Glossary / Defense / CMMC

CMMC

Also known as: Cybersecurity Maturity Model Certification · CMMC compliance

Defense

The Department of Defense's framework for verifying that a contractor's IT systems protect sensitive government data.

Per DFARS 252.204-7021, "The Cybersecurity Maturity Model Certification (CMMC) is a framework for assessing a contractor's compliance with applicable information security protections (see 32 CFR part 170)." Eligibility for many DoD contracts now ties to a verified "CMMC status" at Level 1, 2, or 3 — ranging from a self-assessment up to a formal third-party (C3PAO) or government (DIBCAC) assessment — for any system that will "process, store, or transmit" Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Contractors must "have and maintain for the duration of the contract a current CMMC status," complete annual affirmations of continuous compliance in DoD's Supplier Performance Risk System (SPRS), and flow the requirement down to subcontractors.

Source: DFARS 252.204-7021 (Acquisition.gov)

Where you'll see it

Vendor contractApplicationQuote

Why it matters for your business

  • CMMC status is increasingly a gate to winning and keeping DoD contracts.
  • A lapse or a false compliance affirmation can create contractual, cyber-liability, and even False Claims Act exposure.
  • That exposure is directly relevant to cyber, tech E&O, and reps-and-warranties coverage.

People also ask

What CMMC level does my startup need?

It depends on the data your DoD contract involves: Level 1 (basic, annual self-assessment) for Federal Contract Information, and Level 2 or 3 (with third-party or government assessment) for Controlled Unclassified Information. The required level is specified in the contract.

Does CMMC flow down to subcontractors?

Yes. Prime contractors must flow CMMC requirements down to subcontractors that handle FCI or CUI, so even small suppliers in the defense supply chain can be required to hold a CMMC status.

Ready to take the next step?

Definitions are educational and may be modified by your specific policy language, endorsements, and state rules. For regulatory guidance, refer to the California Department of Insurance or the NAIC.

Reviewed by Andrei Craciunescu, CA Licensed Insurance Broker #4467994

Last updated: July 2026.