TechKnowSurge
NIST CSF GV.OC-03 CompTIA Security+ 5.4 ISC2 CISSP 1.4 NIST NICE K0676 ISC2 CISSP 1.3 NIST CSF GV.PO-01 NIST NICE K0879
VideoSecurityFree

Cybersecurity Maturity Model Certification (CMMC)

The Cybersecurity Maturity Model Certification (CMMC) is a DoD-established framework requiring contractors and vendors to meet defined cybersecurity standards based on the nature of their work with the department. Non-compliance can result in loss of DoD contracts.

Complete this video to capture a CTF flag worth 1 point.

About this video

The U.S. Department of Defense oversees national security through a broad network of branches and agencies, including the Army, Navy, Air Force, Marine Corps, National Guard, and National Intelligence Services. To carry out its mission at scale, the DoD contracts extensively with private businesses and outside organizations, creating a large and complex supply chain. That dependency introduces significant risk: a cyberattack targeting a contractor can serve as a vector for compromising the DoD itself, making the security posture of every vendor a matter of national concern. To address this, the DoD introduced the Cybersecurity Maturity Model Certification, commonly known as CMMC, in 2020. The framework establishes clear cybersecurity requirements for any organization contracting with the DoD, with the goal of ensuring that sensitive defense information and operational capabilities are not undermined through third-party vulnerabilities. The current version of the framework includes three certification levels, and the level required for a given contractor depends on the type of services being provided and the sensitivity of the data involved. CMMC is designed to be scalable and practical. At the foundational level, a self-attestation may be sufficient to demonstrate compliance, while higher-risk engagements require a formal assessment conducted by an accredited third-party organization. The framework includes implementation guidelines to help organizations integrate its requirements into existing operations, along with enforcement mechanisms that carry real consequences. Contractors who fail to achieve or maintain the required certification level risk losing their DoD contracts entirely, making CMMC compliance a business-critical priority for any organization operating in the defense supply chain.

What you'll learn

What's covered

CMMC Overview

Aligned to

NIST CSF
GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed.
GV.PO-01 Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced.
CompTIA Security+
5.4 Summarize elements of effective security compliance.
ISC2 CISSP
1.4 Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context
1.3 Evaluate and apply security governance principles
NIST NICE
K0676 Knowledge of cybersecurity laws and regulations
K0879 Knowledge of industry cybersecurity models and frameworks

Key terms

Cybersecurity Maturity Model Certification
CMMC
A U.S. Department of Defense program that establishes cybersecurity standards and a certification process for defense contractors to ensure they adequately protect sensitive unclassified information. It uses a tiered model requiring third-party assessments to verify compliance before award of DoD contracts.
Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Baseline
A documented set of minimum security standards or performance metrics used as a reference point.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Self-Attestation
A process in which an organization internally verifies and declares its own compliance with required security standards without a third-party assessment.
Third-Party Assessment
An independent evaluation conducted by an external organization to verify that a contractor meets required CMMC certification standards.

Topics

Cmmc Compliance Frameworks Defense Contracting Cybersecurity Governance Risk Management

Transcript

The United States Department of Defense uses a lot of outside companies and organizations to carry out their mission. That is, they'll create contracts with these different businesses that will do certain aspects that help the DoD out. Now, the problem is that if there was an attack on these other businesses and it leveraged these other businesses, that could weaken the Department of Defense. And so the Department of Defense wants to make sure that these companies have a certain level of security. Well, that's where the Cybersecurity Maturity Model Certification comes into play, the CMMC.

Why the DoD Created It

The United States Department of Defense, or DoD, has a huge responsibility. It's in charge of a lot of the national security within the United States. Departments within the DoD would be the Army, the Navy, the Air Force, the Marine Corps, the National Intelligence Services, the National Guard. And so it has a huge responsibility.

Since it relies on a lot of other vendors, a lot of contracts, a lot of outside organizations, a lot of other businesses, it has created the Cybersecurity Maturity Model Certification, or CMMC. It created this in 2020 to ensure that people who are contracting with the DoD meet certain security standards. A compromise of these businesses or organizations could mean a compromise in the DoD and its ability to perform its services.

Who Complies, and How

So who should comply with CMMC? Anybody who's contracting with the Department of Defense.

Now, at the point in time of this recording, there are a couple of versions of the CMMC, but the newest one has three different levels of certification, and depending on what kind of services you're providing for the DoD, you may have to comply with one of these levels of certification.

This is a framework that you integrate into your business, an organization, and it could require just the simple level one self-attestation to make sure that you're complying with it. Or you may be required to bring in a third party to do the certification process as part of the CMMC. It's scalable and flexible depending on, once again, how you're contracting with the DoD.

There's a bunch of implementation guidelines, and also there's enforcement and compliance. To a large degree, you could just lose business, lose your DoD contracts.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →