Glossary Term

CMMC

Cybersecurity Maturity Model Certification - a US Department of Defense framework for assessing and certifying the cybersecurity posture of defense contractors.

What is CMMC?

The Cybersecurity Maturity Model Certification (CMMC) is a unified standard for implementing cybersecurity across the US Defense Industrial Base (DIB). It was developed by the Department of Defense (DoD) to ensure that contractors handling Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) maintain adequate cybersecurity practices.

Maturity Levels

CMMC 2.0 defines three levels:

  • Level 1 (Foundational): 17 practices based on basic safeguarding requirements
  • Level 2 (Advanced): 110 practices aligned with NIST SP 800-171
  • Level 3 (Expert): Enhanced practices based on NIST SP 800-172

Assessment Requirements

Level 1 requires annual self-assessment. Level 2 requires third-party assessment by a CMMC Third-Party Assessment Organization (C3PAO) for contracts involving critical CUI. Level 3 requires government-led assessment.

Impact on Contractors

CMMC certification is becoming a requirement for DoD contract awards. Organizations in the defense supply chain must achieve the appropriate CMMC level before bidding on relevant contracts.

Back to Glossary

Need Expert Guidance?

Our consultants can help you understand and implement the requirements of this standard or framework.