Skip to content
English - United States
  • There are no suggestions because the search field is empty.

What Is CMMC and Who Needs It?

The Department of Defense's cybersecurity certification for contractors and their suppliers.

CMMC (Cybersecurity Maturity Model Certification) is the U.S. Department of Defense program that requires contractors and subcontractors to prove they protect federal contract information and controlled unclassified information, at one of three levels, before they can be awarded contracts that involve that data. If you sell to the DoD or to a company that does, CMMC will eventually appear in your contracts.

Who it applies to

Any organization in the defense supply chain that handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI): prime contractors, and the machine shops, engineering firms, logistics providers and software vendors under them. Flow-down means a small supplier to a large prime must meet the level the prime's contract requires for the data they receive.

The three levels

  • Level 1 (Foundational): basic safeguarding of FCI, validated by annual self-assessment.
  • Level 2 (Advanced): the 110 security requirements of NIST SP 800-171 for protecting CUI, validated by a certified third-party assessor for most contracts.
  • Level 3 (Expert): Level 2 plus additional requirements for the most sensitive programs, assessed by the government.

See CMMC levels explained and what is NIST 800-171.

Timing

CMMC requirements began phasing into DoD contracts in late 2025 under a multi-year rollout, with self-assessments first and third-party certification requirements expanding over the following years. Because certification takes months of preparation, contractors should not wait for the clause to appear.

What it means for IT

Identifying where CUI lives and restricting it, enforcing MFA and access controls, logging, encryption, endpoint protection, incident response, training, and a System Security Plan with a Plan of Action for any gaps. Many contractors choose a CUI enclave (a segmented environment, often in Microsoft GCC High) rather than bringing the whole company into scope.

Common mistakes

Assuming a small company is exempt. Self-attesting to controls that are not actually implemented (which carries False Claims Act risk). Treating it as a document exercise instead of an engineering one.

Mentis Group supports defense-supply-chain manufacturers and engineering firms with CMMC readiness through Enhanced Cybersecurity, including recurring framework audits. See IT for manufacturing and distribution. This is a summary; the DoD CIO publishes the authoritative program details.

Have a question about your own environment? Schedule a consultation with Mentis Group or call (866) 901-7808.