Level 1
Level 1- Scope
- Foundational safeguarding of Federal Contract Information (FCI).
- Assessment
- Annual self-assessment for organizations that handle FCI only.
- Typical audience
- Organizations with basic federal contract information, not CUI.
CMMC EXPLAINED
The Cybersecurity Maturity Model Certification (CMMC) is a Department of Defense program that requires organizations in the Defense Industrial Base to demonstrate cybersecurity practices before handling certain types of federal contract information.

CMMC helps the Department of Defense reduce cybersecurity risk across its supply chain. Contractors and subcontractors that access Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) must show they meet defined cybersecurity practices before performing on applicable contracts.
The program establishes a consistent, verifiable standard so primes, subcontractors, and government customers can trust that sensitive information is protected throughout the defense industrial base.
The Cyber AB is the independent CMMC Accreditation Body — not part of the Department of Defense. We accredit CMMC Third-Party Assessor Organizations (C3PAOs) and maintain official registries so credentials and accreditation status can be verified at the source.
If you are new to CMMC, start here to understand the framework. When you are ready to act — whether getting certified, finding an assessor, or joining the ecosystem — use the linked paths below.
CMMC defines three levels of cybersecurity practices. The level required for your organization depends on the type of information you handle and your contract requirements — not every organization needs the same level.
Specific regulatory requirements and contract clauses should be confirmed with your contracting officer and legal counsel. This overview is for general orientation only.