Guide

What is CMMC?

A plain-language explanation of the Cybersecurity Maturity Model Certification program, who it applies to, and what preparation actually involves.

Intended audience
Contractors and prospective contractors
Difficulty
Beginner
Estimated time
12 minutes
Access
Free
CMMC
NIST SP 800-171
DFARS
Government contracting

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Explain what the CMMC program verifies and why it exists.
  • Distinguish between the FCI-only and CUI-handling populations of contractors.
  • Describe the core artifacts (SSP, POA&M, self-assessment) a company produces during preparation.
  • Identify who is authorized to certify or assess a company, versus who can only help prepare.
  • Estimate a realistic readiness timeline for a small business at different starting points.

The short version

CMMC is the Department of Defense's way of verifying that companies in its supply chain actually implement required security practices, rather than just asserting they do. The security requirements themselves largely come from existing standards; CMMC adds verification.

Who it applies to

  • Companies handling Federal Contract Information (FCI) face basic safeguarding expectations.
  • Companies handling Controlled Unclassified Information (CUI) face the fuller NIST SP 800-171 requirement set.
  • Requirements flow down to subcontractors that handle the same data.

What preparation looks like

  • Determine the data you handle and your system boundary.
  • Implement the required practices and write down how.
  • Produce a System Security Plan and a POA&M for gaps.
  • Collect evidence and perform a self-assessment.

Common misunderstanding

Buying software does not make you certified. Assessment outcomes depend on implemented practices, documentation, and evidence — with the specific level and verification path driven by your contract.

FAQ

  • Does ComplianceAnvil certify us? No. We prepare you; certification and assessment come from authorized parties.
  • How long does readiness take? For a small business with basic controls already in place, weeks of focused work; from a standing start, months.
  • Do we need everything before bidding? No, but you need to know your gaps and have a credible plan.

Key takeaways

  • CMMC adds independent verification on top of security requirements that already exist, primarily from NIST SP 800-171 and FAR/DFARS clauses.
  • The level and assessment path that applies to a company is driven by its specific contract, not by company preference.
  • Buying security software does not equal certification; assessors evaluate implemented practices, documentation, and evidence.
  • A System Security Plan and a Plan of Action and Milestones are expected deliverables, not optional extras.
  • ComplianceAnvil helps organizations prepare but is not a certification authority or assessor.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

Earn a Certificate of Training Completion

Complete every section, acknowledge, and pass the knowledge check.

Sections opened0 of 5
Knowledge check

80% required to pass. Answers are graded on our servers.

1. What does the CMMC program primarily add on top of existing security requirements?

2. Which population faces the fuller NIST SP 800-171 requirement set under CMMC?

3. What is a common misunderstanding about achieving CMMC readiness?

4. Do CMMC requirements flow down to subcontractors handling the same data?

5. What role does ComplianceAnvil play in the CMMC process?

This certificate recognizes completion of educational training material only. It is not a professional certification, accreditation, license, compliance assessment, audit result, or attestation of compliance with any law, regulation, or contract requirement. ComplianceAnvil is not a certification authority, accreditation body, assessor, or law firm.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal); DoD supply chain
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

This resource is educational readiness material. ComplianceAnvil is not a certification authority, assessor, or law firm, and this content is not legal advice or a compliance assessment.

Matched on shared frameworks, topics, and program packs.

Checklist

CMMC Readiness Checklist

Work through the preparation steps most small contractors miss before a CMMC assessment: scope, system boundary, documentation, and evidence.

Intermediate
45 min
Free
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Checklist

Government Contractor Startup Checklist

What to put in place before your first federal award creates security obligations you cannot meet.

Intermediate
40 min
Free
FAR
DFARS

Published · v1.0.0 · 2026-08-01

Exercise

Identify CUI Examples

Practice separating CUI from FCI and from ordinary business information.

Advanced
15 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Checklist

NIST SP 800-171 Preparation Checklist

A plain-language preparation pass across the requirement families, focused on what a small business must produce and prove.

Advanced
60 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Guide

What is NIST SP 800-171?

The requirement set that governs protecting Controlled Unclassified Information in non-federal systems, explained without the jargon.

Intermediate
14 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.