Skip to main content
Category: GRC Frameworks

Cybersecurity Maturity Model Certification

Also known as: CMMC, CMMC 2.0
Simply put

The Cybersecurity Maturity Model Certification (CMMC) is a U.S. Department of Defense program designed to help protect government information from unauthorized access by setting cybersecurity requirements for contractors that work with the DoD. It combines established cybersecurity standards and practices into a certification framework. Companies in the Defense Industrial Base are generally expected to meet these requirements to handle certain government information.

Formal definition

CMMC is a U.S. Department of Defense (DoD) program that applies to contractors and other organizations within the Defense Industrial Base (DIB), intended to verify that they have implemented adequate cybersecurity practices to protect government information such as Controlled Unclassified Information (CUI). The current iteration, CMMC 2.0, streamlines the model into three levels of cybersecurity requirements drawing on existing cybersecurity standards and best practices. Per the DoD's Defense Counterintelligence and Security Agency (DCSA), the program is used to assist industry in meeting the security requirements associated with the applicable federal regulation (32 CFR). CMMC is a sector- and jurisdiction-specific compliance requirement tied to U.S. DoD contracting; it is not a general-purpose cybersecurity standard, and applicability depends on the nature of the contract and the information handled. This entry does not cover specific control mappings, assessment procedures, level-by-level requirements, or the certification and assessment ecosystem.

Why it matters

For organizations in the Defense Industrial Base (DIB), CMMC represents a sector-specific compliance obligation tied to eligibility to handle certain U.S. Department of Defense (DoD) information. Because the program is intended to protect government information such as Controlled Unclassified Information (CUI) from unauthorized access and exposure, contractors that work with the DoD are generally expected to meet the applicable requirements to bid on or perform relevant contracts. This links a firm's cybersecurity posture directly to its commercial access to DoD work, making CMMC a governance and compliance concern rather than a purely technical one.

Who it's relevant to

Defense contractors and subcontractors
Organizations within the Defense Industrial Base that contract with the DoD are the primary audience, as they are generally expected to meet CMMC requirements to handle certain government information, including CUI. Applicability and the required level depend on the nature of the contract and the information handled.
Compliance officers
Compliance teams in DIB organizations are responsible for determining whether and to what extent CMMC applies to their contracts and for mapping the requirement against existing cybersecurity standards and best practices the organization may already follow.
Information security and risk managers
Security and risk functions are relevant because CMMC is intended to verify that adequate cybersecurity practices are in place to protect government information. They typically assess the organization's practices against the applicable CMMC level, though specific control mappings and assessment procedures fall outside the scope of this entry.
Internal auditors and assurance functions
Assurance functions may review the organization's readiness and evidence relevant to CMMC obligations. Their role in providing independent assurance is distinct from management's responsibility to implement and operate the underlying cybersecurity practices.

Inside CMMC

Cybersecurity Maturity Model Certification (CMMC)
A certification framework established by the United States Department of Defense (DoD) to verify that organizations in the Defense Industrial Base (DIB) implement cybersecurity practices appropriate to the sensitivity of the information they handle. Its scope is specific to DoD contractors and subcontractors, not a universal cybersecurity standard.
Protection of federal information categories
The model is oriented toward safeguarding categories of government information handled by contractors, commonly described as Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The applicable protections typically vary according to which category an organization processes or stores.
Maturity or assurance levels
CMMC is structured around tiered levels intended to align the rigor of required practices with the sensitivity of the information involved. Higher levels are generally associated with more extensive requirements and more independent forms of assessment. Specific level numbering and content have evolved over versions, so practitioners should confirm current details against DoD sources.
Assessment and certification mechanism
The framework contemplates verification of practices through mechanisms that may range from self-assessment to assessment by third parties, depending on the level. This distinguishes CMMC from purely self-attested approaches by introducing independent verification for certain tiers.
Relationship to existing security requirements
CMMC draws on established U.S. federal cybersecurity requirements associated with the protection of CUI, including practices linked to NIST guidance issued by the National Institute of Standards and Technology. CMMC functions as a verification and certification layer rather than replacing those underlying requirements.
Contractual applicability
Applicability is generally driven by contract terms within the DoD acquisition process rather than by general law. Whether and at what level CMMC applies typically depends on the specific contract and the information it involves.

