Previous All Posts Next

Pharmacies holding DoD contracts must meet CMMC requirements; this guide maps the specific obligations for a CMMC pharmacy handling Controlled Unclassified Information.

This reference is for pharmacy owners, compliance officers, and security leads at independent or chain pharmacies that serve defense contractors, military treatment facilities, or government agencies. It explains how the CMMC program applies to healthcare data environments, the specific controls required under NIST SP 800-171, and the practical steps to reach certification readiness. We focus on the intersection of healthcare privacy obligations and defense information security, providing a clear path from current state to C3PAO assessment.

Key Takeaways

  • Pharmacies handling Controlled Unclassified Information (CUI) for DoD contracts must implement all 110 controls of NIST SP 800-171 Revision 2.
  • CMMC Level Two certification requires a third-party assessment by a Certified CMMC Professional (C3PAO), not a self-assessment.
  • The CMMC Program rule (32 CFR Part 170) took effect on 2024-12-16, and the acquisition rule (DFARS 252.204-7021) took effect on 2025-11-10.
  • Enclaving CUI into a narrowly scoped boundary, such as a GCC High tenant or dedicated cloud landing zone, reduces the scope of the 110 controls.
  • Post-certification, the System Security Plan (SSP) is a living document, and the Plan of Action and Milestones (POA&M) must be reviewed at least quarterly.

Why CMMC Applies to Your Pharmacy

Many pharmacy operations assume that HIPAA compliance is sufficient for all government-related data. This is a critical misunderstanding. HIPAA protects the privacy and security of electronic Protected Health Information (ePHI). CMMC protects the confidentiality of Controlled Unclassified Information (CUI) in nonfederal systems. When a pharmacy receives or generates CUI in the performance of a DoD contract, the CMMC program applies independently of HIPAA.

CUI was created by Executive Order 13556, signed on 2010-11-04. The National Archives and Records Administration is the Executive Agent, and 32 CFR Part 2002 is the government-wide rule. DoD Instruction 5200.48, issued on 2020-03-06, implements the CUI program inside the Department of Defense. For a pharmacy, this means that any system or network segment that stores, processes, or transmits CUI must meet the security requirements defined in NIST SP 800-171.

The distinction between Federal Contract Information (FCI) and CUI is vital. FCI requires only the 15 basic safeguarding requirements from FAR 52.204-21 and an annual self-assessment. CUI requires the full 110 practices of NIST SP 800-171 Rev 2, organized into 14 domains. If your pharmacy handles only FCI, you are at CMMC Level One. If you handle CUI, you are at CMMC Level Two. The determination of what information is CUI is made by the designating agency, and 32 CFR 2002.16 allows only the designating agency to apply limited dissemination controls.

Identifying Your Information Type

The first step in any CMMC pharmacy engagement is information mapping. You must identify which systems contain CUI. This often involves pharmacy management systems, electronic health record interfaces, or supply chain platforms that interact with defense contractors. 32 CFR 2002.20 requires the CUI banner marking on every page that contains CUI and a designation indicator naming the designating agency. DoD Instruction 5230.24 governs distribution statements on technical documents; a distribution statement does not satisfy CUI marking requirements, and the two are applied in parallel.

DoD's scope estimate for CMMC is 220,966 entities. As of the March 2026 Town Hall, there were 103 C3PAOs. Level 2 certifications grew from 773 in January 2026 to 1,391 in May 2026. This growth indicates that the program is active and expanding. Pharmacies that have not yet addressed CUI are at a disadvantage in the bidding process, as DFARS 252.204-7021 requires a valid CMMC certificate at the specified level before award when the clause appears in a contract or solicitation.

Understanding the CMMC Levels for Healthcare

CMMC 2.0 has three levels. It simplified the original five-level model and aligned Level 2 directly with NIST SP 800-171 Revision 2. For a pharmacy, the relevant levels are typically Level One and Level Two. Level Three adds selected controls from NIST SP 800-172 on top of Level Two and is assessed by the government (DCMA DIBCAC), not a C3PAO. Most pharmacy operations will not reach Level Three unless they are handling information with higher impact ratings.

