CMMC, for the Defense Industrial Base specifically.
The Cybersecurity Maturity Model Certification applies to the US Defense Industrial Base — companies handling federal contract information or controlled unclassified information on DoD contracts. Three certification levels build on NIST SP 800-171 and SP 800-53, with the required level set by the information the contract involves, and the requirement flows down from primes to subcontractors.
For a contractor this is an operating problem, not a documentation problem. A certification examines whether controls are operating — not whether a binder describes them — and stays defensible only while they keep operating after the assessment. The evidence is control state, and control state is continuous.
Who it applies to
Companies across the Defense Industrial Base, prime and subcontractor alike. Level 1 aligns with safeguarding federal contract information; Level 2 with protecting controlled unclassified information under SP 800-171; Level 3 adds a layer of SP 800-53-derived controls for the most critical programs. Because the requirement flows down, subcontractors inherit the level their work supports.
The clock
CMMC phases in through the DoD acquisition rule rather than arriving on a single day. The program rule under 32 CFR Part 170 took effect in December 2024; the contract rule took effect in November 2025 and Year 1 began with it. The rule's phases run to full applicability in November 2028.
| When | What happens |
|---|---|
| 16 December 2024 | CMMC Program rule effective (32 CFR Part 170) |
| 10 November 2025 | Acquisition rule effective (48 CFR) — Year 1 of the phased rollout begins |
| 10 November 2026 | Year 2 begins, as the rule text schedules |
| 10 November 2027 | Year 3 begins, as the rule text schedules |
| 11 November 2028 | Full applicability — CMMC required in all applicable solicitations and contracts |
What it asks, in operating terms
Read as an operating requirement rather than a certification checklist, CMMC reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed before an assessment.
| What CMMC asks | Where it is answered |
|---|---|
| Scope the boundary — which systems touch FCI or CUI | Control library · boundary controls scoped to the enclave |
| Meet SP 800-171 for controlled unclassified information | Framework crosswalks · 800-171 mapped, evidence shared with 800-53 |
| Keep evidence continuous between assessments | Evidence automation · provenance-tracked from connected systems |
| Track open gaps to closure with owners and dates | Risk management · each gap owned, dated, re-reviewed |
| Produce what an assessor samples | Assessor export · per control, sealed |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:
- Data boundary
- FCI and CUI classified · enclave scoped
- 800-171 coverage
- assessed · 3 gaps open
- Gap closures
- tracked · owner and date per item
- Evidence
- continuous · per control
- Export
- sealed · sha256:5a18…c3d0
Where teams usually start
With a demo walked through by TruSecure — the 800-171 mapping on your existing evidence, the gap list with owners and dates, the per-control export an assessor samples from. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
CMMC (Cybersecurity Maturity Model Certification) applies to companies in the US Defense Industrial Base, with three certification levels built on NIST SP 800-171 and 800-53 controls. TruSecure maps the same control evidence used for 800-53 directly onto CMMC level requirements.