Glossary

CMMC

CMMC — Cybersecurity Maturity Model Certification — is the US Department of Defense’s program for verifying that contractors protect sensitive information. Three levels: Level 1 (basic safeguarding of federal contract information, self-assessed), Level 2 (protecting CUI per NIST 800-171 — self-assessment or third-party certification depending on the contract), and Level 3 (enhanced requirements for the most sensitive programs).

Why it reaches companies that don’t feel like defense contractors

Flow-down. Prime contractors push CMMC requirements into their supply chains, so a SaaS tool used by a defense manufacturer can find Level 2 language in a renewal. The trigger is handling CUI — if defense-adjacent customers’ controlled data enters your systems, the requirement follows it.

What Level 2 actually demands

NIST 800-171’s 110 requirements: a hardened enclave or environment for CUI, documented in a System Security Plan, with gaps tracked in a POA&M. The strategic move most companies miss: scope an enclave rather than certifying the whole company — the PCI scope-reduction logic applies identically.

The commercial-program bridge

SOC 2/ISO controls cover real ground toward 800-171, but the documentation artifacts (SSP, POA&M) and specific requirements are their own work. If defense pipeline is real, start with a mapped gap assessment before a contract deadline chooses your timeline for you.

Related Terms

CUI (Controlled Unclassified Information) — CUI is US government information that's sensitive but not classified — export data, defense technical data, and more. Handling it triggers NIST 800-171 and CMMC.

FedRAMP — FedRAMP is the US government's cloud security authorization program — mandatory for selling cloud services to federal agencies, and a major undertaking.

NIST 800-53 — NIST 800-53 is the US government's control catalog — hundreds of controls across 20 families — underlying FedRAMP, FISMA, and federal procurement.