Solutions for Enterprise-Wide Procurement

Cybersecurity Maturity Model Certification (CMMC)

Summary

Effective Dec 16th, 2024, the Department of Defense (DoD) established the Cybersecurity Maturity Model Certification (CMMC) Program to verify Contractors have implemented required security measures necessary to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The mechanisms discussed in this rule will allow the Department to confirm a defense contractor or subcontractor has implemented the security requirements for a specified CMMC level and is maintaining that status (meaning level and assessment type) across the contract period of performance. This rule will be updated as needed, using the appropriate rulemaking process, to address evolving cybersecurity standards, requirements, threats, and other relevant changes.

CMMC Level Selection

An OSA will select the CMMC level it desires to attain. Once the CMMC Program is implemented, a DoD solicitation will specify the minimum CMMC Status required to be eligible for award. One of four CMMC Statuses will be specified:

For more details on Cybersecurity Maturity Model Certification (CMMC), please use the provided links: