No-Obligation Live Demo – Next Tuesday @ 11 AM EST / 8 AM PST / 4 PM UK

Cybersecurity Maturity Model Certification (CMMC)

A US Department of Defense cybersecurity framework setting the security levels contractors must meet to protect FCI and CUI.

A U.S. Department of Defense (DoD) cybersecurity compliance framework that establishes the security requirements contractors must meet to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Under the CMMC 2.0 model, contractors are assessed at one of three levels based on the sensitivity of the information they handle: Level 1 requires basic cybersecurity practices for FCI and annual self-assessments; Level 2 aligns with the 110 security requirements of NIST SP 800-171 for CUI and generally requires third-party certification or, in limited cases, self-assessment; and Level 3 adds selected requirements from NIST SP 800-172 for the DoD’s highest-priority programs and requires government-led assessments. As CMMC requirements are incorporated into DoD solicitations and contracts, the appropriate CMMC level becomes a condition of contract award and continued performance.

Useful Links

Related articles

This session covers how to run proposal review gates that consistently strengthen drafts through structured feedback and resolution tracking.
This session covers how to run proposal review gates that consistently strengthen drafts through structured feedback and resolution tracking.
Stage Gates, now live in VisibleThread's proposal management software, put a checkpoint at every stage boundary on your Tracked Opportunities and Proposals boards. Before a card can move forward, the person moving it has to answer the questions your team defined for that transition. The answers save against the card, permanently.

Related Glossary Terms

The official compilation of permanent U.S. federal laws, providing the statutory basis for many contracting requirements.
A global classification system used to categorize products and services for procurement and spend analysis.
A unique 12-character identifier assigned via SAM.gov to organizations doing business with the federal government, replacing the DUNS number.
See how VisibleThread transforms
t your RFP process.
×

Book a Demo