The Complete Guide to Cybersecurity Maturity Model Certification

Everything You Need to Know About CMMC

  1. 1. What Is CMMC?
  2. 2. Why Is CMMC Important?
  3. 3. Framework and Requirements
  4. 4. Software Alone Isn't the Solution
  5. 5. Obtaining CMMC Certification
  6. 6. What Are the Benefits of Certification?
  7. 7. Possible Impacts of CMMC
  8. 8. CMMC Audit Preparation
  9. 9. Final Thoughts

To ensure that all contractors observe appropriate levels of cybersecurity controls, the Department of Defense (DoD) has created the Cybersecurity Maturity Model Certification (CMMC). Mandatory for all DoD contractors, the certification comes at a time when threat attempts on DoD systems are at an all-time high, with hundreds of thousands of probes every day.

CMMC requirements are robust, and all companies that do business with the DoD must implement this key certification or risk losing contracts. With rolling deadlines beginning in January 2021, now is the time to start preparing.

This guide covers everything you need to know about CMMC and explains how to start the certification process now, so you’ll be ahead of the game later.

What Is CMMC?

The Cybersecurity Maturity Model Certification (CMMC) is a new certification model designed to verify that DoD contractors have sufficient controls to safeguard sensitive data, including Confidential Unclassified Information (CUI) and Federal Contract Information.

Created by the Office of the Under Secretary of Defense for Acquisition and Sustainment (OUSD(A&S)), CMMC is a consolidated cybersecurity standard that’s mandatory for everyone doing business with the DoD. It brings together existing cybersecurity control requirements, such as ISO 27001, ISO 27032, NIST SP 800-171, and NIST SP 800-53, to create more detailed and coordinated cybersecurity standards.

Unlike previous security standards that only called for self-verification in order to achieve compliance, CMMC requires a third-party assessment from a certified auditor.

Why Is CMMC Important?

In 2015, the Department of Defense (DoD) published the Defense Federal Acquisition Regulation Supplement (DFARS) to push private contractors to maintain cybersecurity standards according to the requirements the National Institute of Standards and Technology (NIST) outlined in NIST SP 800-171.

Created to ensure the protection of Confidential Unclassified Information (CUI), the standards outlined in DFARS and NIST 800-171 gave DoD contractors until December 31, 2017 to meet the requirements necessary to be compliant or risk losing DoD contracts.

To be classified as compliant, contractors merely had to attest to meeting the requirements or being in the process of satisfying them.

Unfortunately, self-verification was inadequate and didn’t provide a level of security that could consistently safeguard sensitive information. While some contractors complied with the requirement, others failed to meet the standards.

As a result, U.S. adversaries have been able to develop military equipment based on stolen data. For instance, the Chinese J-20 and J-31 stealth fighter jets suspiciously resemble the American F-35. According to the Pentagon, China may have accessed the F-35 design after an information breach in 2009.

The CMMC Framework and Requirements

Released in January 2020, version 1.0 of the CMMC lays out the framework. It includes 17 domains that are based on cybersecurity best practices. Each domain is broken down into practices and processes that are mapped across five maturity levels. Within each domain, the practices are aligned to a set of capabilities.

The 17 CMMC Domains

The CMMC model consists of 17 domains, 14 of which are derived from the Federal Information Processing Standards (FIPS) Publication 200 and NIST 800-171, and three additional domains.

  1. Access Control (AC)
  2. Identification and Authentication (IA)
  3. Physical Protection (PE)
  4. Asset Management (AM)
  5. Incident Response (IR)
  6. Recovery (RE)
  7. Audit and Accountability (AU)
  8. Maintenance (MA)
  9. Risk Management (RM)
  10. Awareness and Training (AT)
  11. Media Protection (MP)
  12. Security Assessment (CA)
  13. Configuration Management (CM)
  14. Personnel Security (PS)
  15. Situational Awareness (SA)
  16. System and Communications Protection (SC)
  17. System and Information Integrity (SI)

5 CMMC Levels: Processes and Practices

The CMMC acknowledges that not all information shares the same levels of sensitivity, and not all contact participants have the same clearance levels. Because of this, the Cybersecurity Maturity Model Certification measures processes and practices across five maturity levels.

Level Description
Level 1 Basic Cyber Hygiene
Level 2 Intermediate Cyber Hygiene
Level 3 Good Cyber Hygiene
Level 4 Proactive
Level 5 Advanced / Progressive

The achievement of higher CMMC levels enhances the ability of an organization to protect CUI. For Levels 4-5, it also reduces the risk of advanced persistent threats (APTs), which are often executed via multiple incursions, including cyber, physical, and deception.

Obtaining CMMC Certification

All contractors that do business with the DoD will need to meet at least Level 1 CMMC requirements. The exact level at which you need to be certified to be awarded a contract will be specified in the RFP.

Although you do not have to be CMMC certified at the time of the RFP, you will need to be at the time the contract is awarded. That means you will have a window to start and complete certification, but how long that window is will vary from contract to contract. However, to avoid unforeseen delays and the risk of losing a contract, it’s best to not wait until the last minute.

To become CMMC certified, you’ll need to liaise with an accredited, independent third-party assessment organization through the Cybersecurity Maturity Model Certification Accreditation Body (CMMC-AB). You’ll specify your company’s level of cybersecurity maturity and schedule an evaluation.

CMMC assessors will be licensed through the CMMC-AB, but will be employed by a Certified Third-Party Assessment Organization (C3PAO).

What Are the Benefits of Certification?

Because all new DoD contract RFPs and RFIs will require CMMC compliance, those contractors that are certified will have a competitive advantage. What does that mean in real terms? With DoD contracts running five years, putting in the work now to become certified could put you in the lead to land five years of recurring revenue – and position yourself to retain it – while the rest of the market plays catch up.

Beyond easily winning and maintaining DoD contracts, CMMC-compliant companies will be better positioned to:

  • Reduce their risk of data breaches, the cost for which averaged $3.62 million per incidence in 2017
  • Overcome the threats of nation-state actors, which made up 23% of all data breaches in 2019
  • Lower the risk of insider threats
  • Be deemed compliant with other regulations, such as NIST, ISO, HIPAA, FISMA, and SOX

Possible Impacts of CMMC

The Cybersecurity Maturity Model Certification represents a seismic shift for DoD contractors, and will have a significant impact on the industry and its practices. Here are three notable changes that are likely to happen:

  1. Cybersecurity Will Be Undebatable in DoD Procurement. CMMC has put cybersecurity at the forefront of contract evaluation, scrutiny, and oversight.
  2. Some Companies Will Get Disqualified. Those companies that do not have the appropriate level of certification will be automatically disqualified from consideration.
  3. Industry Advisors Will Emerge. The DoD will rely heavily on certified third-party auditing agencies to audit and assess contractors’ CMMC qualification.

CMMC Audit Preparation

Each of the five CMMC levels requires the implementation of different NIST SP 800-171 Rev2 and NIST SP 800-171 Rev B controls. It’s the responsibility of each contractor to implement the necessary controls for the desired level of certification.

If you have implemented all of the NIST SP 800-171 Rev2 controls, then you’ll automatically pass the audit up to Level 2. If you’ve only adopted some, or none, of the controls, you can prepare for the Cybersecurity Maturity Model Certification.

Final Thoughts

CMMC demands superior cybersecurity measures for contractors that wish to continue working with the Department of Defense. The journey will undoubtedly be bumpy for some suppliers, but the DoD is keen to cut ties with non-compliant parties in favor of those trusted to safeguard CUI.