CMMCCybersecurity Maturity Model Certification
A DoD framework requiring defense contractors to meet specific cybersecurity standards before handling federal contract information.
In-Depth
CMMC was developed by the Department of Defense to ensure that contractors in the Defense Industrial Base (DIB) protect sensitive unclassified information. Per 32 CFR 170.14(c), the model has three levels: Level 1 (Foundational), whose 15 requirements are those at 48 CFR 52.204-21(b)(1)(i) through (xv); Level 2 (Advanced), whose requirements are identical to the 110 in NIST SP 800-171 Revision 2; and Level 3 (Expert), which adds selected NIST SP 800-172 requirements. CMMC was phased into DoD contracts through DFARS clause 252.204-7021 beginning in 2025; the Phase 2 transition to third-party assessment was suspended on July 13, 2026 pending an acquisition-reform review, leaving Level 1 and Level 2 self-assessment as the live requirements.
Related Terms
CUI
Government-created or -owned information that requires safeguarding controls per law, regulation, or government-wide policy, but is not classified.
FCI
Information not intended for public release that is provided by or generated for the government under a contract to develop or deliver a product or service.
NIST SP 800-171
The NIST standard for protecting CUI in non-federal systems. Revision 2 — the revision DoD assesses — specifies 110 security requirements and forms the basis of CMMC Level 2 and DFARS 252.204-7012 compliance.
DFARS
DoD-specific supplement to the FAR that implements defense acquisition policies, including cybersecurity clauses like DFARS 252.204-7012 for CUI protection.
SPRS
The Supplier Performance Risk System score (-203 to 110) reflecting a contractor's self-assessed compliance with NIST SP 800-171. Required for DoD contracts involving CUI.
Related Guides
Check Your CMMC Readiness
Run our free compliance tools to see where your organization stands.
Audit Your Tech Stack FreeTurn this gap analysis into a remediation plan
This Cybersecurity Maturity Model Certification explainer is the start, not the answer. Book a 25-minute compliance assessment — you leave with a prioritized roadmap and a fixed-fee implementation quote.
Book a 25-min assessmentRelated: how much CMMC certification costs — DoD’s own priced figures