• 4,000 firms
  • Independent
  • Trusted
Save up to 70% on staff

Home » Glossary » CMMC

CMMC

Definition

CMMC

CMMC is the US defence programme that checks a contractor has the required cybersecurity practices in place before it handles sensitive contract data. The level required depends on the data, and the higher levels swap self-attestation for an independent assessment.

Self-attestation was the model for years, and it did not hold.

Contractors asserted compliance, contracts were awarded, and nobody checked — the programme exists because the department concluded that assertion and implementation had drifted apart.

What replaces it is a tiered system: assert at the bottom, get assessed by an accredited third party in the middle, and face a government assessment at the top.

Key takeaways

  • CMMC applies to defence contractors handling federal contract information or controlled unclassified information.
  • The required level is set by the contract and driven by the data involved.
  • Level 2 assessments may be self-performed or conducted by an accredited third party.
  • Level 3 assessments are performed by the defence department’s own assessment centre.

How it works

The programme is defined in federal regulation. The definitions section of the CMMC programme rule sets out the statuses a contractor can hold, which is the clearest way to understand how the tiers operate.

Those statuses distinguish who did the assessing. A Final Level 1 (Self) status reflects a self-assessment, while Final Level 2 (C3PAO) reflects an assessment by an accredited third-party assessment organisation.

At the top, Final Level 3 (DIBCAC) status comes from an assessment by the defence contract management agency’s own cybersecurity assessment centre. The government does that one itself.

The data type drives the level. Federal contract information is defined in the acquisition regulation, and controlled unclassified information in a separate part of federal regulation — and which one you handle decides where you sit.

The security requirements themselves are not new. They come from the existing defence acquisition framework, where clause 252.204-7012 and the assessment provisions at 252.204-7019 and 252.204-7020 already applied.

LevelWho assessesTypical trigger
Level 1The contractor itselfFederal contract information only
Level 2 (Self)The contractor itselfSome controlled unclassified information
Level 2 (C3PAO)Accredited third partyMost controlled unclassified information
Level 3 (DIBCAC)The defence departmentThe most sensitive programmes

Conditional and final statuses also exist — a conditional status means gaps remain with a plan to close them, which is not the same as being finished.

Examples

Defence supply chains reach far past the primes, and the certification requirement follows the data rather than the contract value. Every case here turns on a distinction that sounds pedantic until it costs money.

A small machine shop handling drawings needs a level appropriate to the information, not to its size. Twelve employees does not exempt anyone.

A prime flows requirements to subcontractors who had not budgeted for an assessment. Assessment cost lands on the supplier, which reshapes government outsourcing pricing.

A contractor holds a conditional status and bids as though it were final. The distinction is recorded, and a contracting officer can see it.

A provider invests in controls before a contract requires them, treating cybersecurity outsourcing capability as a market entry cost. That is expensive and usually correct.

Related terms

Defence cybersecurity requirements arrive through several instruments at once, and contractors conflate the programme with the clauses. The definitions here are deliberately confined, because these terms get swapped constantly.

FAQ

Who needs CMMC?

Defence contractors and subcontractors handling federal contract information or controlled unclassified information. The requirement arrives through the contract.

What decides which level applies?

The type of information involved. Federal contract information alone points to the lowest level; controlled unclassified information raises it.

What is a C3PAO?

An accredited third-party assessment organisation authorised to conduct Level 2 assessments, as distinct from a contractor assessing itself.

Who performs Level 3 assessments?

The defence department’s own cybersecurity assessment centre, rather than a commercial assessor.

Does ISO 27001 satisfy CMMC?

No. It is a separate international certification. It may help you prepare, and it does not produce a CMMC status.

What is a conditional status?

A status granted where gaps remain alongside a plan to close them. It is distinguishable from a final status and contracting officers can see the difference.

Review source partners in the Outsource Accelerator hubs directory and ask which level the contract will require, not which is claimed.

Companies you might be interested in

Get Inside Outsourcing

An insider's view on why remote and offshore staffing is radically changing the future of work.

Order now

Start your
journey today

  • Independent
  • Secure
  • Transparent

About OA

Outsource Accelerator is the trusted source of independent information, advisory and expert implementation of Business Process Outsourcing (BPO).

The #1 outsourcing authority

Outsource Accelerator offers the world’s leading aggregator marketplace for outsourcing. It specifically provides the conduit between world-leading outsourcing suppliers and the businesses – clients – across the globe.

The Outsource Accelerator website has over 5,000 articles, 450+ podcast episodes, and a comprehensive directory with 4,700+ BPO companies… all designed to make it easier for clients to learn about – and engage with – outsourcing.

About Derek Gallimore

Derek Gallimore has been in business for 20 years, outsourcing for over eight years, and has been living in Manila (the heart of global outsourcing) since 2014. Derek is the founder and CEO of Outsource Accelerator, and is regarded as a leading expert on all things outsourcing.

“Excellent service for outsourcing advice and expertise for my business.”

Learn more
Banner Image
Get 3 Free Quotes Verified Outsourcing Suppliers
4,000 firms.Just 2 minutes to complete.
SAVE UP TO
70% ON STAFF COSTS
Learn more

Connect with over 4,000 outsourcing services providers.

Banner Image

Transform your business with skilled offshore talent.

  • 4,000 firms
  • Simple
  • Transparent
Banner Image