Blog
CMMC v1.0 vs. CMMC 2.0 - What's the Difference?
February 5, 2024|CMMC, Compliance
The Cybersecurity Maturity Model Certification (CMMC) framework has undergone significant changes from its original version (CMMC v1.0) to the revised version (CMMC v2.0). These changes were made in response to feedback from industry stakeholders and to streamline the implementation process for defense contractors while still ensuring the protection of Controlled Unclassified Information (CUI) within the Defense Industrial Base (DIB). Here's a summary of the key differences between CMMC v1.0 and CMMC v2.0:
Levels of Certification
- CMMC v1.0: Introduced a model with five levels of certification, each with a set of progressively more stringent cybersecurity practices and processes. These levels ranged from basic cyber hygiene to advanced cybersecurity capabilities.
- CMMC v2.0: Simplified the model to three levels, effectively condensing and reorganizing the original five levels. Level 1 remains focused on basic cyber hygiene, Level 2 aligns closely with NIST SP 800-171 and serves as the primary level for protecting CUI, and Level 3 is designed for reducing the risk of Advanced Persistent Threats (APTs) with more advanced cybersecurity practices.
Assessment Requirements
- CMMC v1.0: Required third-party assessments for most levels to verify the implementation of the necessary cybersecurity practices and processes.
- CMMC v2.0: Introduces a more tailored approach to assessments. Level 1 allows for self-assessments, Level 2 (which covers the majority of contractors handling CUI) requires third-party assessments for critical national security information and allows for self-assessments in less critical areas, and Level 3 requires government-led assessments. This change aims to reduce the compliance burden on smaller contractors and streamline the certification process.
Practices and Processes
- CMMC v1.0: Included a total of 171 practices across five levels, with additional processes aimed at institutionalizing cybersecurity practices at the higher levels.
- CMMC v2.0: Streamlines practices to eliminate redundancies and align more closely with NIST SP 800-171, reducing the total number of practices, especially at the intermediate levels. The focus on processes has been adjusted to emphasize the maturity of cybersecurity practices at higher levels.
Flexibility and Waivers
- CMMC v1.0: Offered little in the way of flexibility for contractors to deviate from the specified requirements.
- CMMC v2.0: Provides a mechanism for waivers in certain circumstances, offering some flexibility for contractors facing unique challenges or when working on specific types of contracts. This approach acknowledges the diverse nature of the defense industrial base and the varying levels of cyber threat across different contracts.
Overall Goals
Both CMMC v1.0 and v2.0 aim to enhance the cybersecurity posture of the defense supply chain. However, CMMC v2.0 seeks to achieve this goal in a way that is more accessible and less burdensome for small and medium-sized enterprises (SMEs), without compromising the security of CUI. The adjustments made in CMMC v2.0 reflect a balancing act between maintaining rigorous cybersecurity standards and acknowledging the practical implementation challenges faced by contractors, particularly those with limited resources.
The transition from CMMC v1.0 to v2.0 demonstrates the DoD's willingness to adapt and refine its approach based on stakeholder feedback and the evolving cybersecurity landscape.
Additional Information
On December 26, 2023, the Department of Defense published for comment a proposed rule for the Cybersecurity Maturity Model Certification (CMMC) 2.0 program at https://www.regulations.gov/docket/DOD-2023-OS-0063
Dept. of Defense CIO CMMC Resources - https://dodcio.defense.gov/CMMC/Resources/