CMMC is a standard for implementing cybersecurity. Its framework includes a certification element to confirm processes and practices are in place at your organization. The intention is to protect sensitive unclassified information in the supply chain. All organizations that conduct business with the Department of Defense (DoD) will soon be required to be CMMC certified. For the 220,000 DoD contractors and sub-contractors, this is critical news. In addition, Microsoft is now advising that organizations need GCC High licenses to demonstrate CMMC maturity levels.
The CMMC 2.0 model has 3 maturity levels, and the level of your organization and your CMMC 2.0 requirements are based on the level of data your company handles. For instance, CMMC Level 1 (Foundational) is for companies that handle Federal Contact Information (FCI) such as non-technical data and has 15 requirements which are aligned with FAR clause 52.204-21. Level 2 and Level 3 is for companies that handle Controlled Unclassified Information (CUI).
Many other organizations across all industries are looking to CMMC as a benchmark for compliance. For example, CMMC and FedRAMP share a common security model. FedRAMP (Federal Risk and Authorization Management Program) is an extensive process requiring a third-party audit to assess the security of Cloud solutions and services used by the U.S. federal agencies.
CMMC FAQ:
-
+-
What is CMMC?
- CMMC, or the Cybersecurity Maturity Model Certification, is a standard for cybersecurity implementation within the Defense Industrial Base (DIB). This framework is responsible for ensuring that Controlled Unclassified Information (CUI) is protected.
- The CMMC framework is mandatory for any organization that contracts with the Department of Defense (DoD). CMMC compliance began in 2020, but the DoD will continue to add new standards into new contracts until all entities are covered by 2025.
-
+-
What are the three CMMC levels of maturity?
Organizations looking to become CMMC compliant are assessed on three maturity levels:
- Level 1: Basic Safeguarding of Data- This maturity level is structured around protecting Federal Contract Information (FCI), or government information not intended for public release.
- These practices are considered foundational and are required for all higher CMMC maturity levels.
- This level includes annual Self Assessment and Annual Affirmation of 15 security requirements in FAR clause 52.204-21.
- Certification at this level indicates that an organization possesses the basic capabilities to protect CUI and has effectively implemented the security requirements of NIST SP 800-171 R2, another security framework.
- A level 2 CMMC certification signifies that an organization adequately maintains security activities, policies, and procedures, and demonstrates proper planning to manage certain activities.
- Either a self-assessment or a C3PAO assessment every three years, as specified in the solicitation.
- Decided by the type of information processed, transmitted, or stored on the contractor or subcontractor information systems.
- Annual Affirmation, verify compliance with the 110 security requirements from NIST SP 800-171 R2.
- Organizations that meet level 3 CMMC requirements are hyper-focused on protecting CUI from APTs through optimized cybersecurity capabilities.
- Organizations at this level are required to continually improve and standardize their cyber hygiene practices across the entirety of their infrastructure.
- Achieve CMMC Status of Final Level 2.
- Undergo an assessment every three years by the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).
- Provide an annual affirmation verifying compliance with the 24 identified requirements from NIST SP 800-172.
-
+-
Who assesses CMMC compliance?
- CMMC compliance is assessed by CMMC Third Party Assessment Organizations (C3PAOs). Many organizations work with cybersecurity or CMMC consultants to prepare for their assessment with a C3PAO.
-
+-
What is DFARS?
The Defense Federal Acquisition Regulation Supplement (DFARS) is an amendment to a series of rules that regulate the DoD and other government agencies’ purchasing of goods and services.
Defense contractors must be DFARS compliant to conduct business with the DoD.
-
+-
How Can an Organization Become DFARS Compliant?
Organizations must complete and submit self-assessments to the DoD annually. These assessments must include the following:
- A System Security Plan (SSP)
- A Plan of Action and Milestones (POAM)
- A CUI Environment Management Team (CEMT) -
+-
How are DFARS and CMMC related?
Both DFARs and CMMC have the same goals: protecting CUI. CMMC builds on what was started with DFARs, and the documentation developed while becoming DFARS compliant is essential to advancing through CMMC levels. While there’s some overlap between the two, it’s possible to be DFARS compliant without being CMMC compliant and vice versa.
-
+-
What’s the Difference Between CMMC and NIST SP 800-171?
CMMC is the vehicle that determines NIST SP 800-171 compliance. CMMC is a third-party assessment required to be certified as NIST SP 800-171 compliant.
-
+-
I already have NIST 800-171 R2 implemented, what’s next?
Your organization has achieved Level 2 CMMC. If it is appropriate for your organization, then Level 2 CMMC can be achieved with 24 more security activities from NIST SP 800-172. Organizations who have achieved Level 3 are hyper-focused on protecting CUI from APTs through optimized cybersecurity capabilities.
-
+-
Who Will Perform My CMMC Assessment?
CMMC assessments must be performed by an authorized and accredited C3PAO listed on the CMMC-AB marketplace. While IT consultants, Registered Practitioners and other parties can help you prepare for your CMMC assessment, only authorized and accredited C3PAOs can conduct the assessment itself.
-
+-
How Often Does My Organization Need to Be Reassessed?
A CMMC certification will be valid for 3 years with Annual Affirmation required
-
+-
What CMMC level Is required for a contract?
The required CMMC level varies. The DoD will tell you what CMMC level is required in Requests for Information (RFIs) and Requests for Proposals (RFPs).
-
+-
Can a Managed Service Provider (MSP) Help With CMMC Certification?
The short answer is – Yes! CMMC compliance preparation is tedious and resource-intensive, and it can be pricey if key resources like compliance officers and full-time IT staff are not involved. Managed service providers familiar with CMMC and IT in the manufacturing industry can provide strategic and reliable audit preparation. Working with an MSP can help ensure you submit a strong risk score to the DoD, which will help you continue your contract and position your organization favorably for future contracts.
How Interlink Can Help:
While the DoD works out every little detail about CMMC and puts it out in the open by 2026, you just cannot wait about in anticipation. You must start gearing up to conduct a thorough and accurate self-assessment and do whatever it takes after that to fulfill today’s cybersecurity requirements. This way, you will comply and will also be prepared for every future development with respect to CMMC.
Navigating through the complexities of CMMC can be both complex and overwhelming. Interlink’s experts are ready to both discuss how CMMC will impact your organization and help you facilitate this process.


.webp?width=1145&height=298&name=CMMC_Interlink-Header%20(1).webp)
