CMMC Ready Now
Back to Knowledge Center
Getting Started6 min read

What Is CMMC?

The Cybersecurity Maturity Model Certification is the DoD's unified cybersecurity standard for defense contractors — replacing the self-attestation honor system with mandatory third-party verification.

The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense's framework for ensuring that contractors in the defense industrial base (DIB) adequately protect federal contract information (FCI) and controlled unclassified information (CUI). Codified in 32 CFR Part 170 and implemented through DFARS 252.204-7021, CMMC establishes tiered cybersecurity requirements that contractors must achieve before certain DoD contracts can be awarded.

CMMC exists because the traditional honor-system approach to cybersecurity compliance was failing. Foreign adversaries — primarily China, Russia, Iran, and North Korea — were systematically stealing hundreds of billions of dollars in defense intellectual property from the defense supply chain, often through small and medium-sized contractors whose security posture was weakest. DoD estimated that adversaries were exfiltrating critical technical data from contractors who were self-certifying compliance while actually having significant unmitigated gaps.

CMMC 2.0 vs. the original model

CMMC was first introduced in 2020 as a five-level model. In November 2021, DoD overhauled it into CMMC 2.0, reducing it to three levels and aligning it more closely with existing NIST standards. The final 32 CFR rule was published October 15, 2024. The companion 48 CFR rule, which embeds CMMC requirements into the Federal Acquisition Regulation system, was published in June 2025. As of Phase 2 (which began June 11, 2025), new DoD contracts involving CUI are now required to include DFARS 252.204-7021.

Key fact

CMMC does not create new cybersecurity requirements. The controls come from NIST SP 800-171 (Level 2) and NIST SP 800-172 (Level 3), which contractors were already obligated to implement under DFARS 252.204-7012. CMMC adds the verification mechanism — it ensures compliance is real, not just claimed.

Who governs CMMC?

  • DoD: writes the rules and sets CMMC requirements in contracts
  • Cyber AB (Cybersecurity Maturity Model Certification Accreditation Body): accredits and oversees the C3PAO ecosystem at cyberab.org
  • C3PAOs (Certified Third-Party Assessment Organizations): conduct Level 2 assessments
  • DCSA (Defense Counterintelligence and Security Agency): leads Level 3 government assessments

Ready to start your CMMC journey?

Book a free 30-minute call with Rick to get a straight answer on where you stand and what to do next.