A US Department of Defense certification programme that requires contractors to prove specific cybersecurity controls before handling regulated defence information. In identity terms, it converts access governance, authentication, and auditability into assessable evidence rather than self-declared policy.
Expanded Definition
Cybersecurity maturity model Certification, often abbreviated as CMMC, is a compliance framework that turns baseline cybersecurity expectations into a condition of doing business for defence contractors. In NHI and agentic environments, its practical impact is not just about endpoints or networks. It also affects whether service accounts, API keys, certificates, and automated workflows can be proven to have controlled access, traceable use, and defined ownership. Guidance varies across vendors on how directly CMMC should be mapped to machine identity controls, but the operational expectation is consistent: evidence matters more than intent. For a broader NHI framing, see Ultimate Guide to NHIs — What are Non-Human Identities and the challenge summary in Ultimate Guide to NHIs — Key Challenges and Risks. The closest external baseline is the NIST identity guidance that CMMC programmes commonly lean on for assurance concepts, especially around authentication, access control, and audit evidence. The most common misapplication is treating CMMC as a paperwork exercise, which occurs when contractors document controls without proving that identities, secrets, and logs actually behave that way in production.
Examples and Use Cases
Implementing CMMC rigorously often introduces evidence-collection overhead, requiring organisations to weigh auditability against delivery speed and operational flexibility.
- A defence subcontractor inventories all service accounts and assigns explicit owners so auditors can trace which workload is allowed to access CUI and why.
- A platform team replaces long-lived shared secrets with managed rotation and logging because screenshots of policy are not enough to satisfy control evidence.
- An engineering group separates development and production credentials, then preserves change records and access logs to show that privileged activity is reviewable.
- A contractor aligns identity proofing and authenticator strength with NIST SP 800-63B concepts where workforce or operator access gates regulated environments.
- An assessor compares secret-sharing practices against patterns highlighted in the 2024 Non-Human Identity Security Report, which found that 23.7% of organisations share secrets through insecure methods such as email or messaging applications.
In practice, CMMC becomes most relevant when teams must prove that non-human access is not only configured, but also governed, reviewed, and revocable. The overlap with broader NHI controls is clear in incidents analysed in 52 NHI Breaches Analysis and in the control themes surfaced by CISA cyber threat advisories, where exposed credentials and weak governance repeatedly amplify impact.
Why It Matters in NHI Security
CMMC matters because regulated defence work depends on demonstrable control over machine identities, not just human users. When service accounts are over-privileged, credentials are reused, or logs cannot show who accessed what, the organisation may still be “secure” on paper while failing the evidence test that certification requires. That is especially important for NHI programmes, where access is often automated, ephemeral, and distributed across pipelines, cloud services, and third-party integrations. NHIMG research shows the maturity gap is already material: 88.5% of organisations say their non-human IAM practices lag behind or are merely on par with their human IAM efforts, which means the control environment CMMC expects is often not yet in place. The same risk pattern is visible in the broader NHI breach landscape discussed in Ultimate Guide to NHIs — Why NHI Security Matters Now. For threat modelling around autonomous systems and tool-using agents, the MITRE ATLAS adversarial AI threat matrix is also relevant when agentic access is part of the environment. Organisations typically encounter CMMC urgency only after a contract review, assessment finding, or incident exposes undocumented machine access, at which point the certification requirement becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-63, NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | AAL2 | CMMC evidence often depends on strong, verifiable authenticator assurance for regulated access. |
| NIST CSF 2.0 | PR.AC-1 | CMMC maps cleanly to controlled access, identity governance, and auditability outcomes. |
| NIST Zero Trust (SP 800-207) | SC-7 | Zero trust principles reinforce continuous verification and least privilege expected in CMMC programs. |
| NIST AI RMF | Agentic workflows that touch regulated data require governable, inspectable identity and access risk controls. | |
| OWASP Non-Human Identity Top 10 | NHI-01 | CMMC issues commonly emerge from weak machine identity governance and secret handling. |
Require assurance-level proof for identities that access regulated defence data and preserve it as audit evidence.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 17, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org