Governance Briefing — DoD releases CMMC Version 1.0 for defense contractors
On 31 January 2020 the U.S. Department of Defense published Cybersecurity Maturity Model Certification (CMMC) Version 1.0, setting a five-tier certification path that contractors must meet to handle controlled unclassified information.
The U.S. Department of Defense released the Cybersecurity Maturity Model Certification (CMMC) Version 1.0 on 31 January 2020. The framework consolidates NIST SP 800-171 controls with additional practices across five maturity levels, requiring third-party certification for defense industrial base contractors that handle Controlled Unclassified Information (CUI) or Federal Contract Information.
Program managers and supply-chain leads should map existing security controls to the CMMC practices, identify required level targets by contract type, and prepare for third-party assessments that become gating requirements in defense solicitations.
Continue in the Governance pillar
Return to the hub for curated research and deep-dive guides.
Latest guides
-
Public-Sector Governance Alignment Playbook — Zeph Tech
Align OMB Circular A-123, GAO Green Book, OMB M-24-10 AI guidance, EU public sector directives, and UK Orange Book with digital accountability, risk management, and service…
-
Third-Party Governance Control Blueprint — Zeph Tech
Deliver OCC, Federal Reserve, PRA, EBA, DORA, MAS, and OSFI third-party governance requirements through board reporting, lifecycle controls, and resilience evidence.
-
Governance, Risk, and Oversight Playbook — Zeph Tech
Operationalise board-level governance, risk oversight, and resilience reporting aligned with Basel Committee principles, ECB supervisory expectations, U.S. SR 21-3, and OCC…




