Venvera CMMC 2.0 dashboard
The CMMC 2.0 dashboard - shown with sample data.

The Cybersecurity Maturity Model Certification (CMMC) 2.0 is a U.S. Department of Defense (DoD) framework that ensures organisations in the Defense Industrial Base (DIB) adequately protect sensitive information. CMMC 2.0 streamlines the original five-level model into three levels aligned with existing federal standards, primarily NIST SP 800-171 and NIST SP 800-172.

Venvera covers the full CMMC 2.0 lifecycle:

  • Practices & Domains - Browse and manage the 110+ security practices across 14 domains
  • Controls - Implement operational controls mapped to CMMC practices
  • Gap Assessment & SPRS Score - Evaluate readiness and calculate your Supplier Performance Risk System score
  • Evidence - Collect and organise artifacts that demonstrate practice implementation
  • POA&Ms - Track Plan of Action & Milestones for remediation
  • Assessments - Manage self-assessments, C3PAO, and DIBCAC engagements
  • Management Reviews - Record governance decisions and action items
  • Readiness - Track certification milestones and pre-assessment preparation

The Three CMMC 2.0 Levels

LevelNamePracticesAssessmentWhat it protects
Level 1Foundational17 practices (FAR 52.204-21)Annual self-assessmentFederal Contract Information (FCI)
Level 2Advanced110 practices (NIST SP 800-171 r2)Triennial C3PAO or self-assessmentControlled Unclassified Information (CUI)
Level 3Expert110+ practices (NIST SP 800-172 subset)Government-led (DIBCAC) assessmentCUI on highest-priority programs

Key Concepts

CUIControlled Unclassified Information - sensitive but unclassified information requiring safeguarding per NIST SP 800-171
FCIFederal Contract Information - information not intended for public release, provided by or generated for the government under a contract
C3PAOCMMC Third-Party Assessment Organisation - accredited to conduct Level 2 assessments
DIBCACDefense Industrial Base Cybersecurity Assessment Center - conducts Level 3 assessments
SPRSSupplier Performance Risk System - DoD portal for submitting self-assessment scores (range: -203 to 110)
SSPSystem Security Plan - formal document describing security requirements and controls
POA&MPlan of Action & Milestones - document identifying tasks to correct deficiencies