A DoD-mandated certification program focused on third-party verification of contractors’ implementation of cybersecurity controls. CMMC ensures that Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) are protected in alignment with DFARS 252.204‑7012 and NIST 800‑171 requirements. Launched via the 32 CFR Part 170 Final Rule on October 16, 2024, it mandates certification for organizations handling CUI to qualify for DoD contracts.