All organizations that process, store, or transmit CUI must undergo Cybersecurity Maturity Model Certification (CMMC) to validate their cybersecurity practices and demonstrate protection for controlled unclassified information.
CMMC security requirements vary by level, with more advanced practices to reduce cybersecurity risk as more CUI is present or as the contractor moves further up the DoD supply chain, which requires a higher certification level.
Leading DoD contractors are choosing CyberStrong to protect and secure controlled unclassified information and to prepare for the CMMC.
CMMC certification requirements depend on the certification level.
Here is a short explanation of the certification levels, with each level building upon the previous level’s requirements. For example, to complete Level 2, you will need to have completed all the requirements of Level 1 plus additional requirements.
| Level 1: | Basic Cyber Hygiene | DoD service providers who prefer to pass an examination at this level should execute 7 controls of NIST 800-171 rev1. |
| Level 2: | Good Cyber Hygiene | To accomplish Level 3 certification, you must implement the last 45 controls of NIST 800-171 Rev. 1 and 13 new "Other" controls. |
| Level 3: | Good Cyber Hygiene | To accomplish Level 3 certification, the last 45 controls of NIST 800-171 Rev1 and 13 new "Other" controls must be implemented. |
| Level 4: | Proactive Cybersecurity | Along with controls from levels 1 through 3, 11 additional controls of NIST 800-171 Rev. 2 plus 15 new "Other" controls are required. |
| Level 4: | Advanced/ Progressive Cybersecurity | For the maximum level, DoD specialists must carry out the last four controls in NIST 800-171 Rev. 2 together with 11 new "Other" controls. |
Read more:
Copyright © 2026 CyberSaint Security. All Rights Reserved. Privacy Policy.