Common Questions About CMMC 1.0
For updated common questions about the new CMMC 2.0, check out our updated blog here.
We know how confusing CMMC can be for many businesses. Luckily, Bravo is here to help! The Cybersecurity Maturity Model Certification (CMMC) is a new standard introduced by the Department of Defense that will serve as framework to enforce Defense Federal Acquisition Regulation Supplement (DFARS) requirements.
Unlike NIST 800-171, becoming CMMC certified entails a third-party audit of your business, instead of conducting it yourself. While CMMC and NIST seem similar, CMMC builds upon the framework of NIST 800-171 to better encompass cybersecurity posture and standing. Companies can capitalize on already-in-progress NIST initiatives as they work toward their appropriate CMMC Level Compliance.
So, how do you prepare for this audit? Here’s some commonly asked questions and answers:
[wm_accordion mode=”accordion”][wm_item title=”Do I need to be CMMC Certified?”]
Anyone who does business with the Department of Defense (DoD) must be certified, even subcontractors.[/wm_item][wm_item title=”Can I not do self-certification for CMMC?”]No, the CMMC requires that a third-party be involved to audit your company in order to accurately assess its security posture in accordance with criterion provided by the DoD. Upon being certified, you will be designated to one of the five levels specified within CMMC.[/wm_item][wm_item title=”What are the levels of CMMC?”]CMMC is made up of five levels. Starting at Level One, they are Basic Cyber Hygiene, Intermediate Cyber Hygiene, Good Cyber Hygiene, Proactive Cyber Controls, and lastly, Advanced/Progressive Cyber Protection. The higher the level you are awarded, the more advanced your security posture.
[/wm_item][/wm_accordion]
We will continue to periodically update this list of questions for your convenience.


