Skip to main content
Category: CMMC & DIB Assessment

Cybersecurity Maturity Model Certification

Also known as: CMMC, CMMC 2.0
Simply put

The Cybersecurity Maturity Model Certification (CMMC) is a U.S. Department of Defense program intended to help companies in the defense industrial base meet required security standards for protecting sensitive government information. It sets tiered cybersecurity requirements that contractors must meet, with the level depending on the type and sensitivity of the information they handle. Because the program is still evolving, contractors should confirm current requirements against official DoD sources.

Formal definition

CMMC is the Department of Defense's program to verify that contractors and subcontractors in the defense industrial base have implemented adequate security requirements for handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Under CMMC 2.0, the model is structured around three levels of increasing cybersecurity rigor, with the applicable level determined by the type and sensitivity of the FCI or CUI involved. The program assesses compliance with cybersecurity standards and is associated with codification under 32 CFR; contractors should note that program structure and rollout have changed over time (including announced changes affecting Phase II requirements), and specific control mappings, phase timelines, and assessment obligations should be verified against the current authoritative DoD text. CMMC assessment and certification are distinct concepts, and readers should not treat this entry as covering contractual clause specifics or implementation details, which must be confirmed against current official sources.

Why it matters

For the defense industrial base, CMMC represents the DoD's mechanism for verifying that contractors and subcontractors actually protect the Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) they handle, rather than relying on self-attestation alone. Because the required level of cybersecurity rigor scales with the type and sensitivity of the information involved, the program directly affects a company's eligibility to compete for and perform on DoD contracts. Compliance officers and information system security managers should treat CMMC as a gating requirement tied to contract performance, not an optional maturity exercise.

A critical point for practitioners is that CMMC is still evolving, and its structure and timelines have changed over time. Notably, DoD CIO materials reference an announced suspension of CMMC Phase II requirements, which illustrates that phase timelines and rollout obligations are subject to change and must be verified against current authoritative DoD text before making compliance or contracting decisions. Assuming that a prior understanding of the program remains current is a common and consequential mistake.

Readers should also avoid two frequent errors: conflating CMMC assessment with certification, which are distinct concepts, and treating CMMC compliance as equivalent to being secure. Meeting the applicable CMMC level demonstrates that specified security requirements have been assessed, but it does not by itself guarantee protection against all threats, nor does it substitute for verifying the specific contractual clauses and implementation details that govern a given engagement.

Who it's relevant to

Defense contractors and subcontractors
Companies in the defense industrial base that handle FCI or CUI are the primary audience, since the applicable CMMC level and associated assessment obligations can affect eligibility to compete for and perform on DoD contracts. These organizations should verify their required level and current obligations against authoritative DoD sources.
Compliance officers and ISSMs
Those responsible for meeting adequate security requirements need to track CMMC's evolving structure, distinguish assessment from certification, and confirm which cybersecurity standards apply based on the sensitivity of the information handled. They should account for announced changes, such as those affecting Phase II requirements.
Government contracting and acquisition personnel
Individuals involved in structuring or awarding DoD contracts need to understand that CMMC requirements scale with information sensitivity and that program timelines have shifted over time. Contractual clause specifics and implementation details fall outside this entry and must be confirmed against current official DoD text.
Assessors and auditors
Those evaluating contractor compliance should recognize that CMMC assesses cybersecurity standards at progressively advanced levels and that assessment and certification are distinct concepts. Current control mappings and assessment obligations should be verified against the authoritative DoD program materials.

Inside CMMC

Cybersecurity Maturity Model Certification (CMMC)
A U.S. Department of Defense program intended to verify that defense contractors and subcontractors in the Defense Industrial Base (DIB) implement required cybersecurity practices to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). It is a DoD-driven framework, distinct from the underlying NIST publications it references.
Maturity/Assessment Levels
CMMC organizes cybersecurity requirements into tiered levels of increasing rigor, with lower levels generally addressing basic safeguarding of FCI and higher levels addressing protection of CUI. The specific number, naming, and scope of levels have changed across program revisions, so practitioners should confirm the current level structure against official DoD sources.
Relationship to NIST SP 800-171
CMMC requirements for protecting CUI draw substantially on the security requirements in NIST SP 800-171, which is maintained by NIST. CMMC is the DoD verification and certification layer built on top of those requirements; the two are related but not interchangeable, and the applicable NIST SP 800-171 revision matters.
Relationship to DFARS Clause 252.204-7012
DFARS clause 252.204-7012 establishes contractual safeguarding and cyber incident reporting obligations tied to NIST SP 800-171 for covered defense information. CMMC is a separate program and should not be conflated with this clause, though both are part of the broader DoD contractor cybersecurity landscape.
Assessment and Certification Ecosystem
CMMC contemplates assessments that may be conducted through self-assessment and/or third-party assessment depending on the level and program requirements, with an accreditation and assessor ecosystem overseen in connection with the CMMC Accreditation Body. The precise assessment method for each level is subject to the current program rules and should be verified.
Phased Rollout and Revisions
CMMC has been implemented through a phased approach and has undergone revisions to its model structure and requirements over time. Because terminology, level definitions, and rollout timing continue to evolve, practitioners should treat any specific structure as revision-dependent and confirm against current DoD guidance and applicable rulemaking.

