The Cybersecurity Maturity Model Certification (CMMC) 2.0 is a U.S. Department of Defense (DoD) framework that ensures organisations in the Defense Industrial Base (DIB) adequately protect sensitive information. CMMC 2.0 streamlines the original five-level model into three levels aligned with existing federal standards, primarily NIST SP 800-171 and NIST SP 800-172.

Venvera covers the full CMMC 2.0 lifecycle:

  • Practices & Domains — Browse and manage the 110+ security practices across 14 domains
  • Controls — Implement operational controls mapped to CMMC practices
  • Gap Assessment & SPRS Score — Evaluate readiness and calculate your Supplier Performance Risk System score
  • Evidence — Collect and organise artifacts that demonstrate practice implementation
  • POA&Ms — Track Plan of Action & Milestones for remediation
  • Assessments — Manage self-assessments, C3PAO, and DIBCAC engagements
  • Management Reviews — Record governance decisions and action items
  • Readiness — Track certification milestones and pre-assessment preparation

The Three CMMC 2.0 Levels

LevelNamePracticesAssessmentWhat it protects
Level 1Foundational17 practices (FAR 52.204-21)Annual self-assessmentFederal Contract Information (FCI)
Level 2Advanced110 practices (NIST SP 800-171 r2)Triennial C3PAO or self-assessmentControlled Unclassified Information (CUI)
Level 3Expert110+ practices (NIST SP 800-172 subset)Government-led (DIBCAC) assessmentCUI on highest-priority programs

Key Concepts

CUIControlled Unclassified Information — sensitive but unclassified information requiring safeguarding per NIST SP 800-171
FCIFederal Contract Information — information not intended for public release, provided by or generated for the government under a contract
C3PAOCMMC Third-Party Assessment Organisation — accredited to conduct Level 2 assessments
DIBCACDefense Industrial Base Cybersecurity Assessment Center — conducts Level 3 assessments
SPRSSupplier Performance Risk System — DoD portal for submitting self-assessment scores (range: -203 to 110)
SSPSystem Security Plan — formal document describing security requirements and controls
POA&MPlan of Action & Milestones — document identifying tasks to correct deficiencies