code/+/trust primary logo full color svg

CMMC (Cybersecurity Maturity Model Certification)

Definition

CMMC is the DoD's certification program verifying that defense contractors protect federal contract information and controlled unclassified information.

CMMC ends the era of self-attested cybersecurity on DoD contracts. Previously, contractors self-assessed their NIST 800-171 compliance and submitted a score to the SPRS database. CMMC adds mandatory third-party verification -- a C3PAO conducts an independent assessment and certifies the level.

CMMC levels

  • Level 1 (Foundational) -- 17 basic cyber hygiene practices; annual self-assessment; applies to contracts with only FCI (Federal Contract Information), not CUI
  • Level 2 (Advanced) -- 110 practices aligned to NIST 800-171; C3PAO assessment every 3 years; required for most DoD CUI contracts
  • Level 3 (Expert) -- 134+ practices; government-led assessment; applies to the most critical defense programs

CMMC implementation timeline

CMMC requirements began appearing in DoD contracts in 2025. By 2026, most contracts handling CUI require Level 2 certification as a contract award condition -- not a future compliance checkbox. If you are pursuing DoD software work in 2026, your CMMC Level 2 assessment should be underway now.

Related terms

See how we implement this

Need help implementing this in your business?

Code and Trust translates AI concepts like cmmc (cybersecurity maturity model certification) into working implementations, starting with a workflow audit that shows exactly where it creates ROI.

Schedule AI Audit →