CMMC 2.0 Policy & Compliance Reference – Cybersecurity Reference
CMMC 2.0
Policy & Compliance Reference
Controlled Unclassified Information (CUI) & Federal Contract Information (FCI)


Regulatory Basis and Policy Authority

1. Regulatory Basis and Policy Authority

The Cybersecurity Maturity Model Certification (CMMC) 2.0 is a mandatory cybersecurity framework enforced by the Department of Defense (DoD) through the Defense Federal Acquisition Regulation Supplement (DFARS). It establishes minimum cybersecurity standards that all organizations in the Defense Industrial Base (DIB) must meet as a condition of contract award. CMMC 2.0 supersedes CMMC 1.0 and was formalized through 32 CFR Part 170, effective December 16, 2024.

Authority
CMMC 2.0 is legally mandated under 32 CFR Part 170. Failure to meet the required CMMC Level in a DoD solicitation renders a contractor ineligible for contract award. Misrepresentation of CMMC compliance status may constitute a violation of the False Claims Act (31 U.S.C. § 3729).

1.1 Legislative and Regulatory Lineage

CMMC 2.0 is the product of a multi-year regulatory evolution rooted in protection of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The following regulatory instruments form the foundational chain of authority:

Instrument Year Requirement
FAR 52.204-21 2016 Basic safeguarding of covered contractor information systems handling FCI. 15 basic safeguarding requirements.
DFARS 252.204-7012 2017 Adequate security for covered contractor information systems. Mandates NIST SP 800-171 compliance and cyber incident reporting.
NIST SP 800-171 Rev 2 2020 110 security requirements across 14 families for protecting CUI in non-federal systems.
CMMC 1.0 2020 Initial DoD framework with 5 maturity levels and third-party assessment requirements.
CMMC 2.0 (32 CFR Part 170) 2024 Streamlined to 3 levels. Aligns directly with NIST SP 800-171 and 800-172. POA&M allowances introduced.

1.2 Scope of Applicability

CMMC applies to all organizations that handle FCI or CUI as part of DoD contracts, subcontracts, or task orders — including prime contractors, subcontractors at all tiers, suppliers, cloud service providers, and managed security service providers that process, store, or transmit covered information on behalf of a DIB entity.

Policy Note
CMMC requirements flow down to all subcontractors at every tier. Prime contractors are responsible for ensuring that their subcontractors meet the applicable CMMC Level required by the contract. A subcontractor that handles CUI must meet at minimum CMMC Level 2.

The following information types determine CMMC Level applicability:

  • Federal Contract Information (FCI):Information provided by or generated for the Government under a contract that is not intended for public release. Requires Level 1 compliance (FAR 52.204-21).
  • Controlled Unclassified Information (CUI):Information the Government creates or possesses that requires safeguarding per law, regulation, or policy (32 CFR Part 2002 / CUI Registry). Requires Level 2 or Level 3.
  • CUI with Enhanced Protection Requirements:CUI in programs with elevated sensitivity (e.g., weapons systems, nuclear, critical infrastructure). May require Level 3.


CMMC 2.0 Framework Architecture

2. CMMC 2.0 Framework Architecture

CMMC 2.0 streamlines the original five-level model into three distinct certification levels, each building upon the previous. The framework directly maps to NIST SP 800-171 (Levels 1 and 2) and NIST SP 800-172 (Level 3). Each level specifies a defined set of practices organized across 14 security domains, a prescribed assessment method, and an allowance (or restriction) on the use of Plans of Action and Milestones (POA&Ms) to address gaps.

2.1 The Three Certification Levels

Level Name Practices Assessment Information Type NIST Basis
1 Foundational 17 Annual Self-Assessment FCI only FAR 52.204-21
2 Advanced 110 Third-Party (C3PAO) or Self-Assessment* CUI NIST SP 800-171 Rev 2
3 Expert 134 Government-Led (DCSA/DIBCAC) CUI (High Priority) NIST SP 800-171 + 800-172

* Level 2 self-assessment is permitted for programs designated as non-prioritized acquisitions. DoD contract solicitations specify which Level 2 assessment path applies.

2.2 Level 1 — Foundational

Level 1 Policy
Applicable to contractors that handle Federal Contract Information (FCI) but NOT Controlled Unclassified Information (CUI). 17 practices derived from FAR 52.204-21. Annual self-assessment required with annual affirmation by a senior company official in the Supplier Performance Risk System (SPRS).

Level 1 represents the minimum security hygiene baseline for participation in the Defense Industrial Base. The 17 practices span 6 of the 14 CMMC domains and address the fundamental protections necessary to safeguard FCI from unauthorized access and disclosure. Level 1 does not require independent third-party assessment.

Level 1 practice domains and their associated safeguarding requirements:

Domain Abbr. L1 Practices Core Requirement
Access Control AC 2 Limit system access to authorized users and transactions; limit access to CUI types.
Identification & Authentication IA 2 Identify users, processes, and devices. Authenticate prior to allowing access.
Media Protection MP 1 Sanitize or destroy information system media containing FCI before disposal or reuse.
Physical Protection PE 4 Limit physical access to organizational systems to authorized individuals.
System and Communications Protection SC 2 Monitor, control, and protect communications at external boundaries.
System and Information Integrity SI 3 Identify, report, and correct information and system flaws in a timely manner.

