{"id":137,"date":"2025-06-09T21:04:19","date_gmt":"2025-06-09T21:04:19","guid":{"rendered":"https:\/\/myauditiq.com\/?page_id=137"},"modified":"2025-06-11T12:43:23","modified_gmt":"2025-06-11T12:43:23","slug":"faqs","status":"publish","type":"page","link":"https:\/\/myauditiq.com\/?page_id=137","title":{"rendered":"FAQs"},"content":{"rendered":"\n<p class=\"has-contrast-color has-text-color has-link-color wp-elements-8cea5d9d48b41de1254b8b71caba1417\">The Cybersecurity Maturity Model Certification (CMMC) is a framework developed by the U.S. Department of Defense (DoD) to enhance the cybersecurity posture of contractors handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p class=\"has-large-font-size\"><strong>Why Do You Need to Do CMMC?<\/strong><\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>Required for DoD Contracts<\/strong> \u2013 Any organization that wants to bid on DoD contracts must meet the documented CMMC requirements.<\/li>\n\n\n\n<li><strong>Protect Sensitive Information<\/strong> \u2013 Ensure that you follow best cybersecurity practices to safeguard FCI and CUI data from cyber threats.<\/li>\n\n\n\n<li><strong>Competitive Advantage<\/strong> \u2013 Companies with the appropriate, and higher, CMMC certification level can access more contracts and demonstrate cybersecurity maturity to partners and customers.<\/li>\n\n\n\n<li><strong>Regulatory Compliance<\/strong> \u2013 CMMC aligns with existing regulations like NIST 800-171, helping you meet or exceed broader cybersecurity obligations.<\/li>\n\n\n\n<li><strong>Risk Reduction<\/strong> \u2013 Reduces your risk of cyber incidents that could lead to financial loss, reputational damage, or national security threats.<\/li>\n<\/ol>\n\n\n\n<p class=\"has-large-font-size\"><strong>Which CMMC level is right for you?<\/strong><\/p>\n\n\n\n<p><strong>Federal Contract Information (FCI)<\/strong> is information provided by or generated for the U.S. government under a contract that <strong>is not intended for public release<\/strong>. It includes data related to contract performance but does <strong>not<\/strong> include publicly available information.<\/p>\n\n\n\n<p><strong>Why Is FCI Important?<\/strong><\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>CMMC Compliance<\/strong> \u2013 If your company is limited to FCI, you must comply with <strong>CMMC Level 1<\/strong> security requirements.<\/li>\n\n\n\n<li><strong>Basic Cybersecurity Protections<\/strong> \u2013 Organizations must implement <strong>17 basic cybersecurity practices,<\/strong> as defined by <strong>FAR 52.204-21,<\/strong> to safeguard FCI from unauthorized access.<\/li>\n\n\n\n<li><strong>Entry Requirement for DoD Contractors<\/strong> \u2013 If your company currently contracts with the DoD, you must secure Level One certification in 2025 to maintain existing contracts or bid on new DoD opportunities.<\/li>\n<\/ol>\n\n\n\n<p><strong>Controlled Unclassified Information (CUI)<\/strong> is government-created or owned information that requires safeguarding or dissemination controls under federal regulations but is <strong>not classified<\/strong>.<\/p>\n\n\n\n<p class=\"has-medium-font-size\"><strong>Why Is CUI Important?<\/strong><\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>Regulatory Requirement<\/strong> \u2013 Organizations handling CUI must comply with security standards like <strong>NIST 800-171<\/strong> and require <strong>CMMC Level 2<\/strong>.<\/li>\n\n\n\n<li><strong>National Security &amp; IP Protection<\/strong> \u2013 CUI includes sensitive data &nbsp;and financial records that would potentially pose national security risks, if exposed.<\/li>\n\n\n\n<li><strong>DoD Contracting Requirement<\/strong> \u2013 If your company contracts with the &nbsp;US <strong>DoD or is planning to do so,<\/strong>. protecting CUI is mandatory to qualify for contracts.<\/li>\n<\/ol>\n\n\n\n<p><strong>Examples of CUI<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Technical drawings and schematics<\/li>\n\n\n\n<li>Export-controlled research (ITAR, EAR)<\/li>\n\n\n\n<li>Law enforcement reports<\/li>\n\n\n\n<li>Critical infrastructure details<\/li>\n<\/ul>\n\n\n\n<p class=\"has-large-font-size\"><strong>What are the requirements of each level?<\/strong><\/p>\n\n\n\n<p><strong>CMMC 2.0 Levels &amp; Requirements<\/strong><\/p>\n\n\n\n<p><strong>\ud83d\udd39 Level 1: Foundational<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Who Needs It?