So, you’ve got a basic understanding of CMMC. Now the big question: Does it apply to your business? The answer depends on whether you work with the U.S. Department of Defense (DoD) and what kind of information you handle. Let’s break it down with some real-world examples.
Who Needs CMMC?
If your business does any of the following, CMMC probably applies to you:
- You sell products or services directly to the DoD. Example: A company that manufactures replacement parts for military vehicles.
- You’re a subcontractor for a company that works with the DoD. Example: A small IT firm providing help desk support for a major defense contractor.
- You handle certain types of government data. Specifically, if you work with Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) (more on that in a moment), CMMC matters.
If none of that applies to you, you probably don’t need to worry about CMMC. But if you’re unsure, keep reading.
What Kind of Information Triggers CMMC Requirements?
CMMC compliance isn’t about just working with the DoD—it’s about the type of data you handle. The DoD deals with two key categories of information:
- Federal Contract Information (FCI)
- This is basic contract-related information that isn’t meant for public release. It includes things like:
- Internal DoD policies related to contracts
- Project schedules
- Non-public pricing details
- CMMC Level 1 (Foundational) applies if you handle FCI. You can self-certify compliance, meaning you don’t need an external audit.
Example: A logistics company that coordinates military supply shipments but doesn’t deal with sensitive engineering specs.
- Controlled Unclassified Information (CUI)
- This is sensitive, but not classified, government data that requires protection. Examples include:
- Technical drawings for military equipment
- Blueprints for DoD buildings
- Research data on new defense technologies
- CMMC Level 2 (Advanced) applies if you handle CUI. This requires a more detailed cybersecurity program and an external assessment.
Example: A software company that builds applications to help track military inventory. Since their software stores CUI, they need to meet Level 2 requirements.
What About Higher Levels?
CMMC Level 3 (Expert) is for companies that handle the most sensitive types of CUI. These are usually major defense contractors working on top-tier projects.
Example: A cybersecurity firm contracted to test the security of DoD networks. Since their work involves critical defense infrastructure, they must meet the highest security standards.
How to Figure Out if CMMC Applies to You
If you’re still unsure, here’s a simple process to follow:
- Check your contracts. If you have a government contract, look for terms like “FCI” or “CUI.”
- Ask your prime contractor. If you’re a subcontractor, your main contractor should know what level of CMMC applies.
- Look at your data. If your company deals with engineering, logistics, IT, or research for the DoD, you’re probably handling FCI or CUI.
The Bottom Line
If your business is part of the DoD supply chain and handles sensitive government data, CMMC applies to you. Understanding where you fit in the framework helps you prepare for compliance and avoid surprises down the road.
Next up in the CMMC for n00bs series: What If I Don’t Get Certified?



