01Introduction
Companies that handle Department of Defense information now need a verified cybersecurity level to win and keep contracts. CMMC turned self-attested NIST compliance into a contract condition.
02What is CMMC?
The Cybersecurity Maturity Model Certification (CMMC) 2.0 is the US DoD program that verifies contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The program rule took effect in December 2024, and contract requirements began phasing in from November 2025.
It has three levels. Level 1 covers 15 basic requirements with annual self-assessment. Level 2 covers the 110 requirements of NIST SP 800-171, mostly assessed by a certified third party (C3PAO). Level 3 adds a subset of NIST SP 800-172, including penetration testing, assessed by the government. It pairs naturally with FedRAMP for cloud providers.
03How CMMC works
The path runs through scoping, gap closure and assessment.
- 1.
Scope CUI
Identify where FCI and CUI are stored, processed and transmitted, and draw the assessment boundary.
- 2.
Gap assessment
Compare against the NIST SP 800-171 requirements, documented in a system security plan.
- 3.
Remediate
Close gaps and track remaining items in a plan of action and milestones (POA&M), which has strict limits.
- 4.
Assess and affirm
Complete a self- or third-party assessment and submit an annual affirmation in SPRS.
04Threats and risks
The defense industrial base is a persistent target.
Nation-state espionage
Targeted theft of design data and program information from contractors and subcontractors.
Flow-down gaps
Primes inheriting risk from smaller suppliers with weaker controls.
False Claims Act exposure
Misrepresenting compliance can lead to legal liability, not just lost contracts.
Lost eligibility
Without the required level, a contractor can't be awarded the contract.
05How Parameter helps
Parameter helps contractors test that CUI-facing systems hold up, and document it.
Security assessment evidence
The pentesting agents test applications and APIs that handle CUI and record the results.
Vulnerability scanning
Managed vulnerability scanning supports the scanning requirement.
Cloud configuration
Cloud Security checks the cloud environments inside the CUI boundary.

