What is Cybersecurity Maturity Model Certification?
Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense program that verifies whether contractors and their suppliers protect the government information they handle. It applies to any company in the defense supply chain that stores or processes federal contract information or controlled unclassified information (CUI), from prime contractors to a machine shop that makes one part. Rather than trusting a contractor's own statement of compliance, CMMC requires an assessment, and the result becomes a condition of being awarded a contract.
The current version, CMMC 2.0, has three levels. Level 1 covers basic safeguarding of federal contract information and is met by an annual self-assessment against a short list of practices such as limiting system access and keeping antivirus current. Level 2 applies to contractors handling CUI and requires the 110 security requirements of NIST SP 800-171; most Level 2 contractors need an assessment by an authorized CMMC Third-Party Assessment Organization (C3PAO) every three years, with a self-assessment allowed for a smaller set of contracts. Level 3 adds requirements from NIST SP 800-172 for the most sensitive programs and is assessed by the government. Results are recorded in the Supplier Performance Risk System, and a senior company official must affirm compliance each year.
For a small manufacturer or engineering firm the hard part is rarely the technology. It is the documentation: a system security plan that describes every control and the evidence that each one operates, plus a plan of action and milestones for any gap. Scoping matters too. A company that isolates the systems and people that touch CUI into a defined enclave, often built on Microsoft 365 GCC High or a segmented network, can shrink the assessment to a fraction of its environment. Getting the scope wrong is a costly mistake, because every device in scope must meet every requirement.
NetSys's CMMC compliance service helps government contractors close the gap between their current environment and NIST SP 800-171, using its managed services for the controls that must run continuously, such as 24/7 monitoring, privileged access management, patching, and multi-factor authentication. The blog post on CMMC 2.0 compliance for small businesses explains the phased rollout and what each level asks of a subcontractor.
Why it matters for a small business
If any part of your revenue comes from defense work, even as a third-tier supplier, CMMC decides whether you can keep it. Primes are already pushing the requirement down to their suppliers, and a missing certification will eventually mean a lost bid regardless of how good your product is. The requirements are achievable for a small firm, but they take months to implement and document. Starting now, with a clear scope and a gap assessment, is far cheaper than scrambling when a contract renewal depends on it.
Cybersecurity Maturity Model Certification (CMMC): FAQs
What is Cybersecurity Maturity Model Certification and who needs it?
CMMC is the Department of Defense's program for verifying that contractors protect the information the government shares with them. Any company that handles federal contract information or controlled unclassified information under a DoD contract will need it, including subcontractors far down the supply chain. The level required depends on the information involved: Level 1 for federal contract information, Level 2 for CUI, and Level 3 for the most sensitive programs. The requirement appears in the contract itself, so check your solicitations and ask your prime.
What is the difference between CMMC Level 1 and Level 2?
Level 1 protects federal contract information, the routine information exchanged under a contract, and is met with an annual self-assessment against basic practices such as unique user accounts and current antivirus. Level 2 protects controlled unclassified information and requires all 110 security requirements in NIST SP 800-171, along with a system security plan and supporting evidence. Most Level 2 contractors must pass an assessment by an authorized third-party assessment organization every three years. The jump from Level 1 to Level 2 is substantial in both effort and documentation.
Can a small business become CMMC compliant with Microsoft 365?
Yes, with the right configuration and the right edition. Microsoft 365 provides many of the technical controls NIST SP 800-171 asks for, including multi-factor authentication, device compliance through Intune, audit logging, encryption, and data loss prevention. Contractors handling CUI subject to export controls often need the GCC High environment rather than the commercial one, so confirm that requirement before migrating. The platform alone does not make you compliant; policies and documented evidence still have to be produced and maintained.
More terms
Dark Web Monitoring
Dark web monitoring is a service that searches criminal forums and breach dumps for a company's domains, credentials and data, then alerts it on a match.
Conditional Access
Conditional Access is an Entra ID feature that checks each sign-in against user, device, location and risk policies, then allows, blocks or asks for MFA.
Data Loss Prevention (DLP)
Data loss prevention (DLP) is a set of policies and tools that detect sensitive information and stop it from leaving the business by email, cloud or device.
Co-Managed IT
Co-managed IT is a model in which a business's internal IT staff and an outside managed service provider share responsibility for systems and support.
Get the controls, not just the definition.
A NetSys engineer can tell you in fifteen minutes whether you have this covered, and what it would take if you do not. Month to month, no long-term contract.
