TrustCloud raises $15M, led by ServiceNow Ventures, with participation from Cisco Investments. Read more →

CMMC FAQ

Estimated reading: 1 minute 2214 views
  1. Self-attest L1 starts with a CMMC L1 for the basic set of requirements from CMMC. Level 1 protects Federal Contract Information (FCI).
  2. Mature with Level 2 if you handle CUI, add policies and procedures and a few controls.

Each CMMC level is built on the one below it, so compliance with the lower-level requirements and the use of additional processes are needed to implement the cyber security-based practices.

  1. Level 1: This is the most “basic cybersecurity practice,” such as using antivirus software and ensuring employees change their passwords regularly. This should be done to protect Federal Contract Information (FCI).
  2. Level 2: This is likely to be the level that most contractors fall into. Level 2 is an intermediate level between Level 1 and Level 3 and consists of good cyber hygiene. This level must be completed if the organization holds CUI (Controlled Unclassified Information) on their network.
  3. Level 3: At the expert level, the organization must demonstrate the effectiveness of the level 1 and level 2 practices.

Join the conversation

You might also be interested in

NIST CSF Overview and Guides

The NIST CSF Overview and Guides talk about the Cybersecurity Framework (CSF), which is...

Boost resilient security posture: Proven 10 steps for strong controls

Discover ten expert steps to easily implement controls and build a resilient security posture....

Unlock business success: Choose the right control framework

The journey toward selecting the right control frameworks is not just a compliance exercise;...

Vital data privacy & AI ethics: Essential practices every organization must follow

Learn how to strengthen data privacy while using AI. Discover ethical best practices to...

Master change management in GRC: Build effective policies for 2025

Learn how to create change management policies that reduce risk, support compliance, and drive...

Essentials for workstation monitoring: Safeguard trust, compliance & security

Explore key takeaways on monitoring employee workstations: balancing security and privacy, ensuring compliance, and...

Unlock effective agile compliance management strategies for evolving regulations

Discover effective agile compliance management strategies to navigate evolving regulatory frameworks. Learn how to...

Why are employee all hands meetings important?

Discover how all-hands meetings boost communication, transparency, and engagement. Learn how to run impactful...
OR

TrustCommunity

Instant support with our AI chatbot

Please login with your TrustCloud credentials to continue