2.3 Level 2 — Advanced

Level 2 Policy
Applicable to contractors that handle Controlled Unclassified Information (CUI). 110 practices, fully aligned with all 110 security requirements in NIST SP 800-171 Rev 2. Third-party assessment by a Certified Third-Party Assessment Organization (C3PAO) is required for prioritized acquisitions. POA&Ms are permitted for a defined subset of non-critical practices with a 180-day resolution timeline.

Level 2 is the most broadly applicable CMMC Level across the DIB. Virtually every contractor handling CUI, including but not limited to technical data, engineering drawings, export-controlled items, and personnel records, must meet Level 2. The 110 practices are organized across all 14 domains and are directly traceable to NIST SP 800-171 Rev 2 security requirements.

Assessment pathway determination for Level 2:

  • Prioritized Acquisitions:Programs identified by DoD as having higher CUI sensitivity. C3PAO assessment required. Certificate valid for 3 years.
  • Non-Prioritized Acquisitions:Self-assessment with SPRS score submission and senior official affirmation. Annual reaffirmation required.
  • POA&M Allowance:Contractors may receive a conditional certification with open POA&M items, provided no critical practices are deficient. All POA&Ms must be closed within 180 days of assessment.
  • Critical Practices:11 practices are designated as non-deferrable. A deficiency in any critical practice results in immediate assessment failure with no POA&M allowance.

2.4 Level 3 — Expert

Level 3 Policy
Applicable to contractors working on the DoD’s highest priority programs involving advanced persistent threat (APT) risk. 134 total practices: all 110 from NIST SP 800-171 plus 24 additional practices drawn from NIST SP 800-172. Government-led assessment by the Defense Contract Security Agency (DCSA) Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). No POA&Ms permitted at this level.

Level 3 is reserved for a small subset of the DIB — those contractors whose systems process CUI associated with critical programs or technologies. The 24 additional practices from NIST SP 800-172 address enhanced security requirements designed to defend against sophisticated nation-state and APT-level threats. Level 3 assessments are conducted solely by the government with no commercial third-party involvement.

The 24 NIST SP 800-172 enhanced requirements added at Level 3 address the following security themes:

  • Advanced Configuration Management:Automated mechanisms to enforce configuration baselines and detect unauthorized changes.
  • Incident Response Enhancement:Organizationally defined incident response teams; cyber threat intelligence integration.
  • Risk Management Rigor:Penetration testing and red team exercises; supply chain risk management programs.
  • System and Communication Defense:Deception technologies; advanced traffic filtering; protected DNS services.
  • Threat Hunting:Proactive, intelligence-driven threat hunting on organizational networks.
  • Software Supply Chain:Verification of software provenance; integrity checking of software components.


Domain-by-Domain Practice Requirements

3. Domain-by-Domain Practice Requirements

CMMC 2.0 organizes all practices across 14 security domains. Each domain maps to a corresponding NIST SP 800-171 family (Levels 1 and 2) and is extended by NIST SP 800-172 requirements at Level 3. The following domain profiles provide the practice count at each level, key technical requirements, and policy implications for IT and security practitioners.

Practice Count Note
Level practice counts are cumulative: Level 2 includes all Level 1 practices plus additional Level 2-only practices. Level 3 includes all Level 1 and Level 2 practices plus the 24 enhanced practices from NIST SP 800-172. Domain-level counts reflect only the practices added at each level, not cumulative totals.

3.1 Access Control (AC)

[AC] Access Control
Practices by Level Level 1 · 2Level 2 · 22Level 3 · 25
Key Requirements Limit system access to authorized users, processes, and devices per the principle of least privilege. Control the flow of CUI in accordance with approved authorizations. Separate duties of individuals to reduce the risk of malevolent activity. Employ the principle of least privilege, including for specific security functions and privileged accounts. Use non-privileged accounts when accessing non-security functions; prohibit privileged functions over non-privileged connections. Prevent non-privileged users from executing privileged functions and capture execution in audit logs. Control remote access sessions; employ cryptography to protect confidentiality. Authorize wireless access prior to allowing connections; protect wireless access using authentication and encryption. Control connection of mobile devices; prohibit use of portable storage unless identifiable owner exists. [L3] Employ dual authorization for critical and privileged commands; enforce separation of duties.

3.2 Audit and Accountability (AU)

[AU] Audit and Accountability
Practices by Level Level 1 · 0Level 2 · 9Level 3 · 11
Key Requirements Create and retain system audit logs to enable monitoring, analysis, investigation, and reporting of unlawful or unauthorized activity. Ensure actions of individual users can be traced to those users to hold them accountable. Review and update logged events; protect audit logs from unauthorized access, modification, and deletion. Alert in the event of audit process failures; correlate audit record review, analysis, and reporting. Provide audit record reduction and report generation to support on-demand analysis and reporting. Provide system capability to compare and synchronize internal clocks with authoritative sources. [L3] Employ automated mechanisms to integrate audit review, analysis, and reporting processes. [L3] Analyze audit records to identify anomalies or suspicious activity indicative of APT.

