Contacts
Schedule a Demo
Close

Contacts

11921 Freedom Dr Suite 730
Reston, VA 20190

(571) 497-5687

info@kovr.ai

CMMC 2.0 Primer

Announcing partnership with Fortreum to define the future of compliance

The Cybersecurity Maturity Model Certification (CMMC) 2.0 was introduced by the Department of Defense in November 2021 as a streamlined evolution of the original CMMC framework. This certification program aims to protect sensitive defense information shared with contractors and subcontractors in the Defense Industrial Base (DIB). The framework establishes cybersecurity standards across three progressive levels, ensuring Defense Industrial Base contractors implement appropriate cybersecurity practices based on the type of information they handle.

  • CMMC 2.0 Level 1 requires companies handling Federal Contract Information (FCI) to implement 15 basic cybersecurity practices, conduct annual self-assessments, and meet minimum security standards.
  • CMMC 2.0 Level 2 requires companies handling Controlled Unclassified Information (CUI) to implement 110 security controls based on NIST SP 800-171, undergo third-party assessments, and achieve a minimum score of 88.
  • CMMC 2.0 Level 3 requires companies handling the most sensitive data to implement advanced cybersecurity practices based on NIST SP 800-172, undergo government-led assessments, and meet the highest security standards.

Companies seeking CMMC certification must work with authorized Third-Party Assessment Organizations (3PAOs) that have been vetted and approved by The Cyber AB, the official CMMC Accreditation Body. Organizations can find a current list of authorized 3PAOs on the Cyber AB website, which is regularly updated as new assessment organizations complete the rigorous authorization process.

Leave a Comment

Your email address will not be published. Required fields are marked *