The U.S. Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) program has finally moved from concept to contract language. Cybersecurity compliance for companies hoping to participate in the defense supply chain is now a prerequisite for doing business, right alongside AS9100, ITAR, Nadcap, and IPC standards.
For years, many organizations have self-attested to cybersecurity compliance. Unfortunately, a series of high-profile cyber incidents demonstrated that self-attestation didn’t always translate into effective implementation. Sensitive information would leak through vulnerabilities in the Defense Industrial Base (DIB), often via suppliers and subcontractors. The DoD wants verification that contractors handling sensitive information are actually protecting it. CMMC 2.0 is the DoD’s answer.
The CMMC 2.0 framework establishes three levels of cybersecurity maturity:
- Level 1, Foundational: Focuses on basic cyber hygiene and protection of Federal Contract Information (FCI). Organizations perform annual self-assessments.
- Level 2, Advanced: Aligns with the 110 security controls contained in NIST SP 800-171, the long-established standard for protecting Controlled Unclassified Information (CUI). Depending on the program, organizations may perform self-assessments or undergo third-party assessments by authorized C3PAOs.
- Level 3, Expert: Applies to a relatively small group of contractors supporting critical national security programs and includes additional government-led assessment requirements.
To continue reading this article, which appeared in the August 2026 SMT007 Magazine, click here.