CMMC 2.0: Cybersecurity Maturity Model Certification

CMMC 2.0 is the US Department of Defense's mandatory cybersecurity certification framework for defense contractors and suppliers handling Federal Contract Information or Controlled Unclassified Information.

🛡️ STATUS BADGE: 🟢 ELIGIBLE (Self-Hosted)

Executive Summary: What is it?

The Cybersecurity Maturity Model Certification (CMMC) 2.0 is a US Department of Defense (DoD) program that requires all contractors, subcontractors, and suppliers in the Defense Industrial Base (DIB) to achieve a verified cybersecurity posture before handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). CMMC is not a product certification — it is an organizational certification that validates a contractor's security practices against a tiered model built on NIST SP 800-171 (Level 2) and NIST SP 800-172 (Level 3). Phase 1 implementation began November 2025; full enforcement across all DoD contracts is mandatory by October 2026.

CFO / Business Impact: What does it cost/risk?

Technical Reality: How does it work?