Level One: Federal Contract Information

Level One covers Federal Contract Information (FCI). It includes 15 basic safeguarding requirements from FAR 52.204-21, an annual self-assessment, and an annual senior official affirmation to DoD. This level is appropriate for pharmacies that handle only FCI, such as basic contract documents that do not contain CUI. The self-assessment is submitted to the Supplier Performance Risk System (SPRS). The SPRS self-assessment score ranges from minus 203 to 110, with controls carrying 1, 3, or 5 point weights.

Level Two: Controlled Unclassified Information

Level Two covers Controlled Unclassified Information (CUI). It requires all 110 practices of NIST SP 800-171 Rev 2, organized into 14 domains. For most programs, a C3PAO assessment is required, with triennial reassessment and annual senior official affirmation. Only a C3PAO can issue a CMMC Level 2 certificate. The C3PAO submits results to eMASS, and the certificate is stored in SPRS. An RPO prepares a contractor but cannot conduct the assessment or issue a certificate. The list of authorized C3PAOs is maintained at cyberab.org/marketplace.

Attribute CMMC Level One CMMC Level Two
Information Type Federal Contract Information (FCI) Controlled Unclassified Information (CUI)
Security Standard FAR 52.204-21 (15 requirements) NIST SP 800-171 Rev 2 (110 controls)
Assessment Method Annual Self-Assessment C3PAO Third-Party Assessment
Reassessment Frequency Annual Triennial
Senior Official Affirmation Annual Annual

NIST SP 800-171 requires FIPS-validated cryptography to protect the confidentiality of CUI. Strong but unvalidated encryption does not meet the requirement. This is a common gap in pharmacy environments where legacy systems may use older encryption standards. DoD CIO FAQ clarifications state that encrypted CUI is still CUI, and encrypted CUI in a cloud still needs FedRAMP Moderate or equivalency. VDI endpoints are out of scope only in a KVM-only configuration.

Building Your Compliance Program

Compliance is not a one-time project. It is a continuous process. The path from gap assessment to C3PAO-ready typically takes 6 to 18 months depending on starting security posture and CUI environment complexity. A typical CMMC Level 2 readiness engagement runs 12 to 14 weeks for a mid-size contractor: Discovery (week 1), Gap Analysis (weeks 2-4), Remediation Sprint (weeks 5-12), and C3PAO Readiness Handoff (weeks 13-14).

Enclaving CUI to Reduce Scope

One of the most effective strategies for a pharmacy is enclaving CUI into a narrowly scoped boundary. This could be a GCC High tenant or a dedicated cloud landing zone. Enclaving keeps the 110 controls from applying across the entire enterprise network. It reduces audit surface, shortens timelines, and lowers ongoing cost. It is one of the biggest drivers of quote variance. If your pharmacy has a large enterprise network, enclaving is essential to make CMMC compliance manageable.

DFARS 252.204-7012 requires adequate security, defined as the 110 controls of NIST SP 800-171, on every covered contractor information system. It must be flowed down to subcontractors, including for commercial products and services, when performance involves covered defense information. A subcontractor reports its own incidents to DoD and gives the report number to the next higher tier. A cyber incident affecting covered defense information must be reported to DoD within 72 hours of discovery through the DoD reporting portal at dibnet.dod.mil, which requires a DoD-approved medium assurance certificate obtained in advance.

After a reported incident, the contractor must preserve images of affected systems and monitoring data for at least 90 days, submit isolated malicious software to the government, and hold cloud providers to a FedRAMP Moderate baseline. These requirements are strict and require a mature incident response plan. Petronella Technology Group, Inc. provides incident response coordination and policy development to ensure these requirements are met.

Evaluating Your Readiness

Before engaging a C3PAO, you must be ready. The readiness deliverables include an SSP covering all 110 NIST SP 800-171 controls with owners and evidence pointers, 14 control-family policies plus an incident response plan, an acceptable use policy and media protection policy, a live POA&M, a mock assessment using the Cyber AB CMMC Assessment Process (CAP), a baselined SPRS score, and a C3PAO shortlist with warm introductions.

