Skip to main content
Category: Standards and Frameworks

Cybersecurity Maturity Model Certification

Also known as: CMMC, CMMC 2.0
Simply put

The Cybersecurity Maturity Model Certification (CMMC) is a U.S. Department of Defense program designed to help protect government information from unauthorized access and exposure. It applies to companies in the Defense Industrial Base that contract with the DoD, requiring them to meet defined cybersecurity practices. The current iteration, CMMC 2.0, streamlines the program into three levels of cybersecurity requirements.

Formal definition

CMMC is a U.S. Department of Defense program that establishes cybersecurity requirements for Defense Industrial Base (DIB) contractors, intended to assist industry in meeting adequate security requirements referenced under 32 CFR. The framework draws on a combination of existing cybersecurity standards and best practices to protect government information, including controlled unclassified information (CUI). The CMMC 2.0 iteration streamlines the model into three cybersecurity levels. CMMC is distinct from SOC 2 and ISO/IEC 27001; it is a DoD-specific program tied to defense contracting requirements rather than an AICPA attestation examination or an accredited ISMS certification, and applicability, level, and assessment method depend on the nature of the contract and the information handled. Note that specific level definitions, control counts, and assessment procedures are set by the DoD program and applicable regulations and are not detailed in the evidence provided here.

Why it matters

For companies in the Defense Industrial Base (DIB), CMMC is directly tied to eligibility to contract with the U.S. Department of Defense. Because the program is intended to protect government information, including controlled unclassified information (CUI), from unauthorized access and exposure, meeting the applicable CMMC requirements can be a condition of participating in defense work. Contractors and subcontractors that handle sensitive government information may find that their required CMMC level and assessment approach depend on the nature of the contract and the type of information they handle.

CMMC 2.0 matters because it consolidates the program into three cybersecurity levels, which affects how organizations plan and prioritize their security investments. Rather than being an AICPA attestation examination like SOC 2 or an accredited management-system certification like ISO/IEC 27001, CMMC is a DoD-specific program grounded in defense contracting requirements. Organizations that already maintain SOC 2 reports or ISO 27001 certification should not assume those outcomes automatically satisfy CMMC; the frameworks are distinct, and mapping between them is at best partial.

Because the specific level definitions, control counts, and assessment procedures are established by the DoD program and applicable regulations, organizations should confirm current requirements against authoritative DoD and regulatory sources rather than relying on generalized descriptions. Applicability and level typically vary by contract, so the practical impact of CMMC on a given company depends heavily on its role in the defense supply chain and the sensitivity of the information it processes.

Who it's relevant to

Defense Industrial Base contractors
CMMC applies to companies in the Defense Industrial Base that contract with the DoD. For these organizations, meeting the applicable cybersecurity practices can be tied to their ability to participate in defense contracts, with the required level typically depending on the contract and the information involved.
Subcontractors handling government information
Organizations within the defense supply chain that handle government information, including controlled unclassified information (CUI), may fall within scope. The applicable CMMC level and assessment approach generally vary based on the nature of the work and the sensitivity of the information handled.
GRC and compliance teams managing multiple frameworks
Compliance and GRC professionals who oversee SOC 2, ISO/IEC 27001, and CMMC should treat these as distinct programs. CMMC is a DoD-specific program rather than an AICPA attestation or accredited ISMS certification, and satisfying SOC 2 or ISO 27001 does not automatically satisfy CMMC requirements.
Security engineers implementing defense-facing controls
Engineers responsible for protecting CUI and other government information may need to align their control implementations with the applicable CMMC level. Because specific control counts and assessment procedures are defined by the DoD program and applicable regulations, teams should confirm current requirements against authoritative sources.

Inside CMMC

Cybersecurity Maturity Model Certification (CMMC)
A framework established by the U.S. Department of Defense to verify that contractors and subcontractors in the Defense Industrial Base implement appropriate safeguards for federal contract information and controlled unclassified information. It is distinct from both SOC 2 and ISO 27001, and satisfying either of those frameworks does not automatically satisfy CMMC requirements.
Maturity Levels
CMMC organizes its requirements into tiered levels reflecting increasing rigor of cybersecurity practices, with the applicable level typically determined by the sensitivity of the information a contractor handles under a given DoD contract. The specific level required depends on the contract and scope.
Assessment and Verification
Depending on the level and contract, CMMC may involve self-assessment or a third-party assessment. This differs from a SOC 2 examination, which is an attestation performed by a licensed CPA firm under AICPA SSAE 18, and from ISO 27001, which is a certification issued by an accredited certification body.
Scope Boundary
CMMC applies to the environment and information covered by a DoD contract. As with a SOC 2 report or an ISO 27001 certificate, the outcome speaks only to what falls within the defined scope and does not extend to systems or data outside that boundary.

