An organization’s certification level is determined by the type and amount of FCI and/or CUI it possesses and/or creates. Level 1 certification will be required for all companies and institutions in contract with the DoD. Level 2 certification will be required for any contract handling CUI. At present, Drexel University plans to obtain a Level 2 certification.
A “C3PAO” or CMMC Third-Party Assessment Organization is an entity certified to provide consultative advice OR certifies assessments.
To review a full list of CMMC terms, please visit the CyberAB’s Glossary.
Meeting all CMMC requirements is important in order to remain eligible for DoD research contracts. Not being compliant may impact Drexel’s research status.
Individuals or groups seeking to do business with the DoD should:
- Review the Request for Information (RFI) and Request for Proposal (RFP) for the appropriate CMMC level.
- Ensure the appropriate cybersecurity measures in place for the required CMMC level.
- Possess the appropriate level of CMMC certification before accepting an award.
- Ensure compliance with NIST 800-171, the NDAA 889 regulation, etc.