What is Cybersecurity Maturity Model Certification (CMMC)?

Image source:  Canva
Image source: Canva

POSTED:  October 2, 2025

What is Cybersecurity Maturity Model Certification (CMMC)?

CMMC is a framework developed by the U.S. Department of Defense (DoD) to protect controlled unclassified information (CUI) within the defense industrial base [1]. It sets cybersecurity standards that contractors must meet to securely handle sensitive government data. CMMC is a tiered certification framework designed to assess and verify an organization’s ability to safeguard CUI and federal contract information (FCI). It is structured into multiple levels, each defining security requirements that organizations must meet before bidding on DoD contracts.

The CMMC framework builds upon existing regulations like National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 but introduces a certification requirement to validate compliance. CMMC applies to any organization in the DoD supply chain and helps protect against cyberthreats by enforcing stricter cybersecurity controls.

CMMC consists of different levels that define the cybersecurity maturity of an organization:

Level 1 (Foundational)

  • Who It Applies to:  Companies that handle FCI but not CUI [2].

  • Requirements:  Must implement 17 basic cybersecurity practices aligned with Federal Acquisition Regulation (FAR) 52.204-21 (“Basic Safeguarding of Covered Contractor Information Systems”).

  • Assessment:  Annual self-assessment (no third-party audit required).

Level 2 (Advanced)

  • Who It Applies to:  Companies that process, store, or transmit CUI.

  • Requirements:  Must comply with NIST SP 800-171, which includes 110 cybersecurity controls for protecting CUI.

  • Assessment:  Prioritized programs (critical national security), which require a triennial certified third-party assessment organization (C3PAO) audit; nonprioritized programs require an annual self-assessment.

Level 3 (Expert)

    • Who It Applies to:  Companies working on the most sensitive DoD contracts involving CUI with heightened security risks.

    • Requirements:  Must comply with NIST SP 800-171, plus additional security controls from NIST SP 800-172 for advanced threat protection.

    • Assessment:  Triennial government-led assessment conducted by Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).

      CMMC Model

 Figure 1.  Diagram of the Three Levels Found in the CMMC Model (Source:  DoD Chief Information Officer [CIO]).

Relevant Applications to the U.S. Department of Defense (DoD)

Defense Contractors Adopting CMMC

Major defense contractors like Lockheed M artin, Northrop Grumman, and Raytheon are required to comply with CMMC regulations to continue working on sensitive government projects [3]. These companies have invested in advanced cybersecurity frameworks, hired compliance experts, and undergone third-party assessments to ensure they meet at least CMMC Level 3 for handling CUI.

Universities and Research Institutions Adopting CMMC for Federal Grants

Many universities and research institutions that work on DoD-funded projects must comply with CMMC guidelines. Schools like the Massachusetts Institute of Technology Lincoln Laboratory and Johns Hopkins Applied Physics Laboratory have implemented strict cybersecurity measures to protect sensitive research data and prevent foreign adversaries from exploiting government-funded innovations.

Additional Resources

Latest Related News/Articles

References

[1] About CMMC (DoD CIO).

[2] Protecting Controlled Unclassified Information (NIST).

[3] CMMC Resources (The Johns Hopkins University Applied Physics Laboratory).