Cybersecurity Maturity Model Certification 2.0 — 14 domains, three levels, and NIST SP 800-171 Rev 2 alignment. Required for DoD contractors handling FCI or CUI.
Level 2 maps 1-to-1 with the 110 security requirements across 14 families in NIST SP 800-171 Rev 2. Each domain contains multiple practices; Level 1 draws a subset from six of these domains.
| Abbr | Domain | NIST Section | Key focus areas |
|---|---|---|---|
| AC | Access Control | § 3.1 | Least privilege, remote access, account management, CUI flow control |
| AT | Awareness & Training | § 3.2 | Security awareness, role-based training, insider threat awareness |
| AU | Audit & Accountability | § 3.3 | Audit log creation, protection, review, and retention |
| CM | Configuration Management | § 3.4 | Baseline configs, change control, least functionality, deny-by-default |
| IA | Identification & Authentication | § 3.5 | MFA for privileged/remote access, password complexity, device authentication |
| IR | Incident Response | § 3.6 | IR capability, incident tracking, testing, and reporting to DoD |
| MA | Maintenance | § 3.7 | Controlled maintenance, sanitization of media removed for maintenance |
| MP | Media Protection | § 3.8 | CUI media access, transport, sanitization, and disposal |
| PS | Personnel Security | § 3.9 | Screening, termination/transfer procedures for CUI-handling roles |
| PE | Physical Protection | § 3.10 | Facility access controls, visitor management, physical protection of CUI |
| RA | Risk Assessment | § 3.11 | Periodic risk assessments, vulnerability scanning, remediation prioritization |
| CA | Security Assessment | § 3.12 | System security plan, controls assessment, plan of action & milestones (POA&M) |
| SC | System & Comms Protection | § 3.13 | Network segmentation, CUI encryption in transit, boundary protection |
| SI | System & Info Integrity | § 3.14 | Malware protection, security alerts, patching, anomaly detection |
All CMMC and NIST source documents are publicly available at no cost. ISO standards are not referenced by CMMC.
| Document | Source | Purpose |
|---|---|---|
| CMMC Model v2.0 | DoD / dodcio.defense.gov | Definitive model document; practice and process requirements by level |
| NIST SP 800-171 Rev 2 | csrc.nist.gov | 110 CUI protection requirements = Level 2 practices |
| NIST SP 800-171A | csrc.nist.gov | Assessment procedures for 800-171 — the how-to-assess companion |
| NIST SP 800-172 | csrc.nist.gov | Enhanced requirements for high-value CUI — Level 3 additions |
| NIST SP 800-171 Rev 3 | csrc.nist.gov | Upcoming revision — monitor for incorporation into CMMC model |