No history yet

Introduction to CMMC 2.0

What is CMMC 2.0

The Cybersecurity Maturity Model Certification (CMMC) is a framework from the U.S. Department of Defense (DoD). Its purpose is to protect sensitive government information that is shared with private contractors. Think of it as a security standard that all companies in the Defense Industrial Base (DIB) must meet if they want to work with the DoD.

The main focus is on safeguarding Controlled Unclassified Information (CUI). CUI is information that isn’t classified but is still considered sensitive and requires protection. This could be anything from technical drawings of a new vehicle to project management details.

CMMC ensures that the entire defense supply chain, from major corporations to small businesses, has a baseline level of cybersecurity to protect against threats.

The Three Levels of CMMC

CMMC 2.0 simplifies the original framework into three progressive levels. Each level builds on the previous one, requiring more advanced cybersecurity practices. The level a company needs to achieve depends on the sensitivity of the information it handles for the DoD.

Let's break down what each level entails.

LevelTitleGeneral RequirementsAssessment Type
Level 1FoundationalBasic cyber hygiene. Implements 17 specific security practices.Annual Self-Assessment
Level 2AdvancedProtects CUI. Aligns with the 110 security controls from NIST SP 800-171.Triennial 3rd-party assessment for critical CUI; annual self-assessment for others.
Level 3ExpertProtects CUI from Advanced Persistent Threats (APTs). Builds on Level 2 with over 110 additional practices based on NIST SP 800-172.Triennial Government-Led Assessment

Choosing the Right Level

Not every contractor needs to reach the highest level. If a company only handles Federal Contract Information (FCI)—information not intended for public release—it will likely only need to meet Level 1 requirements.

Companies that handle the more sensitive CUI will need to achieve Level 2. This is the most common target for organizations in the DIB. Level 3 is reserved for companies working on the DoD's highest-priority programs, which require the most stringent security measures against sophisticated cyber threats.

Ensure participants understand the goals of CMMC and why it is essential for contract compliance.

Understanding this structure is the first step for any organization that works with the Department of Defense. It clarifies the path to compliance and helps protect critical national security information.