---
title: "Cybersecurity Maturity Model Certification (CMMC): What, How, When and Why?"
description: For almost two years now, the US Department of Defense (DOD) has been reviewing a process designed to ensure defense contracts meet very specific cybersecurity standards when it comes to handling unclassified information.
image: https://csacyber.com/hubfs/11-e1644932665609.png
---

[Skip to content](https://csacyber.com/blog/cybersecurity-maturity-model-certification-cmmc-what-how-when-and-why#main-content)

[![CSA Cyber - Cyber Security Solutions to Protect your People](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=300&height=108&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber - Cyber Security Solutions to Protect your People")](https://csacyber.com/)

- Services 
    - [Offensive Security Services](https://csacyber.com/offensive-security-services) 
          - [Penetration Testing](https://csacyber.com/penetration-testing)
          - [Red Teaming and attack simulations](https://csacyber.com/offensive-security-services#red-teaming)
          - [Continuous testing](https://csacyber.com/offensive-security-services#continuous-assurance)
          - [Managed offensive security](https://csacyber.com/offensive-security-services#managed-offensive)
    - [Consultancy Services](https://csacyber.com/cyber-consultancy-services) 
          - [Frameworks & assessments](https://csacyber.com/cyber-consultancy-services/frameworks-and-assessments)
          - [Data protection](https://csacyber.com/cyber-consultancy-services#data-protection)
          - [Virtual leadership](https://csacyber.com/cyber-consultancy-services#virtual-leadership)
          - [Technical security consulting](https://csacyber.com/cyber-consultancy-services#technical-consultancy)
          - [Governance, Risk & Compliance (GRC)](https://csacyber.com/cyber-consultancy-services/governance-risk-and-compliance-services)
    - [Extended Managed Security Services](https://csacyber.com/extended-managed-security-services) 
          - [Microsoft Sentinel SIEM](https://csacyber.com/extended-managed-security-services#microsoft-sentinel)
          - [SOC services](https://csacyber.com/extended-managed-security-services#soc-services)
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/extended-managed-security-services#cyber-helpdesk)
    - [Incident Response Services](https://csacyber.com/incident-response-services) 
          - [Emergency Incident Response](https://csacyber.com/urgent/emergency-incident-response)
          - [Incident Response Retainer](https://csacyber.com/incident-response-services)
          - [Cyber Incident Readiness & Response Planning](https://csacyber.com/incident-response-services)
          - [Tabletop Exercises & Live-Range Engagements](https://csacyber.com/incident-response-services)
    - [Specialist Security Services](https://csacyber.com/specialist-services) 
          - [AI Security](https://csacyber.com/cyber-services-for-ai)
          - [Operational Technology (OT)](https://csacyber.com/specialist-services#operational-technology)
          - [Cyber security for Private Equity](https://csacyber.com/specialist-services#mergers-and-acquisitions)
          - [Cyber training and education](https://csacyber.com/specialist-services#training-and-education)
          - [Virtual leadership](https://csacyber.com/specialist-services#leadership)
    - [Cyber Technologies](https://csacyber.com/cyber-technologies) 
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/cyber-technologies#sentinelone)
          - [AppGuard Endpoint & Server Zero Trust Protection](https://csacyber.com/cyber-technologies#appguard)
          - [Qualys Vulnerability Management as a Service (VMaaS)](https://csacyber.com/cyber-technologies#qualys-vmaas)
          - [Lookout Mobile Device Protection](https://csacyber.com/cyber-technologies#lookout)
          - [ThreatER DNS Protection](https://csacyber.com/cyber-technologies#threater-dns)
          - [Cyber Security Awareness & Training platform](https://csacyber.com/cyber-technologies#boxphish)
- [About](https://csacyber.com/about-us) 
    - [Careers](https://csacyber.com/careers)
    - [Certifications](https://csacyber.com/certifications-and-awards)
- [Blog](https://csacyber.com/blog)
- [Support Centre](https://csacyber.com/support)
- Resources 
    - [Case Studies](https://csacyber.com/case-studies)
    - [Downloads & Reports](https://csacyber.com/downloads-and-reports)
    - [Webinars](https://csacyber.com/webinars)
    - [Partners](https://csacyber.com/partners)
    - [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)
- [Contact](https://csacyber.com/contact-us)

- Search Search
  
  Search

 January 9, 2024

 4 min read time

# Cybersecurity Maturity Model Certification (CMMC): What, How, When and Why?

![Cyber Security Associates](https://app.hubspot.com/settings/avatar/d41d8cd98f00b204e9800998ecf8427e) [Written by: Cyber Security Associates -](https://csacyber.com/blog/author/cyber-security-associates)

[Consultancy](https://csacyber.com/blog/tag/consultancy) 

![](https://csacyber.com/hubfs/11-e1644932665609.png)

For almost two years now, the US Department of Defense (DOD) has been reviewing a process designed to ensure defense contracts meet very specific cybersecurity standards when it comes to handling unclassified information. Known as the Cybersecurity Maturity Model Certification (CMMC), the process will make sure that all defense contractors meet at least a basic level of digital security hygiene in order to increase the DOD’s supply chain risk posture and reduce the threat of potential leaks and information breaches. Here, our Risk Advisory Senior Director, Craig Moores, and Senior Consultant, Tim Hodgkins, explain the ‘what’, ‘how’, ‘when’ and ‘why’ of CMMC.