3.3 Awareness and Training (AT)

[AT] Awareness and Training
Practices by Level Level 1 · 0Level 2 · 3Level 3 · 3
Key Requirements Ensure all personnel are aware of the security risks associated with their activities and of the applicable policies, standards, and procedures. Ensure that personnel are trained to carry out assigned information security responsibilities. Provide security awareness training on recognizing and reporting potential indicators of insider threat. [L3] Provide role-based training focused on advanced threat techniques including social engineering targeting CUI.

3.4 Configuration Management (CM)

[CM] Configuration Management
Practices by Level Level 1 · 0Level 2 · 9Level 3 · 13
Key Requirements Establish and maintain baseline configurations and inventories of all organizational systems. Establish and enforce security configuration settings for information technology products employed in organizational systems. Track, review, approve, and log changes to organizational systems. Analyze the security impact of changes prior to implementation. Define, document, approve, and enforce physical and logical access restrictions associated with changes to organizational systems. Employ the principle of least functionality by configuring systems to provide only essential capabilities. Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services. [L3] Verify the integrity and correctness of security-critical or essential software using root of trust mechanisms. [L3] Employ automated discovery and management tools to maintain current system component inventories.

3.5 Identification and Authentication (IA)

[IA] Identification and Authentication
Practices by Level Level 1 · 2Level 2 · 11Level 3 · 13
Key Requirements Identify system users, processes acting on behalf of users, and devices; authenticate prior to allowing access. Use multifactor authentication (MFA) for local and network access to privileged accounts and network access to non-privileged accounts. Employ replay-resistant authentication mechanisms for network access to privileged and non-privileged accounts. Prevent reuse of identifiers for defined periods; disable identifiers after inactivity. Enforce minimum password complexity and change requirements; prohibit password reuse. Store and transmit only cryptographically-protected passwords. Employ automated tools to support the management of organizational accounts. [L3] Employ passwordless or phishing-resistant MFA using hardware tokens or derived credentials.

3.6 Incident Response (IR)

[IR] Incident Response
Practices by Level Level 1 · 0Level 2 · 3Level 3 · 5
Key Requirements Establish an operational incident-handling capability including preparation, detection, analysis, containment, recovery, and user response activities. Track, document, and report incidents to appropriate officials and/or authorities. Test the incident response capability organizationally and update the incident response plan based on lessons learned. [L3] Establish and maintain a cyber incident response team capable of responding to APT-level threats. [L3] Perform root cause analysis on confirmed incidents; integrate findings into the threat intelligence program.

3.7 Maintenance (MA)

[MA] Maintenance
Practices by Level Level 1 · 0Level 2 · 6Level 3 · 6
Key Requirements Perform maintenance on organizational systems; provide controls on the tools, techniques, mechanisms, and personnel for maintenance. Ensure equipment removed for maintenance is sanitized of CUI. Check media containing diagnostic and test programs for malicious code before use. Require MFA to establish remote maintenance sessions; terminate sessions when complete. Supervise maintenance activities of personnel without required access authorization.

3.8 Media Protection (MP)

[MP] Media Protection
Practices by Level Level 1 · 1Level 2 · 9Level 3 · 9
Key Requirements Protect system media containing CUI, both paper and digital; limit access to authorized users. Sanitize or destroy system media before disposal or reuse; use approved sanitization techniques (NIST SP 800-88). Mark media with necessary CUI markings and distribution limitations. Control access to media containing CUI; account for media during transport. Implement cryptographic mechanisms to protect CUI during transport unless protected by physical safeguards. Control the use of removable media on system components; prohibit portable storage without identifiable owner.

3.9 Personnel Security (PS)

[PS] Personnel Security
Practices by Level Level 1 · 0Level 2 · 2Level 3 · 2
Key Requirements Screen individuals prior to authorizing access to organizational systems containing CUI. Ensure CUI is protected during and after personnel actions such as terminations and transfers.

3.10 Physical Protection (PE)

[PE] Physical Protection
Practices by Level Level 1 · 4Level 2 · 6Level 3 · 6
Key Requirements Limit physical access to organizational systems, equipment, and operating environments to authorized individuals. Protect and monitor the physical facility and support infrastructure for organizational systems. Escort visitors and monitor visitor activity; maintain audit logs of physical access. Control and manage physical access devices; enforce access control for output devices. Protect CUI during transport and control CUI on devices removed from facilities.

3.11 Risk Assessment (RA)

[RA] Risk Assessment
Practices by Level Level 1 · 0Level 2 · 3Level 3 · 5
Key Requirements Periodically assess the risk to organizational operations, assets, and individuals resulting from the operation of organizational systems and the associated processing, storage, and transmission of CUI. Scan for vulnerabilities in organizational systems periodically and when new vulnerabilities are identified; remediate vulnerabilities in accordance with risk assessments. Remediate vulnerabilities in accordance with risk assessments. [L3] Employ threat intelligence to inform risk assessments; implement a vulnerability management program with SLA-based remediation timelines. [L3] Conduct penetration testing and red team assessments of systems handling CUI.

