Also known as: Cybersecurity Maturity Model Certification · CMMC compliance
The Department of Defense's framework for verifying that a contractor's IT systems protect sensitive government data.
Per DFARS 252.204-7021, "The Cybersecurity Maturity Model Certification (CMMC) is a framework for assessing a contractor's compliance with applicable information security protections (see 32 CFR part 170)." Eligibility for many DoD contracts now ties to a verified "CMMC status" at Level 1, 2, or 3 — ranging from a self-assessment up to a formal third-party (C3PAO) or government (DIBCAC) assessment — for any system that will "process, store, or transmit" Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Contractors must "have and maintain for the duration of the contract a current CMMC status," complete annual affirmations of continuous compliance in DoD's Supplier Performance Risk System (SPRS), and flow the requirement down to subcontractors.
Source: DFARS 252.204-7021 (Acquisition.gov)
It depends on the data your DoD contract involves: Level 1 (basic, annual self-assessment) for Federal Contract Information, and Level 2 or 3 (with third-party or government assessment) for Controlled Unclassified Information. The required level is specified in the contract.
Yes. Prime contractors must flow CMMC requirements down to subcontractors that handle FCI or CUI, so even small suppliers in the defense supply chain can be required to hold a CMMC status.
Definitions are educational and may be modified by your specific policy language, endorsements, and state rules. For regulatory guidance, refer to the California Department of Insurance or the NAIC.
Last updated: July 2026.