Common questions

Answers to the questions practitioners most commonly ask about CMMC.

Is CMMC the same thing as a SOC 2 report or an ISO 27001 certificate?
No. CMMC is a distinct U.S. Department of Defense framework for assessing the cybersecurity maturity of defense contractors and is not interchangeable with either. A SOC 2 report is an attestation examination performed by a licensed CPA firm under the AICPA SSAE 18 standard, while ISO/IEC 27001 is a certification of an information security management system issued by an accredited certification body. CMMC follows its own assessment ecosystem and requirements, so achieving CMMC status does not produce a SOC 2 report or an ISO 27001 certificate, and holding either of those does not by itself satisfy CMMC.
Does passing a CMMC assessment guarantee my organization is free from breaches?
No. Like other compliance outcomes, a CMMC assessment reflects the controls and scope evaluated at the time of the assessment and does not guarantee freedom from security incidents. It attests to the state of the assessed environment against the applicable requirements rather than providing an absolute assurance of security. Organizations should treat CMMC status as evidence of a defined level of practice within a defined scope, not as a warranty against future compromise.
How should we determine which scope applies to a CMMC assessment?
Scope is defined by the systems, environments, and information involved in the relevant work, and the appropriate boundary depends on your specific engagement and contractual context. In most cases, organizations identify the assets that store, process, or transmit the protected information in scope and draw the assessment boundary accordingly. Because scoping decisions materially affect the assessment, they should be confirmed with the parties responsible for the assessment rather than assumed.
Can existing SOC 2 or ISO 27001 work be reused when preparing for CMMC?
Some prior compliance work may be relevant, but reuse is typically partial. Mapping between frameworks is possible, yet satisfying one framework does not automatically satisfy another, so control evidence and documentation often need to be reviewed, adapted, or supplemented to align with CMMC's specific requirements. Organizations commonly perform a gap analysis to identify where existing controls carry over and where additional work is needed.
Who performs a CMMC assessment and what role do internal teams play?
The assessment is conducted within CMMC's own assessment ecosystem, and the outcome depends on the assessor and the defined scope. Internal teams typically prepare by documenting controls, gathering evidence, and confirming that in-scope systems reflect the intended requirements. Because outcomes depend on the assessor, scope, and applicable requirements, organizations should coordinate expectations with the responsible assessment party before the assessment begins.
How do we maintain CMMC readiness over time rather than treating it as a one-time event?
Readiness is generally maintained by treating the underlying controls as ongoing operational practices rather than point-in-time exercises. In most programs this involves keeping documentation current, monitoring the effectiveness of controls within the defined scope, and reassessing when the environment or scope changes. Ongoing maintenance helps ensure that the assessed state continues to reflect actual practice, though specific expectations vary by scope and applicable requirements.

Common misconceptions

Achieving SOC 2 or ISO 27001 means an organization automatically meets CMMC requirements.
CMMC is a separate framework with its own requirements. Mapping between these frameworks may be partial at best, and satisfying one does not automatically satisfy another. Overlap in controls does not equate to compliance across frameworks.
A CMMC outcome is the same kind of deliverable as a SOC 2 report.
A SOC 2 examination results in an attestation report issued by a CPA firm and attests only to the controls and period covered. CMMC operates under a different assessment and verification model tied to DoD contracting, and the two should not be treated as interchangeable.
Meeting CMMC guarantees an organization is free from breaches.
As with a SOC 2 report, which does not guarantee freedom from breaches, a favorable CMMC outcome reflects the assessed controls within a defined scope and is not a warranty against security incidents.

Best practices

Define and document the scope precisely, identifying the systems and information subject to CMMC requirements before beginning any assessment activity.
Determine the applicable maturity level based on the specific DoD contract and the sensitivity of the information handled, rather than assuming a single level applies universally.
Where an organization also maintains SOC 2 or ISO 27001, treat any control mappings as partial and validate CMMC requirements independently rather than relying on prior framework outcomes.
Clarify with contracting parties whether self-assessment or third-party assessment is required for the relevant level, since the verification approach varies by scope.
Maintain clear boundaries between CMMC evidence and evidence prepared for other frameworks, keeping in mind that each deliverable speaks only to its defined scope and period.
Consult authoritative DoD and CMMC sources for current level structures, control counts, and assessment requirements, since these details vary and should not be assumed from other frameworks.