Complete Guide

What is CMMC?

The Cybersecurity Maturity Model Certification is the DoD's framework for verifying that defense contractors can protect sensitive government information. Here's everything you need to know.

CMMC at a Glance

The Cybersecurity Maturity Model Certification (CMMC) is a program established by the U.S. Department of Defense (DoD) to protect the Defense Industrial Base (DIB) from increasingly sophisticated cyber threats.

Before CMMC, defense contractors were expected to self-attest their compliance with NIST SP 800-171 security requirements. CMMC adds independent verification so organizations can confirm their cybersecurity posture against the applicable requirements.

🔑 Key Takeaway

CMMC doesn't introduce entirely new security requirements — it primarily adds a verification mechanism to the existing NIST SP 800-171 framework that defense contractors were already expected to follow under DFARS 252.204-7012.

The Three CMMC Levels

CMMC 2.0 streamlined the original five-level model into three levels, each designed for different types of information sensitivity:

Level Security Requirements Assessment Protects
Level 1 15 security requirements from FAR 52.204-21 Annual self-assessment and annual affirmation FCI
Level 2 110 security requirements from NIST SP 800-171 Revision 2 Self-assessment or C3PAO certification assessment, depending on the solicitation or contract CUI
Level 3 110 Level 2 requirements plus 24 selected enhanced security requirements from NIST SP 800-172 Government assessment (DCMA DIBCAC) and annual affirmation Critical CUI

Most defense contractors handling technical data will need Level 2 certification. See the full Level 2 requirements breakdown →

Who Needs CMMC Certification?

CMMC applies to all organizations in the Defense Industrial Base (DIB) supply chain that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI):

🏭

Prime Contractors

Large defense primes like Lockheed Martin, Raytheon, and Northrop Grumman — and their direct contract operations.

🔗

Subcontractors

Any subcontractor at any tier that processes, stores, or transmits FCI/CUI as part of a DoD contract.

🏢

Small Manufacturers

Small and mid-size manufacturers supplying parts, components, or services to defense programs.

💻

IT & MSP Providers

Managed service providers and IT companies that support DIB organizations' infrastructure and data.

CMMC Implementation Timeline

CMMC is being rolled out in phases through the DFARS rulemaking process:

1

Phase 1 — 2025

Level 1 and Level 2 self-assessments begin appearing in new DoD contract solicitations. Organizations must submit scores to SPRS.

2

Phase 2 — 2026

Level 2 C3PAO assessments become required for contracts involving critical CUI programs. Third-party certification becomes mandatory.

3

Phase 3 — 2027

Level 3 government-led assessments (DIBCAC) begin for the most sensitive defense programs.

4

Phase 4 — 2028

Full CMMC implementation across all applicable DoD contracts. CMMC certification becomes a standard contract requirement.

How to Prepare for CMMC

Whether you're just learning about CMMC or ready to start your certification journey, here are the key steps:

  1. Determine your required level — Review your DoD contracts to identify whether you handle FCI (Level 1) or CUI (Level 2/3)
  2. Conduct a gap assessment — Compare your current cybersecurity posture against NIST SP 800-171 requirements
  3. Define your CUI boundary — Identify where CUI flows in your organization and consider creating a CUI enclave
  4. Remediate gaps — Implement missing controls, update policies, and deploy required security technologies
  5. Create your SSP and POA&M — Document your security system plan and any remaining items needing remediation
  6. Schedule your assessment — Engage a C3PAO or complete your self-assessment

Read our detailed Assessment Preparation Guide →

🤖 Get CMMC Answers

ChatCMMC is designed to retrieve information from selected official DoD, federal regulatory, and NIST sources. Ask any question about CMMC compliance and review the cited source before making decisions. Try ChatCMMC →