US Department of Defense cybersecurity maturity model for defence contractors.
CMMC (Cybersecurity Maturity Model Certification) is the US Department of Defense programme requiring defence contractors to achieve certified cybersecurity maturity levels. CMMC 2.0 has three levels: Level 1 (foundational, self-assessment), Level 2 (advanced, third-party assessment for critical programmes), and Level 3 (expert, government assessment). CMMC builds on NIST SP 800-171 requirements. Contractors handling Controlled Unclassified Information (CUI) must achieve appropriate certification.
Why It Matters
The DSC Perspective:
CMMC affects any organisation in the US defence supply chain. If you work with US defence contractors or have US defence aspirations, CMMC certification may be required. Preparation takes significant time and investment.
