Watch DemoRead About It
Browse ServicesService Provider InfoSign In / Up
IT & Cyber SecurityFederalComing soon

CMMC Compliance

Service description

CMMC (Cybersecurity Maturity Model Certification) compliance refers to the mandatory adherence of Department of Defense (DoD) contractors to cybersecurity standards aimed at protecting sensitive information, specifically Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). CMMC 2.0, the current version, streamlines compliance into three levels, each with specific requirements based on the type of information handled. Depending on the level, compliance is verified through self-assessment, third-party assessments (by C3PAOs), or government-led assessments (by DIBCAC). CMMC compliance is heavily based on the NIST SP 800-171 standard. Level 1 compliance requires annual assessment. Levels 2 & 3 compliance requires assessment every 3 years.

Common industries

Applies to Department of Defense contractors and subcontractors handling federal contract or controlled unclassified information.

ROI

Certification is a prerequisite to win and keep DoD contracts — the return is continued eligibility for that revenue.

Benefit

Prepare for and achieve Cybersecurity Maturity Model Certification, required for Department of Defense contractors handling federal contract information.

Why get it

Contractors must hold the required CMMC status to win and keep covered contracts. Handling government information without the required safeguards puts that work at risk.

When you benefit

A one-time readiness effort, then periodic assessment and an annual affirmation to stay current.

What it costs

Typically a project fee.

When you pay

Readiness work is usually a fixed project fee or hourly, scaled to the number of systems and the gaps found. Ongoing monitoring and affirmation support is often a monthly fee. Any required third-party assessment is paid for separately.

Other costs

Third-party assessment fees where required, security tools and upgrades to close gaps, and staff time.

Risks to know

A contractor without the required CMMC status can lose contracts or be ineligible for new ones. An official of the company must affirm continued compliance each year, so the records behind it must be accurate. Covered contractors must also report cyber incidents to the Department of Defense within 72 hours of discovery.

When risks arise

Gaps surface at assessment, or when a solicitation sets a CMMC level the business lacks. An incident can start the 72-hour reporting clock at any time.

The process

The provider scopes the systems that handle covered information and assesses them against the required level. The business closes the gaps found, with the provider supporting remediation and documentation. Where the level requires it, a third-party assessor then evaluates the business, and the business affirms its status.

Your commitment

The business identifies which contracts and systems handle federal contract information or controlled unclassified information, and names an official to affirm compliance. It should give the provider access to its IT environment and policies, and budget time to fix gaps.

Documents to gather

Helpful reading

Further research

Suggest an edit to this page →

Not open yet

CMMC Compliance isn’t taking requests yet. Join the waitlist. It is listed in your requests tray.