CMMC compliance applies to organizations working with the Department of Defense and its supply chain. Understanding who must comply, which level applies, and how to prepare can make the process more manageable.
What is CMMC?
The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense’s (DoD) cybersecurity framework for organizations that process, store, or transmit sensitive government information. It defines security requirements to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) while creating a consistent cybersecurity standard across the Defense Industrial Base (DIB).
Depending on the contract and the type of information involved, organizations may need to complete a self-assessment or an independent assessment before they can win or continue working on DoD contracts. Meeting CMMC requirements helps organizations protect sensitive data and demonstrate to the DoD and their customers that they have appropriate cybersecurity controls in place.
Get CMMC Compliant 90% Faster
Who needs to comply with CMMC?
Not every business requires CMMC compliance. The framework applies primarily to organizations that do business with the DoD or participate in its supply chain.
Organizations that may require CMMC certification include:
- Prime defense contractors
- Defense subcontractors
- Organizations handling Federal Contract Information (FCI)
- Organizations handling Controlled Unclassified Information (CUI)
- Suppliers and service providers handling FCI or CUI for DoD contracts
Organizations that only handle FCI generally have lower compliance obligations than those handling CUI, which requires more comprehensive cybersecurity controls. Because CMMC requirements are contract-driven, organizations should carefully review solicitation and contract language to determine which certification level applies.
CMMC certification levels
CMMC consists of three certification levels based on the sensitivity of the information an organization handles and the level of cybersecurity required.
Level 1
Designed for organizations that handle Federal Contract Information (FCI). Organizations complete an annual self-assessment to demonstrate compliance.
Level 2
Applies to organizations handling Controlled Unclassified Information (CUI). Depending on the contract, organizations must complete either a self-assessment or an assessment by a Certified Third-Party Assessment Organization (C3PAO).
Level 3
Required for organizations supporting the highest-risk DoD programs. Compliance is verified through a government-led assessment.
As organizations move to higher CMMC levels, they must implement more advanced security controls and meet stricter assessment requirements. Understanding which level applies is the first step toward meeting CMMC requirements and maintaining continuous compliance.
Streamline GRC workflows with no blind spots.
How to prepare for CMMC compliance
Preparing for certification requires planning, documentation, and the implementation of appropriate security controls. While every organization’s journey is different, most can prepare for CMMC by following these key steps:
1. Determine your required CMMC level
Review your DoD contracts to determine whether your organization handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). This determines which CMMC certification level and security requirements apply.
2. Assess your current security controls
Evaluate your existing cybersecurity program against the applicable CMMC requirements to identify gaps before the formal assessment. Many organizations use cybersecurity tools to assess controls, track remediation, and simplify evidence collection.
3. Address compliance gaps
Implement the required technical, administrative, and operational controls. Update policies, procedures, and supporting documentation to strengthen your security posture.
4. Prepare documentation and evidence
Collect evidence showing that security controls are implemented and operating effectively. Keeping it organized simplifies assessments and reduces preparation time.
5. Complete the required assessment
Depending on your certification level and contract requirements, complete either a self-assessment or an independent assessment performed by an authorized C3PAO.
6. Maintain continuous compliance
Organizations should continuously monitor security controls, update documentation, remediate identified issues, and maintain evidence to remain prepared for future assessments and contract requirements.
💡For a step-by-step breakdown of the process, download our CMMC compliance checklist to help your organization prepare for certification.
