What is CMMC?
CMMC (Cybersecurity Maturity Model Certification) is the US Department of Defense program that requires contractors in the defense industrial base to prove they protect federal contract information and controlled unclassified information. CMMC 2.0 has three levels.
Definition
CMMC is a US Department of Defense certification program that verifies whether a company in the defense supply chain has the cybersecurity practices needed to protect sensitive but unclassified government information.
Background
CMMC applies to the defense industrial base: contractors and subcontractors that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). CMMC 2.0 defines three levels: Level 1 (Foundational) covers basic safeguarding of FCI; Level 2 (Advanced) aligns with the 110 controls of NIST SP 800-171 for protecting CUI; and Level 3 (Expert) adds a subset of NIST SP 800-172 for the highest-priority programs. Depending on level, a company either self-assesses or undergoes a third-party assessment.
Why it matters
For defense contractors, CMMC is becoming a condition of doing business: without the required level, you can’t be awarded or keep the relevant contracts. Because much of it maps to NIST SP 800-171, the work also strengthens your general security posture.
Step by step
- Determine whether you handle FCI, CUI, or both, and which CMMC level your contracts require.
- Scope the systems that store, process, or transmit that information.
- Assess against the required practices (NIST SP 800-171 for Level 2) and identify gaps.
- Remediate gaps and document a System Security Plan and Plan of Action & Milestones.
- Complete the required self-assessment or third-party assessment for your level.
- Maintain the controls and re-assess on the required cadence.
Examples
- A small parts manufacturer handling CUI targets CMMC Level 2 and works through the NIST SP 800-171 controls.
- A supplier that only receives FCI scopes to Level 1 and completes an annual self-assessment.
Common mistakes
- Assuming CMMC doesn’t apply to subcontractors; it flows down the supply chain.
- Under-scoping where CUI actually lives, which understates the work required.
- Treating the System Security Plan and POA&M as paperwork rather than a live program.
FAQ
How many levels does CMMC 2.0 have?
Three: Level 1 (Foundational) for FCI, Level 2 (Advanced) aligned to NIST SP 800-171 for CUI, and Level 3 (Expert) which adds elements of NIST SP 800-172.
How does CMMC relate to NIST SP 800-171?
CMMC Level 2 is built directly on the 110 security requirements of NIST SP 800-171, so implementing 800-171 is the core of Level 2 readiness.
Who needs CMMC?
Companies in the US defense industrial base that handle Federal Contract Information or Controlled Unclassified Information under Department of Defense contracts.
Related
Do this in Keel, not a spreadsheet
Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free