CMMC Foundations
Your plain-English map to the CMMC program, from the data it protects to the people who assess you.
Tuition
$349
Beginner
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
8 hours
Estimated time
What you will be able to do
- You will be able to explain what the CMMC 2.0 program is, why the Department of Defense created it, and which contractors have to comply.
- You will be able to tell Federal Contract Information and Controlled Unclassified Information apart and spot each one in everyday business documents.
- You will be able to match a contract to the right CMMC level and its assessment type, whether that is a self-assessment, a third-party assessment, or a government-led one.
- You will be able to find your way around the 14 requirement families of NIST SP 800-171 and explain in plain terms what each one protects.
- You will be able to read a Supplier Performance Risk System (SPRS) score and a Plan of Action and Milestones (POA&M) and explain what they reveal about a company's readiness.
- You will be able to name the main players in the CMMC ecosystem, including the accreditation body, CMMC Third-Party Assessment Organizations (C3PAOs), assessors, and Registered Provider Organizations (RPOs), and know who to turn to for what.
- You will be able to guide a small business through the stages of a CMMC assessment, from setting the scope to earning certification.
- You will be able to describe where a CMMC practitioner or consultant adds value, and the conflict-of-interest lines an ethical practitioner never crosses.
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
Why CMMC Exists: The Data and the Rules
Before you can learn the rules, you need to know what they protect and why they appeared. This module traces the story from the defense supply chain and the sensitive data flowing through it to the government's decision to require the Cybersecurity Maturity Model Certification (CMMC). By the end, you will be able to tell Federal Contract Information (FCI) from Controlled Unclassified Information (CUI), the distinction the entire program is built on.
2 lessons · 5 quiz questions
- 02
The Three Levels of CMMC 2.0
Cybersecurity Maturity Model Certification (CMMC) 2.0 sorts defense contractors into three levels based on how sensitive the information they handle is and how much assurance the government needs. This module walks through Level 1 Foundational, Level 2 Advanced, and Level 3 Expert: what each one requires, how a company figures out which level applies to it, who performs the assessment, and how often it must happen.
2 lessons · 5 quiz questions · assignment
- 03
Inside NIST SP 800-171: The Control Backbone
Most of CMMC (Cybersecurity Maturity Model Certification) rests on a single document from the National Institute of Standards and Technology (NIST): Special Publication 800-171. This module opens it up and shows how its 14 families of security requirements are organized and what they ask a company to do. You will also see how readiness is measured through a Supplier Performance Risk System (SPRS) score and a Plan of Action and Milestones (POA&M).
2 lessons · 5 quiz questions
- 04
The CMMC Ecosystem and Your Role
CMMC runs on a network of organizations and roles, and knowing who does what is half a consultant's job. This module introduces the program's accreditation body (the Cyber AB), the CMMC Third-Party Assessment Organizations that certify contractors, and the assessors, Registered Provider Organizations, and Registered Practitioners who help companies prepare. You will follow an assessment from the first scoping call to the final decision, and see where an ethical practitioner adds real value.
2 lessons · 5 quiz questions · assignment