The U.S. Cybersecurity Maturity Model Certification programme assesses protection of information handled in defence contracting. The current model has three levels, addressing Federal Contract Information and increasingly demanding protection of Controlled Unclassified Information. See the official CMMC guidance for businesses.
Scope and assessment
The required level and assessment type depend on the relevant contract or solicitation and information handled. Level 1 uses annual self-assessment and affirmation. Level 2 uses the specified self-assessment or third-party assessment cycle, with annual affirmation. Level 3 adds government assessment and further requirements. Consult the official programme and contracting guidance for the applicable conditions.
Assessment and annual affirmation are different activities. Check the required assessment type, cycle and affirmation separately for the contract in scope.
Use in CSFaaS
The reviewed reference library lists CMMC 2.0 - EN. Inspect its source scope and underlying requirements before use; a catalogue entry's name or row count does not establish contract readiness.
Document the relevant systems, information boundaries, controls, gaps and evidence. Framework maturity scores are internal programme information and do not replace the required CMMC assessment, status or affirmation.