Not sure if CMMC applies to you? If you're anywhere in the DoD contract chain, it probably does.
The Cybersecurity Maturity Model Certification (CMMC) is the Department of Defense's (DoD) required certification program for contractors handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). CMMC 2.0 aligned the model to NIST SP 800-171 and introduced three levels, with requirements now appearing in DoD contracts on a phased schedule through 2028. The question might not just be whether CMMC applies to you — it's more likely about which level, when, and how much of your existing program can carry you there.
Who's in scope:
- Prime contractors holding DoD contracts involving FCI or CUI
- Subcontractors at any tier when CMMC requirements flow down from a prime
- Suppliers and service providers in the Defense Industrial Base supply chain
- Cloud and MSP partners whose services touch the CUI environment (shared-responsibility scope)
- Any organization preparing for upcoming DoD solicitations naming CMMC as a contract award condition

