CMMC · 6 min read
CMMC 2.0 Explained
What the Cybersecurity Maturity Model Certification is, its levels, and who in the defense supply chain actually needs it.
Why CMMC exists
CMMC (Cybersecurity Maturity Model Certification) is a U.S. Department of Defense program that verifies defense contractors are actually protecting sensitive government information on their systems. Before CMMC, contractors *self-attested* to following the rules, and many didn't. CMMC adds independent verification so the DoD can trust that protections are real.
It applies to the Defense Industrial Base (DIB): the contractors and subcontractors that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).
The three levels
- Level 1 (Foundational): protects FCI. 15 basic safeguarding requirements from FAR 52.204-21. Annual self-assessment.
- Level 2 (Advanced): protects CUI. The 110 requirements of NIST SP 800-171 Rev. 2. Most CUI contractors need a third-party (C3PAO) assessment every three years.
- Level 3 (Expert): for the highest-priority programs. 800-171 plus a subset of NIST SP 800-172 enhanced requirements, assessed by the government (DIBCAC).
FCI vs CUI
- FCI (Federal Contract Information): information provided by or generated for the government under a contract, not intended for public release. Drives Level 1.
- CUI (Controlled Unclassified Information): information the government requires to be safeguarded under law/regulation (e.g., technical drawings, specs). Drives Level 2+.
Knowing *which* type of data a contract involves is what determines the level, and therefore the cost and effort.
Scoring and POA&Ms
Level 2 uses a 110-point scoring method (each met requirement adds to the score). A contractor can earn a conditional certification with a limited POA&M: but only 1-point requirements are POA&M-eligible, and the score must be at least 88/110 (80%). The highest-weighted (3- and 5-point) requirements must be fully met at assessment time, and the POA&M must close within 180 days.
