- CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense's mandatory framework for verifying cybersecurity across the defense industrial base.
- CMMC requirements apply to any organization handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) as a DoD contractor or subcontractor.
- CMMC 2.0 defines three certification levels: Foundational (Level 1), Advanced (Level 2), and Expert (Level 3), each with its own control set and assessment method.
- Certification is not self-declared for most contractors: Level 2 and Level 3 require a third-party or government-led assessment before contract award.
- CMMC data protection depends on knowing where CUI and FCI live, which is why data discovery, classification, and loss prevention tools are core to passing an assessment.
What Is CMMC?
CMMC is the U.S. Department of Defense's mandatory cybersecurity certification program for verifying that defense contractors and subcontractors protect sensitive government data. The full name, Cybersecurity Maturity Model Certification, describes a tiered model: contractors are assessed against one of three levels of cybersecurity maturity, and the level required depends on the sensitivity of the information they handle. CMMC exists because self-attestation under earlier frameworks left the defense industrial base (DIB) exposed to data theft and supply chain compromise.
The current version, CMMC 2.0, was finalized in late 2024 and took effect as a federal rule (48 CFR) on November 10, 2025. CMMC 2.0 replaced the original five-tier model with three levels, mapped requirements directly to established NIST cybersecurity standards, and introduced a phased rollout across DoD contracts. Where CMMC differs most from prior compliance regimes is enforcement: contractors can no longer simply attest to their own security posture. Most must now pass a formal assessment before a contract can be awarded.
What Is CMMC Certification?
CMMC certification is the formal process by which a defense contractor demonstrates it has implemented the cybersecurity controls required for its designated CMMC level. Certification must be valid at the time of contract award and maintained throughout the contract period, not treated as a one-time audit.
CMMC certification is achieved through one of three assessment pathways, depending on the contractor's required level:
- Annual self-assessment, used for Level 1 and some Level 2 contracts.
- Third-party assessment, conducted by a Certified Third-Party Assessment Organization (C3PAO) accredited by the Cyber AB, required for most Level 2 contracts involving CUI.
- Government-led assessment, conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), required for Level 3.
Certification also requires the contractor to document its security posture in a System Security Plan (SSP), remediate any identified control gaps, and demonstrate that controls are operationally effective rather than simply written into policy. From a data security standpoint, certification depends on knowing exactly where FCI and CUI live in the environment. An organization cannot certify controls over data it cannot locate, which is why data security posture management (DSPM) plays a direct role in supporting the assessment process.
CMMC 2.0 Levels Explained
There are three CMMC 2.0 levels, and each builds on the last with a broader control set and a more rigorous assessment method.
| Level | Name | Who it applies to | Number of controls | Assessment type |
|---|---|---|---|---|
| Level 1 | Foundational | Contractors handling FCI only | 17 practices | Annual self-assessment |
| Level 2 | Advanced | Contractors handling CUI | 110 practices (NIST SP 800-171) | Third-party C3PAO assessment for most contracts; self-assessment for select non-prioritized CUI |
| Level 3 | Expert | Contractors on critical or high-priority DoD programs | 110+ practices (NIST SP 800-172 adds 24 controls) | Government-led DIBCAC assessment |
Level 1 (Foundational) applies to contractors who handle only Federal Contract Information, typically administrative or logistical data. It requires 17 basic practices drawn from FAR clause 52.204-21, covering access control, media sanitization, and physical protection of information systems. Verification is an annual self-assessment, but the attestation is legally binding under the False Claims Act.
Level 2 (Advanced) is where most defense contractors operate. It applies to any organization handling CUI and requires all 110 security practices in NIST SP 800-171, spanning 14 control domains including access control, audit and accountability, configuration management, and system and information integrity. Most Level 2 contracts require a formal C3PAO assessment rather than self-attestation.
Level 3 (Expert) is reserved for contractors on the DoD's most sensitive programs. It builds on all 110 Level 2 controls and adds 24 practices from NIST SP 800-172, addressing threats from Advanced Persistent Threat (APT) actors. Assessment is conducted by DIBCAC, a government body, rather than a commercial C3PAO.
What Are CMMC Requirements?
CMMC requirements fall into three categories that apply across all levels: control implementation, documentation, and assessment.
- Control implementation: Organizations must implement the technical and administrative practices defined for their level, from 17 basic safeguards at Level 1 to 110 or more practices at Levels 2 and 3, most of which map to NIST SP 800-171 and NIST SP 800-172.
- Documentation: Every contractor must maintain a System Security Plan (SSP) describing how each required control is implemented. Gaps that cannot be immediately remediated are tracked in a Plan of Action and Milestones (POA&M) with defined closure timelines, typically within 180 days.
- Assessment: Depending on level, requirements are verified through annual self-assessment, third-party C3PAO assessment, or government-led DIBCAC assessment. Certification must be current at the time of contract award.
A requirement that cuts across all three categories is data visibility: organizations must be able to show precisely where FCI and CUI reside across cloud storage, SaaS applications, endpoints, and email systems before they can document or pass an assessment against controls designed to protect that data.
