The Cybersecurity Maturity Model Certification (CMMC) is a framework established by the U.S. Department of Defense (DoD) to enhance the protection of sensitive unclassified information within the Defense Industrial Base (DIB). The model introduces a set of cybersecurity standards that contractors and subcontractors must meet to handle Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
The CMMC framework features three cumulative compliance levels: Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert). Each tier aligns security controls with the sensitivity of the defense information handled by a contractor.
Level 1: Foundational:
Level 2: Advanced:
Level 3: Expert:
This is part of a series of articles about cyber risk management.
In this article:
CMMC Level 1 is the entry point of the model, focusing on basic safeguarding of Federal Contract Information (FCI). The requirements align with FAR 52.204-21 and consist of 17 cybersecurity practices. These practices include measures such as limiting physical access, updating antivirus software, and enforcing secure password policies. The intent is to establish basic cyber hygiene that protects FCI from common threats.
Organizations seeking Level 1 certification are typically required to perform annual self-assessments and attest to the implementation of these practices. At this level, there is no requirement for extensive documentation or process maturity. The emphasis is on consistent execution of straightforward security activities that form the baseline for further cybersecurity improvements.
CMMC Level 2 increases requirements and targets organizations that handle Controlled Unclassified Information (CUI). At this level, organizations must comply with all 17 Level 1 practices and implement an additional 93 practices, many of which align with NIST SP 800-171. The focus shifts from basic cyber hygiene to protecting CUI against more sophisticated threats, such as advanced persistent threats (APTs).
Unlike Level 1, Level 2 requires organizations to document their practices and processes, demonstrating that security controls are institutionalized and repeatable. Third-party assessments are required to achieve certification, providing independent validation that the controls are implemented and maintained. This level marks a transition from foundational security to a managed approach to cybersecurity.
CMMC Level 3 is the highest tier, reserved for organizations with critical roles in the defense supply chain. This level builds on the requirements of Levels 1 and 2 by adding 35 more practices, for a total of 128. The additional controls counter advanced persistent threats and draw from NIST SP 800-172.
To achieve Level 3 certification, organizations must demonstrate implementation of all required practices and advanced process maturity. This includes continuous monitoring, proactive threat hunting, and the ability to respond to emerging threats. Assessments at this level are conducted by government-led teams, reflecting the risk and sensitivity associated with Level 3 environments.
CMMC Level 1 requirements are based on the 17 security requirements defined in FAR 52.204-21. These controls focus on basic cybersecurity practices that help protect Federal Contract Information (FCI) from unauthorized access and disclosure. The requirements cover areas such as access control, identification and authentication, media protection, physical security, system integrity, and limiting access to authorized users and devices.
Examples of Level 1 controls include:
Organizations are also expected to protect information during transmission, dispose of media securely, and monitor systems for signs of compromise. These practices establish a security baseline that reduces exposure to common cyber threats.
Organizations must implement each required practice and perform annual self-assessments to confirm compliance. They must also provide an annual affirmation that the controls remain in place. Although formal process documentation is limited at this level, organizations still need evidence that the practices are consistently applied during normal operations. Maintaining records of implemented controls, employee training, and system configurations can help demonstrate compliance during reviews.
CMMC Level 2 requirements align with the 110 security requirements in NIST SP 800-171 Rev. 2. These controls are intended to protect Controlled Unclassified Information (CUI) and cover 14 security domains, including access control, audit and accountability, configuration management, incident response, risk assessment, security awareness, and system and communications protection.
Compared to Level 1, Level 2 requires a more structured and risk-based approach to cybersecurity. Organizations must implement technical, administrative, and operational controls that protect CUI throughout its lifecycle. This often includes:
In addition to implementing the required controls, organizations must maintain supporting documentation such as a system security plan (SSP) and plans of action and milestones (POA&M), where permitted. Most organizations handling CUI must successfully complete an assessment by a Certified Third-Party Assessment Organization (C3PAO), while a limited number of lower-risk contracts may allow annual self-assessments when specified by the DoD. Because Level 2 assessments evaluate both technical controls and supporting evidence, organizations often spend significant time preparing documentation, validating configurations, and addressing security gaps before the assessment.
CMMC Level 3 builds on all Level 2 requirements by adding selected security requirements from NIST SP 800-172. These additional controls strengthen an organization’s ability to detect, resist, and recover from advanced persistent threats. The requirements emphasize enhanced monitoring, threat-informed security operations, stronger access protections, and improved incident response capabilities.
At this level, organizations are expected to operate a mature cybersecurity program that goes beyond implementing security controls. They must:
Security operations become more proactive, with greater emphasis on analyzing attacker behavior, protecting high-value assets, and minimizing the impact of potential breaches. Organizations pursuing Level 3 must first achieve Level 2 certification before undergoing a government-led assessment for the additional Level 3 requirements.
Maintaining compliance requires continuous operation of security controls, regular reviews of the cybersecurity program, and the ability to demonstrate that defensive measures are effective against evolving threats. Since Level 3 is intended for organizations supporting sensitive defense programs, ongoing security improvement and operational resilience are required to meet certification requirements.
