Technology

Cybersecurity Maturity Model Certification (CMMC)

Published August 7, 2026

The Cybersecurity Maturity Model Certification is a unified standard for implementing and verifying cybersecurity across the Defense Industrial Base. It is designed to protect Federal Contract Information and Controlled Unclassified Information that is shared with contractors and subcontractors within the supply chain of the U.S. Department of Defense.

What Is CMMC?

CMMC is a framework that combines various cybersecurity standards and best practices into a tiered model. It maps controls from established frameworks such as NIST SP 800-171 and NIST SP 800-53, and adds a certification component to verify that a company has implemented the required safeguards. Instead of relying solely on self-attestation, the model requires assessments conducted by accredited third-party organizations or government assessors, depending on the sensitivity of the information handled.

How the Model Works

The framework is structured into three progressive maturity levels, each building on the requirements of the level below it.

  • Level 1 (Foundational): Focuses on basic cyber hygiene practices. It requires the implementation of 15 controls aligned with the protection of Federal Contract Information.
  • Level 2 (Advanced): Aligns with the 110 security controls from NIST SP 800-171. It requires a company to establish, document, and maintain a comprehensive security program for protecting Controlled Unclassified Information.
  • Level 3 (Expert): Targets a subset of controls from NIST SP 800-172. It is intended for companies working with the highest-priority defense programs and requires advanced capabilities to counter sophisticated persistent threats.

A contract will specify the required CMMC level. A company must achieve a valid certification at that level to be eligible for the award.

Why CMMC Matters

The primary driver for CMMC is the protection of sensitive national security information that resides on contractor networks. Traditional self-attestation revealed a gap between stated security postures and actual implementation. CMMC addresses this by providing a verifiable mechanism to ensure that a contractor’s cybersecurity practices are real, consistent, and effective, thereby reducing the risk of data exfiltration by adversaries.

Common Use Cases

  • A small machine shop bidding on a DoD contract for spare parts must achieve Level 1 certification.
  • A software development firm handling technical design data for a new aircraft system must achieve Level 2 certification.
  • A research laboratory involved in a next-generation weapons program must achieve Level 3 certification.

Benefits and Limitations

Benefits:

  • Provides a clear, standardized path for cybersecurity improvement.
  • Creates a competitive advantage for certified companies.
  • Enhances the overall security posture of the defense supply chain.

Limitations:

  • Achieving and maintaining certification requires a significant investment of time and resources.
  • The assessment process can be complex for small businesses with limited IT staff.
  • Certification is a point-in-time assessment and requires continuous monitoring to remain valid.

Frequently Asked Questions

Is CMMC required for all DoD contracts? Not all, but it is a requirement in an increasing number of solicitations. The specific level required will be stated in the contract.

Who conducts the assessment? Level 1 allows for self-assessments in some cases. Level 2 requires a triennial assessment by a CMMC Third-Party Assessment Organization. Level 3 assessments are conducted by government assessors.

How long is a certification valid? A CMMC certification is generally valid for three years, provided the company maintains its security posture and reports any significant changes.

Related Concepts

  • NIST SP 800-171: The foundational standard for protecting Controlled Unclassified Information in non-federal systems.
  • FedRAMP: A government-wide program that provides a standardized approach to security assessment and authorization for cloud products and services.
  • Zero Trust Architecture: A security model that assumes no implicit trust and is a core principle behind the advanced controls at CMMC Level 3.