The Cybersecurity Maturity Model Certification (CMMC) is a US Department of Defense program that verifies whether defense contractors and their subcontractors have put required cybersecurity practices in place. It covers two kinds of information: federal contract information (FCI), which is non-public information from a government contract, and controlled unclassified information (CUI), which is sensitive but not classified. Required levels are written into contracts, and the program is being phased in over several years. This entry is general information, not legal advice; confirm requirements with your contracting officer, counsel or a certified assessor.
At a glance
- CMMC has three levels; the contract states which one applies.
- Level 1 covers basic safeguarding of FCI; Level 2 covers protection of CUI using the NIST SP 800-171 requirements; Level 3 adds selected enhanced requirements.
- Validation is a self-assessment, an assessment by a certified third-party assessment organization (C3PAO), or a government assessment, depending on the level and contract.
- Status is reported in the Defense Department’s systems, and a company official affirms ongoing compliance.
- Rollout is phased and has changed over time; check the current status with the Defense Department.
What problem it solves
For years, defense contractors were already required to protect CUI using NIST SP 800-171, but compliance was largely self-attested and inconsistent. Sensitive design and program information leaked through suppliers that had weak controls.
CMMC adds verification. Instead of simply promising, contractors show their status through structured assessments, and the required level becomes a condition of contract award. For a mid-sized manufacturer, engineering firm or IT services company in the defense supply chain, that turns cybersecurity from a checkbox into a requirement for keeping business.
How it works
Scoping. The contractor identifies where FCI and CUI are stored, processed and transmitted, and which people, systems and external providers touch them. Many companies shrink scope by isolating CUI in a dedicated enclave.
Implementing requirements. The contractor puts the required practices in place and documents them in a system security plan.
Assessment. Depending on the level and contract, the contractor self-assesses, hires a C3PAO, or is assessed by the Defense Department’s assessment center.
Reporting and affirmation. Results are entered in the Defense Department’s systems, and a senior official affirms compliance, typically every year.
Plans of action. At some levels, a limited number of unmet requirements can sit on a plan of action and milestones for a fixed period; Level 1 allows none.
CMMC levels
The table summarizes the levels as set out in the program rule. Details, timing and enforcement can change, so confirm against the current rule and your contract.
| Level | Who it applies to | How it is validated | Typical evidence |
|---|---|---|---|
| Level 1 (Self) | Contracts involving FCI only | Annual self-assessment against the basic safeguarding requirements | Self-assessment result and annual affirmation |
| Level 2 (Self) | Contracts involving CUI where the contract allows self-assessment | Self-assessment against NIST SP 800-171, repeated every three years | Assessment score, system security plan, annual affirmation |
| Level 2 (C3PAO) | Contracts involving CUI that require third-party certification | Assessment by a certified third-party assessment organization every three years | Certificate of status, system security plan, annual affirmation |
| Level 3 | Contracts involving CUI in especially sensitive programs | Government assessment of selected enhanced requirements, building on a Level 2 (C3PAO) status | Government-issued status plus continued Level 2 status |
When it matters for buyers
- When a contract or prime asks for a CMMC level. Everything in scope must support it.
- When choosing cloud email, file sharing and collaboration. Under DFARS 252.204-7012, external cloud services that store, process or transmit covered defense information are expected to meet the FedRAMP Moderate baseline or equivalent, which narrows choices.
- When hiring an MSP or MSSP. Providers with administrative or security roles typically fall in scope and should be able to show how they support your assessment.
- When building a CUI enclave. Private cloud or a separate tenant can limit what must be assessed.
- When responding to export-controlled work. ITAR and EAR data often sits in the same environment.
Our governance, risk and compliance overview covers readiness advisors and tools that track CMMC requirements.
Questions to ask vendors
- Will your service store, process or transmit our CUI, and how does that affect our assessment scope?
- Do you hold FedRAMP Moderate (Class C) certification or documented equivalency for the specific service we would buy?
- Can you provide a customer responsibility matrix showing which requirements you meet and which stay with us?
- Have you supported clients through C3PAO assessments, and will you participate in ours?
- Are your administrators US persons, and where are they located, if we also handle ITAR data?
- What evidence will you provide each year to support our affirmation?
How it differs from NIST SP 800-171
NIST Special Publication 800-171 is the set of security requirements for protecting CUI in contractor systems. CMMC is the Defense Department’s program for verifying that contractors meet those requirements, plus the basic Level 1 safeguards and enhanced Level 3 requirements. In short, 800-171 says what to do and CMMC checks that it was done. Unlike the voluntary NIST Cybersecurity Framework (NIST CSF), CMMC is a contract requirement. It is also separate from ITAR and the EAR, which control who may receive certain data, and from FedRAMP, which covers cloud services sold to federal agencies.
