Cybersecurity Maturity Model Certification 2.0 Level 2
US Department of Defense cybersecurity certification framework for the defense industrial base. Level 2 aligns to NIST SP 800-171 Rev 2 (110 security requirements) across 14 domains: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity. Required for contractors handling Controlled Unclassified Information (CUI). Third-party assessment (C3PAO) mandatory.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| AC | Access Control | |
| AT | Awareness and Training | |
| AU | Audit and Accountability | |
| CA | Security Assessment | |
| CM | Configuration Management | |
| IA | Identification and Authentication | |
| IR | Incident Response | |
| MA | Maintenance | |
| MP | Media Protection | |
| PE | Physical Protection | |
| PS | Personnel Security | |
| RA | Risk Assessment | |
| SC | System and Communications Protection | |
| SI | System and Information Integrity |