CMMC (Cybersecurity Maturity Model Certification)
Definition
A United States Department of Defense framework that certifies defence contractors at one of five tiers of cybersecurity capability. Each tier requires the practices of lower tiers plus additional controls. The required tier is specified in the contract and must be achieved before bid award.
- Issuing body
- US Department of Defense
- Structure
- Five capability tiers
- Tier logic
- Each tier adds to the lower tier's practices
- Timing
- Required tier must be met before bid award
Common questions
How does a contractor know which CMMC tier it needs to achieve?+
The required tier is specified directly in the specific defence contract or solicitation, based on the sensitivity of the information the contractor will handle, so the same company may need different tiers for different contracts.
What happens if a contractor cannot demonstrate the required CMMC tier?+
They are ineligible for bid award on that contract, since certification at the specified tier is a prerequisite rather than something that can be completed after the contract is awarded.
Related terms
- Audit Programme Maturity
- The degree to which an organisation's audit activities are systematically planned, resourced, executed, measured, and improved. Maturity is usually described on a...
- Enterprise Risk Management (ERM) Integration
- The practice of aligning audit planning with the organisation's ERM risk register so that audit coverage tracks actual risk. When the risk...
- Lessons-Learned Review
- A structured post-cycle review that identifies what worked, what failed, and what should change in the next audit cycle. The output is...
- Mean Time to Close (MTTC)
- The average elapsed time between the date a finding is formally reported and the date remediation is verified as complete. MTTC is...
- Repeat Finding Rate
- The percentage of findings in the current audit cycle that were also identified in the prior cycle. A high repeat finding rate...