CMMC

Cybersecurity Maturity Model Certification

The DoD's mandatory cybersecurity certification standard for the Defense Industrial Base, built on three maturity levels.

What It Is

CMMC 2.0 is organized into three maturity levels. Level 1 (Foundational) covers 17 basic safeguarding practices verified by annual self-assessment and protects Federal Contract Information (FCI). Level 2 (Advanced) aligns to the 110 security requirements in NIST SP 800-171 and protects Controlled Unclassified Information (CUI), requiring either self-assessment or a third-party assessment depending on the contract. Level 3 (Expert) adds a subset of NIST SP 800-172 enhanced requirements and is government-led, reserved for the DoD’s highest-priority programs.

The required level is specified directly in a contract’s solicitation and flows down to subcontractors. Assessments for Level 2 are performed by accredited C3PAOs (Certified Third-Party Assessment Organizations) under the oversight of the Cyber AB, and certification must be maintained and periodically reassessed to remain contract-eligible.

Who It Applies To

Any company in the Defense Industrial Base (DIB), prime contractor or subcontractor, that processes, stores, or transmits Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on a DoD contract. The specific level required is set by the contracting officer for each solicitation.

How We Help

  • Map current controls against the required CMMC level and identify gaps

  • Close gaps across the 110 NIST SP 800-171 practices for Level 2

  • Prepare System Security Plans (SSPs) and Plans of Action and Milestones (POA&Ms)

  • Build audit-ready evidence packages for C3PAO assessments

  • Provide ongoing monitoring to maintain certification between assessment cycles

Ready to close your compliance gaps?

Get a free security assessment, no obligation.