If you do business with the Department of Defense (DoD), you’ve probably heard about the Cybersecurity Maturity Model Certification (CMMC). CMMC is the DoD’s framework for making sure contractors properly safeguard sensitive information.
With CMMC 2.0, organizations fall into three levels of requirements depending on what kind of data they handle. Here’s what you need to know.
Level 1 – Foundational: Covers 17 basic safeguarding practices (from FAR 52.204-21) designed to protect Federal Contract Information (FCI). Think of this as good cybersecurity hygiene: restricting access to systems, identifying users, and protecting data when it’s transmitted.
Level 2 – Advanced: Requires 110 security practices aligned with NIST SP 800-171 to protect Controlled Unclassified Information (CUI). This is where requirements get more detailed: multi-factor authentication, vulnerability scans, incident response planning, and more.
Level 3 – Expert: Applies to contractors working with the most sensitive programs. It draws from NIST SP 800-172 and focuses on advanced, proactive defenses.
Every requirement falls under one of 14 domains. These categories give structure to the framework:
Instead of dropping 110 technical requirements here (you can view the full list in the official DoD documents), let’s look at some examples at each level:
Level 1 Practices:For contractors, compliance with CMMC isn’t optional. It’s the key to keeping and winning DoD contracts. The challenge is that the framework can feel overwhelming. It’s not just about technology. It’s also about policies, processes, and training.
At ComTec Solutions, our CMMC Ready services are designed to align directly with the requirements and best practices of CMMC 2.0. When you partner with us, you get the tools and support you need to reach and maintain compliance, including:
And beyond the core tools, we also provide optional services to help you prepare for and sustain compliance:
Whether you’re just starting at Level 1 or preparing for Level 2 certification, we’ll make sure you have the people, processes, and technology in place to succeed.
Ready to take the next step? Contact us today to talk with our CMMC experts.