> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# CMMC v2.0

> Achieve Cybersecurity Maturity Model Certification for the US defense supply chain.

> Achieve Cybersecurity Maturity Model Certification for the US defense supply chain.

The Cybersecurity Maturity Model Certification (CMMC) 2.0 is a US Department of Defense program that verifies defense contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). CMMC 2.0 has three levels, building on NIST SP 800-171 and 800-172.

<Note>
  CMMC certification is required for contractors and subcontractors in the Defense Industrial Base (DIB) that handle FCI or CUI.
</Note>

## Who needs CMMC v2.0?

<CardGroup cols={2}>
  <Card title="Defense contractors" icon="shield-halved">
    Any organization in the DoD supply chain handling FCI or CUI must achieve the required CMMC level.
  </Card>

  <Card title="Subcontractors" icon="link">
    Flow-down requirements mean subcontractors must also meet CMMC levels appropriate to the data they handle.
  </Card>
</CardGroup>

## Key components

<CardGroup cols={3}>
  <Card title="Level 1 — Foundational" icon="1">
    17 basic safeguarding practices for protecting FCI. Annual self-assessment.
  </Card>

  <Card title="Level 2 — Advanced" icon="2">
    110 practices aligned with NIST SP 800-171. Third-party assessment for prioritized programs.
  </Card>

  <Card title="Level 3 — Expert" icon="3">
    Adds NIST SP 800-172 enhanced practices. Government-led assessment.
  </Card>

  <Card title="CUI protection" icon="file-shield">
    Controls specifically designed to protect Controlled Unclassified Information.
  </Card>
</CardGroup>

## How DSALTA helps with CMMC v2.0

<Steps>
  <Step title="Activate CMMC">
    Select CMMC v2.0 and your target level. DSALTA maps the relevant practices to controls.
  </Step>

  <Step title="Review mapped controls">
    Review NIST 800-171-aligned controls and assign owners.
  </Step>

  <Step title="Collect evidence automatically">
    Connect integrations to gather technical evidence continuously.
  </Step>

  <Step title="Document an SSP">
    Build your System Security Plan and Plan of Action & Milestones (POA\&M).
  </Step>

  <Step title="Prepare for assessment">
    Organize evidence for self-assessment or a C3PAO assessment.
  </Step>
</Steps>

## Frequently asked questions

<AccordionGroup>
  <Accordion title="Which CMMC level do I need?" icon="layer-group">
    It depends on the data you handle. Level 1 for FCI only; Level 2 for most CUI; Level 3 for the most sensitive programs. Your DoD contract specifies the requirement.
  </Accordion>

  <Accordion title="How does CMMC relate to NIST 800-171?" icon="arrows-left-right">
    CMMC Level 2 maps directly to the 110 controls in NIST SP 800-171. If you already meet 800-171, you are well positioned for Level 2.
  </Accordion>
</AccordionGroup>

## Related pages

* [Active Frameworks](/guides/compliance/frameworks-active)
* [Available Frameworks](/guides/compliance/frameworks-available)
* [Controls](/guides/compliance/controls)
* [Audits](/guides/compliance/audits)