<\/strong> DoD Contractors that handle <strong>Federal Contract Information (FCI)<\/strong> but dot <strong>not<\/strong> have visibility to Controlled Unclassified Information (CUI).<\/li>\n\n\n\n<li><strong>Requirements:<\/strong><\/li>\n\n\n\n<li><strong>17 security practices<\/strong> from <strong>FAR 52.204-21<\/strong><\/li>\n\n\n\n<li>Includes <strong>basic cybersecurity hygiene<\/strong> (e.g., using strong passwords, antmalware, and limiting access to contractor systems)<\/li>\n\n\n\n<li><strong>Self-assessment<\/strong> and submission required <strong>annually<\/strong><\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>Level 2: Advanced <em>(Aligned with NIST 800-171)<\/em><\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Who Needs It?<\/strong> Contractors with access to &nbsp;<strong>Controlled Unclassified Information (CUI)<\/strong><\/li>\n\n\n\n<li><strong>Requirements:<\/strong><\/li>\n\n\n\n<li><strong>110 security practices<\/strong> from <strong>NIST SP 800-171<\/strong><\/li>\n\n\n\n<li>Includes <strong>access controls, encryption, multi-factor authentication (MFA), and incident response<\/strong><\/li>\n\n\n\n<li><strong>Third-party certification required<\/strong> every <strong>3 years<\/strong> for <strong>prioritized<\/strong> contracts<\/li>\n\n\n\n<li><strong>Self-assessment<\/strong> required <strong>annually<\/strong> for <strong>non-prioritized<\/strong> contracts<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p><strong>\ud83d\udd39 Level 3: Expert <em>(Aligned with NIST 800-172)<\/em><\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Who Needs It?<\/strong> Contractors with access to to <strong>CUI critical to national security<\/strong><\/li>\n\n\n\n<li><strong>Requirements:<\/strong><\/li>\n\n\n\n<li><strong>110+ security practices<\/strong> from <strong>NIST SP 800-171<\/strong> <strong>+ additional NIST 800-172 controls<\/strong><\/li>\n\n\n\n<li>Focuses on <strong>advanced threat detection, zero trust, and resilience against nation-state threats<\/strong><\/li>\n\n\n\n<li><strong>DoD-led government assessment<\/strong> every <strong>3 years<\/strong><\/li>\n<\/ul>\n\n\n\n<p class=\"has-large-font-size\"><strong>Why Is CMMC Certification Important?<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Mandatory for DoD Contracts<\/strong> \u2013 Determines if a company is capable of bidding and fulfilling contracts.<\/li>\n\n\n\n<li><strong>Protects National Security<\/strong> \u2013 Enhances cybersecurity resilience in the DoD supply chain.<\/li>\n\n\n\n<li><strong>Competitive Advantage<\/strong> \u2013 Timely Certification strengthens reputation within the prime contractors and government agency ecosystem<a href=\"#_msocom_1\">[RP1]<\/a>&nbsp;.<\/li>\n<\/ul>\n\n\n\n<p>What does AuditIQ offer?<\/p>\n\n\n\n<p>A <strong>CMMC SaaS based Compliance Platform<\/strong> designed to help DoD contractors <strong>achieve CMMC Level 1 compliance<\/strong> and <strong>prepare for Level 2 certification<\/strong>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Cybersecurity Maturity Model Certification (CMMC) is a framework developed by the U.S. Department of Defense (DoD) to enhance the cybersecurity posture of contractors handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Why Do You Need to Do CMMC? Which CMMC level is right for you? Federal Contract Information (FCI) is information provided [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-137","page","type-page","status-publish","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.3.1 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>FAQs -<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/myauditiq.com\/?page_id=137\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FAQs -\" \/>\n<meta property=\"og:description\" content=\"The Cybersecurity Maturity Model Certification (CMMC) is a framework developed by the U.S. Department of Defense (DoD) to enhance the cybersecurity posture of contractors handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Why Do You Need to Do CMMC? Which CMMC level is right for you? Federal Contract Information (FCI) is information provided [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/myauditiq.com\/?page_id=137\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-11T12:43:23+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/myauditiq.com\/?page_id=137\",\"url\":\"https:\/\/myauditiq.com\/?page_id=137\",\"name\":\"FAQs -\",\"isPartOf\":{\"@id\":\"https:\/\/myauditiq.com\/#website\"},\"datePublished\":\"2025-06-09T21:04:19+00:00\",\"dateModified\":\"2025-06-11T12:43:23+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/myauditiq.com\/?page_id=137#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/myauditiq.com\/?page_id=137\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/myauditiq.com\/?page_id=137#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/myauditiq.