Cybersecurity Maturity Model Certification (CMMC) is a framework that the Department of Defense developed to ensure that contractors and subcontractors achieve and maintain predetermined levels of compliance to protect federal contract information (FCI) and controlled unclassified information (CUI).
CMMC is designed to enhance security of FCI and CUI to thwart any country or person acting with malicious intent.
Any organization that handles FCI or CUI as part of its work as a contractor, subcontractor or supplier to the U.S government will need to attain CMMC certification.
Under CMMC, the implementation of cybersecurity requirements may be assessed by authorized, independent, third party auditors.
Future government contracts will say whether an organization will need to be certified at level 1, 2 or 3. To be compliant, organizations will identify what level of certification they need and either self attest or apply for an auditor to help.
CMMC 2.0 will include three levels: foundational, advanced, and expert.
At CMMC Level 1, basic safeguarding requirements are in place (such as antivirus software and physical security). Organizations who wish to achieve certifications at this level must implement 17 controls of NIST 800-171.
At CMMC Level 2, assessors will ensure security requirements for CUI specified in NIST 800-171 are implemented.
CMMC Level 3 is focused on reducing the risk from Advanced Persistent Threats (APTs). The DoD is still determining the specific security requirements for the Level 3, but has indicated that its requirements will be based on NIST 800-171 110 controls plus a subset of NIST 800-172 controls.
We've helped companies just like yours learn what steps to take to achieve compliance.
It can take months to become fully compliant and the controls outlined in NIST 800-171 provide the basis for CMMC compliance.

Questions about Cybersecurity Maturity Model Certification (CMMC)? A cybersecurity expert explains what's new and what it means.
Organizations that meet the cybersecurity policies during CMMC assessment will qualify for opportunities to bid on government contracts and subcontracts.
Browse everything we have published on CMMC, NIST 800-171, HIPAA and wider IT compliance in one place.
Fill out the simple form.
Meet with an IT professional for a discovery call.
Never worry about your IT and let us bring the right solution to your business.
Fill out our form.
.webp)