3.12 Security Assessment (CA)

[CA] Security Assessment
Practices by Level Level 1 · 0Level 2 · 4Level 3 · 5
Key Requirements Periodically assess the security controls in organizational systems to determine if the controls are effective. Develop and implement plans of action designed to correct deficiencies and reduce or eliminate vulnerabilities in organizational systems (POA&M). Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls. Develop, document, and periodically update system security plans (SSPs) that describe system boundaries, operating environments, implementation of security requirements, and relationships with other systems. [L3] Establish and operate a continuous monitoring program that feeds into a security operations center (SOC).

3.13 System and Communications Protection (SC)

[SC] System and Communications Protection
Practices by Level Level 1 · 2Level 2 · 16Level 3 · 20
Key Requirements Monitor, control, and protect communications at the external boundaries and key internal boundaries of organizational systems. Employ architectural designs, software development techniques, and systems engineering principles promoting security. Implement subnetworks for publicly accessible system components; separate CUI systems from general-use systems. Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission (TLS 1.2+ minimum, TLS 1.3 preferred). Terminate network connections after defined periods of inactivity or at end of sessions. Establish and manage cryptographic keys when cryptography is employed; use FIPS-validated cryptography. Prohibit remote activation of collaborative computing devices; provide indication of use to present users. Control and monitor use of mobile code and VoIP technologies. [L3] Employ deception technologies and techniques to identify unauthorized use of organizational systems. [L3] Use encrypted DNS and implement protective DNS services to block access to malicious domains.

3.14 System and Information Integrity (SI)

[SI] System and Information Integrity
Practices by Level Level 1 · 3Level 2 · 7Level 3 · 9
Key Requirements Identify, report, and correct information and system flaws in a timely manner. Provide protection from malicious code at appropriate locations within organizational systems. Monitor system security alerts and advisories; take action in response. Update malicious code protection mechanisms; perform periodic scans and real-time scans. Monitor organizational systems to detect attacks and indicators of potential attacks; identify unauthorized use. Identify unauthorized use of organizational systems. [L3] Employ advanced endpoint detection and response (EDR) tools with behavioral analysis capabilities. [L3] Implement threat hunting capabilities to proactively search for APT indicators of compromise.


Assessment and Certification Process

4. Assessment and Certification Process

The CMMC assessment process is the formal mechanism by which an organization’s cybersecurity practices are evaluated against the applicable CMMC Level requirements. Assessment requirements vary by level and contract designation, but all paths require formal affirmation and score submission to the Supplier Performance Risk System (SPRS).

4.1 SPRS Score Calculation

All DoD contractors subject to DFARS 252.204-7012 are required to calculate a system security score and submit it to SPRS prior to contract award. The SPRS score is a quantitative measure of compliance with NIST SP 800-171 requirements:

Scoring Formula
Maximum Score: 110 points (full compliance). Each of the 110 NIST SP 800-171 practices is assigned a point value. Unimplemented practices result in point deductions. Minimum acceptable SPRS score for contract eligibility is typically specified in the solicitation. A score of 110 indicates full compliance with no open deficiencies.

NIST SP 800-171 DoD Assessment Methodology scoring weights:

Impact Value Description
High 5 pts Critical security controls. Deduction of 5 points per unimplemented high-impact requirement.
Medium 3 pts Significant controls. Deduction of 3 points per unimplemented medium-impact requirement.
Low 1 pt Supporting controls. Deduction of 1 point per unimplemented low-impact requirement.

4.2 Level 2 Third-Party Assessment (C3PAO)

For prioritized Level 2 acquisitions, assessment must be conducted by a DoD-authorized Certified Third-Party Assessment Organization (C3PAO). C3PAOs are listed in the CMMC Marketplace (cyberAB.org) and must be authorized by the CMMC Accreditation Body (CyberAB). Assessors conducting the assessment must hold Certified CMMC Assessor (CCA) credentials.

The Level 2 C3PAO assessment process consists of the following phases:

  • Pre-Assessment:Contractor submits System Security Plan (SSP), network diagrams, and supporting documentation. C3PAO performs document review.
  • Assessment Execution:C3PAO conducts on-site or remote assessment activities including interviews, document review, and technical testing of implemented practices.
  • Preliminary Findings:C3PAO provides draft findings. Contractor may submit additional evidence or clarification for specific findings.
  • Final Assessment Report:C3PAO issues final report to the CMMC Third Party Assessment Organization (C3PAO) and submits results to the CMMC eMASS system.
  • Certification Decision:DoD reviews assessment results. Conditional certification may be granted with open POA&Ms for non-critical practices, valid for 180 days pending closure.
  • Certificate Validity:CMMC Level 2 certificates are valid for 3 years. Annual affirmations by a senior company official are required in years 2 and 3.

