CMMC
Also known as: Cybersecurity Maturity Model Certification
DoD certification framework for protecting federal contract information and controlled unclassified information.
Cybersecurity Maturity Model Certification (CMMC) is the US Department of Defense framework for verifying the cybersecurity practices of contractors handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI), launched in 2020 as CMMC 1.0 and substantially revised as CMMC 2.0 (announced November 2021, with rulemaking ongoing through 2024). CMMC 2.0 has three levels: Level 1 (Foundational, 17 practices, self-assessment) covering basic cyber hygiene for FCI; Level 2 (Advanced, 110 practices aligned with NIST 800-171, third-party assessment for prioritized CUI or self-assessment for non-prioritized) covering CUI protection; Level 3 (Expert, 110+ practices including NIST 800-172 enhancements, government-led assessment) for highest-priority CUI involving advanced persistent threats. The framework grew out of substantial cybersecurity concerns about defense industrial base supply chain — DoD contractors with weak cybersecurity have been substantial vectors for nation-state intelligence-gathering targeting US defense capabilities. CMMC requires third-party certification (for Levels 2 and 3) by accredited CMMC Third-Party Assessment Organizations (C3PAOs), with the CMMC Accreditation Body (now Cyber AB) overseeing the assessor ecosystem. Implementation has been controversial — small and mid-sized defense contractors face substantial cost and complexity in achieving certification, with concerns about the program's impact on the defense industrial base. Final rule publication occurred in October 2024 with phased rollout through 2028.
Core components
- Three levels in CMMC 2.0: Level 1 (Foundational, 17 practices), Level 2 (Advanced, 110 practices, NIST 800-171 aligned), Level 3 (Expert, 110+ practices, NIST 800-172 aligned)
- Self-assessment (Level 1 and some Level 2) and third-party assessment (most Level 2 and Level 3)
- CMMC Third-Party Assessment Organizations (C3PAOs)
- Cyber AB (CMMC Accreditation Body)
- Phased rollout 2025-2028
- Application to DoD contractors handling FCI and CUI
- Connection to NIST 800-171 (CUI protection requirements)
- Distinction from CMMC 1.0 (which had 5 levels and more practices)
Primary use case
Cybersecurity certification for US Department of Defense contractors and subcontractors; foundation for protecting Federal Contract Information and Controlled Unclassified Information; basis for substantial cybersecurity program development in defense industrial base; reference framework for emerging similar programs in other federal agencies; integration with broader federal cybersecurity requirements; foundation for substantial commercial assessment and consulting practice.
Common criticisms
- Substantial cost and complexity for small and mid-sized defense contractors — certification can cost tens to hundreds of thousands of dollars, with concerns about market consolidation away from small businesses
- CMMC 1.0's five levels were substantially simplified to three levels in CMMC 2.0 in response to industry feedback, but the program remains complex
- assessor capacity is limited — the C3PAO ecosystem has been slow to scale, creating bottlenecks
- tendency toward checklist compliance rather than substantive security improvement
- alignment with NIST 800-171 means CMMC inherits its critiques
- CMMC 2.0's reduction in third-party assessment requirements (allowing self-assessment for some Level 2 cases) has been criticized as weakening the program
- cross-walking with other federal cybersecurity frameworks (FedRAMP, FISMA RMF) requires substantial duplicative effort
- rulemaking and rollout have been slow, creating uncertainty for contractors
- commercial 'CMMC compliance' tooling and consulting industry has produced varying analytical quality
- geopolitical and economic considerations are entangled with cybersecurity considerations in contested ways.
Lineage
- Siblings
- FedRAMP, NIST 800-53