CMMC (Cybersecurity Maturity Model Certification)
CMMC turns DoD's cybersecurity expectations from a self-attestation into a verified requirement. If your contracts touch Federal Contract Information or Controlled Unclassified Information, your assessment level determines whether you can bid at all.
- Who it's for
- Defense contractors handling FCI or CUI
- Primary benefit
- Eligibility to hold DoD contracts with cybersecurity requirements
- Term / renewal
- Three-year certification cycle with annual affirmations
- Certifying authority
- DoD / accredited C3PAOs
Key takeaways
- Certification opens doors — it does not win proposals on its own.
- Keep your SAM.gov registration, NAICS list, and capability narrative synchronized with the certification record.
- Target set-aside solicitations where the certification narrows the field to a handful of credible bidders.
- Pair the certification with same-scope past performance to convert eligibility into awards.
Eligibility requirements
The required level depends on the data you handle. Level 1 covers basic safeguarding of FCI with 15 practices and annual self-assessment. Level 2 aligns with NIST SP 800-171's 110 controls and typically requires third-party assessment for prioritized programs. Level 3 adds NIST SP 800-172 requirements for the highest-risk programs.
How to apply
Scope your CUI environment, run a gap assessment against NIST SP 800-171, close gaps with documented policies and technical controls, produce a System Security Plan and Plan of Action and Milestones, post your score in SPRS, then engage a C3PAO for third-party assessment where required.
How to use it competitively
Start scoping 12 to 18 months before you need certification, and narrow your CUI enclave aggressively — the cheapest compliance program is the one covering the smallest defensible boundary. In proposals, state your level, assessment date, and SPRS score plainly; ambiguity reads as risk.
FAQ
Which level do I need?
It is specified in the solicitation, based on whether you handle FCI only (Level 1) or CUI (Level 2 or 3).
Can I self-assess?
Level 1 and some Level 2 contracts allow self-assessment; prioritized Level 2 acquisitions require a C3PAO assessment.
How much does it cost?
Costs vary widely with enclave size; small firms commonly spend tens of thousands of dollars across remediation and assessment.
Draft a compliant response for $2
RFP Scribe builds your compliance matrix and first draft from the solicitation and your Company Brain.
Get startedServices that help with this
Buy just the piece you need — most start at a few dollars, no subscription required.
Capability Statement Generator
$10Generate a professional cap statement highlighting your certification.
Buy NowCompliance & Readability Scan
$2Verify your proposal meets all certification-related requirements.
Buy NowPast Performance Narrative Writer
$5Turn contract history into evaluator-ready narratives.
Buy Now