Skip to content

FOR ORGANIZATIONS

Getting CMMC Certified

Organizations in the Defense Industrial Base may need CMMC certification to bid on or perform work under applicable Department of Defense contracts. This page outlines the general path — your specific requirements depend on the information you handle and your contract terms.

Why certification matters

When a DoD contract requires CMMC, your organization must demonstrate conformance at the applicable level before award or during performance, depending on contract requirements. Certification provides verifiable assurance that your cybersecurity practices meet program standards.

Prime contractors and subcontractors throughout the supply chain are affected. Understanding your role and the information you handle is the first step toward readiness.

The general certification path

Most organizations follow a similar sequence: understand what level applies, close gaps through readiness work, undergo the required assessment, and maintain conformance over time. The Cyber AB ecosystem connects you to accredited assessors and verified providers at each stage.

Four steps to certification

  1. Understand your requirements

    Review your contracts and the information you handle to determine which CMMC level applies. Use the level comparison below as decision support — not a legal determination.

  2. Get readiness support

    Close gaps before assessment. The Cyber Engagement Forum supports pre-assessment consulting, gap analysis, and readiness preparation.

  3. Undergo assessment

    Engage an accredited C3PAO for the required third-party assessment, or complete a self-assessment where applicable at Level 1.

  4. Maintain and renew

    Certification is not one-and-done. Plan for ongoing monitoring, reassessment cycles, and contract-driven updates to your security program.

Which level applies to you?

Use this comparison to orient your planning. Your contracting officer and the information you handle determine the authoritative level requirement.

01

Level 1

Level 1
Scope
You handle Federal Contract Information (FCI) but not CUI.
Assessment
Annual self-assessment attestation.
Typical audience
Start with foundational practices and self-assessment guidance.
02

Level 2

Level 2
Scope
You handle Controlled Unclassified Information (CUI) on DoD contracts.
Assessment
Triennial assessment by an accredited C3PAO.
Typical audience
Most defense contractors seeking to bid on CUI-related work.
03

Level 3

Level 3
Scope
You protect high-value assets or face advanced persistent threats.
Assessment
Government-led assessment with C3PAO support.
Typical audience
Organizations with the highest sensitivity and risk profile.