glossary

CMMC

The Department of Defense certification that verifies contractors protect government information.

What Is CMMC?

CMMC, the Cybersecurity Maturity Model Certification, is a US Department of Defense program that requires defense contractors and subcontractors to prove they protect sensitive government information to a defined cybersecurity standard. It has three levels based on data sensitivity, and meeting the required level is increasingly a condition of winning defense contracts.

How It Works

CMMC replaced an older system in which contractors simply self-attested that they met cybersecurity requirements, often inaccurately. It establishes defined levels of security and, for higher levels, requires independent verification rather than self-reporting.

There are three levels. Level 1 (Foundational) covers basic protection of Federal Contract Information through 17 safeguards and an annual self-assessment. Level 2 (Advanced) protects Controlled Unclassified Information and is anchored to the 110 controls of NIST SP 800-171. Level 3 (Expert) applies to the most sensitive programs and involves government-led assessment. Your required level depends on the type of defense information you handle.

The requirement follows the data, not company size. A small business handling Controlled Unclassified Information faces the same underlying obligation as a large contractor, and subcontractors are covered too. Note that the program’s phased rollout has seen changes, so contractors should confirm current timelines, while the underlying obligation to protect defense data remains in effect.

Why It Matters

For any business in the defense supply chain, CMMC is increasingly the price of entry. Once a CMMC requirement appears in a contract, the rule is simple: no certificate, no award. Preparation also takes time, often many months to implement and document the required controls, and certification capacity is limited. Contractors who prepare early protect their eligibility for the contracts they depend on.

Related Terms

For a complete guide, read our full article on what CMMC is and whether it applies to your business.

SecTec helps defense contractors prepare for CMMC and NIST SP 800-171 as part of our managed IT service.

Rated 5 out of 5
15

Years Protecting Businesses

500+
Clients Trust SecTec
100%
Projects

BAA Coverage on Healthcare Engagements

Zero
HIPAA Penalties Under Active Management