CMMC
Definition
CMMC
CMMC is the US defence programme that checks a contractor has the required cybersecurity practices in place before it handles sensitive contract data. The level required depends on the data, and the higher levels swap self-attestation for an independent assessment.
Self-attestation was the model for years, and it did not hold.
Contractors asserted compliance, contracts were awarded, and nobody checked — the programme exists because the department concluded that assertion and implementation had drifted apart.
What replaces it is a tiered system: assert at the bottom, get assessed by an accredited third party in the middle, and face a government assessment at the top.
Key takeaways
- CMMC applies to defence contractors handling federal contract information or controlled unclassified information.
- The required level is set by the contract and driven by the data involved.
- Level 2 assessments may be self-performed or conducted by an accredited third party.
- Level 3 assessments are performed by the defence department’s own assessment centre.
How it works
The programme is defined in federal regulation. The definitions section of the CMMC programme rule sets out the statuses a contractor can hold, which is the clearest way to understand how the tiers operate.
Those statuses distinguish who did the assessing. A Final Level 1 (Self) status reflects a self-assessment, while Final Level 2 (C3PAO) reflects an assessment by an accredited third-party assessment organisation.
At the top, Final Level 3 (DIBCAC) status comes from an assessment by the defence contract management agency’s own cybersecurity assessment centre. The government does that one itself.
The data type drives the level. Federal contract information is defined in the acquisition regulation, and controlled unclassified information in a separate part of federal regulation — and which one you handle decides where you sit.
The security requirements themselves are not new. They come from the existing defence acquisition framework, where clause 252.204-7012 and the assessment provisions at 252.204-7019 and 252.204-7020 already applied.
| Level | Who assesses | Typical trigger |
|---|---|---|
| Level 1 | The contractor itself | Federal contract information only |
| Level 2 (Self) | The contractor itself | Some controlled unclassified information |
| Level 2 (C3PAO) | Accredited third party | Most controlled unclassified information |
| Level 3 (DIBCAC) | The defence department | The most sensitive programmes |
Conditional and final statuses also exist — a conditional status means gaps remain with a plan to close them, which is not the same as being finished.
Examples
Defence supply chains reach far past the primes, and the certification requirement follows the data rather than the contract value. Every case here turns on a distinction that sounds pedantic until it costs money.
A small machine shop handling drawings needs a level appropriate to the information, not to its size. Twelve employees does not exempt anyone.
A prime flows requirements to subcontractors who had not budgeted for an assessment. Assessment cost lands on the supplier, which reshapes government outsourcing pricing.
A contractor holds a conditional status and bids as though it were final. The distinction is recorded, and a contracting officer can see it.
A provider invests in controls before a contract requires them, treating cybersecurity outsourcing capability as a market entry cost. That is expensive and usually correct.
Related terms
Defence cybersecurity requirements arrive through several instruments at once, and contractors conflate the programme with the clauses. The definitions here are deliberately confined, because these terms get swapped constantly.
- Government outsourcing: public sector contracting, the context this programme governs.
- Cybersecurity outsourcing: buying security capability to reach the required level.
- Compliance outsourcing: delegating regulatory work, which cannot produce a certification status.
- Information security analyst: the role implementing the practices an assessment tests.
- Vendor management outsourcing: running supplier assurance, including verifying subcontractor status.
- ISO 27001: an international certification that does not substitute for this programme.
- Security operations outsourcing: delegating monitoring, one practice area among many assessed.
FAQ
Who needs CMMC?
Defence contractors and subcontractors handling federal contract information or controlled unclassified information. The requirement arrives through the contract.
What decides which level applies?
The type of information involved. Federal contract information alone points to the lowest level; controlled unclassified information raises it.
What is a C3PAO?
An accredited third-party assessment organisation authorised to conduct Level 2 assessments, as distinct from a contractor assessing itself.
Who performs Level 3 assessments?
The defence department’s own cybersecurity assessment centre, rather than a commercial assessor.
Does ISO 27001 satisfy CMMC?
No. It is a separate international certification. It may help you prepare, and it does not produce a CMMC status.
What is a conditional status?
A status granted where gaps remain alongside a plan to close them. It is distinguishable from a final status and contracting officers can see the difference.
Review source partners in the Outsource Accelerator hubs directory and ask which level the contract will require, not which is claimed.







Independent




