Skip to main content
4470 Moline Martin Road Millbury, OH 43447

Cybersecurity Maturity Model Certification (CMMC) Compliance

Levison Enterprises is working toward meeting the applicable Cybersecurity Maturity Model Certification (CMMC) requirements. As an electronic contract manufacturer serving the defense industry, we understand the importance of protecting the sensitive information entrusted to us by our customers.

Our established security practices, document controls, and commitment to protecting customer information provide a strong foundation for meeting applicable CMMC requirements. We continue to strengthen these practices to safeguard Controlled Unclassified Information (CUI) and support the cybersecurity requirements of our Department of Defense (DoD) customers.

What Types of Manufacturers Does the DoD Work With?

The U.S. Department of Defense (DoD) relies on a broad network of manufacturers, suppliers, contractors, and other organizations to support its mission. This network is known as the Defense Industrial Base (DIB).

The DIB includes organizations of all sizes, from small and midsize businesses to some of the world’s largest corporations. Companies may work directly with the DoD as prime contractors or support defense programs as subcontractors and suppliers throughout the defense supply chain.

Military helicopter used in the defense industry

Manufacturers within the DIB produce a wide range of products and components, including highly specialized defense equipment and commercial products and technologies that support military applications. Electronic manufacturers play an important role in this supply chain, producing assemblies, components, and other electronic solutions used in defense systems and equipment.

For companies participating in the defense supply chain, cybersecurity is an increasingly important part of doing business. Depending on the contract and the information involved, manufacturers may be required to meet specific cybersecurity requirements, including applicable CMMC requirements for protecting Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).

Who in the Supply Chain Needs CMMC Compliance?

CMMC requirements apply to certain Department of Defense (DoD) contractors and subcontractors, based on the requirements of their specific contracts. The contract will identify the applicable CMMC level and the information that must be protected, such as Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).

Not every organization in the defense supply chain will require the same level of CMMC compliance. The CMMC requirements that apply to your organization depend on the contracts you perform and the type of information your organization handles, stores, or transmits.

Manufacturers may also serve commercial customers or customers outside the DoD. Those customers do not automatically make the organization subject to CMMC requirements. CMMC requirements apply when they are included in an applicable DoD contract or flow down through the defense supply chain.

Defining Your CMMC Scope

For manufacturers handling FCI or CUI, understanding which systems, assets, and processes are involved can be an important part of CMMC preparation. A clearly defined assessment scope can help an organization focus its cybersecurity efforts and avoid unnecessarily bringing unrelated systems or information into the CMMC environment.

For an electronic manufacturer serving both defense and commercial customers, properly defining the CMMC scope can help focus resources on the systems and information that are actually subject to the applicable requirements.

What Is CMMC?

The Cybersecurity Maturity Model Certification (CMMC) program establishes a framework for assessing and verifying that organizations in the Department of Defense (DoD) supply chain have implemented the cybersecurity requirements applicable to their contracts.

CMMC requirements apply to contractors and subcontractors when they are included in an applicable DoD contract or flow down through the defense supply chain. The specific requirements depend on the contract and the type of information an organization handles.

CMMC is designed to help protect sensitive information within the Defense Industrial Base (DIB), including Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

1. Federal Contract Information (FCI)

FCI is information provided by or generated for the Government under a contract to develop or deliver a product or service to the Government that is not intended for public release.

2. Controlled Unclassified Information (CUI)

CUI is information that requires safeguarding or dissemination controls pursuant to and consistent with applicable laws, regulations, and government-wide policies.

How Does CMMC Work?

The CMMC framework has three levels, and the level applicable to an organization is determined by the requirements of its DoD contract.

Level 1

Basic protection for FCI with 15 security requirements.

Level 2

Protection of CUI with 110 NIST SP 800-171 security requirements.

Level 3

Enhanced protection of CUI with additional NIST SP 800-172 requirements.

CMMC Assessments

When a third-party assessment is required, a Certified Third-Party Assessment Organization (C3PAO) conducts the CMMC assessment. C3PAOs are authorized through the CMMC accreditation ecosystem to perform assessments against the applicable CMMC requirements.

The assessment process provides the DoD and organizations within the defense supply chain with greater confidence that required cybersecurity practices have been implemented and are being maintained.

