Cybersecurity Maturity Model Certification (CMMC)
What is the Cybersecurity Maturity Model Certification?
The United States Department of Defense developed the Cybersecurity Maturity Model Certification (CMMC) program to enforce protection of the sensitive unclassified information it shares with its contractors and subcontractors. Contractors must implement progressively more advanced levels of controls depending on the type and sensitivity of the information shared. In November 2021, the Department of Defense announced CMMC 2.0 with an updated structure and requirements. CMMC 2.0 has 3 tiers of certification:
| Tier | Model | Assessment |
|---|---|---|
| Level 3 | 110+ practices aligned with NIST SP 800-171 and 800-172 |
Triennial government-led assessments |
| Level 2 | 110 practices aligned with NIST SP 800-171 |
Triennial third party assessments for critical national security information, triennial self-assessment for select programs |
| Level 1 | 15 practices |
Annual self-assessment & annual affirmation |
Many organizations are working toward CMMC 2.0 compliance, although the rulemaking that will formally implement the program is still in progress.
Who is the intended audience?
The CMMC program applies to contractors and subcontractors of the United States Department of Defense, commonly called the Defense Industrial Base (DIB).
Where can I find more information?
These resources are on the United States Department of Defense and National Institute of Standards and Technology websites:
- Strategic Direction for Cybersecurity Maturity Model Certification Program
- NIST SP 800-171 rev2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- NIST SP 800-172, Enhanced Security Requirements for Protecting Controlled Unclassified Information
How can runZero help me with these controls?
CMMC 2.0 maps to NIST Special Publications 800-171 and 800-172, and both standards group their controls into 14 control families. NIST SP 800-171 defines 110 controls across the 14 control families, and NIST SP 800-172 adds enhanced security requirements for each control family. The table below maps runZero to each control family. Strong alignment means runZero can play a significant role in helping an organization implement safeguards; Partial alignment means runZero can play a complementary role.
| Control Family | Strong alignment | Partial alignment |
|---|---|---|
| Access Control | ✔ | |
| Awareness and Training | ||
| Audit and Accountability | ||
| Configuration Management | ✔ | |
| Identification and Authentication | ✔ | |
| Incident response | ||
| Maintenance | ||
| Media Protection | ||
| Personnel Security | ||
| Physical Protection | ||
| Risk Assessment | ✔ | |
| Security Assessment | ✔ | |
| System and Communications Protection | ||
| System and Information Integrity | ✔ |