4.3 Critical Practices — Non-Deferrable Requirements

Eleven CMMC Level 2 practices are designated as critical. Deficiency in any critical practice at the time of assessment results in automatic failure with no POA&M allowance. These practices represent the minimum non-negotiable security controls required to safeguard CUI:

Practice ID Domain Requirement Summary
AC.L2-3.1.20 Access Control Verify and control/limit connections to external systems.
AC.L2-3.1.22 Access Control Control CUI posted or processed on publicly accessible systems.
IA.L2-3.5.3 Identification & Auth Use multifactor authentication for local and network access.
IA.L2-3.5.4 Identification & Auth Employ replay-resistant authentication mechanisms.
SC.L2-3.13.8 System & Comm. Prot. Implement cryptographic mechanisms to protect CUI in transit.
SC.L2-3.13.10 System & Comm. Prot. Establish and manage cryptographic keys for required cryptography.
SC.L2-3.13.11 System & Comm. Prot. Employ FIPS-validated cryptography when used to protect CUI.
SI.L2-3.14.6 System & Info. Integrity Monitor organizational systems to detect attacks and indicators.
SI.L2-3.14.7 System & Info. Integrity Identify unauthorized use of organizational systems.
CA.L2-3.12.4 Security Assessment Develop, document, and update system security plans (SSPs).
IR.L2-3.6.1 Incident Response Establish operational incident-handling capability.

4.4 Plans of Action and Milestones (POA&M)

A Plan of Action and Milestones (POA&M) is a formal document that describes the corrective actions planned to remediate security deficiencies identified during an assessment. CMMC 2.0 introduced a conditional certification pathway allowing contractors to receive a Level 2 certificate while open POA&M items are resolved, subject to strict limitations.

POA&M Policy
POA&Ms are ONLY permitted at Level 2. Level 1 assessments are pass/fail with no POA&M allowance. Level 3 requires full compliance with no open deficiencies. At Level 2, a maximum of 20% of practices may be open on a POA&M. Critical practices (see Section 4.3) may never be deferred to a POA&M. All POA&M items must be closed within 180 days of initial assessment.

Required POA&M elements per OMB Memorandum M-02-01 and CMMC 2.0 regulations:

  • Practice Identifier:CMMC practice ID and NIST SP 800-171 requirement reference number.
  • Weakness Description:Specific description of the security deficiency, including affected systems and scope.
  • Point of Contact:Named individual responsible for remediation.
  • Resources Required:Budget, personnel, and tooling required to implement the corrective action.
  • Scheduled Completion Date:No later than 180 days from initial assessment date.
  • Milestones with Completion Dates:Intermediate checkpoints demonstrating progress toward full remediation.
  • Changes to Milestones:Documentation of any changes to the original milestone schedule with justification.


System Security Plan and Documentation Requirements

5. System Security Plan and Documentation Requirements

A System Security Plan (SSP) is the foundational documentation artifact required by CMMC 2.0 (via NIST SP 800-171 practice 3.12.4). The SSP describes the system boundary, the security requirements applicable to the system, and the status of implementation for each CMMC practice. It is the primary artifact reviewed during any formal CMMC assessment.

5.1 Required SSP Components

SSP Component Description and Requirements
System Boundary Precise definition of the CMMC Assessment Scope. Identifies all assets (hardware, software, services) that process, store, or transmit CUI. Includes network diagrams showing data flows.
System Description Purpose and function of the system; hardware, OS, application inventory; interconnections with external systems; data types handled (CUI categories and markings).
Security Requirement Status For each of the 110 NIST SP 800-171 requirements: Implementation status (Implemented / Partially Implemented / Not Implemented / Not Applicable). References to policies, procedures, and technical configurations that satisfy each requirement.
Responsible Roles Named roles and personnel responsible for each security requirement. Identifies system owner, ISSO/ISSM, and authorizing official equivalent.
External Systems Inventory of all external systems connected to the assessment scope. Description of data flows and interconnection security agreements (ISAs).
CUI Flow Diagram Visual representation of how CUI flows into, through, and out of the system boundary. Must identify all entry and exit points.
Laws and Regulations Applicable laws, directives, policies, standards, and guidelines (DFARS 252.204-7012, CUI Registry, NIST SP 800-171, ITAR, EAR, etc.).
Supporting Documents Pointers to policies, procedures, and configurations that implement security requirements (e.g., password policy, incident response plan, network configuration guides).

