CMMC
What is CMMC?
The Cybersecurity Maturity Model Certification is a US Department of Defense framework requiring defense contractors to implement cybersecurity practices at specified maturity levels.
Terms that appear alongside cmmc
Each of these is named in at least one of the same controls as cmmc. The number is how many controls name both.
- nist 9 shared controls
- fedramp 8 shared controls
- authorization 7 shared controls
- cybersecurity 6 shared controls
- baseline 5 shared controls
- nist sp 800 171 4 shared controls
- certification 4 shared controls
- audit 3 shared controls
Frameworks that govern cmmc
What the standards actually require on cmmc
Requirements naming cmmc across 6 standards, quoted from the control text.
CMMC 2.0 Level 1 (Foundational) practice IA.L1-3.5.1: Identification - safeguarding Federal Contract Information per FAR 52.204-21(b)(1)(v) (3.5.1).
IA.L1-3.5.1 · Identification →FISMA + FedRAMP coordination for cloud services. FEDRAMP (Federal Risk and Authorization Management Program) operationalizes FISMA for CLOUD SERVICES used by federal agencies (established by OMB Memorandum M-11-30 + modernized by M-24-15 of July 2024).
FISMA-FedRAMP-Cloud-Coordination · FedRAMP for Cloud Services + 800-37 ATO Integration →STATERAMP + GovRAMP are FedRAMP-aligned authorization programs for state + local + tribal governments. STATERAMP (https://stateramp.org/) - non-profit organization + administers state-government cloud authorization mirroring FedRAMP processes + uses FedRAMP-co...
FedRAMP-StateRAMP-GovRAMP · Coordination with StateRAMP, GovRAMP and state + local + tribal government cloud authorization →Section 9.3 of IRS Publication 1075 establishes the technical and procedural security controls + by inheritance from NIST SP 800-53 Rev 5 Security and Privacy Controls for Information Systems and Organizations.
IRSPub1075-Section93-NIST800-53-Inheritance-IRSModerate-Plus-Baseline-FIPS199-HIGH-Confidentiality · IRS Publication 1075 Section 9.3 + NIST SP 800-53 Rev 5 Inheritance + IRS Moderate-Plus Baseline (Not Just Moderate, Less Than High) + FIPS 199 Confidentiality HIGH for FTI + 18 Control Families + 200+ Controls →ITAR technical data + defense services + Deemed Export Rule require careful management of foreign person access to controlled information regardless of physical location.
ITAR-TechnicalData-DefenseServices-DeemedExport-ForeignPerson-Access-USPersons-FOC-AUKUS-Exemptions · ITAR Technical Data + Defense Services + Deemed Export Rule + Foreign Person Access + US Persons Only + FOCI Foreign Ownership Control Influence + AUKUS Pillar 2 Exemptions + DD-2345 MCTL →Aviation supply chain cybersecurity covers: (a) Executive Order 14028 'Improving the Nation's Cybersecurity' SBOM + secure software development practices + NIST SSDF (SP 800-218) alignment;
FAA-CSA-SupplyChain · Supply Chain Cybersecurity (CISA + NIST SSDF + Executive Orders alignment) →Questions people ask about cmmc
What is CMMC?
Why is CMMC important for compliance?
Which compliance frameworks address CMMC?
Where can I learn more about CMMC?
See how CMMC applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.