Guide · CMMC

What is CMMC?

If you sell to the US Department of Defense, you'll hear about CMMC. Here's what it is and what it requires.

The short answer

The Cybersecurity Maturity Model Certification (CMMC) is the US Department of Defense's program requiring contractors that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) to meet defined cybersecurity practices — and, at higher levels, prove it through a third-party assessment.

Who needs it?

Organizations in the US defense industrial base — prime contractors and their subcontractors. The required level depends on the sensitivity of the information you handle.

What's it built on?

CMMC builds on NIST SP 800-171, the standard for protecting CUI. The practices map to controls you can implement and evidence continuously.

Why self-hosting matters for CMMCCUI is highly sensitive and often can't sit in a third-party cloud. Because Vallorix is self-hosted, it can run on-prem or air-gapped — which CUI environments frequently require. See CMMC with Vallorix.

General explainer, not audit advice. CMMC assessments are performed by authorized third parties, not by Vallorix.

See Vallorix on your own infrastructure

Continuous evidence, auditor-ready reports, and controls that stay in your boundary.

Get a demo →
V
Vallorix AssistantAI · answers about compliance & the product
AI assistant · not a human · answers may be imperfect