CMMC is a security standard the Department of Defense requires from contractors who handle sensitive military information
CMMC stands for Cybersecurity Maturity Model Certification. It is a framework the U.S. Department of Defense created to measure how well contractors protect military data and intellectual property. If your company works with the Department of Defense — even indirectly as a subcontractor — you will eventually need to show you meet CMMC requirements to keep winning contracts.
The standard does not apply to every business. It applies to organizations in the Defense Industrial Base: companies that manufacture parts, provide services, or handle information for military projects. A small machine shop that makes components for a defense contractor may need CMMC. A software company that stores military blueprints definitely does. A local IT firm that has no defense work does not.
CMMC certification is not optional for companies that want defense contracts. The Department of Defense began requiring it in 2020 and has been rolling it out across contract types since then. If you bid on a contract that lists CMMC as a requirement and you do not have it, your bid will be rejected.
Key Takeaways
- CMMC is a Department of Defense requirement for contractors who handle military data, and certification is mandatory for most defense contracts issued after 2020.
- The framework has five maturity levels, ranging from basic cyber hygiene (Level 1) to advanced practices like threat intelligence and incident response (Level 5).
- Your company must hire an authorized C3PAO (Certified Third-Party Assessment Organization) to conduct an assessment and issue your certificate.
- Certification costs vary widely depending on company size and current security practices, but most small to mid-size firms spend between $10,000 and $50,000 for the full process.
- Certificates are valid for three years, after which you must undergo reassessment to maintain your certification status.
The five maturity levels and what each one requires
CMMC is organized into five levels. Each level builds on the previous one and requires more sophisticated security controls. Your company does not choose which level to pursue — the Department of Defense specifies which level applies to each contract you bid on.
Level 1 covers basic cyber hygiene: password policies, antivirus software, firewalls, and regular backups. Most small contractors start here. Level 2 adds intermediate practices like access controls, encryption of data in transit, and documented security policies. Level 3 requires advanced controls such as multi-factor authentication, security awareness training, and incident response procedures. Level 4 demands threat intelligence integration and advanced monitoring. Level 5, the highest level, requires continuous monitoring, predictive analytics, and proactive threat hunting — this is rare and typically only required for contracts involving the most sensitive military information.
Most defense contractors operate at Level 2 or Level 3. The Department of Defense has stated that Level 1 will eventually be phased out, so companies should plan to reach at least Level 2 within the next few years.
How the assessment and certification process works
You cannot certify yourself. You must hire a C3PAO — a Certified Third-Party Assessment Organization — to evaluate your company and issue your certificate. The Department of Defense maintains a list of authorized C3PAOs on its website. These organizations have been vetted and trained to conduct CMMC assessments consistently.
The assessment process typically takes two to four months, depending on your company size and how much work you have already done to meet the standard. The C3PAO will review your security policies, interview staff, test your systems, and document whether you meet all the controls required for your target level. If you pass, they issue your certificate. If you fail, they provide a report showing what you need to fix, and you can reassess after making those changes.
Before you hire a C3PAO, you should conduct an internal assessment or hire a consultant to identify gaps in your current security posture. This step is not required, but it usually saves money because you can fix obvious problems before the official assessment begins. Many companies spend three to six months preparing before they schedule their C3PAO assessment.
What CMMC certification costs
There is no single price for CMMC certification because costs depend on your company size, how many employees you have, what systems you run, and how much security work you have already completed. A company with strong existing security practices will spend less than one starting from scratch.
C3PAO assessment fees typically range from $5,000 to $30,000 for a single assessment, with larger organizations paying more. On top of that, you may need to spend money on security improvements: new software licenses, hardware upgrades, staff training, or hiring a consultant to help you prepare. A small company with 10 to 20 employees might spend $10,000 to $25,000 total. A mid-size company with 50 to 100 employees might spend $30,000 to $75,000. These are estimates, not guarantees, and your actual costs will depend on your specific situation.
Some companies hire a CMMC consultant to help them prepare before the C3PAO assessment. This adds cost upfront but often reduces the total time and the risk of failing the assessment. If you fail, you have to pay for another assessment, so investing in preparation can be cost-effective.
Who needs CMMC certification right now
The Department of Defense has been rolling out CMMC requirements gradually across different contract types and security levels. As of now, most new contracts for companies handling controlled unclassified information (CUI) require Level 2 certification. Contracts involving more sensitive information may require Level 3 or higher.
If you are a prime contractor — a company that contracts directly with the Department of Defense — you almost certainly need CMMC. If you are a subcontractor, you need it only if your contract requires you to handle, store, or transmit military data. A company that provides office supplies or janitorial services to a defense contractor does not need CMMC. A company that manufactures parts using military specifications or stores military technical data does.
The Department of Defense publishes contract requirements in solicitations and requests for proposals. If you are bidding on a defense contract, check the statement of work and the security requirements section. If CMMC is listed, you will need it before you can be awarded the contract.
Maintaining your certification after you receive it
CMMC certificates are valid for three years. After three years, you must undergo reassessment to renew your certificate. The reassessment process is similar to the initial assessment but may be shorter if your security posture has remained strong.
Between assessments, you are responsible for maintaining your security controls. If you let your practices slip or fail to update your systems, you may fail your reassessment. The Department of Defense also reserves the right to conduct unannounced assessments or audits of certified companies, though this is not routine.
If your certification expires before you renew it, you lose your certified status and cannot bid on contracts that require CMMC until you are recertified. Plan your reassessment at least three months before your certificate expires to avoid a gap.
Common misconceptions about CMMC
Many companies believe CMMC is a one-time checkbox — that once they are certified, they are done. In reality, certification is an ongoing commitment. You must maintain your security controls, train your staff, and prepare for reassessment every three years.
Another misconception is that CMMC is the same as other security standards like ISO 27001 or NIST Cybersecurity Framework. While CMMC is based on NIST standards, it is specific to the Department of Defense and has its own assessment process and requirements. Having ISO 27001 certification does not automatically may have access to you for CMMC, though it may help you prepare.
Some companies also believe that CMMC applies only to large defense contractors. In fact, small businesses and subcontractors are increasingly required to meet CMMC standards. The Department of Defense has made it clear that the requirement applies across the entire supply chain.
Frequently Asked Questions
Do I need CMMC if I only work with one defense contractor?
It depends on your contract. If your contract with that defense contractor requires you to handle controlled unclassified information or other sensitive military data, then yes, you will need CMMC. Check your contract's security requirements section or ask your contracting officer.
Can I get CMMC certification without hiring a C3PAO?
No. Only a Department of Defense-authorized C3PAO can conduct the official assessment and issue your certificate. You can prepare internally or with a consultant, but the final assessment must be done by a C3PAO.
What happens if I fail my CMMC assessment?
You receive a detailed report showing which controls you did not meet. You then have time to fix those issues and schedule a new assessment with the same or a different C3PAO. You pay for the reassessment separately. There is no limit on how many times you can reassess.
Is CMMC the same as getting a security clearance?
No. CMMC is a certification of your company's security practices and systems. A security clearance is a government information that a person is trustworthy to access classified information. You can have CMMC certification without anyone on your staff having a clearance, and vice versa.
Will CMMC requirements change in the future?
Yes. The Department of Defense has indicated that CMMC will evolve as threats change. The framework itself may be updated, and the levels required for different contract types may shift. Stay informed by checking the official CMMC website and your contracting officer's communications.