POA&Ms are allowed only for "not met" requirements within the limits of 32 CFR 170.21, with a 180-day closeout. This means that if you have gaps, you must have a plan to close them within 180 days. The SSP is a living document, and the POA&M is reviewed at least quarterly. Re-assessment occurs every three years. CMMC compliance is continuous, and you must maintain your controls over time.

DoJ Civil Cyber-Fraud Initiative settlements highlight the risks of non-compliance. Verizon paid $4.09M in 2023, Penn State paid $1.25M in 2024, Raytheon paid $8.4M in May 2025, and Georgia Tech paid $875K on 2025-09-30. These settlements are for civil fraud, not just security breaches. They show that the government is actively pursuing entities that misrepresent their security posture. Accurate self-assessment and honest reporting are critical.

DFARS 252.204-7019 requires a current NIST SP 800-171 assessment summary score in SPRS when an offer is submitted. DFARS 252.204-7020 governs how the assessment is conducted under the DoD Assessment Methodology and gives DoD access to verify it. When DFARS 252.204-7021 appears in a contract or solicitation, the contractor must hold a valid CMMC certificate at the specified level before award. This means that if you do not have a certificate, you cannot be awarded the contract.

For a detailed breakdown of the 110 controls, see our [CMMC Compliance Checklist 2026](/blog/cmmc-compliance-checklist-2026/). For guidance on structuring your compliance program, review our [2026 CMMC Compliance Guide](/compliance/cmmc-compliance-guide/). To discuss your specific pharmacy environment, [contact us](/contact-us/) for a free 30-minute scoping consultation. Our team, including [CMMC consultants](/cmmc-consultant/), is ready to help you navigate this complex landscape.

Step-by-Step Implementation Plan for CMMC Pharmacy Compliance

Compliance is not a single event but a continuous process. The CMMC Program rule, 32 CFR Part 170, took effect on 2024-12-16. The acquisition rule in 48 CFR, specifically DFARS 252.204-7021, was published in the Federal Register on 2025-09-10 and took effect on 2025-11-10. On 2026-07-13, the DoD CIO announced the suspension of the 2026-11-10 Phase II deadline. Phase I self-assessments remain in force, and later milestones are paused until further notice. This pause provides a window to build your program correctly rather than rushing to meet a deadline.

  1. Discovery and Scoping. Identify which systems hold Controlled Unclassified Information (CUI). CUI was created by Executive Order 13556, signed 2010-11-04. The National Archives and Records Administration is the Executive Agent, and 32 CFR Part 2002 is the government-wide rule. DoD Instruction 5200.48, issued 2020-03-06, implements the CUI program inside the Department of Defense. Determine if your pharmacy handles Federal Contract Information (FCI) or CUI. FCI requires the 15 basic safeguarding requirements from FAR 52.204-21. CUI requires the 110 practices of NIST SP 800-171 Revision 2.
  2. Gap Analysis. Map your current controls against the 110 requirements of NIST SP 800-171 Revision 2. These are organized into 14 domains. NIST SP 800-171 requires FIPS-validated cryptography to protect the confidentiality of CUI. Strong but unvalidated encryption does not meet the requirement. Document where you stand. The SPRS self-assessment score ranges from minus 203 to 110, with controls carrying 1, 3, or 5 point weights.
  3. Remediation Sprint. Address gaps. A typical CMMC Level 2 readiness engagement runs 12 to 14 weeks for a mid-size contractor. This phase includes updating policies, implementing technical controls, and training staff. Enclaving CUI into a narrowly scoped boundary, such as a GCC High tenant or a dedicated cloud landing zone, keeps the 110 controls from applying across the entire enterprise network. This reduces audit surface and shortens timelines.
  4. Documentation and SSP Creation. Develop a System Security Plan (SSP) covering all 110 NIST SP 800-171 controls with owners and evidence pointers. Create 14 control-family policies plus an incident response plan. Include an acceptable use policy and media protection policy. The SSP is a living document. There is no prescribed format for the SSP, but you must ensure the required information in NIST SP 800-171 Requirement 3.12.4 is conveyed in those plans.
  5. Mock Assessment. Conduct a mock assessment using the Cyber AB CMMC Assessment Process (CAP). This helps identify remaining gaps before the formal assessment. Only a C3PAO can issue a CMMC Level 2 certificate. The C3PAO submits results to eMASS, and the certificate is stored in SPRS. An RPO prepares a contractor but cannot conduct the assessment or issue a certificate.
  6. Formal Assessment and Certification. Schedule the assessment with a C3PAO. The list of authorized C3PAOs is maintained at cyberab.org/marketplace. As of the March 2026 Town Hall, there were 103 C3PAOs. Level 2 certifications grew from 773 in January 2026 to 1,391 in May 2026. If you have "not met" requirements, a Plan of Action and Milestones (POA&M) is allowed within the limits of 32 CFR 170.21, with a 180-day closeout.
  7. Ongoing Maintenance. CMMC compliance is continuous. The POA&M is reviewed at least quarterly. Re-assessment occurs every three years. Annual senior official affirmation to DoD is required. Maintain the SSP and update it as your environment changes.