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"FAQs\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/myauditiq.com\/#website\",\"url\":\"https:\/\/myauditiq.com\/\",\"name\":\"myauditiq.com\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/myauditiq.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/myauditiq.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/myauditiq.com\/#organization\",\"name\":\"MyAuditIQ\",\"url\":\"https:\/\/myauditiq.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/myauditiq.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/myauditiq.com\/wp-content\/uploads\/2025\/04\/AuditIQ_logo_color_300dpi-1-scaled.png\",\"contentUrl\":\"https:\/\/myauditiq.com\/wp-content\/uploads\/2025\/04\/AuditIQ_logo_color_300dpi-1-scaled.png\",\"width\":2560,\"height\":743,\"caption\":\"MyAuditIQ\"},\"image\":{\"@id\":\"https:\/\/myauditiq.com\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"FAQs -","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/myauditiq.com\/?page_id=137","og_locale":"en_US","og_type":"article","og_title":"FAQs -","og_description":"The Cybersecurity Maturity Model Certification (CMMC) is a framework developed by the U.S. Department of Defense (DoD) to enhance the cybersecurity posture of contractors handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Why Do You Need to Do CMMC? Which CMMC level is right for you? Federal Contract Information (FCI) is information provided [&hellip;]","og_url":"https:\/\/myauditiq.com\/?page_id=137","article_modified_time":"2025-06-11T12:43:23+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/myauditiq.com\/?page_id=137","url":"https:\/\/myauditiq.com\/?page_id=137","name":"FAQs -","isPartOf":{"@id":"https:\/\/myauditiq.com\/#website"},"datePublished":"2025-06-09T21:04:19+00:00","dateModified":"2025-06-11T12:43:23+00:00","breadcrumb":{"@id":"https:\/\/myauditiq.com\/?page_id=137#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/myauditiq.com\/?page_id=137"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/myauditiq.com\/?page_id=137#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/myauditiq.com\/"},{"@type":"ListItem","position":2,"name":"FAQs"}]},{"@type":"WebSite","@id":"https:\/\/myauditiq.com\/#website","url":"https:\/\/myauditiq.com\/","name":"myauditiq.com","description":"","publisher":{"@id":"https:\/\/myauditiq.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/myauditiq.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/myauditiq.com\/#organization","name":"MyAuditIQ","url":"https:\/\/myauditiq.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/myauditiq.com\/#\/schema\/logo\/image\/","url":"https:\/\/myauditiq.com\/wp-content\/uploads\/2025\/04\/AuditIQ_logo_color_300dpi-1-scaled.png","contentUrl":"https:\/\/myauditiq.com\/wp-content\/uploads\/2025\/04\/AuditIQ_logo_color_300dpi-1-scaled.png","width":2560,"height":743,"caption":"MyAuditIQ"},"image":{"@id":"https:\/\/myauditiq.com\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/myauditiq.com\/index.php?rest_route=\/wp\/v2\/pages\/137","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/myauditiq.com\/index.php?rest_route=\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/myauditiq.com\/index.php?rest_route=\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/myauditiq.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/myauditiq.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=137"}],"version-history":[{"count":3,"href":"https:\/\/myauditiq.com\/index.php?rest_route=\/wp\/v2\/pages\/137\/revisions"}],"predecessor-version":[{"id":165,"href":"https:\/\/myauditiq.com\/index.php?rest_route=\/wp\/v2\/pages\/137\/revisions\/165"}],"wp:attachment":[{"href":"https:\/\/myauditiq.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=137"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}