Common questions

Answers to the questions practitioners most commonly ask about CMMC.

Does achieving CMMC certification mean my systems are secure?
No. CMMC certification reflects an assessment of whether specified security practices are implemented as of the assessment; it does not guarantee that a system is secure. Compliance and security are distinct concepts. A certification represents a point-in-time evaluation against a defined set of requirements, while actual security depends on ongoing operational rigor, threat conditions, and continuous vigilance beyond what any certification snapshot can capture. Certification should be treated as evidence of a baseline, not as proof of comprehensive protection.
Is CMMC the same thing as the DFARS clause 252.204-7012 requirement?
No, though they are related. DFARS clause 252.204-7012 and CMMC are distinct authorities and should not be conflated. CMMC is a certification framework overseen within the DoD ecosystem, while the DFARS safeguarding clause is a contractual provision. Contractors should not assume that satisfying one automatically satisfies the other, and should confirm the specific obligations in their contracts against current official sources, since the relationship between contractual clauses and CMMC has evolved across revisions.
How do I determine which CMMC level applies to my contract?
The applicable level generally depends on the type and sensitivity of the information you handle, such as Federal Contract Information or Controlled Unclassified Information (CUI), and on what a given contract specifies. Because level requirements and their triggers are subject to the framework's phased rollout and revisions, you should identify the requirement from your specific contract language and verify it against current authoritative DoD guidance rather than assuming a level based on prior contracts.
Can I self-assess, or do I need a third-party assessment?
This depends on the applicable level and the current requirements of the framework as of the relevant revision. Some levels have, in various iterations of CMMC, contemplated self-assessment while others contemplate third-party assessment. Because these provisions are part of an evolving, phased framework, you should confirm the assessment method required for your specific level and contract against the current official CMMC guidance before proceeding.
What is the relationship between CMMC and NIST SP 800-171?
CMMC has drawn on the security requirements associated with protecting CUI that are addressed in NIST SP 800-171, which is maintained by NIST. However, CMMC is a distinct certification framework and should not be treated as identical to the NIST publication itself. Organizations should map their obligations carefully and verify how the current CMMC revision references or incorporates NIST SP 800-171 against the authoritative sources, since these relationships have changed across versions.
Does a completed CMMC assessment remain valid indefinitely?
No. Like other authorization and certification mechanisms, a CMMC assessment reflects a point in time and is generally subject to defined validity periods and ongoing expectations rather than being permanent. You should confirm the specific validity duration, any continuous or periodic obligations, and re-assessment requirements applicable to your level against current official CMMC guidance, as these details are subject to the framework's revisions.

Common misconceptions

CMMC and NIST SP 800-171 are the same thing.
They are distinct. NIST SP 800-171 is a security requirements publication maintained by NIST, while CMMC is a DoD program that references those requirements and adds a verification/certification layer. Compliance obligations, the applicable revision, and the governing authority differ.
Meeting DFARS clause 252.204-7012 or holding CMMC certification is equivalent to being fully secure.
Compliance and certification demonstrate implementation of specified practices at a point in time; they are not the same as security. Organizations should treat CMMC as one component of an ongoing risk management effort rather than a guarantee of protection.
The CMMC level structure and requirements are fixed and unchanging.
CMMC has been rolled out in phases and revised over time, including changes to level definitions and assessment approaches. Practitioners should not rely on a prior version and must verify the current model and requirements against official DoD sources.

Best practices

Confirm which CMMC level and assessment approach apply to a given contract or data type by consulting the current, official DoD program guidance and applicable rulemaking rather than relying on prior versions.
Distinguish clearly between CMMC, NIST SP 800-171, and DFARS clause 252.204-7012 in internal documentation, and verify the specific NIST SP 800-171 revision referenced by your obligations.
Determine early whether your data involves FCI, CUI, or both, since the applicable safeguarding requirements and CMMC scope generally differ based on the information type.
Treat CMMC certification as a point-in-time result that must be sustained through ongoing cybersecurity practices, and avoid equating certification with comprehensive security.
Flow down applicable requirements to subcontractors as appropriate and confirm their obligations, since the Defense Industrial Base supply chain is within CMMC's intended scope.
Engage qualified assessors and legal or contractual advisors to confirm contractual, implementation, and certification specifics that a general reference cannot resolve, and verify all details against current authoritative sources.