Common Mistakes in CMMC Assessments and How to Avoid Them

Based on our experience preparing contractors, several errors recur. Avoiding them saves time and money.

  • Ignoring the Scope. Many organizations assume all systems are in scope. If you handle CUI, only the systems that process, store, or transmit CUI are in scope for Level 2. Enclaving CUI into a narrowly scoped boundary reduces the number of systems that must meet the 110 controls. This is one of the biggest drivers of quote variance and timeline length.
  • Using Non-FIPS Cryptography. NIST SP 800-171 requires FIPS-validated cryptography to protect the confidentiality of CUI. If you use strong encryption that is not FIPS-validated, you do not meet the requirement. Audit your encryption tools to ensure they are FIPS-validated.
  • Overlooking Incident Reporting. A cyber incident affecting covered defense information must be reported to DoD within 72 hours of discovery through the DoD reporting portal at dibnet.dod.mil. This portal requires a DoD-approved medium assurance certificate obtained in advance. If you do not have this certificate, you cannot report. After a reported incident, you must preserve images of affected systems and monitoring data for at least 90 days, submit isolated malicious software to the government, and hold cloud providers to a FedRAMP Moderate baseline.
  • Assuming Encryption Removes CUI Status. The DoD CIO FAQ clarifies that encrypted CUI is still CUI. Encrypted CUI in a cloud still needs FedRAMP Moderate or equivalency. Do not assume that encrypting data removes the compliance obligation.
  • Flowing Down Clauses Incorrectly. DFARS 252.204-7012 must be flowed down to subcontractors, including for commercial products and services, when performance involves covered defense information. A subcontractor reports its own incidents to DoD and gives the report number to the next higher tier. Ensure your contracts include this clause and that your subcontractors understand their obligations.
  • Treating Compliance as a One-Time Project. CMMC compliance is continuous. The SSP is a living document, and the POA&M is reviewed at least quarterly. Re-assessment occurs every three years. If you stop maintaining your controls after certification, you will fail your next assessment.

How to Choose a CMMC Provider: Questions to Ask

Selecting the right provider is critical. Ask these questions to ensure you are working with a qualified partner.

