CMMC

What the requirement says, before anybody sells you anything.

Five separate pages on this site previously covered overlapping ground. This is the one page, and it links to the entries that go further.

For an independent reference point, see 32 CFR Part 170.

The levels

Three levels

The level that applies is set by your contract. Most suppliers handling controlled unclassified information are at the second, which rests on the security requirements in the relevant NIST publication and is assessed by a third party for most contracts.

The levels in full →

Rests on

The certification programme documentation and the NIST publication it draws its controls from, both published by the issuing bodies.

Which level applies to a given contract is stated in that contract.

What it takes

The work is evidence, not intent

Most suppliers already do much of what the standard asks. What they cannot do is show it: no record of who authorised a transfer, no log from the machine, no document describing the boundary.

An assessment tests what you can demonstrate. That is the project, and it is longer than the technical work.

Timelines

What we will not promise

A duration before seeing your environment.

Timeline boundary

No fixed certification timeline is stated. Duration depends on scope, remediation, evidence history and assessor availability.

Not advice

This page is a description, not advice

Which level applies, what your boundary should be and whether a control is satisfied are questions for a qualified assessor with sight of your environment.