### What is Cybersecurity Maturity Model Certification (CMMC)?

According to official figures from The White House Council of Economic Advisers, malicious cyber activity regularly costs the US economy up to $109 billion per year. Whilst private businesses form their own risk strategies around cybersecurity, albeit with some legislative help to set standards, public sector organizations as broad and far-reaching as the DOD need to develop their own cybersecurity standards and frameworks in order to minimize risk and increase security.

So-called ‘controlled unclassified information’ or CUI, handled by defense industrial base (DIB) contracts, is one of the biggest risk factors currently facing the department. That’s what CMMC aims to fix, by producing a new standard for all DIB contractors to adhere to when it comes to the handling of unclassified information. In the Pentagon’s own words, it will “adequately protect sensitive unclassified information, accounting for information flow down to subcontractors in a multi-tier supply chain”.

### How will CMMC work?

Tim outlines that CMMC, like most new frameworks, is currently undergoing a period of review by the Pentagon before it’s put into practice. The initial version, CMMC 1.0, combines risk controls that are commonly used in cybersecurity frameworks with more tailored controls that are unique to the DOD and DIB contracts. It also outlines five levels of security maturity that will determine which processes and practices a particular contractor will have to abide by when doing business with DOD. Compliance with these levels of security will be mandatory for all contractors, including UK-based contractors and those based in other countries around the world. The five levels are as follows:

##### CMMC Level 1

All federal contract information must be safeguarded. This is the most basic level of security maturity and means that a contractor must be able to guarantee that all data pertaining to the contract is adequately secured.

##### CMMC Level 2

This builds on level one and acts as a transition step to level three, requiring that all contractors be able to demonstrate the ability to self-audit their processes and prove that their policies and processes align with that of the DOD in terms of security.

##### CMMC Level 3

Full protection of uncontrolled classified information. Contractors need to adhere to all of the security requirements set out in NIST 800-171 and NIST 800-53, as well as Aerospace Industries Association National Aerospace Standard 9933, and Critical Security Controls for Effective Capability in Cyber Defense. In short, level three requires contractors to adhere to a plethora of compliance standards and be able to demonstrate that compliance robustly. This is where the majority of contractors will most likely sit.

##### CMMC Levels 4 and 5

In the highest levels of security maturity, contractors will not only need to demonstrate their compliance with all of the above, but will also need to enact their own cybersecurity policies and controls to reduce the risk of Advanced Persistent Threats (APTs).

The kind of service a business provides, and the level of access and engagement it will need in order to provide that service, will determine which level it is assigned. CMMC version 2.0, of which details emerged in November 2021, will seek to narrow these tiers down to three levels in order to simplify things. But rather than making things easier for contractors, this will likely make the distribution and threshold of security standards even higher for basic services. We will discuss CMMC 2.0 in more detail on the blog soon, including how it differs from CMMC 1.0.

### What does this mean for businesses on the ground?

Those doing business with the DOD are going to be forced to review their current internal security standards to understand what more they need to do in order to keep their contracts. For instance, if information flows via email, the DOD will need to know whether or not those emails are encrypted and where they are stored. Likewise, businesses are going to have to take data storage more seriously. Where are shared files located? Is the share file location being regularly recertified to demonstrate ‘good hygiene’ and demonstrate that it’s secure? Organizations bidding for contracts will also need to have tightly controlled access privileges among their team, so that access is only granted on a ‘need to know’ basis. Wider cybersecurity strategies will also be critical. Just because a business can demonstrate good practices around a particular contract or set of data, doesn’t mean it’s bulletproof in other areas. Businesses should therefore take some of the more general requirements and recommendations from CMMC and enact them across all business operations.

### When will CMMC come into effect?

The CMMC framework was first established in November 2020 and has been evolving ever since. However, it’s not yet mandatory as the DOD understands the need to allow most businesses the time to prepare for new security controls and policies. It’s currently regarded as an ‘interim rule’, with the idea that by 2025, all contractors and subcontractors will be subject to the same third-party mandatory audits that keep them in line with one of the three levels of security maturity. Put simply, all businesses looking to win contracts with DOD should already be developing their internal security processes in line with CMMC recommendations, as those recommendations will soon become mandates.

