What is CMMC?
The Cybersecurity Maturity Model Certification (CMMC) is a unified standard for implementing cybersecurity across the US Defense Industrial Base (DIB). It was developed by the Department of Defense (DoD) to ensure that contractors handling Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) maintain adequate cybersecurity practices.
Maturity Levels
CMMC 2.0 defines three levels:
- Level 1 (Foundational): 17 practices based on basic safeguarding requirements
- Level 2 (Advanced): 110 practices aligned with NIST SP 800-171
- Level 3 (Expert): Enhanced practices based on NIST SP 800-172
Assessment Requirements
Level 1 requires annual self-assessment. Level 2 requires third-party assessment by a CMMC Third-Party Assessment Organization (C3PAO) for contracts involving critical CUI. Level 3 requires government-led assessment.
Impact on Contractors
CMMC certification is becoming a requirement for DoD contract awards. Organizations in the defense supply chain must achieve the appropriate CMMC level before bidding on relevant contracts.
Back to Glossary