  • Are you a Registered Provider Organization (RPO)? Only an RPO can prepare a contractor for CMMC. Petronella Technology Group, Inc. is a Cyber AB Registered Provider Organization, RPO #1449. Verify your provider's RPO status on the Cyber AB Marketplace.
  • Do your engineers hold the CMMC Registered Practitioner (CMMC-RP) credential? Every Petronella engineer assigned to a defense client holds the CMMC-RP credential. This ensures that the people preparing you are certified in the specific framework.
  • Will you perform the assessment? An RPO prepares a contractor but cannot conduct the assessment or issue a certificate. Only a C3PAO can issue a CMMC Level 2 certificate. Petronella does not perform Level 2 assessments for clients it has prepared, because Cyber AB independence rules prohibit it. Ask for a list of C3PAOs they can recommend.
  • How do you handle scoping? A good provider will help you define the scope of CUI. Enclaving CUI into a narrowly scoped boundary reduces audit surface and lowers ongoing cost. Ask how they approach scoping and whether they can help you define a GCC High tenant or dedicated cloud landing zone.
  • What is your timeline? A typical CMMC Level 2 readiness engagement runs 12 to 14 weeks for a mid-size contractor. The path from gap assessment to C3PAO-ready typically takes 6 to 18 months depending on starting security posture and CUI environment complexity. Ask for a detailed timeline and milestones.
  • How do you handle POA&Ms? POA&Ms are allowed only for "not met" requirements within the limits of 32 CFR 170.21, with a 180-day closeout. Ask how they track and close out POA&Ms and whether they provide ongoing support for this.

How Petronella Technology Group, Inc. Helps

Petronella Technology Group, Inc. is a cybersecurity, compliance, and private AI firm that serves regulated businesses and defense contractors. We are a Cyber AB Registered Provider Organization, RPO #1449. Every practitioner on our compliance team holds the CMMC-RP designation, not just the principal. Our team includes Blake Rea, Justin Summers, Jonathan Wood, and Craig Petronella. Craig Petronella holds CMMC-RP, CCNA, CWNE, NC Licensed Digital Forensic Examiner license #604180, and an MIT AI certificate. He has 30+ years of experience and founded the company in 2002.

We deliver CMMC and HIPAA engagements remote-first across all 50 states. The first call is a free 30-minute scoping consultation run by a CMMC Registered Practitioner. We do not perform Level 2 assessments for clients we have prepared, because Cyber AB independence rules prohibit it. We do not promise "guaranteed pass" outcomes. Instead, we prepare you thoroughly so you are ready for the assessment.

Our readiness deliverables include an SSP covering all 110 NIST SP 800-171 controls with owners and evidence pointers, 14 control-family policies plus an incident response plan, an acceptable use policy and media protection policy, a live POA&M, a mock assessment using the Cyber AB CMMC Assessment Process (CAP), a baselined SPRS score, and a C3PAO shortlist with warm introductions. Post-certification, we offer a maintenance retainer covering quarterly control reviews, policy refresh, training, and incident response capacity. This ensures your program remains compliant and your SSP stays a living document.

Petronella Technology Group, Inc. is located at 5540 Centerview Dr Suite 200, Raleigh NC 27606. We are BBB accredited with an A+ rating continuously since 2003. Some clients who started in 2003 are still clients. For more information on our CMMC consulting services, visit our CMMC consultant page or our compliance hub.

Related guides from Petronella Technology Group, Inc.

Primary sources for this guide: 32 CFR Part 170 - CYBERSECURITY MATURITY MODEL CERTIFICATION (CMMC) PROGRAM, SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems an.

Related reading

Frequently Asked Questions

Does CMMC apply to pharmacies?

CMMC applies to contractors that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) for the Department of Defense. If your pharmacy handles FCI, you must meet the 15 basic safeguarding requirements from FAR 52.204-21. If you handle CUI, you must meet the 110 practices of NIST SP 800-171 Revision 2.

Every DoD contractor handling FCI must meet the FAR 52.204-21 baseline. Only contractors that receive or generate CUI take on the full NIST SP 800-171 obligation.

What is the difference between Level 1 and Level 2?

Level 1 covers Federal Contract Information (FCI) and requires 15 basic safeguarding requirements from FAR 52.204-21, an annual self-assessment, and an annual senior official affirmation to DoD. Level 2 covers Controlled Unclassified Information (CUI) and requires all 110 practices of NIST SP 800-171 Revision 2, organized into 14 domains, with a C3PAO assessment for most programs, triennial reassessment, and annual senior official affirmation.

