CMMC (Cybersecurity Maturity Model Certification) is the US Department of Defense framework verifying that the defense industrial base - contractors and subcontractors - protects Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). It's built largely on NIST SP 800-171 (plus advanced practices at the top level) and uses tiered maturity levels, with independent third-party assessment at higher levels. It doesn't state “penetration test” as one universal mandate, but its security-assessment requirements and the intent to verify controls actually work mean testing is a standard, expected way to demonstrate control effectiveness. Who complies: any DIB business handling that information under DoD contracts - the requirement flows down through subcontracts. Confirm your target level; it dictates the controls and the validation depth. Detail below; related is NIST CSF.
// 01 What CMMC is
CMMC stands for Cybersecurity Maturity Model Certification - a framework created by the US Department of Defense to verify that companies in the defense industrial base (the contractors and subcontractors that make up the defense supply chain) adequately protect sensitive government information, in particular Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). The key shift: rather than relying on a company's own self-attestation alone, CMMC introduces defined levels of maturity and, for higher levels, independent third-party assessment against a set of security practices drawn largely from NIST SP 800-171. The point is to give the DoD assurance that its suppliers meet a consistent, verifiable standard as a condition of holding relevant contracts - moving cybersecurity from a promise to a checked prerequisite.
// 02 The NIST SP 800-171 basis & where testing fits
CMMC is built on the security requirements in NIST SP 800-171 (with additional practices at the highest level), and its whole intent is to verify that safeguards actually work, not just exist on paper - the same “prove it” philosophy behind the NIST CSF. So while CMMC doesn't contain a single universal control that says the words “penetration test,” its higher levels and 800-171 basis include security-assessment requirements that testing is used to satisfy, and organisations pursuing certification commonly use penetration testing to validate that their controls protect CUI effectively. An organisation should confirm the exact requirement for its target level - but in practice penetration testing is a standard and expected way to demonstrate the assessed controls are effective, and is widely treated as part of preparing for and maintaining certification, exactly as with other framework requirements.
// 03 The levels & who complies
Foundational
Basic safeguarding of Federal Contract Information - a set of foundational practices.
Advanced
Aligns with the full NIST SP 800-171 requirements for CUI; involves independent assessment.
Expert
Adds further advanced practices against the most capable threats.
Who complies
Any DIB contractor/subcontractor handling CUI/FCI - the requirement flows down through subcontracts.
CMMC is structured into maturity levels of increasing rigour: the lowest covers basic FCI safeguarding, the middle aligns with the full 800-171 requirements for CUI and involves independent assessment, and the highest adds advanced practices against the most capable threats. The higher the level, the more comprehensive the practices and the more formal the assessment. It applies across a very wide range of businesses - from large prime contractors to small specialist suppliers deep in the chain - because the requirement flows down through subcontracts. The level a company must meet depends on the sensitivity of the information it handles; any business wanting to win or keep defense-related contracts involving that information must achieve and maintain the required level.
// 04 How testing supports certification
Because the level dictates both the controls to implement and the depth of validation, the practical path is: determine your target level, implement the corresponding 800-171-based practices, and then validate that they actually protect CUI. Penetration testing does the validation work - it demonstrates that the safeguards resist real attack rather than merely appearing in a policy document, generating the evidence assessors and the certification process expect. Findings feed a remediation plan and are retested to closure, and the report can be mapped to the relevant practices to make the evidence explicit. Non-US readers should note CMMC is US-DoD-specific, but the pattern - a maturity model built on a control catalogue, validated by testing - mirrors how GCC regulators like the NCA operate. Engagements follow our methodology; scope carefully around the CUI environment as our scoping guide describes.
// 05 Frequently asked questions
Does CMMC require penetration testing?
There's no single universal control that says the words "penetration test," but CMMC's higher levels and its NIST SP 800-171 basis include security-assessment requirements that testing is used to satisfy, and organisations pursuing certification commonly use testing to validate that controls protect CUI effectively. The intent is to verify safeguards actually work, not just exist. Confirm the exact requirement for your target level, but testing is a standard, expected way to demonstrate control effectiveness.
What is CMMC?
Cybersecurity Maturity Model Certification - a US Department of Defense framework verifying that companies in the defense industrial base (contractors and subcontractors) adequately protect sensitive government information, especially Controlled Unclassified Information and Federal Contract Information. Rather than self-attestation alone, it uses defined maturity levels and, at higher levels, independent third-party assessment against practices drawn largely from NIST SP 800-171, as a condition of holding relevant contracts.
Who needs to comply with CMMC?
Organisations in the US defense industrial base - contractors and subcontractors handling sensitive DoD information such as CUI or FCI on defense contracts. It spans large primes to small suppliers deep in the chain, because the requirement flows down through subcontracts. The level a company must meet depends on the sensitivity of the information it handles. Any business wanting to win or keep such contracts must achieve and maintain the required level.
What are the CMMC levels?
Maturity levels of increasing rigour: the lowest covers basic safeguarding of Federal Contract Information with foundational practices; the middle aligns with the full NIST SP 800-171 requirements for protecting CUI and involves independent assessment; the highest adds advanced practices against the most capable threats. The higher the level, the more comprehensive the practices and formal the assessment. Determine which level your contracts demand - it dictates both controls and validation depth.
// 06 Related reading
- NIST CSF requirements and requirements by framework.
- Scoping a test around the CUI environment.
- Remediation plan and retesting to closure.