CMMC
Understand the US Department of Defense Cybersecurity Maturity Model Certification and what it asks of suppliers.
CMMC: what it is and why it matters
CMMC verifies that defense contractors and subcontractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Level 1 covers FCI with 15 requirements and annual self-assessment, Level 2 covers CUI with 110 requirements from NIST SP 800-171 Rev 2, and Level 3 adds selected NIST SP 800-172 requirements assessed by the government.
The programme sits in regulation: 32 CFR Part 170 and a DFARS contract clause. Its rollout timeline has been changing, so check the official DoD CIO CMMC page for the current phase before planning dates.
Built for the people who carry the work
- Compliance and contracts managers at defense suppliers
- Security leads preparing for a CMMC assessment
- Consultants who advise defense contractors
- Subcontractors who receive flow-down requirements
What you will be able to do
- Explain the three levels and which one applies to a contract
- Describe the 14 domains of the model
- Distinguish FCI from CUI
- Plan a gap assessment against NIST SP 800-171 requirements
- Understand affirmations and how requirements flow down to subcontractors
Subject outline
- 01
Programme structure and levels
- 02
FCI and CUI scoping
- 03
The 14 domains
- 04
Self-assessment and third-party assessment paths
- 05
Plans of action and affirmation
- 06
Flow-down to subcontractors
- 07
Current regulatory status
How it supports real work
Scoping the CUI boundary before an assessment
Preparing evidence organised by requirement
Aligning existing ISO/IEC 27001 controls to NIST SP 800-171
Training, examination and certification are different steps
CMMC is a regulated programme, not an ISO-style standard. Official assessor and professional credentials are issued through the Cyber AB ecosystem. PECB publishes a separate CMMC Foundations credential and states that it is not approved by the Cyber AB.
- Cyber AB credentials such as Certified CMMC Professional have their own prerequisites, including training with an approved provider.
- PECB states that its CMMC Foundations credential is its own and is not a Cyber AB credential.
- This page makes no claim that V-Academy delivers Cyber AB approved training.
Certification bodies set and can change their own exam, eligibility and renewal rules. The details below are what the body publishes; we confirm the current position with you before you enrol.
Sources checked, October 2026: www.federalregister.gov · dodcio.defense.gov
What is confirmed, and what people ask
Delivery information
Delivery details for this course have not been confirmed for publication, so none are listed here. Course length, schedule, language, delivery format and fees are confirmed per enquiry. Certification bodies set their own exam and eligibility rules, and we confirm the route to any certificate before you enrol.
Enquire About This CourseFrequently asked questions
Is CMMC an ISO standard?
No. It is a US Department of Defense programme set out in regulation.
How many levels are there?
Three: Level 1 for FCI, Level 2 for CUI and Level 3 for selected enhanced protection of CUI.
Does this course make me a CMMC assessor?
No. Assessor and professional credentials are issued through the Cyber AB ecosystem and have their own prerequisites.
What is the current phase?
Check the official DoD CIO CMMC page. Dates have been changing and we do not restate them here.
Related courses
Related Valtrenix services
Request course information
Tell us who the training is for and what you want to achieve. We reply with confirmed details only, including what is currently available for CMMC.
- Individual and team training enquiries welcome
- No fees, dates or formats are published until confirmed
- We confirm the certification route before you enrol


