Cybersecurity Maturity Model Certification
The Cybersecurity Maturity Model Certification (CMMC) is a U.S. Department of Defense program designed to help protect government information from unauthorized access by setting cybersecurity requirements for contractors that work with the DoD. It combines established cybersecurity standards and practices into a certification framework. Companies in the Defense Industrial Base are generally expected to meet these requirements to handle certain government information.
CMMC is a U.S. Department of Defense (DoD) program that applies to contractors and other organizations within the Defense Industrial Base (DIB), intended to verify that they have implemented adequate cybersecurity practices to protect government information such as Controlled Unclassified Information (CUI). The current iteration, CMMC 2.0, streamlines the model into three levels of cybersecurity requirements drawing on existing cybersecurity standards and best practices. Per the DoD's Defense Counterintelligence and Security Agency (DCSA), the program is used to assist industry in meeting the security requirements associated with the applicable federal regulation (32 CFR). CMMC is a sector- and jurisdiction-specific compliance requirement tied to U.S. DoD contracting; it is not a general-purpose cybersecurity standard, and applicability depends on the nature of the contract and the information handled. This entry does not cover specific control mappings, assessment procedures, level-by-level requirements, or the certification and assessment ecosystem.
Why it matters
For organizations in the Defense Industrial Base (DIB), CMMC represents a sector-specific compliance obligation tied to eligibility to handle certain U.S. Department of Defense (DoD) information. Because the program is intended to protect government information such as Controlled Unclassified Information (CUI) from unauthorized access and exposure, contractors that work with the DoD are generally expected to meet the applicable requirements to bid on or perform relevant contracts. This links a firm's cybersecurity posture directly to its commercial access to DoD work, making CMMC a governance and compliance concern rather than a purely technical one.
Who it's relevant to
Inside CMMC
Common questions
Answers to the questions practitioners most commonly ask about CMMC.
