The Office of the Under Secretary of Defense for Acquisition and Sustainment (OUSD(A&S)) has outlined a standardized set of cyber-security standards for all contractors wishing to do business with the DoD. The resulting standards has been called the Cyber-Security Maturity Model Certification. Each company much have a third party assessment to reach each of the levels based in the domains outlined below.

Levels

There are 5 total levels in the CMMC each building and including off the ones before it.

Picture depicting level 1 of the CMMC
Picture depicting level 2 of the CMMC
Picture depicting level 3 of the CMMC
Picture depicting level 4 of the CMMC
Picture depicting level 5 of the CMMC
level1
level2
level3
level4
level5
previous arrow
next arrow

Domains

There are 17 domains throughout the 5 levels defined above. They are outlined shortly below:

Picture depicting domain Access Control
Picture depicting domain Asset Management
Picture depicting domain Audit and Accountability
Picture depicting domain Awareness and Training
Picture depicting domain Configuration Management
Picture depicting domain Identification and Authentication domain
Picture depicting domain Incident Response
Picture depicting domain Domain Maintenance
Picture depicting domain Domain Media Protection
Picture depicting domain Personnel Security
Picture depicting domain Physical protection
Picture depicting domain Recovery
Picture depicting domain Risk Management
Picture depicting domain Security Assessment
Picture depicting domain Situational Awareness
Picture depicting domain System and communication protection
Picture depicting domain System and information
domain1
domain2
domain3
domain4
domain5
domain6
domain7
domain8
domain9
domain10
domain11
domain12
domain13
domain14
domain15
domain16
domain17
previous arrow
next arrow

Questions and Answers

Q: What is the CMMC?

A: CMMC stands for Cyber-security Maturity Model Certification. It is a certification created by The Office of the Under Secretary of Defense for Acquisition and Sustainment (OUSD(A&S)) with the goal of assessing contracting companies actual Cyber-Security hygiene based in practices and policy.

Q: What level should I be at?

A: Contracts will be released with a CMMC level requirement but many sources state that level one will be suffcient for most contracts. However, if your work with the government typically involves either the creation or acceptance of CUI marked data then your company should aspire for level 3 or higher.

Q: How do I get certified?

A: This is still in process. The OUSD(A&S)) suggests that companies regularly check with The CMMC regularly for updates. JLGOV will update this page when any updates are released.

Q: How much will certification cost?

A: As of now, the price will be set by the third party assessor company utilized to complete the CMMC assessment.

Q: What can I do to prepare?

A: JLOGV offers Pre-Assessments for companies interested in preparing for an eventual CMMC audit. Click here to learn more about our pre-assessment process.

Sources:

The CMMC