If you sell to the US Department of Defense, you'll hear about CMMC. Here's what it is and what it requires.
The short answer
The Cybersecurity Maturity Model Certification (CMMC) is the US Department of Defense's program requiring contractors that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) to meet defined cybersecurity practices — and, at higher levels, prove it through a third-party assessment.
Who needs it?
Organizations in the US defense industrial base — prime contractors and their subcontractors. The required level depends on the sensitivity of the information you handle.
What's it built on?
CMMC builds on NIST SP 800-171, the standard for protecting CUI. The practices map to controls you can implement and evidence continuously.
General explainer, not audit advice. CMMC assessments are performed by authorized third parties, not by Vallorix.