Cybersecurity Maturity Model Certification
The Cybersecurity Maturity Model Certification (CMMC) is a U.S. Department of Defense program designed to help protect government information from unauthorized access and exposure. It applies to companies in the Defense Industrial Base that contract with the DoD, requiring them to meet defined cybersecurity practices. The current iteration, CMMC 2.0, streamlines the program into three levels of cybersecurity requirements.
CMMC is a U.S. Department of Defense program that establishes cybersecurity requirements for Defense Industrial Base (DIB) contractors, intended to assist industry in meeting adequate security requirements referenced under 32 CFR. The framework draws on a combination of existing cybersecurity standards and best practices to protect government information, including controlled unclassified information (CUI). The CMMC 2.0 iteration streamlines the model into three cybersecurity levels. CMMC is distinct from SOC 2 and ISO/IEC 27001; it is a DoD-specific program tied to defense contracting requirements rather than an AICPA attestation examination or an accredited ISMS certification, and applicability, level, and assessment method depend on the nature of the contract and the information handled. Note that specific level definitions, control counts, and assessment procedures are set by the DoD program and applicable regulations and are not detailed in the evidence provided here.
Why it matters
For companies in the Defense Industrial Base (DIB), CMMC is directly tied to eligibility to contract with the U.S. Department of Defense. Because the program is intended to protect government information, including controlled unclassified information (CUI), from unauthorized access and exposure, meeting the applicable CMMC requirements can be a condition of participating in defense work. Contractors and subcontractors that handle sensitive government information may find that their required CMMC level and assessment approach depend on the nature of the contract and the type of information they handle.
CMMC 2.0 matters because it consolidates the program into three cybersecurity levels, which affects how organizations plan and prioritize their security investments. Rather than being an AICPA attestation examination like SOC 2 or an accredited management-system certification like ISO/IEC 27001, CMMC is a DoD-specific program grounded in defense contracting requirements. Organizations that already maintain SOC 2 reports or ISO 27001 certification should not assume those outcomes automatically satisfy CMMC; the frameworks are distinct, and mapping between them is at best partial.
Because the specific level definitions, control counts, and assessment procedures are established by the DoD program and applicable regulations, organizations should confirm current requirements against authoritative DoD and regulatory sources rather than relying on generalized descriptions. Applicability and level typically vary by contract, so the practical impact of CMMC on a given company depends heavily on its role in the defense supply chain and the sensitivity of the information it processes.
Who it's relevant to
Inside CMMC
Common questions
Answers to the questions practitioners most commonly ask about CMMC.