The first step in determining your required CMMC level is to classify the data you process. Federal Contract Information (FCI) refers to information provided by or generated for the government under contract that is not intended for public release. Controlled Unclassified Information (CUI) refers to sensitive information that requires safeguarding under federal laws and regulations. Handling CUI typically triggers the need for a higher CMMC level.
Review your contracts, workflows, and data repositories to identify whether you handle FCI, CUI, or both. If your organization only processes FCI, Level 1 certification is usually sufficient. However, if you access, store, or transmit CUI, you will need to meet the requirements of Level 2 or, in rare cases, Level 3. Accurate classification at this stage prevents unnecessary compliance burdens and ensures alignment with DoD expectations.
Solicitation documents and contract language specify the CMMC level required for a given project or engagement. These documents often outline the types of information you will handle and the expected security posture. Carefully reviewing these requirements helps avoid misunderstandings and ensures your organization is prepared for the appropriate level of assessment and certification.
Failure to align with contractual requirements can result in disqualification from bidding or termination of existing contracts. Engage with your contracting officer or legal team to clarify ambiguities in the solicitation. Early identification of CMMC requirements in the contract lifecycle allows for planning, budgeting, and timely implementation of required security controls, reducing the risk of noncompliance.
Your position within the Defense Industrial Base (DIB) also affects the CMMC level you need. Prime contractors are responsible for meeting the certification requirements specified in their contracts, but subcontractors must also comply if they receive or process FCI or CUI as part of their work. The required level depends on the information that flows to your organization, not simply your status as a prime or subcontractor.
Map the flow of contract information between your organization, customers, and suppliers to determine where FCI and CUI are stored, processed, or transmitted. If your organization never receives CUI, a lower certification level may be appropriate. However, if CUI is shared with your systems or personnel, you must meet the CMMC requirements associated with that information before performing the work.
After identifying the required certification level, define the scope of the assessment by determining which systems, users, applications, and locations handle FCI or CUI. A clearly defined scope helps ensure that relevant assets are protected while avoiding the cost and complexity of including systems unrelated to the contract.
Document the boundaries of the CMMC environment and identify connections to external systems or service providers. Many organizations reduce the assessment scope by isolating CUI into dedicated environments and limiting access to authorized personnel. Before the assessment, validate that in-scope assets, documentation, and security controls are complete and accurately reflect the environment to be evaluated.
Organizations should consider the following best practices to ensure they meet their CMMC requirements.
Reducing the number of systems that store, process, or transmit FCI and CUI makes the CMMC environment easier to secure and assess. A smaller scope means fewer devices, applications, and users require security controls.
Review business processes to identify where sensitive information is used and eliminate unnecessary copies or transfers. Segment networks, use dedicated systems for sensitive workloads where practical, and restrict access to employees who need it. Limiting the spread of FCI and CUI reduces the attack surface and the effort required during assessments.
Key actions:
Keeping an up-to-date inventory of software helps organizations understand what is running in their environment and identify unauthorized or outdated applications. Without accurate visibility, it is difficult to manage vulnerabilities, investigate incidents, or demonstrate that only approved software is in use.
Maintain a centralized inventory that includes operating systems, installed applications, versions, publishers, and the systems where they are deployed. Regularly compare the inventory against approved software lists and remove applications that are no longer needed. Continuous inventory management also supports patch management and vulnerability remediation required by higher CMMC levels.
Key actions:
Related content: Read our guide to browser hijacking
Application control limits which programs can run on organizational systems, reducing the risk of malware, ransomware, and unauthorized software. Instead of relying only on antivirus tools, organizations can allow trusted applications while preventing unknown or unapproved executables from running.
Define application control policies based on trusted publishers, digital signatures, file paths, or cryptographic hashes, depending on operational requirements. Review exceptions regularly and test policy changes before broad deployment to avoid disrupting business applications. Well-managed application control adds a layer of defense against common attack techniques.
Key actions:
Attackers often use scripts, macros, and command-line tools to execute malicious code after gaining initial access. Restricting these technologies reduces opportunities for attackers to move laterally, establish persistence, or execute payloads within the environment.
Limit script execution to approved administrators and trusted automation tools, and disable unnecessary scripting features where possible. Apply controls to PowerShell, Windows Script Host, macros, and similar technologies, and monitor attempts to execute blocked content.
Key actions:
Related content: Read our guide to ransomware protection
Preparing for a CMMC assessment is easier when evidence is collected throughout the year instead of immediately before the assessment. Continuous evidence collection demonstrates that security controls operate consistently rather than only during a short preparation period.
Maintain records such as security policies, training logs, system configurations, vulnerability scans, patch reports, access reviews, and audit logs in a centralized repository. Regularly review this evidence for completeness and accuracy so that documentation remains aligned with the current environment. Continuous evidence collection helps organizations identify compliance gaps early and address them before formal assessments.
Key actions:
The Cybersecurity Maturity Model Certification (CMMC) is a critical framework for organizations working with the U.S. Department of Defense (DoD), requiring stringent cybersecurity controls to protect controlled unclassified information (CUI) and Federal Contract Information (FCI). Airlock Digital provides precision application control that addresses key requirements across CMMC's practices and capabilities, supporting compliance while reducing risk to sensitive systems.
Key capabilities of Airlock Digital:
Learn more about how Airlock Digital supports CMMC compliance