CMMC (Cybersecurity Maturity Model Certification)

A DoD cybersecurity framework requiring defense contractors to achieve and demonstrate specific cybersecurity practices before being eligible for DoD contracts.

The Cybersecurity Maturity Model Certification (CMMC) is a framework created by the U.S. Department of Defense (DoD) to verify that defense contractors adequately protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI).

CMMC 2.0 Structure

CMMC 2.0 (the current version, effective 2024) has three certification levels. Level 1 requires self-assessment against 17 basic practices from NIST SP 800-171. Level 2 aligns with all 110 practices of NIST SP 800-171 and requires third-party assessment (C3PAO) for most DoD prime contractors. Level 3 adds 24 practices from NIST SP 800-172 and requires government-led assessments for the most sensitive programs.

Who Needs CMMC?

Any company that handles DoD CUI or FCI in performance of a DoD contract must eventually achieve the appropriate CMMC level. This affects over 300,000 companies in the Defense Industrial Base (DIB), including prime contractors, subcontractors, and suppliers.

Preparing for CMMC Assessment

Preparation involves conducting a gap assessment against NIST SP 800-171 controls, developing a System Security Plan (SSP) and Plan of Action & Milestones (POA&M), implementing required controls, and engaging a Certified Third-Party Assessment Organization (C3PAO) for Level 2 and above assessments.

Frequently asked questions

Is CMMC required for all DoD contracts?

Not all — CMMC requirements depend on the type of information handled. Contracts involving only Federal Contract Information (FCI) require Level 1 self-assessment. Contracts involving Controlled Unclassified Information (CUI) typically require Level 2, which for most prime contractors means a third-party assessment by a C3PAO.

How much does CMMC certification cost?

CMMC Level 1 self-assessment has no assessment fee (internal cost only). Level 2 third-party assessments by C3PAOs typically cost $50,000 to $200,000+ depending on company size and environment complexity, plus internal remediation costs to address any gaps.

When do CMMC requirements take effect?

CMMC 2.0 rule-making was finalized in late 2024. DoD began including CMMC requirements in contract solicitations in 2025, with phased rollout. Contractors should begin preparation immediately as assessment timelines for C3PAOs are already extended.

🤖 /llms.txt