Skip to main content
Category: Compliance Frameworks & Standards

Cybersecurity Maturity Model Certification

Also known as: CMMC, CMMC 2.0
Simply put

CMMC is a U.S. Department of Defense program that sets cybersecurity requirements for companies in the Defense Industrial Base, meaning contractors and subcontractors that work with the DoD. Its purpose is to protect sensitive government information from unauthorized access by verifying that contractors are meeting required security practices. The current version, CMMC 2.0, organizes these requirements into three levels of cybersecurity.

Formal definition

CMMC is a Department of Defense certification program that applies to Defense Industrial Base (DIB) contractors and is intended to verify that they meet adequate security requirements, including those associated with the protection of Controlled Unclassified Information (CUI) under 32 CFR. The CMMC 2.0 iteration streamlines requirements into three cybersecurity levels and aligns them with existing standards. A virtual CISO engagement may support an organization's readiness against CMMC requirements through gap assessment, governance, and program development, but the assessment and certification process itself is conducted through the program's designated mechanisms; supporting readiness is distinct from achieving certification, and accountability for meeting DoD contractual obligations remains with the contracting organization.

Why it matters

For companies in the Defense Industrial Base, CMMC represents a shift from self-attestation toward verified cybersecurity requirements as a condition of doing business with the Department of Defense. Because the program is designed to protect sensitive government information, including Controlled Unclassified Information (CUI), from unauthorized access, meeting its requirements can directly affect a contractor's eligibility for DoD contracts. This makes CMMC not merely a technical exercise but a business risk and governance concern that can influence revenue and market access for contractors and subcontractors alike.

The stakes are amplified by the layered structure of the Defense Industrial Base, where prime contractors and their subcontractors may all be subject to requirements depending on the information they handle. Organizations that treat CMMC as a last-minute checklist item often underestimate the governance, documentation, and program maturity work involved. It is important to distinguish between supporting readiness for CMMC and actually achieving certification: the two are not the same, and preparation activities do not by themselves confer certified status.

A common and consequential misunderstanding is assuming that engaging outside help transfers accountability for meeting DoD contractual obligations. It does not. Accountability for satisfying CMMC requirements remains with the contracting organization and its officers, even when external advisors support the effort. Understanding this boundary early helps organizations plan realistically rather than assuming a provider can absorb their compliance responsibility.

Who it's relevant to

Defense Industrial Base Contractors and Subcontractors
Companies that contract or subcontract with the Department of Defense are the primary audience for CMMC, since the program applies to DIB contractors and sets requirements tied to the protection of sensitive government information. Both primes and lower-tier subcontractors may be affected depending on the information they handle, so relevance is not limited to large defense firms.
Security and Compliance Leaders Handling CUI
Leaders responsible for protecting Controlled Unclassified Information need to understand which CMMC level applies to their organization and how the requirements map to their existing security program. Because CMMC is a governance and business risk matter as well as a technical one, this responsibility often extends beyond IT to executives accountable for contractual obligations.
Organizations Engaging a Virtual CISO for Readiness
Companies pursuing outside security leadership to prepare for CMMC benefit from understanding what a vCISO engagement typically covers, such as gap assessment, governance, and program development, and what it does not. Supporting readiness is distinct from achieving certification, and accountability for meeting DoD requirements remains with the contracting organization even when a vCISO directs the preparation effort.
Executives and Officers Accountable for DoD Obligations
Because organizational and contractual accountability for CMMC stays with the client organization and its officers, senior leadership should treat CMMC as a matter of business risk and eligibility, not solely a technical compliance task delegated downward. Their engagement is often essential to providing the stakeholder access and cooperation that readiness efforts depend on.

Inside CMMC

Cybersecurity Maturity Model Certification (CMMC)
A U.S. Department of Defense framework designed to verify that contractors and subcontractors in the Defense Industrial Base implement cybersecurity practices appropriate to the sensitivity of the information they handle, including Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
Tiered Maturity Levels
CMMC organizes required practices into levels reflecting increasing rigor, with lower levels addressing basic safeguarding of FCI and higher levels addressing protection of CUI. The specific practices required depend on the level applicable to a given contract.
Alignment with Existing Standards
CMMC draws substantially on established security requirements, and its practices are commonly mapped to controls found in NIST publications governing the protection of controlled information. The framework's purpose is to assess and confirm implementation rather than to introduce an entirely separate control catalog.
Assessment and Verification
CMMC introduces a verification component intended to move beyond contractor self-attestation for certain levels, involving assessment of whether required practices are actually in place. The assessment mechanism and who may perform it can vary by level.
Scope Definition
A CMMC effort depends on identifying which systems, environments, and data flows handle FCI or CUI. Defining this boundary determines the applicable level and the scope of practices and assessment.