Why CMMC Matters for Data Security
CMMC data protection requirements exist because FCI and CUI, if compromised, create direct national security risk. FCI covers information generated or used under a government contract; CUI covers a broader set of sensitive but unclassified data such as technical specifications, export-controlled research, and defense program details. CMMC treats both categories as assets that require demonstrable, auditable protection, not just policy language.
This is what separates CMMC from earlier compliance regimes: the DoD now requires proof that contractors know where sensitive data lives, who can access it, and how it moves, rather than accepting a signed statement of intent. For data security teams, that shifts CMMC from a legal or contracts problem into an operational one. Data classification, access governance, and exfiltration monitoring become the evidence base for the entire certification.
Common CMMC Compliance Challenges
- Incomplete data visibility: Many organizations cannot fully enumerate where CUI exists across cloud, SaaS, and endpoint environments, which undermines both the SSP and the assessment scope.
- Assessment backlogs: Demand for C3PAO assessments has grown faster than assessor capacity, and scheduling delays can push certification timelines past a contract's award date.
- Scope creep: Organizations that fail to tightly define their assessment boundary end up applying controls to systems that never touch FCI or CUI, adding cost and complexity without reducing risk.
- Treating certification as a one-time event: Controls must remain operationally effective for the life of the contract; organizations that pass an assessment and then stop monitoring their environment risk falling out of compliance before recertification.
- Flowdown gaps: Prime contractors are responsible for verifying that subcontractors hold current certification at the appropriate level, and many primes lack a reliable process for tracking this across a multi-tier supply chain.
How to Achieve CMMC Compliance
- Determine your required level
Review current and prospective DoD contracts to identify whether they involve FCI only (Level 1) or CUI (Level 2 or 3). - Define your assessment scope
Map the people, systems, and facilities that process, store, or transmit FCI or CUI. A tightly scoped boundary reduces both cost and assessment complexity. - Discover and classify sensitive data
Use data security tools, particularly DSPM platforms, to locate CUI and FCI across cloud storage, SaaS applications, and endpoints. Data that cannot be found cannot be included in the SSP or protected against the controls that require it. - Run a gap assessment against NIST SP 800-171
Compare current controls to the requirements for the applicable level, and prioritize remediation by risk. - Implement controls and document everything
Close identified gaps and record every control implementation in the SSP. Track anything that cannot be immediately remediated in a POA&M. - Engage a C3PAO or DIBCAC
For Level 2 and Level 3, schedule the formal assessment well in advance given growing assessor backlogs. - Maintain the certification
Conduct periodic internal reviews, update the SSP as the environment changes, and prepare for recertification cycles. CMMC compliance is a continuous obligation, not a one-time milestone.
How Cyberhaven Addresses CMMC Compliance
Cyberhaven addresses CMMC compliance through a unified AI and data security platform that combines data discovery and classification, DLP, and data lineage to give contractors continuous, auditable visibility into where FCI and CUI live and how that data moves. Unlike point tools that address individual controls in isolation, Cyberhaven's platform ties data visibility directly to policy enforcement, so evidence for the SSP and assessment comes from the same system that prevents unauthorized disclosure in the first place.
DSPM capabilities locate and classify CUI across cloud storage, SaaS applications, and endpoints, closing the visibility gap that undermines most Level 2 assessments. DLP policies then enforce handling rules based on that classification, restricting how FCI and CUI can be shared, transferred, or exposed, which supports controls spanning access control, system and communications protection, and incident response. Data Lineage adds a chain-of-custody view, showing where sensitive data originated and how it has moved, which strengthens both the SSP narrative and ongoing recertification evidence.
Frequently Asked Questions
What is CMMC?
CMMC stands for Cybersecurity Maturity Model Certification. It is the Department of Defense's mandatory framework for verifying that contractors and subcontractors have implemented the cybersecurity controls required to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
What is CMMC certification?
CMMC certification is the formal, verified process through which a defense contractor demonstrates compliance with its required CMMC level. Depending on the level, certification is achieved through self-assessment, a third-party C3PAO audit, or a government-led DIBCAC assessment, and it must remain valid throughout the contract period.
What are CMMC requirements?
CMMC requirements span control implementation (17 to 110 or more practices depending on level), documentation in a System Security Plan, and assessment through self-attestation, C3PAO audit, or government review. All levels also require organizations to know where their FCI and CUI reside.
Who needs CMMC certification?
Any organization that processes, stores, or transmits FCI or CUI as part of a DoD contract, whether a prime contractor, subcontractor, or supplier, must meet the applicable CMMC level. The only exception is contracts limited to commercially available off-the-shelf (COTS) products.
When will CMMC be required?
CMMC requirements began appearing in DoD solicitations on November 10, 2025 (Phase 1). Full enforcement across all applicable DoD contracts is expected by November 10, 2028, with Level 2 third-party requirements expanding in 2026 and 2027.
How long does CMMC certification take?
For Level 2, most mid-sized organizations should budget 8 to 12 months from an initial gap assessment to certified status, assuming proactive remediation and timely C3PAO scheduling. Organizations with larger security gaps or complex environments should plan for longer.

.avif)
.avif)
