CMMC

Also known as: Cybersecurity Maturity Model Certification

framework · cybersecurity · regulatory-standard

DoD certification framework for protecting federal contract information and controlled unclassified information.

Cybersecurity Maturity Model Certification (CMMC) is the US Department of Defense framework for verifying the cybersecurity practices of contractors handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI), launched in 2020 as CMMC 1.0 and substantially revised as CMMC 2.0 (announced November 2021, with rulemaking ongoing through 2024). CMMC 2.0 has three levels: Level 1 (Foundational, 17 practices, self-assessment) covering basic cyber hygiene for FCI; Level 2 (Advanced, 110 practices aligned with NIST 800-171, third-party assessment for prioritized CUI or self-assessment for non-prioritized) covering CUI protection; Level 3 (Expert, 110+ practices including NIST 800-172 enhancements, government-led assessment) for highest-priority CUI involving advanced persistent threats. The framework grew out of substantial cybersecurity concerns about defense industrial base supply chain — DoD contractors with weak cybersecurity have been substantial vectors for nation-state intelligence-gathering targeting US defense capabilities. CMMC requires third-party certification (for Levels 2 and 3) by accredited CMMC Third-Party Assessment Organizations (C3PAOs), with the CMMC Accreditation Body (now Cyber AB) overseeing the assessor ecosystem. Implementation has been controversial — small and mid-sized defense contractors face substantial cost and complexity in achieving certification, with concerns about the program's impact on the defense industrial base. Final rule publication occurred in October 2024 with phased rollout through 2028.

Originators

US Department of Defense (sponsor); CMMC Accreditation Body / Cyber AB (assessor governance); broader cybersecurity policy community; intellectual antecedents in NIST 800-171 (for protecting CUI) and FISMA high

Year / Decade

2020 (CMMC 1.0); 2021 (CMMC 2.0 announcement); 2024 (final rule); 2025-2028 (phased rollout) high

Primary sources

Department of Defense (2020). CMMC 1.0 Model, Department of Defense (2021, 2024 final rule). CMMC 2.0, NIST Special Publication 800-171 (foundational CUI requirements), NIST Special Publication 800-172 (CUI enhanced requirements) high

Core components

Primary use case

Cybersecurity certification for US Department of Defense contractors and subcontractors; foundation for protecting Federal Contract Information and Controlled Unclassified Information; basis for substantial cybersecurity program development in defense industrial base; reference framework for emerging similar programs in other federal agencies; integration with broader federal cybersecurity requirements; foundation for substantial commercial assessment and consulting practice.

Common criticisms

Lineage

Siblings
FedRAMP, NIST 800-53