5.2 Additional Required Policy Documentation

Beyond the SSP, CMMC 2.0 assessors will review organizational policies and procedures to validate that security practices are formally defined, communicated, and maintainable. The following policy documents are routinely requested during Level 2 and Level 3 assessments:

Document Applicable Practices
Access Control Policy AC.L2-3.1.1 through 3.1.22 — Defines authorization, least privilege, remote access, wireless, and mobile device requirements.
Configuration Management Policy & Plan CM.L2-3.4.1 through 3.4.9 — Baselines, change control, least functionality, software restrictions.
Incident Response Plan (IRP) IR.L2-3.6.1 through 3.6.3 — Preparation, detection, reporting, lessons learned, and testing cadence.
Media Protection Policy & Procedures MP.L1-3.8.3 / MP.L2-3.8.1 through 3.8.9 — Handling, marking, transport, sanitization, and disposal.
Personnel Security Policy PS.L2-3.9.1 and 3.9.2 — Screening, termination, and transfer procedures.
Physical Security Policy PE.L1-3.10.1 through 3.10.3 / PE.L2 — Facility access, visitor control, audit logs.
Risk Assessment Policy & Procedures RA.L2-3.11.1 through 3.11.3 — Frequency, scope, vulnerability scanning, and remediation SLAs.
Security Awareness & Training Plan AT.L2-3.2.1 through 3.2.3 — Initial, annual, role-based, and insider threat training requirements.
System & Communications Protection Policy SC.L2-3.13.1 through 3.13.16 — Boundary protection, cryptography, session termination.
Vulnerability Management Plan RA.L2-3.11.2 and 3.11.3 — Scanning cadence, CVSS scoring, remediation timelines.
Contingency Plan / BCDR Plan Supports multiple domains — backup, recovery time objectives, and alternate processing.
Supply Chain Risk Management (SCRM) Plan Applicable at L3 per NIST SP 800-172 — Third-party component verification, provenance.


CMMC Assessment Scoping

6. CMMC Assessment Scoping

Accurate scoping is one of the most technically challenging and consequential activities in CMMC preparation. The CMMC Assessment Scope defines which assets, systems, and environments are subject to assessment. Improper scoping — either too broad or too narrow — creates either assessment risk or compliance gaps. The DoD CMMC Scoping Guidance documents provide definitive categorization of asset types.

6.1 Asset Categories

CMMC scoping guidance defines five asset categories. All assets that fall within the first three categories are in scope for CMMC assessment. Only assets in the latter two categories may be excluded from scope.

Asset Category In Scope? Description
CUI Assets YES Assets that process, store, or transmit CUI. Subject to all 110 Level 2 practices. The core of any CMMC assessment scope.
Security Protection Assets YES Assets providing security functions for CUI Assets (firewalls, IAM systems, SIEM, endpoint protection). Full practice applicability.
Contractor Risk Managed Assets YES Assets on the same network as CUI Assets but that do NOT process CUI. Must be documented and risk-managed. Subset of practices apply.
Specialized Assets SCOPED OT/ICS, IoT, government-furnished equipment. In scope with tailored practice applicability agreed upon with the assessor.
Out-of-Scope Assets NO Assets physically and logically separated from CUI environments with no path to CUI data. Must be documented and justified.

6.2 Cloud Service Provider (CSP) Scoping

Cloud environments present unique scoping challenges for CMMC. Any CSP that processes, stores, or transmits CUI on behalf of a DIB contractor is in scope for CMMC and must meet equivalent security requirements. The following CSP requirements apply:

  • FedRAMP Moderate Equivalent or Higher:CSPs used to process CUI must meet FedRAMP Moderate baseline or a DoD-approved equivalent. This is a prerequisite, not a substitute for CMMC.
  • Shared Responsibility Model:DIB contractors must document which CMMC practices are implemented by the CSP (inherited controls) versus those implemented by the contractor (contractor-responsible controls).
  • External Cloud System Documentation:Cloud services must be identified in the SSP as external systems with interconnection security agreements and data flow documentation.
  • CUI in Cloud:CUI stored in cloud environments must be encrypted at rest and in transit using FIPS-validated cryptographic modules. Contractor must control encryption keys.


NIST SP 800-171 / 800-172 Alignment

7. NIST SP 800-171 / 800-172 Alignment

CMMC 2.0 achieves its technical rigor through direct alignment with NIST SP 800-171 Revision 2 (Levels 1 and 2) and NIST SP 800-172 (Level 3). Understanding this alignment is essential for practitioners performing gap assessments, writing SSPs, and preparing for formal C3PAO evaluations. Every CMMC Level 2 practice has a one-to-one correspondence to a NIST SP 800-171 security requirement.

7.1 NIST SP 800-171 Structure

SP 800-171 Family CMMC Domain
3.1 Access Control (22 reqs) Access Control (AC)
3.2 Awareness and Training (3 reqs) Awareness and Training (AT)
3.3 Audit and Accountability (9 reqs) Audit and Accountability (AU)
3.4 Configuration Management (9 reqs) Configuration Management (CM)
3.5 Identification and Authentication (11 reqs) Identification and Authentication (IA)
3.6 Incident Response (3 reqs) Incident Response (IR)
3.7 Maintenance (6 reqs) Maintenance (MA)
3.8 Media Protection (9 reqs) Media Protection (MP)
3.9 Personnel Security (2 reqs) Personnel Security (PS)
3.10 Physical Protection (6 reqs) Physical Protection (PE)
3.11 Risk Assessment (3 reqs) Risk Assessment (RA)
3.12 Security Assessment (4 reqs) Security Assessment (CA)
3.13 System and Communications Protection (16 reqs) System and Communications Protection (SC)
3.14 System and Information Integrity (7 reqs) System and Information Integrity (SI)

7.2 NIST SP 800-172 Enhanced Practices (Level 3)

NIST SP 800-172 provides enhanced security requirements for protecting CUI associated with critical programs and high-value assets from APT-level threats. The 24 enhanced requirements are organized across 11 of the 14 families and are additive to the 110 SP 800-171 requirements. Level 3 requires implementation of all 134 practices.

