Cybersecurity Maturity Model Certification (CMMC)

Meet CMMC requirements and show your organization complies with Department of Defense requirements for cybersecurity.

What is CMMC?

The Cybersecurity Maturity Model Certification (CMMC) is an assessment framework developed by the U.S. Department of Defense (DoD). The primary objective is to enhance the cybersecurity controls that are in place for organizations supplying the DoD, known as the Defense Industrial Base (DIB). The CMMC model aims to manage risk and verify that DoD contractors can safeguard information classed as Controlled Unclassified Information (CUI) and comply with NIST SP 800-171 DOD assessment requirements and some other cybersecurity requirements.

What is the latest update on CMMC?

The Department of Defense published its Cybersecurity Maturity Model Certification (CMMC) Program final rule (32 CFR Part 170) on October 15, 2024. The final rule is set to come into effect on December 16, 2024. This means that it’s important for defense contractors to understand the timelines for CMMC compliance and identify the changes they might need to make to comply.

Organizations are urged to start their preparations now so that they comply in time. As an authorized C3PAO, NSF can work with you to do this.

Start your CMMC journey to compliance now.

Get your CMMC quote today.

What are the CMMC certification requirements?

There are three levels of the CMMC model. Each one represents a level of cybersecurity maturity and the certification process is different for each level.

Level 1
This level focuses on basic cybersecurity hygiene practices, such as access control and incident reporting. It's designed for organization that handle Federal Contract Information (FCI). Through annual self-assessment and an annual affirmation, organizations required to meet Level 1 must demonstrate they can meet 15 requirements aligned with FAR 52.204-21.

Level 2
This level is designed for organizations that handle Controlled Unclassified Information (CUI). It requires them to comply with 110 practices aligned with NIST SP 800-171. A C3PAO assessment is required every three years (select programs may require self assessment every three years) as well as an annual affirmation.

Level 3
This level is designed for organizations involved with critical DoD programs. It requires them to comply with 110 requirements from NIST SP 800-171 and 24 from NIST SP 800-172. Every three years they must undertake a DIBCAC assessment and complete an annual affirmation to verify compliance with the 110 security requirements in NIST 800-171.

CMMC certification is required for organizations of varying sizes and from a diverse range of organizations in the Defence Industrial Base. NSF is ideally placed to support organizations of all sizes and from many different industries. Contact one of our team to learn how we can work with you to navigate this new and evolving regulatory landscape.

What is the CMMC process?

The CMMC certification process involves several key steps to ensure that organizations meet the necessary requirements for the relevant CMMC status level. Organizations are encouraged to start this process now.

  1. Conduct a CMMC self-assessment: Organizations must conduct a thorough self-assessment to evaluate their current cybersecurity practices against the requirements of CMMC. This CMMC self-assessment helps identify gaps and areas for improvement. NSF can work with you to address any of these areas.
  2. Third-party CMMC audit: Once the self-assessment is complete, organizations must engage an authorized third-party assessment organization(C3PAO), such as NSF to evaluate their compliance with the CMMC requirements. This provides an objective evaluation of the organization's cybersecurity posture. If you are ready, talk to us now to book this in.
  3. CMMC affirmation: Upon successful completion of the third-party CMMC assessment, organizations will receive their CMMC certification. This is valid for three years, after which organizations must undergo re-assessment to maintain their CMMC status. NSF will be able to offer this service. In addition, an annual affirmation is required to verify compliance with the 110 security requirements in NIST 800-171 Revision 2.

Why certify with us

NSF-ISR is an authorized C3PAO. We are listed in the CyberAB Marketplace and we are ready to work with organizations of all sizes to achieve compliance. Benefits of choosing NSF include:

  • Dedicated expertise you can trust. Our CMMC professionals include a certified CMMC Provisional Assessor, certified CMMC Registered Practitioner and certified CMMC Professional.
  • Auditing know-how. Our assessors are fully qualified lead ISO/IEC 27001 and NIST 800-171 auditors.
  • A trusted supplier of information and cyber security services, beyond CMMC. We also provide certification to ISO/IEC 27001 and NIST 800-171, whose frameworks were used as the core to develop CMMC, as well as to ISO/IEC 20000-1 and CSA STAR.
  • Independently accredited. We are an ISO/IEC 17021 accredited certification body and NSF, is ISO/IEC 27001 certified.

NSF-ISR's Security Gap Assessment

Information security is a concern for everyone, and we believe that all businesses can benefit from a comprehensive security assessment. Whether you're looking for a one-time audit or working toward certification, NSF-ISR's Security Gap Assessment is the starting point.
Get Started Today

Share this Article

Get Started With CMMC

Begin your journey to CMMC certification or ask us a question about the steps you need to take.