Mission-Ready Projects Are Our Specialty

Levison Enterprises combines electronic manufacturing expertise with established quality and security processes to support demanding military and aerospace applications. Have a project or question about working with Levison? Speak with our team.

Speak With Our Sales Team

NIST 800-171 and CMMC

US Jet fighters have parts built by military electronic manufacturers like Levison Enterprises

The vast majority of government contractors are familiar with NIST. NIST SP 800-171 establishes the cybersecurity requirements organizations must follow to protect Controlled Unclassified Information (CUI) in nonfederal systems.

CMMC is the Department of Defense’s program for assessing and verifying that defense contractors are meeting applicable cybersecurity requirements. For organizations handling CUI, CMMC Level 2 is based on the 110 security requirements in NIST SP 800-171.

In other words, NIST SP 800-171 defines the cybersecurity requirements, while CMMC provides the assessment framework used to verify that those requirements are being met. Depending on the contract and CMMC level required, an organization may complete a self-assessment or undergo a third-party assessment.

CMMC does not replace NIST SP 800-171. It provides the DoD with a way to verify that contractors are implementing the required cybersecurity protections and maintaining compliance.

Three Levels of CMMC

CMMC does not replace NIST SP 800-171. The Cybersecurity Maturity Model Certification (CMMC) program provides a framework for assessing and verifying that defense contractors have implemented the cybersecurity requirements applicable to their DoD contracts.

For manufacturers and other organizations operating in the defense supply chain, the required CMMC level depends on the type of information involved in the contract. Organizations that handle Controlled Unclassified Information (CUI) will generally need to meet Level 2 or Level 3 requirements.

Level 1: Basic Protection

Level 1 applies to organizations that handle Federal Contract Information (FCI) but do not handle CUI under the applicable contract.

The level includes 15 basic safeguarding requirements from FAR 52.204-21. These requirements cover fundamental cybersecurity practices such as controlling access to systems, identifying and authenticating users, protecting system communications, and managing information on systems.

Level 1 organizations complete an annual self-assessment to demonstrate compliance. A third-party certification assessment is not required for Level 1.

Level 2: Protection of CUI

Level 2 is the primary CMMC level for many defense manufacturers that handle Controlled Unclassified Information. It incorporates the 110 security requirements in NIST SP 800-171 Revision 2.

For a manufacturer like Levison, CUI could be associated with information received or created in connection with a DoD contract, depending on the specific contract and information involved. Meeting Level 2 means having the required security controls in place and being able to demonstrate their implementation through appropriate policies, procedures, documentation, and other evidence.

Depending on the contract, Level 2 may require either a self-assessment or an assessment by a Certified Third-Party Assessment Organization (C3PAO). Level 2 requirements also include an annual affirmation of continued compliance.

Level 3: Enhanced Protection

Level 3 is intended for organizations handling CUI associated with the highest-priority DoD programs and information. It builds on the 110 requirements of NIST SP 800-171 Revision 2 and adds 24 selected requirements from NIST SP 800-172, for a total of 134 requirements.

Level 3 adds enhanced security measures designed to address more sophisticated cyber threats. It is intended for organizations whose contracts specifically require this higher level of protection.

Level 3 assessments are conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) on a three-year cycle, with an annual affirmation of continued compliance.

Which CMMC Level Does Your Contract Require?

The CMMC level you need is determined by your DoD contract, not simply by the fact that you work in the defense industry. If your organization receives, stores, processes, or transmits FCI or CUI, understanding exactly what information your contracts involve is an important first step in determining your CMMC requirements.

For defense manufacturers, preparing for CMMC can involve more than implementing technical safeguards. Organizations may also need to review how CUI moves through their facilities and systems, establish appropriate policies and procedures, document security practices, and maintain evidence that requirements are being met.

Security Is Part of the Supply Chain

Working in the defense supply chain means cybersecurity is part of the job. For manufacturers like Levison Enterprises, CMMC compliance is about protecting the sensitive information that comes with defense contracts while demonstrating that the appropriate safeguards are actually in place.

What is Controlled Unclassified Information?

Controlled unclassified information (CUI) refers to certain types of information produced or accessed by the United States government. CUI is not considered classified information, but still must be safeguarded or disseminated in accordance with applicable laws, regulations, and government-wide policies.

Patent applications, technical defense information, and DOD critical infrastructure security information are all examples of CUI.