Level 3 adds selected controls from NIST SP 800-172 on top of Level 2 and is assessed by the government (DCMA DIBCAC), not a C3PAO.

How long does CMMC compliance take?

A typical CMMC Level 2 readiness engagement runs 12 to 14 weeks for a mid-size contractor. The path from gap assessment to C3PAO-ready typically takes 6 to 18 months depending on starting security posture and CUI environment complexity.

The timeline depends on your starting security posture and the complexity of your CUI environment. Enclaving CUI into a narrowly scoped boundary can shorten the timeline.

Can I use an RPO to certify me?

No. Only a C3PAO can issue a CMMC Level 2 certificate. The C3PAO submits results to eMASS, and the certificate is stored in SPRS. An RPO prepares a contractor but cannot conduct the assessment or issue a certificate.

Petronella Technology Group, Inc. is an RPO. We prepare you for the assessment but do not perform the assessment or issue the certificate.

What happens if I have "not met" requirements?

POA&Ms are allowed only for "not met" requirements within the limits of 32 CFR 170.21, with a 180-day closeout. You must submit a Plan of Action and Milestones to address the gaps.

The POA&M is reviewed at least quarterly. You must close out the POA&M within 180 days.

Is CMMC compliance a one-time project?

No. CMMC compliance is continuous. The SSP is a living document, and the POA&M is reviewed at least quarterly. Re-assessment occurs every three years.

Annual senior official affirmation to DoD is required. You must maintain your controls and update your SSP as your environment changes.

Call Penny, our AI assistant, at 919-348-4912, or use our contact form to schedule a free 30-minute scoping consultation.

Get the CMMC Compliance Guide

Free, practical, and specific to regulated environments. We will email it to you.

No spam. Unsubscribe anytime.

Need help implementing these strategies? Our cybersecurity experts can assess your environment and build a tailored plan. Prefer to write? Send us a message.
Call Penny 919-348-4912

About the Author

Craig Petronella, CEO and Founder of Petronella Technology Group
CEO, Founder & AI Architect, Petronella Technology Group

Craig Petronella founded Petronella Technology Group in 2002 and has spent 30+ years professionally at the intersection of cybersecurity, AI, compliance, and digital forensics. He holds the CMMC Registered Practitioner credential issued by the Cyber AB and leads Petronella as a CMMC-AB Registered Provider Organization (RPO #1449). Craig is an NC Licensed Digital Forensics Examiner (License #604180-DFE) and completed MIT Professional Education programs in AI, Blockchain, and Cybersecurity. He also holds CompTIA Security+, CCNA, and Hyperledger certifications.

He is an Amazon #1 Best-Selling Author of 15+ books on cybersecurity and compliance, host of the Encrypted Ambition podcast (95+ episodes on Apple Podcasts, Spotify, and Amazon), and a cybersecurity keynote speaker with 200+ engagements at conferences, law firms, and corporate boardrooms. Craig serves as Contributing Editor for Cybersecurity at NC Triangle Attorney at Law Magazine and is a guest lecturer at NCCU School of Law. He serves as a digital forensics expert witness for law firms on matters involving cybercrime, cryptocurrency fraud, SIM-swap attacks, and data breaches.

Under his leadership, Petronella Technology Group has served hundreds of regulated SMB clients across NC and the southeast since 2002, earned a BBB A+ rating every year since 2003, and been featured as a cybersecurity authority on CBS, ABC, NBC, FOX, and WRAL. The company leverages SOC 2 Type II certified platforms and specializes in AI implementation, managed cybersecurity, CMMC/HIPAA/SOC 2 compliance, and digital forensics for businesses across the United States.

CMMC-RP NC Licensed DFE MIT Certified CompTIA Security+ Expert Witness 15+ Books
Related Service
Achieve Compliance with Expert Guidance

CMMC, HIPAA, NIST, PCI-DSS - we have 80% of documentation pre-written to accelerate your timeline.

Learn About Compliance Services
Previous All Posts Next
Questions about this topic? Talk to our team. Call Penny 919-348-4912 Message us