A U.S. Department of Defense (DoD) cybersecurity compliance framework that establishes the security requirements contractors must meet to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Under the CMMC 2.0 model, contractors are assessed at one of three levels based on the sensitivity of the information they handle: Level 1 requires basic cybersecurity practices for FCI and annual self-assessments; Level 2 aligns with the 110 security requirements of NIST SP 800-171 for CUI and generally requires third-party certification or, in limited cases, self-assessment; and Level 3 adds selected requirements from NIST SP 800-172 for the DoD’s highest-priority programs and requires government-led assessments. As CMMC requirements are incorporated into DoD solicitations and contracts, the appropriate CMMC level becomes a condition of contract award and continued performance.
Cybersecurity Maturity Model Certification (CMMC)
A US Department of Defense cybersecurity framework setting the security levels contractors must meet to protect FCI and CUI.
Useful Links
Related articles
BD, capture and proposal alignment is something most organizations believe they already have, until a deadline exposes where it breaks. At WPS, a Health Solutions Company, the three functions were moving in parallel but not in sync, and the cost was showing up long before anyone started writing.
Casual drinks with the people who win federal business. Alongside AFCEA LA Space Industry Days.
Related Glossary Terms
The official compilation of permanent U.S. federal laws, providing the statutory basis for many contracting requirements.
A global classification system used to categorize products and services for procurement and spend analysis.
A unique 12-character identifier assigned via SAM.gov to organizations doing business with the federal government, replacing the DUNS number.
See how VisibleThread transforms
t your RFP process.
t your RFP process.