Common questions

Answers to the questions practitioners most commonly ask about CMMC.

Does hiring a virtual CISO guarantee that my organization will achieve CMMC certification?
No. A virtual CISO can support your CMMC readiness by helping assess current practices against the required controls, identifying gaps, prioritizing remediation, and guiding governance and documentation efforts. However, certification is determined through a formal assessment process, not by the engagement of an advisor. A vCISO typically supports readiness and directs the program; the actual certification outcome depends on your organization's implementation, evidence, and the assessment itself. Framing a vCISO as a certification guarantee overstates what any advisory engagement can promise.
Is a virtual CISO the same as a CMMC assessor or a managed security service provider (MSSP)?
No, and conflating these roles is a common mistake. A virtual CISO provides executive-level strategy, governance, and risk guidance, and helps direct a CMMC readiness program. A CMMC assessor conducts the formal evaluation that leads to a certification decision, a role that is generally kept independent from those advising on readiness to avoid conflicts of interest. An MSSP delivers operational services such as monitoring and tool administration. These functions serve different purposes, and in many engagements a vCISO would coordinate with, rather than replace, an assessor or an MSSP.
How can a virtual CISO help my organization prepare for CMMC?
In many engagements, a virtual CISO supports CMMC readiness by helping interpret which level applies to your contractual obligations, mapping existing practices to the relevant control requirements, identifying gaps, and building a prioritized remediation roadmap. They typically provide governance structure, policy and documentation guidance, and executive-level direction. The value of this support often depends on organizational maturity, stakeholder access, and how clearly the engagement scope is defined. Hands-on operational implementation is generally out of scope unless explicitly contracted.
Who remains accountable for CMMC compliance decisions during a vCISO engagement?
Accountability for security and compliance decisions usually remains with the client organization and its officers, even when a virtual CISO advises and directs the readiness effort. A vCISO provides guidance and can help shape decisions, but legal and organizational accountability for meeting contractual and regulatory obligations typically stays with the client unless a contract specifies otherwise. It is important to distinguish the advisory responsibility a vCISO holds from the accountability retained by the organization.
What CMMC-related tasks are typically outside a virtual CISO's scope?
A virtual CISO generally focuses on strategy, governance, risk management, and program direction. Hands-on operational tasks such as configuring tools, SOC monitoring, or executing incident response are typically out of scope unless explicitly contracted. Similarly, conducting the formal CMMC assessment that leads to certification is generally a separate, independent function. Organizations should define scope clearly so that expectations about who performs implementation versus who provides direction are understood from the outset.
What organizational factors influence how effective a vCISO can be on CMMC readiness?
Effectiveness often depends on several factors that vary by organization, including current security maturity, the willingness of stakeholders to cooperate, access to the people and systems handling relevant information, and a clearly defined engagement scope. Because CMMC readiness involves both technical controls and governance, business, and risk considerations, treating it as a purely technical exercise can limit progress. A vCISO can direct and prioritize the work, but sustained implementation typically relies on internal commitment and resources.

Common misconceptions

A virtual CISO engagement guarantees CMMC certification.
A vCISO can typically support readiness by advising on governance, gap identification, program development, and preparation for assessment, but a vCISO does not confer or guarantee certification. Certification depends on the applicable assessment process, the client's actual implementation of required practices, and factors outside the advisor's control.
CMMC is a single uniform standard that applies the same way to every contractor.
CMMC uses tiered levels, and the requirements that apply depend on the type of information handled and the terms of a given contract. The applicable level and scope must be determined for each organization rather than assumed to be uniform.
Meeting CMMC is purely a technical exercise handled by IT.
CMMC readiness is substantially a governance and business risk function involving scoping, documentation, policy, and organizational accountability, not only technical tooling. A vCISO advises and directs at the executive level, but legal and organizational accountability for compliance and security decisions typically remains with the client organization and its officers.

Best practices

Define the CMMC scope early by identifying which systems, environments, and data flows handle FCI or CUI, since this determines the applicable level and the practices in play.
Confirm the specific level required by the relevant contracts before designing a program, rather than assuming a single uniform requirement applies.
Frame vCISO involvement around readiness support such as governance, gap assessment, and program development, and clarify in the engagement scope that hands-on operational tasks and formal assessment activities may be out of scope unless explicitly contracted.
Document practices, policies, and evidence in a way that supports assessment, recognizing that verification for certain levels goes beyond self-attestation.
Clarify accountability in writing, confirming that the vCISO advises and directs while legal and organizational accountability for security and compliance decisions remains with the client and its officers unless a contract specifies otherwise.
Set expectations that engagement value depends on organizational maturity, client cooperation, and stakeholder access, and avoid promising guaranteed certification outcomes.