Compliance

CMMCCybersecurity Maturity Model Certification

A DoD framework requiring defense contractors to meet specific cybersecurity standards before handling federal contract information.

In-Depth

CMMC was developed by the Department of Defense to ensure that contractors in the Defense Industrial Base (DIB) protect sensitive unclassified information. Per 32 CFR 170.14(c), the model has three levels: Level 1 (Foundational), whose 15 requirements are those at 48 CFR 52.204-21(b)(1)(i) through (xv); Level 2 (Advanced), whose requirements are identical to the 110 in NIST SP 800-171 Revision 2; and Level 3 (Expert), which adds selected NIST SP 800-172 requirements. CMMC was phased into DoD contracts through DFARS clause 252.204-7021 beginning in 2025; the Phase 2 transition to third-party assessment was suspended on July 13, 2026 pending an acquisition-reform review, leaving Level 1 and Level 2 self-assessment as the live requirements.

Check Your CMMC Readiness

Run our free compliance tools to see where your organization stands.

Audit Your Tech Stack Free

Turn this gap analysis into a remediation plan

This Cybersecurity Maturity Model Certification explainer is the start, not the answer. Book a 25-minute compliance assessment — you leave with a prioritized roadmap and a fixed-fee implementation quote.

Book a 25-min assessment

Related: how much CMMC certification costs — DoD’s own priced figures