Cybersecurity Maturity Model Certification (CMMC) Compliance
Levison Enterprises is working toward meeting the applicable Cybersecurity Maturity Model Certification (CMMC) requirements. As an electronic contract manufacturer serving the defense industry, we understand the importance of protecting the sensitive information entrusted to us by our customers.
Our established security practices, document controls, and commitment to protecting customer information provide a strong foundation for meeting applicable CMMC requirements. We continue to strengthen these practices to safeguard Controlled Unclassified Information (CUI) and support the cybersecurity requirements of our Department of Defense (DoD) customers.
Table of Contents
- What Types of Manufacturers Does the DoD Work With?
- Who in the Supply Chain Needs to Have the CMMC Compliance?
- What is CMMC?
- NIST800-171 and CMMC
- Levels of CMMC
- What is Controlled Unclassified Information?
- What is the Difference Between CUI and FCI?
- Why Electronic Contact Manufacturers are Concerned About Protecting CUI
- Why is CMMC Important?
- Benefits of CMMC Compliance
- CMMC at Levison Enterprises
What Types of Manufacturers Does the DoD Work With?
The U.S. Department of Defense (DoD) relies on a broad network of manufacturers, suppliers, contractors, and other organizations to support its mission. This network is known as the Defense Industrial Base (DIB).
The DIB includes organizations of all sizes, from small and midsize businesses to some of the world’s largest corporations. Companies may work directly with the DoD as prime contractors or support defense programs as subcontractors and suppliers throughout the defense supply chain.

Manufacturers within the DIB produce a wide range of products and components, including highly specialized defense equipment and commercial products and technologies that support military applications. Electronic manufacturers play an important role in this supply chain, producing assemblies, components, and other electronic solutions used in defense systems and equipment.
For companies participating in the defense supply chain, cybersecurity is an increasingly important part of doing business. Depending on the contract and the information involved, manufacturers may be required to meet specific cybersecurity requirements, including applicable CMMC requirements for protecting Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).
Who in the Supply Chain Needs CMMC Compliance?
CMMC requirements apply to certain Department of Defense (DoD) contractors and subcontractors, based on the requirements of their specific contracts. The contract will identify the applicable CMMC level and the information that must be protected, such as Federal Contract Information (FCI) or Controlled Unclassified Information (CUI).
Not every organization in the defense supply chain will require the same level of CMMC compliance. The CMMC requirements that apply to your organization depend on the contracts you perform and the type of information your organization handles, stores, or transmits.
Manufacturers may also serve commercial customers or customers outside the DoD. Those customers do not automatically make the organization subject to CMMC requirements. CMMC requirements apply when they are included in an applicable DoD contract or flow down through the defense supply chain.
Defining Your CMMC Scope
For manufacturers handling FCI or CUI, understanding which systems, assets, and processes are involved can be an important part of CMMC preparation. A clearly defined assessment scope can help an organization focus its cybersecurity efforts and avoid unnecessarily bringing unrelated systems or information into the CMMC environment.
For an electronic manufacturer serving both defense and commercial customers, properly defining the CMMC scope can help focus resources on the systems and information that are actually subject to the applicable requirements.
What Is CMMC?
The Cybersecurity Maturity Model Certification (CMMC) program establishes a framework for assessing and verifying that organizations in the Department of Defense (DoD) supply chain have implemented the cybersecurity requirements applicable to their contracts.
CMMC requirements apply to contractors and subcontractors when they are included in an applicable DoD contract or flow down through the defense supply chain. The specific requirements depend on the contract and the type of information an organization handles.
CMMC is designed to help protect sensitive information within the Defense Industrial Base (DIB), including Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
1. Federal Contract Information (FCI)
FCI is information provided by or generated for the Government under a contract to develop or deliver a product or service to the Government that is not intended for public release.
2. Controlled Unclassified Information (CUI)
CUI is information that requires safeguarding or dissemination controls pursuant to and consistent with applicable laws, regulations, and government-wide policies.
How Does CMMC Work?
The CMMC framework has three levels, and the level applicable to an organization is determined by the requirements of its DoD contract.
Level 1
Basic protection for FCI with 15 security requirements.
