Skip to main content
FRAMEWORK

CMMC, for the Defense Industrial Base specifically.

The Cybersecurity Maturity Model Certification applies to the US Defense Industrial Base — companies handling federal contract information or controlled unclassified information on DoD contracts. Three certification levels build on NIST SP 800-171 and SP 800-53, with the required level set by the information the contract involves, and the requirement flows down from primes to subcontractors.

For a contractor this is an operating problem, not a documentation problem. A certification examines whether controls are operating — not whether a binder describes them — and stays defensible only while they keep operating after the assessment. The evidence is control state, and control state is continuous.

Who it applies to

Companies across the Defense Industrial Base, prime and subcontractor alike. Level 1 aligns with safeguarding federal contract information; Level 2 with protecting controlled unclassified information under SP 800-171; Level 3 adds a layer of SP 800-53-derived controls for the most critical programs. Because the requirement flows down, subcontractors inherit the level their work supports.

The clock

CMMC phases in through the DoD acquisition rule rather than arriving on a single day. The program rule under 32 CFR Part 170 took effect in December 2024; the contract rule took effect in November 2025 and Year 1 began with it. The rule's phases run to full applicability in November 2028.

CMMC · phased rollout
WhenWhat happens
16 December 2024CMMC Program rule effective (32 CFR Part 170)
10 November 2025Acquisition rule effective (48 CFR) — Year 1 of the phased rollout begins
10 November 2026Year 2 begins, as the rule text schedules
10 November 2027Year 3 begins, as the rule text schedules
11 November 2028Full applicability — CMMC required in all applicable solicitations and contracts

What it asks, in operating terms

Read as an operating requirement rather than a certification checklist, CMMC reduces to a handful of standing asks — each answerable with evidence on demand, not reconstructed before an assessment.

CMMC requirements · how TruSecure answers them
What CMMC asksWhere it is answered
Scope the boundary — which systems touch FCI or CUIControl library · boundary controls scoped to the enclave
Meet SP 800-171 for controlled unclassified informationFramework crosswalks · 800-171 mapped, evidence shared with 800-53
Keep evidence continuous between assessmentsEvidence automation · provenance-tracked from connected systems
Track open gaps to closure with owners and datesRisk management · each gap owned, dated, re-reviewed
Produce what an assessor samplesAssessor export · per control, sealed

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a readiness file is made of:

CMMC readiness · Level 2 excerptSample data
Data boundary
FCI and CUI classified · enclave scoped
800-171 coverage
assessed · 3 gaps open
Gap closures
tracked · owner and date per item
Evidence
continuous · per control
Export
sealed · sha256:5a18…c3d0

Where teams usually start

With a demo walked through by TruSecure — the 800-171 mapping on your existing evidence, the gap list with owners and dates, the per-control export an assessor samples from. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

CMMC (Cybersecurity Maturity Model Certification) applies to companies in the US Defense Industrial Base, with three certification levels built on NIST SP 800-171 and 800-53 controls. TruSecure maps the same control evidence used for 800-53 directly onto CMMC level requirements.