the first month, complete your CUI boundary scoping and run a NIST SP 800-171 gap assessment against your existing ISO controls. In the second month, draft your SSP and build sample POA&M entries for the gaps you found, prioritizing MFA rollout and log retention. In the third month, close the highest-priority technical gaps and prepare the evidence package a self-assessment or C3PAO review would expect.

Bring in outside specialists when the gaps involve FIPS-validated cryptography selection or CUI boundary disputes across complex network segments. For budgeting and defending the estimate to leadership, a cost calculator built around ISO domains and maturity levels is the faster starting point before specialist fees enter the picture.

CMMC Level 3 and the Full Scope Beyond Level 2

Most of the CMMC vs. ISO 27001 conversation centers on Level 2, since that is where the bulk of CUI-handling contractors land, but Level 3 matters for anyone supporting the DoD’s highest-risk programs. Level 3 keeps every Level 2 requirement in place and adds a smaller, selected set of practices from NIST SP 800-172, which focuses on defending against advanced persistent threats rather than baseline hygiene.

Where Level 2 is largely about demonstrated, auditable implementation of the 110 SP 800-171 practices, Level 3 assessments are conducted by the government directly rather than through a C3PAO, reflecting the sensitivity of the programs involved. ISO 27001 has no equivalent tier: its ISMS model scales by risk assessment outcome, not by a fixed ladder of government-defined levels. An organization that needs Level 3 should not expect an ISO certificate, however mature, to cover more than a fraction of the additional work, since SP 800-172 practices address threat scenarios ISO’s general-purpose Annex A controls were never written to anticipate. Treat Level 3 as its own project with its own specialist input, built on top of the Level 2 groundwork rather than layered directly onto an ISO program.

Implementing ISO 27001 Alongside a CMMC Push

Organizations rarely have the luxury of pursuing ISO 27001 and CMMC readiness in strict sequence, especially when a contract deadline is already on the calendar. The practical integration point is the risk assessment: build it once, scoped broadly enough to cover both the ISMS and the CUI environment, and let it feed both the ISO Statement of Applicability and the CMMC gap analysis.

Policy documentation is the next shared layer. An access control policy, an incident response plan, and a vendor management process written to satisfy ISO Annex A can usually be extended, not rewritten, to meet CMMC’s more specific evidence expectations. The alternative, running two separate documentation efforts in parallel, tends to produce inconsistent policies that confuse both auditors.

Timing matters too. Teams that schedule their ISO Stage 2 audit and their CMMC self-assessment within the same quarter often find that the evidence-gathering exercise for one directly feeds the other, since access logs, training records, and risk treatment plans serve both reviews. The main caution is scope: an ISMS scoped around a single business unit will not automatically cover the CUI boundary a DoD contract requires, so the scoping conversation has to happen before either audit is booked, not during it.

What This Means for Subcontractors and Supply Chain Partners

CMMC flows downhill through the supply chain. A prime contractor handling CUI is generally required to pass that same requirement to any subcontractor that touches the same information, which means a small subcontractor several tiers down can find itself needing Level 2 certification even without a direct DoD contract in hand. This is where the ISO-first approach pays off disproportionately for smaller suppliers: an existing ISMS gives them a credible head start when a prime contractor starts asking security questions during vendor due diligence.

ISO 27001 certification, while not a CMMC substitute, still functions as a useful signal in commercial supply chain relationships and in early-stage vendor screening, because it demonstrates an independently audited security program exists. Primes evaluating subcontractors often use ISO certification as a filter before CMMC status even enters the conversation, simply because it is a faster proxy for “this vendor has a functioning security program.”

The practical risk for supply chain partners is timing mismatch: a subcontractor that waits until a prime demands CMMC evidence before starting any security program work will be months behind. Building the ISMS first, then layering CMMC-specific artifacts on top once a contract requirement is confirmed, keeps a smaller supplier from being dropped from a bid list for lack of readiness.

Comparing the Cost and Resource Burden of Each Path

Budgeting for ISO 27001 and CMMC requires different inputs, because the cost drivers are not the same. ISO 27001 costs scale primarily with organizational size, the complexity of your ISMS scope, and the certification body’s audit fees across the Stage 1 and Stage 2 process plus three years of surveillance. CMMC costs scale with the specific technical gaps you have to close, since prescriptive requirements like FIPS-validated cryptographic modules, MFA deployment across every remote and privileged access point, and CUI boundary re-architecture can require new infrastructure spending that a risk-based ISO program might never have required.