Family Enhanced Practices Focus Area
Access Control (AC) 4 Advanced session control, dual authorization, separation of duties enforcement.
Awareness & Training (AT) 1 Role-based training for advanced threat techniques and social engineering.
Configuration Management (CM) 4 Automated inventory management; software integrity verification via root of trust.
Incident Response (IR) 2 APT-capable IR team; root cause analysis integration with threat intel.
Risk Assessment (RA) 2 Threat intelligence-informed risk assessment; penetration testing mandate.
Security Assessment (CA) 1 Continuous monitoring program feeding a SOC.
System & Comm. Protection (SC) 4 Deception technologies; protective DNS; encrypted DNS; advanced filtering.
System & Info. Integrity (SI) 2 Advanced EDR with behavioral analysis; proactive threat hunting.
Identification & Auth. (IA) 2 Phishing-resistant MFA; hardware-based credentials.
Configuration Mgmt. (CM) – Add. 1 Automated mechanisms to enforce baseline configurations.
Access Control (AC) – Add. 1 Prevent lateral movement via advanced network access enforcement.


Implementation and Compliance Roadmap

8. Implementation and Compliance Roadmap

Organizations pursuing CMMC compliance should follow a structured, phased approach that prioritizes high-risk gaps, establishes foundational documentation, and systematically advances toward the required certification level. The following roadmap provides a practical framework for IT and security teams managing a CMMC readiness program.

8.1 Pre-Assessment Preparation (All Levels)

Phase 1 — Scoping and Gap Assessment (Months 1–2)

  • Define Assessment Scope:Identify all assets that process, store, or transmit CUI. Classify assets using the five categories in Section 6. Document scope in the SSP.
  • CUI Flow Mapping:Trace all CUI ingress and egress paths. Identify all systems, users, and processes that touch CUI. Document in data flow diagrams.
  • Conduct NIST SP 800-171 Self-Assessment:Evaluate all 110 practices against current implementations. Calculate SPRS score. Document all deficiencies.
  • Identify Critical Practice Gaps:Prioritize the 11 critical practices (Section 4.3). Any gap in a critical practice must be remediated before assessment.
  • Develop POA&M:For all non-critical deficiencies, create POA&M entries with resource estimates and projected completion dates within 180 days.

Phase 2 — Documentation Development (Months 2–4)

  • Draft System Security Plan (SSP):Complete all SSP components per Section 5.1. Map each NIST SP 800-171 requirement to specific implementations.
  • Develop Supporting Policies:Create or update all policy documents in Section 5.2. Ensure policies reference CMMC/NIST practice IDs.
  • Implement Awareness Training:Deploy annual security awareness training. Document completion records. Develop role-based training for privileged users.

Phase 3 — Technical Remediation (Months 3–6)

  • MFA Deployment:Enable MFA for all accounts with access to CUI systems. Prioritize privileged accounts and remote access paths.
  • Encryption Implementation:Enforce TLS 1.2+ on all CUI data in transit. Enable FIPS-validated encryption at rest on CUI systems and removable media.
  • Audit Logging:Deploy centralized log management. Configure audit logging on all CUI systems. Establish log retention per policy (minimum 1 year recommended).
  • Vulnerability Management:Establish authenticated vulnerability scanning schedule. Implement risk-based remediation SLAs (e.g., critical: 15 days, high: 30 days).
  • Configuration Hardening:Apply CIS Benchmarks or DISA STIGs to all systems in scope. Disable unnecessary services, ports, and protocols.
  • Endpoint Protection:Deploy and centrally manage EDR on all CUI endpoints. Enable behavioral detection. Automate signature updates.

8.2 Assessment Readiness (Months 5–6)

  • Internal Mock Assessment:Conduct an internal assessment against all 110 practices. Use NIST SP 800-171A assessment procedures to validate implementations.
  • Engage C3PAO:Select a DoD-authorized C3PAO from the CyberAB Marketplace. Submit pre-assessment documentation package (SSP, network diagrams, POA&M).
  • Remediate Remaining Gaps:Address all critical practice deficiencies before the formal assessment. Update POA&M with current status of all open items.
  • Update SPRS Score:Submit updated SPRS score reflecting post-remediation status. Ensure senior official affirmation is current.
  • Incident Response Test:Conduct tabletop exercise to validate IRP. Document test results and update plan.