Level 2
Protection of CUI with 110 NIST SP 800-171 security requirements.
Level 3
Enhanced protection of CUI with additional NIST SP 800-172 requirements.
CMMC Assessments
When a third-party assessment is required, a Certified Third-Party Assessment Organization (C3PAO) conducts the CMMC assessment. C3PAOs are authorized through the CMMC accreditation ecosystem to perform assessments against the applicable CMMC requirements.
The assessment process provides the DoD and organizations within the defense supply chain with greater confidence that required cybersecurity practices have been implemented and are being maintained.
NIST 800-171 and CMMC

The vast majority of government contractors are familiar with NIST. NIST SP 800-171 establishes the cybersecurity requirements organizations must follow to protect Controlled Unclassified Information (CUI) in nonfederal systems.
CMMC is the Department of Defense’s program for assessing and verifying that defense contractors are meeting applicable cybersecurity requirements. For organizations handling CUI, CMMC Level 2 is based on the 110 security requirements in NIST SP 800-171.
In other words, NIST SP 800-171 defines the cybersecurity requirements, while CMMC provides the assessment framework used to verify that those requirements are being met. Depending on the contract and CMMC level required, an organization may complete a self-assessment or undergo a third-party assessment.
CMMC does not replace NIST SP 800-171. It provides the DoD with a way to verify that contractors are implementing the required cybersecurity protections and maintaining compliance.
Three Levels of CMMC
CMMC does not replace NIST SP 800-171. The Cybersecurity Maturity Model Certification (CMMC) program provides a framework for assessing and verifying that defense contractors have implemented the cybersecurity requirements applicable to their DoD contracts.
For manufacturers and other organizations operating in the defense supply chain, the required CMMC level depends on the type of information involved in the contract. Organizations that handle Controlled Unclassified Information (CUI) will generally need to meet Level 2 or Level 3 requirements.
Level 1: Basic Protection
Level 1 applies to organizations that handle Federal Contract Information (FCI) but do not handle CUI under the applicable contract.
The level includes 15 basic safeguarding requirements from FAR 52.204-21. These requirements cover fundamental cybersecurity practices such as controlling access to systems, identifying and authenticating users, protecting system communications, and managing information on systems.
Level 1 organizations complete an annual self-assessment to demonstrate compliance. A third-party certification assessment is not required for Level 1.
Level 2: Protection of CUI
Level 2 is the primary CMMC level for many defense manufacturers that handle Controlled Unclassified Information. It incorporates the 110 security requirements in NIST SP 800-171 Revision 2.
For a manufacturer like Levison, CUI could be associated with information received or created in connection with a DoD contract, depending on the specific contract and information involved. Meeting Level 2 means having the required security controls in place and being able to demonstrate their implementation through appropriate policies, procedures, documentation, and other evidence.
Depending on the contract, Level 2 may require either a self-assessment or an assessment by a Certified Third-Party Assessment Organization (C3PAO). Level 2 requirements also include an annual affirmation of continued compliance.
Level 3: Enhanced Protection
Level 3 is intended for organizations handling CUI associated with the highest-priority DoD programs and information. It builds on the 110 requirements of NIST SP 800-171 Revision 2 and adds 24 selected requirements from NIST SP 800-172, for a total of 134 requirements.
Level 3 adds enhanced security measures designed to address more sophisticated cyber threats. It is intended for organizations whose contracts specifically require this higher level of protection.
Level 3 assessments are conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) on a three-year cycle, with an annual affirmation of continued compliance.
Which CMMC Level Does Your Contract Require?
The CMMC level you need is determined by your DoD contract, not simply by the fact that you work in the defense industry. If your organization receives, stores, processes, or transmits FCI or CUI, understanding exactly what information your contracts involve is an important first step in determining your CMMC requirements.
For defense manufacturers, preparing for CMMC can involve more than implementing technical safeguards. Organizations may also need to review how CUI moves through their facilities and systems, establish appropriate policies and procedures, document security practices, and maintain evidence that requirements are being met.