Related Posts

## You may also like this

[Similar Articles](https://csacyber.com/blog)

[![](https://csacyber.com/hs-fs/hubfs/20230510-N1005919-Edit1.jpg?width=624&height=427&name=20230510-N1005919-Edit1.jpg)](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 August 24, 2026

 2 min read

### [FluidOne Group appoints Charly Davis as Managing Director of CSA Cyber to advance its security-first strategy](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 Experienced industry leader joins FluidOne to strengthen integrated cyber, IT and secure networking...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Untitled%20design.jpg?width=624&height=427&name=Untitled%20design.jpg)](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 August 20, 2026

 2 min read

### [CSA Cyber and FluidOne named as suppliers on G-Cloud 15](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 CSA Cyber (CSA), part of the FluidOne Group, has been named as a supplier on Government Commercial...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Engineered%20to%20Endure%20Campaign%20Assets%20(2).png?width=624&height=427&name=Engineered%20to%20Endure%20Campaign%20Assets%20(2).png)](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 August 20, 2026

 6 min read

### [Why organisations lose security visibility without realising it](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 Before an organisation can understand risk, maintain control or respond effectively to emerging...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![CSA Cyber Logo FNL_Full Logo](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=3463&height=1248&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber Logo FNL_Full Logo")](https://csacyber.com/)

Established in 2013, Cyber Security Associates Limited trading as CSA Cyber provides cyber consultancy and cyber managed services which help to detect, protect and educate against the ever-changing cyber threat. We have built our team from a foundation of Government (ex-Military) and Commercially experienced specialists all holding current and relevant cyber certifications. Today our core services are based around a 24/7 Security Operations Centre (SOC) based in Gloucester.

#### News & Resources

- [Blog](https://csacyber.com/blog)
- [Case Studies](https://csacyber.com/case-studies)
- [Downloads & Reports](https://csacyber.com/downloads-and-reports)
- [Webinars](https://csacyber.com/webinars)
- [Careers](https://csacyber.com/careers)
- [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)

#### Quick Links

- [About Us](https://csacyber.com/about-us)
- [Certifications](https://csacyber.com/certifications-and-awards)
- [Our Parent Company](https://www.fluidone.com)
- [Partners](https://csacyber.com/partners)
- [Contact Us](https://csacyber.com/contact-us)
- [Anti Bribery Policy](https://csacyber.com/hubfs/CSAAnti-BriberyPolicy.pdf)
- [Complaints Policy](https://csacyber.com/hubfs/CSAComplaintsPolicy.pdf)
- [Corporate Social Responsibility Policy](https://csacyber.com/hubfs/CSACorporateSocialResponsibilityPolicy.pdf)
- [Slavery and Human Trafficking Statement](https://csacyber.com/hubfs/CSASlaveryandHumanTraffickingStatement.pdf)
- [NCSC CHECK Status Verification](https://www.ncsc.gov.uk/organisation/csa-cyber/check-penetration-testing)
- [CREST Approved Certification Verification](https://www.crest-approved.org/member_companies/csa-cyber/)

#### Contact Information

**United Kingdom - London**

Cyber Security Associates Ltd

5 Hatfields, London, SE1 9PG

 

**United Kingdom - Gloucester**

Cyber Security Associates Ltd

Unit 11, Wheatstone Court, Waterwells Business Park, GL2 2AQ

 

**Phone:** [+44(0) 300 303 4691](tel:03003034691)

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

**United States of America**

Cyber Security Associates Inc.

6010 W. Spring Creek Pkwy, Plano, Texas, 75024

 

**Phone:** [+1 469 750 1695](tel:14697501695) 

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

[![trust-pilot](https://csacyber.com/hs-fs/hubfs/trust-pilot.png?width=178&height=104&name=trust-pilot.png)](https://uk.trustpilot.com/review/csa.limited)

 

---

- [Website Terms of Use](https://csacyber.com/website-terms-of-use)
- [Website Privacy Policy](https://csacyber.com/privacy-notice)
- [Website Cookie Policy](https://csacyber.com/cookie-policy)

 Copyright 2026. Cyber Security Associates Ltd [Follow us on Facebook](https://www.facebook.com/CSALIMITED/) [Follow us on LinkedIn](https://www.linkedin.com/company/csa-cyber/) [Follow us on Twitter](https://twitter.com/cybersecurityis) [Follow us on Facebook](https://www.youtube.com/@cybersecurityassociateslim) [Follow us on Facebook](https://www.instagram.com/cybersecurityassociates)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Cyber Security Associates",
    "url" : "https://csacyber.com/blog/author/cyber-security-associates"
  },
  "dateModified" : "2024-12-07T12:34:48.776Z",
  "datePublished" : "2024-01-09T05:15:00.000Z",
  "headline" : "Cybersecurity Maturity Model Certification (CMMC): What, How, When and Why?",
  "image" : [ "https://csacyber.com/hubfs/11-e1644932665609.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://csacyber.com/blog/cybersecurity-maturity-model-certification-cmmc-what-how-when-and-why",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://csacyber.com/hubfs/csacyber-logo-black-01.svg"
    },
    "name" : "Cyber Security Associates Ltd"
  }
}
```