CMMC
By U.S. Department of Defense
S. Department of Defense program requiring contractors and subcontractors in the defense industrial base to demonstrate specific cybersecurity practices before being awarded certain contracts.
Definition
The Cybersecurity Maturity Model Certification, or CMMC, is a U.S. Department of Defense program requiring contractors and subcontractors in the defense industrial base to demonstrate specific cybersecurity practices before being awarded certain contracts. It assigns organizations to maturity levels, each requiring an increasing set of security practices largely drawn from NIST guidance, and verification ranges from self-assessment at lower levels to third-party or government-led assessment at higher levels handling more sensitive information.
Overview
CMMC was created in response to a recurring problem in defense contracting: contractors were contractually required to protect sensitive but unclassified information, yet the Department of Defense had limited ability to verify that required cybersecurity practices were actually implemented rather than merely claimed. Earlier self-attestation models under existing contract clauses left significant gaps, and incidents involving compromised defense supply chain data made a verification mechanism a priority. Mechanically, CMMC organizes cybersecurity practices into a small number of maturity levels, with the specific practices at each level drawn heavily from existing NIST publications, particularly NIST 800-171 for protecting controlled unclassified information. Lower levels covering basic safeguarding of federal contract information can be satisfied through a contractor's own self-assessment, while higher levels involving controlled unclassified information require assessment by an accredited third-party organization, and the most sensitive programs may require government-led assessment. Contracts specify the required CMMC level, and contractors must achieve and maintain certification at that level to remain eligible. CMMC differs from FedRAMP in that FedRAMP governs cloud service providers selling to any federal agency, while CMMC specifically governs the defense industrial base, the network of contractors and subcontractors supporting Department of Defense contracts, regardless of whether cloud services are involved. It is also narrower in practice reach than a general framework like ISO 27001, since it applies specifically to entities handling defense-related information rather than being a generic security certification. In practice, defense contractors of all sizes, from large primes to small subcontractors supplying components or services, must determine which CMMC level their contracts require and prepare accordingly, often years before a contract's award since certification and remediation take substantial lead time. Because requirements can flow down through subcontract tiers, even small businesses with no direct government contract may need certification if they supply a prime contractor handling controlled unclassified information. The program has been a significant burden for smaller subcontractors, who often lack dedicated security staff and must invest heavily in documentation, technical controls, and assessment costs to remain eligible for defense work. Because the underlying practices largely mirror NIST 800-171 and 800-53 concepts, organizations already compliant with those frameworks have a head start, but achieving formal CMMC certification is still a distinct undertaking with its own assessment and documentation requirements that a general NIST-aligned security posture does not automatically satisfy. Assessment costs and remediation timelines also scale with certification level, so a subcontractor targeting only basic safeguarding requirements faces a materially lighter lift than one supporting programs that require handling controlled unclassified information at a higher assessed level.
Key Concepts
- Applies specifically to contractors in the U.S. defense industrial base
- Organizes required practices into a small set of maturity levels
- Draws heavily on NIST 800-171 practices for controlled unclassified information
- Uses self-assessment at lower levels and third-party assessment at higher ones
- Flows down through subcontract tiers to smaller suppliers
- Ties certification directly to eligibility for specific defense contracts
- Requires periodic reassessment to maintain certified status
- Overseen by Department of Defense-affiliated accreditation infrastructure