DEFENSE & CMMC
What Is CMMC (Cybersecurity Maturity Model Certification)?
DEFINITION
CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense program that verifies defense contractors protect Federal Contract Information and Controlled Unclassified Information. It defines three levels of security requirements, from basic safeguarding self-assessments to third-party and government-led assessments, and it conditions eligibility for DoD contract awards on meeting the level specified in each solicitation.
CMMC is the Department of Defense's mechanism for verifying, rather than trusting, that companies in the defense industrial base actually implement required cybersecurity safeguards. The program is codified in federal regulation and defines three levels. Level 1 covers contractors that handle only Federal Contract Information and requires an annual self-assessment against the 15 basic safeguarding requirements of FAR 52.204-21. Level 2 covers contractors that handle Controlled Unclassified Information and is assessed against the 110 requirements of NIST SP 800-171. Level 3 adds enhanced requirements assessed by the government for a small set of contractors supporting the most sensitive programs.
CMMC applies to prime contractors and to subcontractors at every tier that handle FCI or CUI, so the requirement flows down through the defense supply chain. Small manufacturers and service providers are covered just as large primes are.
As of mid-2026, the practical picture is split. Phase 1 obligations remain mandatory: self-assessments, posting scores in SPRS, and annual affirmations by an Affirming Official. Phase 2, the third-party assessments conducted by C3PAOs, was suspended by DoD memoranda in July 2026 pending a Reform Task Force review. Contractors should keep their Level 2 posture assessment-ready rather than pausing. See NIST 800-171 vs CMMC and our defense and government practice for how the pieces fit together.
Running a program that has to satisfy this?
A Z Cyber advisor can walk your current posture against the requirement and show you what a running program looks like on Glance.
Meet Your Security Team →