Common questions

Answers to the questions practitioners most commonly ask about CMMC.

Is CMMC a certification that any organization can pursue to demonstrate general cybersecurity maturity?
No. CMMC (Cybersecurity Maturity Model Certification) is a program administered within the context of the U.S. Department of Defense supply chain, intended to assess the protection of certain categories of information handled by defense contractors and subcontractors. It is not a general-purpose maturity badge that applies to organizations outside that context. Applicability depends on the nature of the information involved and the relevant contractual requirements, so it should not be treated as a universal cybersecurity standard.
Does achieving CMMC guarantee that an organization is secure against cyber incidents?
No. CMMC is designed to assess whether specified practices and requirements are in place at a point in time; it does not guarantee protection against breaches or incidents. As with any control assessment, it provides a degree of assurance about the presence and, at higher levels, the maturity of controls rather than an assurance of outcomes. Organizations should continue to manage cyber risk on an ongoing basis regardless of certification status.
How should an organization determine whether CMMC applies to it and at what level?
Applicability and the relevant level are typically driven by contractual requirements flowing from the U.S. Department of Defense and the type of information the organization handles. Organizations commonly begin by identifying whether they process, store, or transmit the categories of information the program is concerned with, then review applicable contract clauses and any guidance from the contracting entity. Because requirements can vary by contract and evolve over time, the specific determination should be confirmed against the current program rules and contract terms rather than assumed.
Who within an organization is typically responsible for preparing for and maintaining CMMC readiness?
Responsibility commonly spans several functions. Management (often the first line) typically owns the implementation and operation of the required practices, while compliance, risk, and information security functions (frequently second line) may support scoping, policy alignment, and monitoring. Independent assessment is a separate activity from these management responsibilities and should not be conflated with them. Clear allocation of decision rights and accountability across these roles is generally advisable.
How does CMMC preparation relate to existing risk and compliance processes an organization may already run?
CMMC-related requirements can generally be integrated with an organization's broader risk management and compliance activities rather than run in isolation. Many organizations map the required practices against controls they already maintain, identify gaps, and treat those gaps through their existing risk treatment processes. Integrating in this way may reduce duplication, though the specific requirements of the program remain distinct from any single internal framework.
What should organizations keep in mind about scoping the environment subject to CMMC?
Scoping typically focuses on the systems, people, and processes that handle the categories of information the program addresses, and defining this boundary carefully affects both the assessment and the effort required. A narrower, well-justified scope may reduce complexity, but scoping decisions should reflect where the relevant information actually resides and flows. Because scoping rules are tied to program requirements that can change, organizations should confirm current guidance rather than rely on prior assumptions. This entry does not provide implementation specifics, tooling recommendations, or legal advice.

Common misconceptions

CMMC is a general-purpose or globally applicable cybersecurity standard that any organization must adopt.
CMMC is specific to the U.S. Department of Defense supply chain and is generally invoked through DoD contracts. Organizations outside that context, or in other jurisdictions and sectors, are not typically subject to it, though they may reference related NIST guidance independently.
Achieving CMMC certification guarantees an organization is secure or free from breaches.
Certification is intended to verify that specified practices are in place at a point in time; it does not guarantee outcomes or eliminate cyber risk. It is an assurance and verification activity, not a warranty of security, and it does not substitute for ongoing risk management.
All CMMC levels rely on self-assessment, so certification is essentially self-declared.
The model contemplates differing verification approaches by level, with independent third-party assessment associated with certain tiers rather than self-attestation across the board. The degree of external assurance therefore varies with the level required.

Best practices

Confirm applicability and the required level through the specific DoD contract terms and current DoD guidance, rather than assuming a uniform requirement across all engagements.
Identify and map the categories of information handled, such as Federal Contract Information and Controlled Unclassified Information, since applicable protections commonly vary by category.
Align implementation with the underlying NIST-based requirements referenced by CMMC, treating certification as a verification layer over an established control baseline.
Distinguish the assessment approach applicable to your target level, clarifying whether self-assessment or independent third-party assessment is expected and preserving the independence of any assurance activity.
Verify version-specific details, level definitions, and assessment expectations against authoritative DoD sources, as these have evolved over time.
Extend applicable requirements to relevant subcontractors and supply chain partners where contracts require flow-down, and document the scope boundaries of what the certification does and does not cover.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps