// Capability Statement — Download PDF
Insights / CMMC
CMMC

CMMC, explained for the defense industrial base.

What the Cybersecurity Maturity Model Certification requires at each level, who needs it, and the scoping and evidence moves that make assessment survivable.

If your company touches Department of Defense contracts — prime or sub, product or service — the Cybersecurity Maturity Model Certification (CMMC) is the compliance wave that decides whether you stay eligible. It exists for a blunt reason: adversaries steal controlled unclassified information (CUI) from the defense supply chain, and self-attestation didn't stop it.

The levels, without the fog

LevelWho it hitsWhat it takes
Level 1 — FoundationalFCI only (basic contract info)17 practices, annual self-assessment
Level 2 — AdvancedAnyone handling CUI (most of the DIB)NIST 800-171's 110 controls; third-party assessment for most
Level 3 — ExpertHighest-sensitivity programs800-171 + 800-172 enhancements; government-led assessment

The center of gravity is Level 2: NIST 800-171's 110 controls, assessed by a C3PAO for most contractors. If you've followed our ATO explainer, the shape is familiar — controls, evidence, POA&Ms — scaled to companies instead of systems.

How to get ready without panic

Scope ruthlessly. CMMC applies where CUI lives. Segment your environment so CUI touches the smallest possible enclave, and the assessed boundary shrinks with it — often the single highest-ROI move available.

Gap-assess against 800-171 now. Your SPRS score is already reportable. An honest gap assessment with a costed remediation plan beats optimistic self-scoring that an assessor later dismantles.

Fix the recurring offenders. MFA everywhere, FIPS-validated encryption, logging and retention, access reviews, incident response you've rehearsed. The same dozen controls fail in most first assessments.

Make evidence a habit. Assessors accept what they can verify. The same evidence-automation discipline that accelerates ATOs (our home turf) makes CMMC assessments boring — which is the goal.

Put this to work

Need it done, not just explained?

This is the work we do every day. Tell us where your program stands and we'll give you a straight answer.

Talk to Ausper