Cybersecurity Maturity Model Certification
DoD framework verifying cybersecurity practices of contractors handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
What CMMC draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
- Sensitive Data DiscoveryFinds and classifies the regulated data, so everything downstream knows what is in scope.
- Policy & ComplianceTurns the captured activity into the report shape the framework asks for.
- Compliance Advisory ServicesOrganises the gap register, the remediation roadmap, and the auditor-ready pack.
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Create Audit Records
Organizations MUST create system audit logs and records to enable monitoring, analysis, and investigation.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
User Accountability
MUST ensure actions can be traced to individual users uniquely.
Governance requirements ask who is accountable and how they know. Role-based access lets auditors and risk owners see the evidence without touching the data, and scheduled reporting puts the same posture view in front of the people who have to sign. What the platform supplies is the substantiation behind the sign-off; naming the accountable owner remains yours.
Audit Process Failure
MUST alert in the event of an audit logging process failure.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Monitor Communications
MUST monitor organizational systems including inbound/outbound communications for attacks.
Rules catch what you already thought of. Behavioural models baseline every user and application against their own history and their peer group, then score deviations in real time — so a service account reading tables it has never touched surfaces without anyone having written a rule for it first. That is what makes monitoring hold up as access patterns change, instead of decaying into a ruleset nobody maintains.
What CMMC covers
Borrowed: CUI per 32 CFR 2002; FCI per FAR 52.204-21
Two borrowed classes. Federal contract information is the lower tier; controlled unclassified information is the higher one.
In scope
- Federal contract information — information provided by or generated for the Government under a contract, not intended for public release
- Controlled unclassified information — information requiring safeguarding under law, regulation or Government-wide policy
CUI Specified
The instrument's own term, kept as it writes it — these labels differ between frameworks on purpose.
- CUI categories carrying handling controls beyond the CUI Basic baseline, set by the authorising law rather than by the contract
CMMC defines NEITHER class itself. It borrows both, which means a dispute about scope is a dispute about the CUI Registry and the contract clauses, not about the CMMC model.
32 CFR Part 2002 · as at 2026-08
How CMMC is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The Department of Defense contractually; the Department of Justice under the False Claims Act.
| Published maximum | Charged | As at |
|---|---|---|
| Treble damages | under the False Claims Act, plus per-claim civil penalties | 2026-08 |
The exposure here is not a compliance fine but a fraud claim. The DOJ Civil Cyber-Fraud Initiative treats an inaccurate security assessment score or a false affirmation as a misrepresentation, and liability can arise with no breach and no harm to the government at all. One contractor settled for USD 4.6 million after reporting a positive score when the true score was negative 142.
Phase II of the CMMC rollout was suspended in July 2026. During the interim, the Department enforces against NIST SP 800-171 self-assessment rather than requiring third-party certification — which moves the exposure onto the accuracy of your own assessment.
Uncapped exposure that sits outside this instrument
These come from company law rather than from CMMC, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Who the instrument makes accountable
32 CFR Part 170 requires a named Affirming Official to attest to compliance in the Supplier Performance Risk System, and to re-affirm annually. That affirmation is the statement a False Claims Act case is built on, which is why the name on it matters.
The insurance position
False Claims Act exposure is commonly excluded from D&O and cyber wordings as a fine or penalty, and treble damages may be treated as punitive and therefore uninsurable in some states.
How this class of policy is commonly written. Only your own policy answers what it covers.
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for CMMC,
not configured for it afterwards
CUI Protection Policy
Monitor all access to Controlled Unclassified Information
CMMC Assessment Evidence
Practice-by-practice evidence documentation
CUI Data Patterns
Identify and classify CUI categories in databases
Audit Health Monitoring
Alert on audit system failures per AU.L2-3.3.4
Other Government frameworks
Walk into the CMMC audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.