CMMC
CMMC — the Cybersecurity Maturity Model Certification — is the U.S. Department of Defense's program for verifying that its contractors actually protect sensitive government information. If you're in the defense supply chain and you're seeing "CMMC Level 2" in contract language, here's the plain-language version: what it is, the three levels, how it maps to NIST 800-171 and 800-53, who needs it, how assessment works, and how to get ready.
CMMC checklist
A practical Level 1 & Level 2 readiness checklist.
Free readiness assessment
See your CMMC gaps in minutes.
Map to other frameworks
How CMMC lines up with NIST 800-171, 800-53 & SOC 2.
Illustrative statuses. Your real assessment is generated from your answers in the app. Standpoint is a self-assessment aid, not legal advice.
What is CMMC?
CMMC is a certification program, not a new set of controls invented from scratch. The DoD already required contractors to protect its information — CMMC adds a verification layer so the department can trust that the required safeguards are genuinely in place rather than just self-attested on paper. The current version, CMMC 2.0, streamlined an earlier five-level model down to three, and aligned its technical requirements directly with existing NIST standards so contractors aren't chasing a separate rulebook.
The two kinds of information CMMC protects
CMMC exists to protect two categories of government information that flow to contractors: - FCI — Federal Contract Information: information provided by or generated for the government under a contract that isn't intended for public release. - CUI — Controlled Unclassified Information: more sensitive government information that requires safeguarding under law or policy (e.g., technical data, specifications). CUI is what drives the higher CMMC levels.
The three CMMC 2.0 levels
Most of the defense supply chain lands at Level 1 or Level 2. Level 2 is where the bulk of the work sits, because it maps to the full 110 requirements of NIST 800-171.
How CMMC relates to NIST 800-171 and 800-53
This is the key insight that saves duplicate work. CMMC Level 2 is essentially NIST SP 800-171 — the 110 requirements for protecting CUI in non-federal systems. NIST 800-171, in turn, was derived from the moderate-baseline controls in NIST SP 800-53. So the security work you do for 800-53 or 800-171 is largely the same work CMMC assesses — the difference is that CMMC adds formal certification on top. If you've been building toward 800-53 or 800-171, you're already most of the way to CMMC Level 2.
How does CMMC assessment work?
The path depends on your level. Level 1 is an annual self-assessment with an executive affirmation. Level 2 generally requires an assessment by a C3PAO (a CMMC Third-Party Assessment Organization) every three years, with annual affirmations in between; a limited set of Level 2 cases allow self-assessment. Level 3 is assessed by the government (DCMA's DIBCAC). Software like Standpoint helps you get ready and organize evidence; the certification itself is issued through the DoD's authorized ecosystem, not by a tool.
A practical path to readiness
- Determine your level. Do you handle FCI (Level 1) or CUI (Level 2)? Contract language and your data flows decide this. - Scope your environment. Identify where FCI/CUI lives — the systems and people in the assessment boundary. - Run a gap assessment. For Level 2, measure against the 110 NIST 800-171 requirements. - Remediate and evidence. Close gaps, write your System Security Plan (SSP), and keep a POA&M for anything outstanding. - Get your SPRS score in, then assess. Submit your score, then self-assess or engage a C3PAO for certification. The fastest start is a gap assessment. Our free CMMC readiness assessment shows where you stand, and the implementation checklist turns it into a working plan.
CMMC work counts elsewhere too
The crosswalk maps your CMMC evidence onto the frameworks it overlaps — so you move forward on several at once.