Cybersecurity Maturity Model Certification (CMMC)

View as Markdown

What is the Cybersecurity Maturity Model Certification?

The United States Department of Defense developed the Cybersecurity Maturity Model Certification (CMMC) program to enforce protection of the sensitive unclassified information it shares with its contractors and subcontractors. Contractors must implement progressively more advanced levels of controls depending on the type and sensitivity of the information shared. In November 2021, the Department of Defense announced CMMC 2.0 with an updated structure and requirements. CMMC 2.0 has 3 tiers of certification:

Tier Model Assessment
Level 3 110+ practices aligned with
NIST SP 800-171 and 800-172
Triennial government-led assessments
Level 2 110 practices aligned with
NIST SP 800-171
Triennial third party assessments for critical
national security information, triennial
self-assessment for select programs
Level 1 15 practices

Annual self-assessment & annual affirmation

Many organizations are working toward CMMC 2.0 compliance, although the rulemaking that will formally implement the program is still in progress.

Who is the intended audience?

The CMMC program applies to contractors and subcontractors of the United States Department of Defense, commonly called the Defense Industrial Base (DIB).

Where can I find more information?

These resources are on the United States Department of Defense and National Institute of Standards and Technology websites:

How can runZero help me with these controls?

CMMC 2.0 maps to NIST Special Publications 800-171 and 800-172, and both standards group their controls into 14 control families. NIST SP 800-171 defines 110 controls across the 14 control families, and NIST SP 800-172 adds enhanced security requirements for each control family. The table below maps runZero to each control family. Strong alignment means runZero can play a significant role in helping an organization implement safeguards; Partial alignment means runZero can play a complementary role.

Control Family Strong alignment Partial alignment
Access Control ✔
Awareness and Training
Audit and Accountability
Configuration Management ✔
Identification and Authentication ✔
Incident response
Maintenance
Media Protection
Personnel Security
Physical Protection
Risk Assessment ✔
Security Assessment ✔
System and Communications Protection
System and Information Integrity ✔
Updated