CMMC — Cybersecurity Maturity Model Certification
CMMC readiness consulting for defence suppliers: FCI/CUI scoping, NIST SP 800-171 gap assessment, SSP preparation and SPRS self-assessment support.
CMMC readiness consulting for defence suppliers: FCI/CUI scoping, NIST SP 800-171 gap assessment, SSP preparation and SPRS self-assessment support.
The Cybersecurity Maturity Model Certification (CMMC) is the U.S. Department of Defense framework for verifying that contractors and subcontractors handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) implement an appropriate set of cybersecurity controls. Level 2 uses NIST SP 800-171 Rev. 2; the Level 3 model adds selected NIST SP 800-172 requirements. The programme defines self-assessment, C3PAO and DIBCAC assessment routes. Their current procurement use is subject to the suspension described below. Nesil provides readiness consulting and does not issue CMMC certificates.
Reviewed 12 September 2026. The 13 July 2026 announcement suspended the Phase II transition and subsequent implementation milestones. Phase I self-assessments and DFARS 252.204-7012 information-protection obligations remain in effect.
During the suspension, procurement requirements may specify Level 1 (Self) or Level 2 (Self), but not Level 2 (C3PAO) or Level 3 (DIBCAC). Review solicitation amendments and contract modifications with the contracting officer. Do not treat 10 November 2026 as a confirmed Phase II start date.
Sources: official CMMC announcement, implementation memorandum (PDF) and DFARS 252.204-7021 assessment status definitions.
CMMC Level 2 controls are drawn from NIST SP 800-171. Existing ISO/IEC 27001 policies and control evidence can support readiness. We map that evidence to the applicable requirements and identify remaining gaps; ISO 27001 certification does not automatically establish CMMC compliance.
Nesilgrup Bilişim Teknoloji Ticaret A.Ş., as a TSE-approved Class A Penetration Testing Company and CREST member, delivers penetration testing and cybersecurity services in line with national and international standards. Our team is made up of OSCP-certified experts. TSE-STF-065 | CREST Member | CISSP-Certified Experts | ISO/IEC 27001 & ISO/IEC 27701
© 2026 Nesilgrup Bilişim Teknoloji Ticaret A.Ş. All rights reserved.