TroutTrout
Back to Glossary
CMMCCybersecurity Maturity Model Certification

CMMC

3 min read

CMMC (Cybersecurity Maturity Model Certification) is the U.S. Department of Defense program that verifies a contractor protects the sensitive information it handles before that contractor can be awarded work. It maps existing federal security requirements to certification levels and forces companies in the Defense Industrial Base to prove compliance instead of just claiming it. The final rule (32 CFR Part 170) took effect December 16, 2024, and CMMC clauses started appearing in DoD contracts through 2025 and 2026.

What are the CMMC levels?

CMMC 2.0 has three levels, not the five that the original 2020 model used.

  • Level 1 (Foundational): protects Federal Contract Information against the 15 basic requirements in FAR 52.204-21. Met by annual self-assessment.
  • Level 2 (Advanced): protects Controlled Unclassified Information against the 110 controls in NIST SP 800-171 Rev 2. Most contracts require a third-party assessment by a C3PAO every three years.
  • Level 3 (Expert): adds a subset of NIST SP 800-172 controls for the highest-priority programs, assessed by the government itself (DIBCAC).

The level a contractor needs is written into each solicitation. Most of the Defense Industrial Base lands at Level 2.

Who must comply with CMMC?

Any organization in the DoD supply chain that handles FCI or CUI: prime contractors, subcontractors, manufacturers, and service providers. The requirement flows down. A prime that holds CUI passes the obligation to every subcontractor that touches it, which is why a small machine shop supplying parts for a weapons program can find itself needing Level 2. If you cannot show your certification, you cannot be awarded the contract.

Why does CMMC matter for OT and industrial environments?

Defense manufacturing runs on operational technology: PLCs, CNC machines, HMIs, and test rigs that were never built to satisfy modern access control, logging, or encryption requirements. NIST SP 800-171 does not exempt them. When a CNC controller processes a CUI-bearing part program, that machine is in scope. Most of these assets cannot run MFA, cannot generate audit logs, and speak plaintext protocols. That gap is what a compensating control or a documented CMMC Enduring Exception exists to close, usually by moving enforcement off the asset and onto the network around it.

How is CMMC different from NIST SP 800-171?

NIST SP 800-171 is the control catalog. CMMC is the enforcement mechanism. For years contractors self-attested to 800-171 compliance, and many overstated it. CMMC adds independent assessment, a pass or fail certification, and an Affirming Official who signs under penalty of the False Claims Act. Same controls, real consequences.

How Access Gate helps

Access Gate hosts the compensating controls that specialized OT assets cannot run themselves. It enforces identity and MFA at the network boundary before a session reaches a controller, logs every session for the assets that cannot log, and encrypts transport for devices that speak plaintext, all without changing the asset. The CMMC Shared Responsibility Matrix shows which controls the overlay covers and which stay with your SSP. See CMMC compliance for the full picture.

Related terms