CMMC 2.0

Cybersecurity Maturity Model Certification: practices and domains, gap assessment, SPRS score, evidence, POA&Ms and assessment preparation.

CMMC 2.0 Overview & Key Concepts

What CMMC 2.0 is, why the Defense Industrial Base must meet it, how its three levels map to NIST SP 800-171 and 800-172, and the concepts the module uses.

1 min

Practices & Domains

The 14 CMMC domains with Level 1 and Level 2 practice counts, each practice tied to its NIST SP 800-171 or FAR 52.204-21 clause, and the statuses you set.

1 min

Controls

The Controls page is where you define, implement, and track the operational controls that satisfy CMMC practices. While practices describe what must be achieved, controls describe...

1 min

Gap Assessment & SPRS Score

The Gap Assessment evaluates your organisation's current implementation status against all CMMC practices for your target level. It produces a domain-by-domain breakdown and...

1 min

Evidence Collection

The Evidence page helps you collect and organise the artifacts that prove your CMMC practices are implemented and your controls are operating

1 min

POA&Ms

A Plan of Action Milestones (POA M) documents known security deficiencies and the specific steps your organisation will take to remediate them. Under CMMC 2.0, POA Ms play a...

1 min

Assessments & Findings

Log self-assessments, C3PAO and DIBCAC engagements, record outcomes, and prepare for a Level 2 C3PAO assessment with the evidence and POA&M in order.

1 min

Management Reviews

Management Reviews provide governance oversight for your CMMC programme. Regular reviews ensure senior leadership stays informed about cybersecurity posture, assessment readiness,...

1 min

Certification Readiness

The Readiness page tracks your journey from initial CMMC programme setup through certification and ongoing

1 min