CUI is targeted by cybercriminals because it is subject to fewer controls than classified information. The loss of aggregated CUI is one of the most serious threats to national security.

What is the Difference Between CUI and FCI?

In addition to protecting CUI, CMMC is also designed to safeguard Federal Contract Information (FCI.) FCI refers to information provided by or generated for the government under contract that is not intended for public release, as well as enhanced security for controlled unclassified data generated during contracted activities.

All CUI is considered FCI. But not all FCI is CUI.  Examples of FCI would be emails, policies, contract performance reports, organizational charts, and process documentation.

FCI is considered less sensitive and requires less cybersecurity protection, but it is just as important.

Why Electronic Contract Manufacturers are Concerned about Protecting CUI

Cybersecurity breaches—unauthorized access to networks, applications, data, and other systems—are a global concern. But they can have even bigger ramifications for your business, specifically loss of contracts and the sizable profits that come with them.

CUI can be used for malicious purposes such as technical, economic, political, or military agendas by the threat actor. Many of the attacks are retaliatory in nature, as a result of sanctions, or are targeted at industrial espionage.

A CMMC electronic contract manufacturer is more resilient to cyber-attacks from both outside and inside your organization. CUI will be strongly protected from other countries, as well as a rogue employee. Businesses that attain and support CMMC compliance have proven their willingness and ability to protect sensitive data, making them a valuable electronic contract manufacturing partner.

Why is CMMC Important?

Intellectual property theft is a severe problem in the manufacturing industry. Cybercrime is predicted to cost the global economy around $600 billion every year. By relying on a large network of contractors to carry out its purpose, the DoD is entrusting crucial data to each of them. A cybersecurity breach can lead to a slew of serious problems that may even endanger human life.

The DoD recognizes the burden and disproportionate danger cybercrime imposes on its subcontractor base, many of which are tiny firms with a fraction of the resources of their bigger counterparts. The DoD released CMMC to enable the adoption of best practices in cybersecurity with a “defense in depth” strategy throughout DoD’s entire global contractor base.

Benefits of CMMC

For defense contractors and manufacturers, CMMC provides a structured way to protect sensitive information and demonstrate that appropriate cybersecurity practices are in place. Compliance can help organizations strengthen their cybersecurity, protect Controlled Unclassified Information (CUI), and reduce cybersecurity risks throughout the U.S. Defense Industrial Base (DIB).

Other benefits of CMMC compliance include:

  • Strengthening cybersecurity practices to better protect systems and sensitive information.
  • Reducing the risk of cyberattacks and data breaches by implementing required security controls.
  • Improving incident response and recovery capabilities when cybersecurity incidents occur.
  • Protecting CUI and other sensitive information as it moves through the defense supply chain.
  • Demonstrating cybersecurity readiness to DoD customers and other organizations within the defense supply chain.
  • Maintaining eligibility for contracts that require CMMC compliance.

For companies working in the defense industry, CMMC compliance can also provide a competitive advantage. Demonstrating that your organization has implemented the required cybersecurity protections can help position your company for opportunities that require CMMC compliance.

For an electronic manufacturer like Levison Enterprises, cybersecurity is an important part of supporting customers throughout the defense supply chain. Understanding your contract requirements and implementing the appropriate CMMC practices can help protect sensitive information while keeping your organization prepared for DoD contracting opportunities.

CMMC at Levison Enterprises

Exceptional Quality Every Time with Levison Enterprises

Levison Enterprises is an electronic contract manufacturer (ECM) committed to quality, security, and the protection of the sensitive information entrusted to us by our customers. Many of the cybersecurity practices required under CMMC were already incorporated into our existing processes and best practices.

A key part of our approach is document control and understanding how sensitive information moves through our organization. We maintain comprehensive Data Flow Diagrams (DFDs) to identify where Controlled Unclassified Information (CUI) is stored, processed, and transmitted. We also maintain documentation detailing when, where, and how applicable security controls are implemented.

Levison Enterprises continues to strengthen its cybersecurity practices and meet the requirements applicable to our defense-related work. By maintaining appropriate safeguards for CUI and other sensitive information, we help reduce cybersecurity risks throughout the defense supply chain and protect the information entrusted to us by our government and defense-industry customers.

Our commitment to security is part of our commitment to being a trusted electronic manufacturing partner for the defense industry.