What is CMMC?
A plain-language explanation of the Cybersecurity Maturity Model Certification program, who it applies to, and what preparation actually involves.
Published · v1.0.0 · 2026-08-01
Checklist
Work through the preparation steps most small contractors miss before a CMMC assessment: scope, system boundary, documentation, and evidence.
Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team
Complete the items in order. Anything you cannot answer with a document or a screenshot is a gap, not a maybe. Track unresolved items in your POA&M so nothing gets lost between now and your assessment.
Progress is saved in this browser only. It is not a compliance record.
Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.
U.S. Government Publishing Office
32 CFR Part 170 — Cybersecurity Maturity Model Certification Program(opens in a new tab)Link last confirmed 2026-02-01
NIST · Revision 3
SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems(opens in a new tab)Link last confirmed 2026-02-01
Acquisition.gov
DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting(opens in a new tab)Link last confirmed 2026-02-01
Defense Logistics Agency
Supplier Performance Risk System (SPRS)(opens in a new tab)Link last confirmed 2026-02-01
Complete every section, acknowledge, and pass the knowledge check.
This certificate recognizes completion of educational training material only. It is not a professional certification, accreditation, license, compliance assessment, audit result, or attestation of compliance with any law, regulation, or contract requirement. ComplianceAnvil is not a certification authority, accreditation body, assessor, or law firm.
Version v1.0.0 · Document owner: ComplianceAnvil Content Team
This resource is educational readiness material. ComplianceAnvil is not a certification authority, assessor, or law firm, and this content is not legal advice or a compliance assessment.
Matched on shared frameworks, topics, and program packs.
A plain-language explanation of the Cybersecurity Maturity Model Certification program, who it applies to, and what preparation actually involves.
Published · v1.0.0 · 2026-08-01
What to put in place before your first federal award creates security obligations you cannot meet.
Published · v1.0.0 · 2026-08-01
Practice separating CUI from FCI and from ordinary business information.
Published · v1.0.0 · 2026-08-01
A plain-language preparation pass across the requirement families, focused on what a small business must produce and prove.
Published · v1.0.0 · 2026-08-01
How to recognize CUI, why marking matters, and what changes the moment you handle it.
Published · v1.0.0 · 2026-08-01
The requirement set that governs protecting Controlled Unclassified Information in non-federal systems, explained without the jargon.
Published · v1.0.0 · 2026-08-01
Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.