For a better experience, click the Compatibility Mode icon above to turn off Compatibility Mode, which is only for viewing older websites.

Cybersecurity Maturity Model Certification (CMMC)

With the increasing frequency and complexity of cyber-attacks against the defense industrial base (DIB), the Department of Defense (DoD) developed the Cybersecurity Maturity Model Certification (CMMC) Program. CMMC is designed to strengthen the cybersecurity of the DIB to better protect DoD’s information. CMMC assesses and provides assurance that contractors and subcontractors (current and prospective) are compliant with existing information safeguarding requirements for federal contract information (FCI) and controlled unclassified information (CUI). CMMC consists of three maturity levels, each with a specific assessment type, as depicted below.

Chart showing the CMMC Program information

CMMC certification is now required for all entities, including academic institutions, that want to do business with the DoD. Contracts specify the certification level needed to bid and receive awards. Prime contractors must flow these requirements down to their subcontractors, who must continue doing so throughout the DIB supply chain. CMMC took effect on December 16, 2024, and is being added to contracts in phases under a four‑phase implementation plan that will roll out over three years. The phases are as follows: 

Chart showing the phases of the CMMC rollout into contracts 

How does CMMC affect Drexel?

Meeting all CMMC requirements is important to remain eligible for DoD research contracts. Not being compliant may impact Drexel’s research status.

Individuals or groups seeking to do business with the DoD should:

  • Review the Request for Information (RFI) and Request for Proposal (RFP) for the appropriate CMMC level.
  • Ensure the appropriate cybersecurity measures are in place for the required CMMC level.
  • Possess the appropriate level of CMMC certification before accepting an award.
  • Ensure compliance with NIST 800-171, the NDAA 889 regulation, etc.

FAQs

    What types of assessments are required for each CMMC level?

    • Level 1- Basic Safeguarding of FCI – Annual self-assessment and annual affirmation of compliance with the 15 security requirements in FAR clause 52.204-21
    • Level 2- Broad Protection of CUI – Either a self-assessment or an independent assessment by an authorized CMMC Third-Party Assessment Organization (C3PAO) every three years. (The solicitation will specify the assessment requirement.) Additionally, an annual affirmation to verify continued compliance with the 110 security requirements in NIST SP 800-171.
    • Level 3- Higher Level Protection of CUI Against Advanced Persistent Threats- Achieve CMMC Level 2 certification first, then undergo an assessment every three years by the Defense Contract Management Agency’s (DCMA) Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). Annual affirmations are required every year to verify continued compliance with CMMC Level 2 as well as the 24 identified requirements in NIST SP 800-172.

    Note: All assessment results and annual affirmations of continued compliance are entered into SPRS.

    Terminology

    • What is Federal Contract Information or FCI?
      • FCI is defined in section 4.1901 of the Federal Acquisition Regulation (FAR), as “information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, excluding information provided by the Government to the public (such as that on public websites) or simple transactional information, such as that necessary to process payments.”
    • What is Controlled Unclassified Information or CUI?
      • CUI is defined in Title 32 CFR 2002.4(h), as “information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls.”

    For additional terms, please visit the Cyber AB’s Terminology website.

    Have a question that isn’t answered on this webpage?

Resources

Drexel University Office of Research and Innovation:

CMMC: