.png)
.png)

CMMC 2.13
Framework Name
Cybersecurity Maturity Model Certification (CMMC), Model Overview Version 2.13
Type
Mandatory for US defense contractors and subcontractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI)
Region / Jurisdiction
United States (Defense Industrial Base)
Enforcing Body / Certifying Party
The US Department of War (the recently renamed US Department of Defense). Verification depends on level: Level 1 is self-assessed, Level 2 was designed to require assessment by an accredited Certified Third-Party Assessment Organization (C3PAO), and Level 3 involves government-led assessment
Penalty / Consequence of Non-Compliance
Loss of eligibility for defense contracts, and real legal exposure: the Department of Justice has already pursued False Claims Act cases against contractors who falsely certified compliance they hadn't actually implemented, including a settlement of several hundred thousand dollars in one recent case
What It Is & Why It Matters
CMMC is the verification mechanism the Department of War uses to confirm that defense contractors actually meet the security requirements laid out in NIST SP 800-171, rather than simply attesting to it. It has three levels: Level 1 covers basic protections for less sensitive Federal Contract Information, Level 2 covers the full set of NIST SP 800-171 requirements for Controlled Unclassified Information, and Level 3 adds enhanced requirements from NIST SP 800-172 for the most sensitive work.
It matters because it's the program that turns "we say we're compliant" into "someone independently checked." That shift, from self-attestation to verified assessment, has been the whole point, and it directly affects who can win defense contracts. It's also, right now, a framework in genuine flux, which is worth understanding before treating any of this as settled.
Who Needs It
- You are a defense contractor or subcontractor handling Federal Contract Information or Controlled Unclassified Information
- You provide IT, cloud, or managed services to a company in the defense supply chain
- You are preparing for or currently hold a CMMC certification and need to track how the program's requirements are changing
- You are evaluating whether to enter the defense contracting space and want to understand the current verification landscape