CMMC is how the Defense Department verifies that a contractor's cybersecurity actually matches what it claims, rather than relying on self-attestation alone, through either a self-assessment or a third-party assessment depending on the level required. It is built on the security controls in NIST SP 800-171, so meeting that standard is the underlying work either way. Requirements are phasing into DoD contracts and subcontracts over time rather than applying everywhere at once, so check the specific solicitation, and your place in the supply chain, rather than assuming CMMC does or does not apply to you.
In a sentence
"Offerors must have the required CMMC certification level at the time of award." If you handle sensitive defense information at all, start on your CMMC posture well before a solicitation requires it, since assessment and remediation both take real time.