Skip to content

CMMC EXPLAINED

What Is CMMC?

The Cybersecurity Maturity Model Certification (CMMC) is a Department of Defense program that requires organizations in the Defense Industrial Base to demonstrate cybersecurity practices before handling certain types of federal contract information.

Why CMMC exists

CMMC helps the Department of Defense reduce cybersecurity risk across its supply chain. Contractors and subcontractors that access Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) must show they meet defined cybersecurity practices before performing on applicable contracts.

The program establishes a consistent, verifiable standard so primes, subcontractors, and government customers can trust that sensitive information is protected throughout the defense industrial base.

Where The Cyber AB fits

The Cyber AB is the independent CMMC Accreditation Body — not part of the Department of Defense. We accredit CMMC Third-Party Assessor Organizations (C3PAOs) and maintain official registries so credentials and accreditation status can be verified at the source.

If you are new to CMMC, start here to understand the framework. When you are ready to act — whether getting certified, finding an assessor, or joining the ecosystem — use the linked paths below.

CMMC levels at a glance

CMMC defines three levels of cybersecurity practices. The level required for your organization depends on the type of information you handle and your contract requirements — not every organization needs the same level.

01

Level 1

Level 1
Scope
Foundational safeguarding of Federal Contract Information (FCI).
Assessment
Annual self-assessment for organizations that handle FCI only.
Typical audience
Organizations with basic federal contract information, not CUI.
02

Level 2

Level 2
Scope
Advanced practices aligned with NIST SP 800-171 for protecting Controlled Unclassified Information (CUI).
Assessment
Triennial third-party assessment by an accredited C3PAO.
Typical audience
Most organizations that handle CUI on behalf of the Department of Defense.
03

Level 3

Level 3
Scope
Expert-level practices for organizations with high-value assets or heightened risk.
Assessment
Government-led assessment with C3PAO participation; requires qualified lead assessors.
Typical audience
Organizations with the most sensitive defense information and advanced threat exposure.

Specific regulatory requirements and contract clauses should be confirmed with your contracting officer and legal counsel. This overview is for general orientation only.