Compliance frameworks
CMMC (Cybersecurity Maturity Model Certification)
Cybersecurity Maturity Model Certification is the US Department of Defense program, codified at 32 CFR Part 170, for verifying that defense contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). It has three levels: Level 1 (FCI, self-assessment), Level 2 (CUI, aligned with NIST SP 800-171), and Level 3 (aligned with a subset of NIST SP 800-172). Rollout is phased. On July 13, 2026, DoD suspended Phase II, which would have added third-party certification, so the program currently operates in Phase 1 with self-assessments at Levels 1 and 2.