What Is CMMC (Cybersecurity Maturity Model Certification)?

Related problems: A defense prime says we need CMMC to keep our contract; Not sure which CMMC level applies to us; Need an IT environment and providers that can pass a CMMC assessment; Our MSP and cloud tools have to fit inside our assessment scope

The Cybersecurity Maturity Model Certification (CMMC) is a US Department of Defense program that verifies whether defense contractors and their subcontractors have put required cybersecurity practices in place. It covers two kinds of information: federal contract information (FCI), which is non-public information from a government contract, and controlled unclassified information (CUI), which is sensitive but not classified. Required levels are written into contracts, and the program is being phased in over several years. This entry is general information, not legal advice; confirm requirements with your contracting officer, counsel or a certified assessor.

At a glance

  • CMMC has three levels; the contract states which one applies.
  • Level 1 covers basic safeguarding of FCI; Level 2 covers protection of CUI using the NIST SP 800-171 requirements; Level 3 adds selected enhanced requirements.
  • Validation is a self-assessment, an assessment by a certified third-party assessment organization (C3PAO), or a government assessment, depending on the level and contract.
  • Status is reported in the Defense Department’s systems, and a company official affirms ongoing compliance.
  • Rollout is phased and has changed over time; check the current status with the Defense Department.

What problem it solves

For years, defense contractors were already required to protect CUI using NIST SP 800-171, but compliance was largely self-attested and inconsistent. Sensitive design and program information leaked through suppliers that had weak controls.

CMMC adds verification. Instead of simply promising, contractors show their status through structured assessments, and the required level becomes a condition of contract award. For a mid-sized manufacturer, engineering firm or IT services company in the defense supply chain, that turns cybersecurity from a checkbox into a requirement for keeping business.

How it works

Scoping. The contractor identifies where FCI and CUI are stored, processed and transmitted, and which people, systems and external providers touch them. Many companies shrink scope by isolating CUI in a dedicated enclave.

Implementing requirements. The contractor puts the required practices in place and documents them in a system security plan.

Assessment. Depending on the level and contract, the contractor self-assesses, hires a C3PAO, or is assessed by the Defense Department’s assessment center.

Reporting and affirmation. Results are entered in the Defense Department’s systems, and a senior official affirms compliance, typically every year.

Plans of action. At some levels, a limited number of unmet requirements can sit on a plan of action and milestones for a fixed period; Level 1 allows none.

CMMC levels

The table summarizes the levels as set out in the program rule. Details, timing and enforcement can change, so confirm against the current rule and your contract.

Level Who it applies to How it is validated Typical evidence
Level 1 (Self) Contracts involving FCI only Annual self-assessment against the basic safeguarding requirements Self-assessment result and annual affirmation
Level 2 (Self) Contracts involving CUI where the contract allows self-assessment Self-assessment against NIST SP 800-171, repeated every three years Assessment score, system security plan, annual affirmation
Level 2 (C3PAO) Contracts involving CUI that require third-party certification Assessment by a certified third-party assessment organization every three years Certificate of status, system security plan, annual affirmation
Level 3 Contracts involving CUI in especially sensitive programs Government assessment of selected enhanced requirements, building on a Level 2 (C3PAO) status Government-issued status plus continued Level 2 status

When it matters for buyers

  • When a contract or prime asks for a CMMC level. Everything in scope must support it.
  • When choosing cloud email, file sharing and collaboration. Under DFARS 252.204-7012, external cloud services that store, process or transmit covered defense information are expected to meet the FedRAMP Moderate baseline or equivalent, which narrows choices.
  • When hiring an MSP or MSSP. Providers with administrative or security roles typically fall in scope and should be able to show how they support your assessment.
  • When building a CUI enclave. Private cloud or a separate tenant can limit what must be assessed.
  • When responding to export-controlled work. ITAR and EAR data often sits in the same environment.

Our governance, risk and compliance overview covers readiness advisors and tools that track CMMC requirements.

Questions to ask vendors

  • Will your service store, process or transmit our CUI, and how does that affect our assessment scope?
  • Do you hold FedRAMP Moderate (Class C) certification or documented equivalency for the specific service we would buy?
  • Can you provide a customer responsibility matrix showing which requirements you meet and which stay with us?
  • Have you supported clients through C3PAO assessments, and will you participate in ours?
  • Are your administrators US persons, and where are they located, if we also handle ITAR data?
  • What evidence will you provide each year to support our affirmation?

How it differs from NIST SP 800-171

NIST Special Publication 800-171 is the set of security requirements for protecting CUI in contractor systems. CMMC is the Defense Department’s program for verifying that contractors meet those requirements, plus the basic Level 1 safeguards and enhanced Level 3 requirements. In short, 800-171 says what to do and CMMC checks that it was done. Unlike the voluntary NIST Cybersecurity Framework (NIST CSF), CMMC is a contract requirement. It is also separate from ITAR and the EAR, which control who may receive certain data, and from FedRAMP, which covers cloud services sold to federal agencies.

Frequently Asked Questions

Which CMMC level do we need?
It depends on the information in your contracts. Contracts involving only federal contract information typically call for Level 1. Contracts involving controlled unclassified information (CUI) typically call for Level 2, and some sensitive programs call for Level 3. The solicitation states the required level, so check with your contracting officer or prime.
Can we self-assess for CMMC?
For Level 1, yes. For Level 2, some contracts allow a self-assessment while others require an assessment by a certified third-party assessment organization (C3PAO). Level 3 is assessed by the government. The contract determines which applies.
Is CMMC in effect now?
CMMC requirements began appearing in Defense Department contracts in phases, starting with self-assessments. The planned move to required third-party assessments was paused in 2026 while the department reviewed the program, so check the current status on the DoD CIO CMMC site and with your contracting officer.
Do our cloud and MSP providers need to be compliant too?
Often, yes. Providers that store, process or transmit CUI, or that provide security functions for your environment, are typically within your assessment scope. Under contracts that include DFARS 252.204-7012, an external cloud provider that stores, processes or transmits covered defense information is expected to meet security requirements equivalent to the FedRAMP Moderate baseline. Confirm how your assessor will treat each provider.
What is the difference between CMMC and NIST SP 800-171?
NIST SP 800-171 is the set of security requirements for protecting CUI. CMMC is the program that verifies a contractor has implemented them, through self-assessment, third-party assessment or government assessment depending on the level.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.