Security Is Part of the Supply Chain
Working in the defense supply chain means cybersecurity is part of the job. For manufacturers like Levison Enterprises, CMMC compliance is about protecting the sensitive information that comes with defense contracts while demonstrating that the appropriate safeguards are actually in place.
What is Controlled Unclassified Information?
Controlled unclassified information (CUI) refers to certain types of information produced or accessed by the United States government. CUI is not considered classified information, but still must be safeguarded or disseminated in accordance with applicable laws, regulations, and government-wide policies.
Patent applications, technical defense information, and DOD critical infrastructure security information are all examples of CUI.
CUI is targeted by cybercriminals because it is subject to fewer controls than classified information. The loss of aggregated CUI is one of the most serious threats to national security.
What is the Difference Between CUI and FCI?
In addition to protecting CUI, CMMC is also designed to safeguard Federal Contract Information (FCI.) FCI refers to information provided by or generated for the government under contract that is not intended for public release, as well as enhanced security for controlled unclassified data generated during contracted activities.
All CUI is considered FCI. But not all FCI is CUI. Examples of FCI would be emails, policies, contract performance reports, organizational charts, and process documentation.
FCI is considered less sensitive and requires less cybersecurity protection, but it is just as important.
Why Electronic Contract Manufacturers are Concerned about Protecting CUI
Cybersecurity breaches—unauthorized access to networks, applications, data, and other systems—are a global concern. But they can have even bigger ramifications for your business, specifically loss of contracts and the sizable profits that come with them.
CUI can be used for malicious purposes such as technical, economic, political, or military agendas by the threat actor. Many of the attacks are retaliatory in nature, as a result of sanctions, or are targeted at industrial espionage.
A CMMC electronic contract manufacturer is more resilient to cyber-attacks from both outside and inside your organization. CUI will be strongly protected from other countries, as well as a rogue employee. Businesses that attain and support CMMC compliance have proven their willingness and ability to protect sensitive data, making them a valuable electronic contract manufacturing partner.
Benefits of CMMC
For defense contractors and manufacturers, CMMC provides a structured way to protect sensitive information and demonstrate that appropriate cybersecurity practices are in place. Compliance can help organizations strengthen their cybersecurity, protect Controlled Unclassified Information (CUI), and reduce cybersecurity risks throughout the U.S. Defense Industrial Base (DIB).
Other benefits of CMMC compliance include:
- Strengthening cybersecurity practices to better protect systems and sensitive information.
- Reducing the risk of cyberattacks and data breaches by implementing required security controls.
- Improving incident response and recovery capabilities when cybersecurity incidents occur.
- Protecting CUI and other sensitive information as it moves through the defense supply chain.
- Demonstrating cybersecurity readiness to DoD customers and other organizations within the defense supply chain.
- Maintaining eligibility for contracts that require CMMC compliance.
For companies working in the defense industry, CMMC compliance can also provide a competitive advantage. Demonstrating that your organization has implemented the required cybersecurity protections can help position your company for opportunities that require CMMC compliance.
For an electronic manufacturer like Levison Enterprises, cybersecurity is an important part of supporting customers throughout the defense supply chain. Understanding your contract requirements and implementing the appropriate CMMC practices can help protect sensitive information while keeping your organization prepared for DoD contracting opportunities.
CMMC at Levison Enterprises

Levison Enterprises is an electronic contract manufacturer (ECM) committed to quality, security, and the protection of the sensitive information entrusted to us by our customers. Many of the cybersecurity practices required under CMMC were already incorporated into our existing processes and best practices.
A key part of our approach is document control and understanding how sensitive information moves through our organization. We maintain comprehensive Data Flow Diagrams (DFDs) to identify where Controlled Unclassified Information (CUI) is stored, processed, and transmitted. We also maintain documentation detailing when, where, and how applicable security controls are implemented.
Levison Enterprises continues to strengthen its cybersecurity practices and meet the requirements applicable to our defense-related work. By maintaining appropriate safeguards for CUI and other sensitive information, we help reduce cybersecurity risks throughout the defense supply chain and protect the information entrusted to us by our government and defense-industry customers.
Our commitment to security is part of our commitment to being a trusted electronic manufacturing partner for the defense industry.