Cybersecurity Maturity Model Certification
The Cybersecurity Maturity Model Certification (CMMC) is a U.S. Department of Defense program intended to help companies in the defense industrial base meet required security standards for protecting sensitive government information. It sets tiered cybersecurity requirements that contractors must meet, with the level depending on the type and sensitivity of the information they handle. Because the program is still evolving, contractors should confirm current requirements against official DoD sources.
CMMC is the Department of Defense's program to verify that contractors and subcontractors in the defense industrial base have implemented adequate security requirements for handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Under CMMC 2.0, the model is structured around three levels of increasing cybersecurity rigor, with the applicable level determined by the type and sensitivity of the FCI or CUI involved. The program assesses compliance with cybersecurity standards and is associated with codification under 32 CFR; contractors should note that program structure and rollout have changed over time (including announced changes affecting Phase II requirements), and specific control mappings, phase timelines, and assessment obligations should be verified against the current authoritative DoD text. CMMC assessment and certification are distinct concepts, and readers should not treat this entry as covering contractual clause specifics or implementation details, which must be confirmed against current official sources.
Why it matters
For the defense industrial base, CMMC represents the DoD's mechanism for verifying that contractors and subcontractors actually protect the Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) they handle, rather than relying on self-attestation alone. Because the required level of cybersecurity rigor scales with the type and sensitivity of the information involved, the program directly affects a company's eligibility to compete for and perform on DoD contracts. Compliance officers and information system security managers should treat CMMC as a gating requirement tied to contract performance, not an optional maturity exercise.
A critical point for practitioners is that CMMC is still evolving, and its structure and timelines have changed over time. Notably, DoD CIO materials reference an announced suspension of CMMC Phase II requirements, which illustrates that phase timelines and rollout obligations are subject to change and must be verified against current authoritative DoD text before making compliance or contracting decisions. Assuming that a prior understanding of the program remains current is a common and consequential mistake.
Readers should also avoid two frequent errors: conflating CMMC assessment with certification, which are distinct concepts, and treating CMMC compliance as equivalent to being secure. Meeting the applicable CMMC level demonstrates that specified security requirements have been assessed, but it does not by itself guarantee protection against all threats, nor does it substitute for verifying the specific contractual clauses and implementation details that govern a given engagement.
Who it's relevant to
Inside CMMC
Common questions
Answers to the questions practitioners most commonly ask about CMMC.