Also known as: Cybersecurity Maturity Model Certification · CMMC compliance · CMMC certification · CMMC 2.0
The Department of Defense's framework for verifying that a contractor's IT systems protect sensitive government data.
Per DFARS 252.204-7021, "The Cybersecurity Maturity Model Certification (CMMC) is a framework for assessing a contractor's compliance with applicable information security protections (see 32 CFR part 170)." The current program — commonly called CMMC 2.0 and codified in 32 CFR part 170 (effective December 16, 2024) — streamlined the original five-tier model into three levels. Eligibility for many DoD contracts now ties to a verified "CMMC status" at Level 1, 2, or 3 for any system that will "process, store, or transmit" Federal Contract Information (FCI) or Controlled Unclassified Information (CUI): Level 1 is an annual self-assessment against the 15 basic safeguarding requirements of FAR 52.204-21; Level 2 requires meeting the 110 requirements of NIST SP 800-171 (self-assessment for some programs, but certification by a third-party assessor — a C3PAO — for most); and Level 3 adds a subset of NIST SP 800-172 controls and is assessed by the government (DIBCAC). Contractors must "have and maintain for the duration of the contract a current CMMC status," complete annual affirmations of continuous compliance in DoD's Supplier Performance Risk System (SPRS), and flow the requirement down to subcontractors.
Source: CMMC Program Rule — 32 CFR Part 170 (eCFR)
CMMC 2.0 is the current version of the program, codified in 32 CFR part 170 (effective December 16, 2024). It streamlined the original five maturity levels into three (Level 1 self-assessment, Level 2 aligned to NIST SP 800-171, Level 3 aligned to NIST SP 800-172).
Compliance means actually meeting the required security controls (e.g., the 110 requirements of NIST SP 800-171 for Level 2). Certification is the verification step — for most Level 2 contracts a third-party assessor (C3PAO) certifies that compliance; Level 1 is self-assessed and Level 3 is assessed by the government (DIBCAC).
It depends on the data your DoD contract involves: Level 1 (basic, annual self-assessment) for Federal Contract Information, and Level 2 or 3 (with third-party or government assessment) for Controlled Unclassified Information. The required level is specified in the contract.
Yes. Prime contractors must flow CMMC requirements down to subcontractors that handle FCI or CUI, so even small suppliers in the defense supply chain can be required to hold a CMMC status.
Definitions are educational and may be modified by your specific policy language, endorsements, and state rules. For regulatory guidance, refer to the California Department of Insurance or the NAIC.
Last updated: July 2026.