CMMC (Cybersecurity Maturity Model Certification)

CMMC turns DoD's cybersecurity expectations from a self-attestation into a verified requirement. If your contracts touch Federal Contract Information or Controlled Unclassified Information, your assessment level determines whether you can bid at all.

Who it's for
Defense contractors handling FCI or CUI
Primary benefit
Eligibility to hold DoD contracts with cybersecurity requirements
Term / renewal
Three-year certification cycle with annual affirmations
Certifying authority
DoD / accredited C3PAOs

Key takeaways

  • Certification opens doors — it does not win proposals on its own.
  • Keep your SAM.gov registration, NAICS list, and capability narrative synchronized with the certification record.
  • Target set-aside solicitations where the certification narrows the field to a handful of credible bidders.
  • Pair the certification with same-scope past performance to convert eligibility into awards.

Eligibility requirements

The required level depends on the data you handle. Level 1 covers basic safeguarding of FCI with 15 practices and annual self-assessment. Level 2 aligns with NIST SP 800-171's 110 controls and typically requires third-party assessment for prioritized programs. Level 3 adds NIST SP 800-172 requirements for the highest-risk programs.

How to apply

Scope your CUI environment, run a gap assessment against NIST SP 800-171, close gaps with documented policies and technical controls, produce a System Security Plan and Plan of Action and Milestones, post your score in SPRS, then engage a C3PAO for third-party assessment where required.

How to use it competitively

Start scoping 12 to 18 months before you need certification, and narrow your CUI enclave aggressively — the cheapest compliance program is the one covering the smallest defensible boundary. In proposals, state your level, assessment date, and SPRS score plainly; ambiguity reads as risk.

FAQ

Which level do I need?

It is specified in the solicitation, based on whether you handle FCI only (Level 1) or CUI (Level 2 or 3).

Can I self-assess?

Level 1 and some Level 2 contracts allow self-assessment; prioritized Level 2 acquisitions require a C3PAO assessment.

How much does it cost?

Costs vary widely with enclave size; small firms commonly spend tens of thousands of dollars across remediation and assessment.

Draft a compliant response for $2

RFP Scribe builds your compliance matrix and first draft from the solicitation and your Company Brain.

Get started

Services that help with this

Buy just the piece you need — most start at a few dollars, no subscription required.

Browse all services