8.3 Post-Certification Maintenance

Maintenance Policy
CMMC certification is not a one-time event. Level 2 certificates are valid for 3 years with annual senior official affirmations in years 2 and 3. Level 1 requires annual self-assessment and affirmation. Any significant change to the system boundary or security architecture requires notification to the assessing body and may require re-assessment.
  • Continuous Monitoring:Maintain ongoing vulnerability scanning, log review, and configuration compliance checks. Feed findings into the POA&M process.
  • Change Management:Assess security impact of all changes to in-scope systems. Document changes in the SSP and notify C3PAO/DIBCAC of significant boundary changes.
  • Annual Training:Refresh security awareness training annually. Update role-based training for new threats and techniques.
  • Annual Affirmation:A senior company official (e.g., CISO, CIO, or CEO) must annually affirm continued compliance in SPRS.
  • Incident Reporting:Report cyber incidents to DIBNet within 72 hours per DFARS 252.204-7012. Preserve forensic data for 90 days.


Cyber Incident Reporting Requirements

9. Cyber Incident Reporting Requirements

DFARS 252.204-7012 establishes mandatory cyber incident reporting requirements for all DoD contractors subject to CMMC. These requirements are independent of CMMC Level — all contractors handling CUI must comply with incident reporting obligations, regardless of whether formal CMMC certification has been achieved.

9.1 Reporting Obligations

Incident Policy
Contractors must report cyber incidents that affect covered contractor information systems or the CUI residing therein to the DoD via the DIBNet portal (dibnet.dod.mil) within 72 hours of discovery. Rapid reporting is required even if the full scope of the incident has not yet been determined.

Required reporting elements for cyber incident notifications:

Required Element Description
Company Identification Company name, CAGE code, contract numbers affected by the incident.
Incident Discovery Date Date and time the incident was first discovered.
Location of Compromise Physical and logical location(s) of the systems involved.
CUI Data Categories Types of CUI potentially compromised (categories per CUI Registry).
Compromised Systems List of affected systems, IP addresses, hostnames, and operating systems.
Attack Vector Known or suspected initial access vector (e.g., phishing, exploitation, insider).
Malware Indicators Malware hashes, C2 IP addresses, domain names, and other IOCs if known.
Media Preservation Contractor must preserve images of compromised systems for 90 days and provide to DoD upon request.

9.2 Malware Submission

In addition to portal reporting, contractors must submit malicious software discovered in connection with a reported cyber incident to the DoD Cyber Crime Center (DC3) or the CERT Coordination Center (CERT/CC) for analysis. This obligation exists alongside the 72-hour reporting requirement and does not extend the reporting deadline.



References, Authorities, and Resources

10. References, Authorities, and Resources

10.1 Authoritative References

Document Description / URL
32 CFR Part 170 CMMC 2.0 Final Rule — Codifies assessment, certification, and enforcement requirements. Federal Register Vol. 89, No. 220.
DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting — Primary contractual vehicle for CMMC flow-down.
DFARS 252.204-7021 CMMC Requirements clause — Contract-specific CMMC Level requirements, self-attestation, and C3PAO assessment obligations.
NIST SP 800-171 Rev 2 Protecting Controlled Unclassified Information in Nonfederal Systems — 110 requirements, foundation of Levels 1 and 2.
NIST SP 800-172 Enhanced Security Requirements for CUI — 24 enhanced requirements, basis for Level 3.
NIST SP 800-171A Rev 3 Assessing Security Requirements for CUI — Assessment procedures used by C3PAOs and DIBCAC assessors.
NIST SP 800-88 Rev 1 Guidelines for Media Sanitization — Required reference for MP domain practices.
CUI Registry (Archives.gov) Authoritative list of CUI categories, subcategories, and applicable safeguarding and dissemination controls.
DoD CMMC Scoping Guidance Asset category definitions, scoping methodology, and cloud scoping guidance for Level 1, 2, and 3.
DoD CMMC Assessment Process Official assessment methodology documents for Level 1 (self), Level 2 (C3PAO), and Level 3 (DIBCAC).

10.2 Key Program Resources

  • CMMC Program Office:https://www.acq.osd.mil/cmmc/
  • CyberAB (Accreditation Body):https://cyberab.org — CMMC Marketplace, C3PAO directory, CCA credential verification.
  • Supplier Performance Risk System (SPRS):https://www.sprs.csd.disa.mil — Self-assessment score submission and affirmation portal.
  • DIBNet Portal:https://dibnet.dod.mil — Cyber incident reporting portal per DFARS 252.204-7012.
  • DoD Cyber Crime Center (DC3):https://www.dc3.mil — Malware submission and cyber intelligence sharing for DIB.
  • CUI Registry:https://www.archives.gov/cui — Authoritative source for CUI category definitions and handling requirements.
  • Project Spectrum (DoD):https://www.projectspectrum.io — Free CMMC readiness tools and resources for small DIB businesses.
Document Notice
This document is prepared for informational and internal compliance planning purposes by IT and cybersecurity professionals within the Defense Industrial Base. It does not constitute legal advice and does not supersede official DoD, CMMC Program Office, or regulatory guidance. Organizations should consult with a Registered Practitioner Organization (RPO) or legal counsel for contract-specific compliance determinations.