The Cybersecurity Maturity Model Certification (CMMC) program is a core element of the Department of Defense’s (DoD) information security requirements for its partners in the Defense Industrial Base (DIB). Its purpose is to ensure the safeguarding of sensitive unclassified information shared between the DoD and its contractors and subcontractors. This program is designed to bolster the DoD’s confidence in contractors and subcontractors by verifying their compliance with cybersecurity requirements for programs and systems that handle controlled unclassified information.

The CMMC 2.0 program encompasses three main components:

  1. Tiered Model: CMMC mandates that companies entrusted with national security information adhere to cybersecurity standards that progressively advance based on the sensitivity and type of the information. Additionally, the program establishes guidelines for extending the requirement to protect information that is flowed down to subcontractors and vendors.

  2. Assessment Requirement: CMMC assessments will enable the DoD to validate the implementation of well-defined cybersecurity standards (Like NIST SP 800-171) by contractors and subcontractors.

  3. Implementation through Contracts: Once CMMC is fully implemented, contractors responsible for handling sensitive unclassified DoD information will need to attain a designated CMMC level as a prerequisite for being awarded a contract.

