◦ Reference · Framework

CMMC

Cybersecurity Maturity Model Certification, administered by the DoD to gate defense industrial base (DIB) contractors handling Federal Contract Information and Controlled Unclassified Information. CMMC 2.0 collapses the prior five levels to three (Level 1 self-attestation through Level 3 C3PAO assessment). Attention is triggered by a Level breakdown that lets the prime contractor lose flow-down eligibility, by an SPRS score that drops below the solicitation threshold, by a missing NIST SP 800-171 control assessment, and by an incident that requires a 72-hour cyber-incident reporting under DFARS 252.204-7012.

/cmmc