# CMMC Overview | Secureframe

> Learn the basics of CMMC, including its history, purpose, and to whom the law applies. 

canonical: https://secureframe.com/hub/cmmc/overview

Ensuring the security of sensitive information is a top priority for businesses and the American government, especially when working with the U.S. Department of Defense (DoD). That's where the Cybersecurity Maturity Model Certification (CMMC) comes in. This framework helps companies protect sensitive DoD-related information from cyber threats and unauthorized access.

Whether you're a contractor or subcontractor, CMMC compliance is essential. It not only ensures you're eligible for DoD contracts, but also boosts your overall security. And for organizations outside the Defense Industrial Base, CMMC certification can be a powerful way to set yourself apart from competitors.

If you’re curious about what CMMC is and how to become certified, you’ve come to the right place. We’ve broken down the CMMC framework into a series of straightforward, easy-to-understand articles on the fundamentals of CMMC compliance.

You’ll learn about the different CMMC levels, key cybersecurity requirements, how to achieve certification, and the benefits of compliance — everything you need to understand CMMC and decide if pursuing certification is the right move for your business.

## Beginner: I'm New to CMMC

**Let’s start from the top. **

Navigating federal compliance can feel overwhelming, especially if you’re new to the world of government contracting. If you're a Department of Defense (DoD) contractor or subcontractor, you’ve probably heard about CMMC 2.0 — but understanding what it means and how it affects you can be daunting. 

In this section, we’ll simplify CMMC 2.0 by breaking down the basics to help you get comfortable with the essentials of compliance.

Here’s what you need to know.

## The essentials of CMMC 2.0

The Cybersecurity Maturity Model Certification (CMMC) was created to ensure that DoD contractors protect sensitive information like Controlled Unclassified Information (CUI) and Federal Contract Information (FCI).

CMMC 2.0, the latest version, was introduced in late 2021 as a more streamlined and flexible version of the original framework. The changes aim to make compliance more accessible to small businesses while still maintaining strict security controls.

While CMMC 2.0 is still under revision, DoD contractors and subcontractors need to pay close attention and start preparing now, since compliance will be required as early as 2026.  

## Who created CMMC and why? 

The Department of Defense developed the CMMC to combat the increasing threats to sensitive information within its supply chain. The goal is to protect critical data by requiring defense contractors to meet specific cybersecurity standards. This is crucial for safeguarding both FCI and CUI, which are regularly handled throughout the Defense Industrial Base (DIB).

CMMC ensures that all parties, whether they’re prime contractors or subcontractors, adhere to the same security standards, reducing the risk of breaches from less secure vendors.

## CMMC certification levels

CMMC 2.0 compliance is required for any organization that works within the DoD supply chain. This includes both prime contractors and subcontractors that handle FCI or CUI. In general, if your company is involved in bidding for or fulfilling DoD contracts, you’ll likely need to meet specific CMMC 2.0 requirements, depending on the type of information your company manages.

CMMC 2.0 is structured into three levels:

- **Level 1 - Foundational**: Focuses on basic cyber hygiene, suitable for all contractors handling Federal Contract Information (FCI), with 17 essential requirements.
- **Level 2 - Advanced**: Aligns with NIST SP 800-171, targeting intermediate cyber hygiene for organizations handling Controlled Unclassified Information (CUI), incorporating 110 comprehensive requirements.
- **Level 3 - Expert**: Targets advanced cybersecurity practices for highly sensitive information, with 130 practices aimed at protecting against Advanced Persistent Threats (APT).

Each level of CMMC 2.0 represents a step up in cybersecurity maturity, ensuring that organizations progressively enhance their ability to protect sensitive information and respond to cyber threats.

## How do you become CMMC 2.0 certified? 

The certification process varies by level.

- **Level 1** involves an annual self-assessment.
- **Level 2** requires either a self-assessment (for a subset of contractors) or an independent assessment by a certified third-party assessment organization (C3PAO).
- **Level 3** certification requires a government-led assessment due to the heightened security concerns at this level.

It’s crucial to know which level applies to your business so you can begin the certification process and stay compliant.

In this section, we’ll dive deeper into the details of CMMC 2.0 to explore specific requirements, including the CMMC 2.0 controls and how the standard compares to other federal frameworks.
