Governance, risk & compliance
CMMC v2.0
Cybersecurity Maturity Model Certification - Required for DoD contractors handling CUI/FCI.
Three levels from basic safeguarding (Level 1) to advanced protection against APTs (Level 3).
Assessment tiers & levels Lavawall supports
Lavawall assesses CMMC at every level below, so you can start where you are and step up as your program matures.
| Tier / level | What it covers | Builds on lower |
|---|---|---|
| Level 1 – Foundational | 17 practices from FAR 52.204-21. Basic safeguarding of Federal Contract Information (FCI). Annual self-assessment required. | — |
| Level 2 – Advanced | 110 practices aligned to NIST SP 800-171 Rev 2. Protection of Controlled Unclassified Information (CUI). Requires C3PAO assessment for critical programs or self-assessment for non-critical. | Yes |
| Level 3 – Expert | 110+ practices from NIST SP 800-171 plus select NIST SP 800-172 enhanced requirements. Protection against Advanced Persistent Threats (APTs). Government-led DIBCAC assessment required. | Yes |
How Lavawall® helps you get to CMMC compliance
Most of CMMC comes down to technical controls you have to run and prove: keeping systems patched, hardening configuration, detecting breaches early, backing up what matters, controlling access, and keeping evidence that all of it actually happened. Lavawall® runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to CMMC, and tracks your posture continuously instead of once a year at audit time.
- Assess your current state against CMMC in the Lavawall GRC module, with the questionnaire and control set built in.
- Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
- Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.
Related
Lavawall® supports CMMC as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.
At a glance
- Framework
- CMMC v2.0
- Category
- Security
- Region
- USA
- Levels
- 3 assessment tiers
Map this framework freeTalk to our team