Staffing is the other major variable. An ISO 27001 program typically needs a dedicated ISMS owner and periodic internal audit support. CMMC compliance adds the ongoing burden of POA&M tracking, continuous affirmation, and incident reporting readiness, which tend to require more sustained operational attention than an annual ISO surveillance cycle.

Organizations that already hold ISO certification generally face a smaller incremental cost for CMMC than those starting from nothing, since the governance and documentation habits transfer, but the technical remediation items, especially cryptography and MFA, often require capital spending regardless of certification history. Estimating these costs early, rather than discovering them mid-assessment, is the difference between a defensible budget line and a scramble before a contract deadline.

Why Durable Security Practices Beat Checklist Patching

Compliance is not a one-time audit you pass and then forget. The organizations that struggle most with CMMC are the ones that treated their ISO certificate as a finish line rather than a maintenance commitment, and then had to rebuild institutional habits from scratch when a new framework showed up.

Prioritize the controls that reduce real risk and audit exposure at the same time: multifactor authentication, centralized logging, and a tested incident response process matter whether or not an assessor is watching. Passing an audit and being secure are related but different claims, and the gap between them usually shows up in evidence integrity, meaning whether your records actually reflect what happened, not just what the policy says should happen.

— Martin

Estimate Your ISO 27001 Effort Before You Commit Budget

Mapping ISO 27001 against CMMC is only useful if you can turn the gap list into a number leadership will approve. We built our real-time calculator to take your company size, industry, and current security maturity and return a tailored estimate of what full ISO 27001 implementation will cost and how long it will take, with every assumption editable so you can challenge or adjust it rather than take a black-box number on faith.

Ismscalculator

Start with our free 2-minute readiness check to see where your gaps sit before committing to a full project plan. From there, our maturity assessment benchmarks your program across all four ISO/IEC 27001:2022 control themes against model reference values, so you can show a contracting officer or internal stakeholder exactly where you stand rather than describing it in general terms. Our ISO 27001 Readiness Assessment builds on that with a deeper review when you need more than a quick check.

Once you have a maturity picture, our cost calculator turns it into a budget, with exportable PDF reports and shareable links so you can save multiple scenarios and compare them side by side as your CMMC gap list evolves. If you want to see how the numbers are built before you rely on them, our cost model methodology lays out the full calculation logic. Run the free check today and turn your ISO-to-CMMC roadmap into a number you can present to stakeholders.

FAQ

Is ISO 27001 certification available in the USA?

Yes. ISO 27001 certification is performed by accredited certification bodies operating in the United States, following the same Stage 1 and Stage 2 audit process and three-year cycle used worldwide. It is not a government-issued credential, so any accredited certification body can issue it to a U.S. organization.

What are the key differences between CMMC Level 2 and ISO 27001?

CMMC Level 2 is a mandatory DoD certification aligned to NIST SP 800-171 Rev 2 with prescriptive technical requirements like mandatory MFA and FIPS-validated cryptography, while ISO 27001 is a voluntary, risk-based standard that lets organizations justify their own control choices. The two overlap heavily at the policy level, but CMMC adds specific artifacts like the SSP and POA&M that ISO does not require in that format.

Is CMMC for DoD only?

CMMC applies to organizations in the Defense Industrial Base that handle Federal Contract Information or Controlled Unclassified Information under DoD contracts, including subcontractors several tiers down the supply chain. It is not a general commercial security certification the way ISO 27001 is.

Is NIST equivalent to ISO 27001?

Not exactly. NIST SP 800-171 is a prescriptive practice list that CMMC Level 2 is directly built on, while ISO 27001 is a broader, risk-based management system standard that overlaps with much of NIST’s intent but follows a different structure and certification process.

Sources

Prêt à estimer vos coûts ISO 27001 ?

Utilisez notre calculateur gratuit pour obtenir une estimation personnalisée des coûts, de l'effort et du calendrier basée sur votre profil d'entreprise.

Calculez votre estimation — gratuit
Retour à tous les articles