Issue link: https://iconnect007.uberflip.com/i/1546025
12 SMT007 MAGAZINE I AUGUST 2026 contractors handling sensitive information are actu- ally protecting it. CMMC 2.0 is the DoD's answer. The CMMC 2.0 framework establishes three levels of cybersecurity maturity: • Level 1, Foundational: Focuses on basic cyber hygiene and protection of Federal Contract Information (FCI). Organizations perform an- nual self-assessments. • Level 2, Advanced: Aligns with the 110 secu- rity controls contained in NIST SP 800-171, the long-established standard for protecting Controlled Unclassified Information (CUI). De- pending on the program, organizations may perform self-assessments or undergo third- party assessments by authorized C3PAOs. • Level 3, Expert: Applies to a relatively small group of contractors supporting critical na- tional security programs and includes addi- tional government-led assessment require- ments. The framework may sound technical, but the underlying objective is to establish confidence that sensitive information is protected throughout the defense supply chain. How We Got Here The roots of CMMC go back much further than most people realize. In 2010, Executive Order 13556 established a government-wide framework for handling CUI. Several years later, DFARS clause 252.204-7012 required defense contractors to implement cybersecurity controls in accordance with NIST SP 800-171. The challenge wasn't defining the requirements but verifying compliance. As cyberattacks increas- ingly targeted defense suppliers, the DoD recog- nized a recurring pattern: Adversaries weren't always attacking prime contractors directly. Instead, they were looking for easier entry points, such as smaller suppliers, manufacturing partners, design firms, and subcontractors that possessed valuable technical data but often lacked the cybersecurity resources of larger organizations. In many cases, the weakest link wasn't at the top of the supply chain, but somewhere in the middle. That realization led to the launch of CMMC 1.0 in 2019. Why CMMC 1.0 Struggled When CMMC 1.0 was introduced, industry reaction was immediate. Many organizations supported the goal of improving cybersecurity but raised concerns about the program's complexity, cost, and imple- mentation. The original model included five maturity levels and a large number of practices and process requirements that many companies found difficult to interpret. Smaller contractors worried about certification costs. Industry questioned whether there were enough qualified assessors to support the entire DIB. Program governance and accredita- tion processes were still evolving. Table 1: Defense-related cyberattacks leading to CMMC certifications INCIDENT YEAR SIGNIFICANCE Operation Aurora 2009–2010 Targeted technology and defense firms to steal intellectual property; highlighted advanced persistent threats (APTs) and supplier vulnerabilities. RSA SecurID Breach 2011 Compromise of authentication technology used throughout government and defense sectors. Lockheed Martin Attack 2011 Attackers leveraged information obtained from the RSA breach to target one of the largest U.S. defense contractors.

