Effective Dec 16th, 2024, the Department of Defense (DoD) established the Cybersecurity Maturity Model Certification (CMMC) Program to verify Contractors have implemented required security measures necessary to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The mechanisms discussed in this rule will allow the Department to confirm a defense contractor or subcontractor has implemented the security requirements for a specified CMMC level and is maintaining that status (meaning level and assessment type) across the contract period of performance. This rule will be updated as needed, using the appropriate rulemaking process, to address evolving cybersecurity standards, requirements, threats, and other relevant changes.
An OSA will select the CMMC level it desires to attain. Once the CMMC Program is implemented, a DoD solicitation will specify the minimum CMMC Status required to be eligible for award. One of four CMMC Statuses will be specified:
Level 1 (Self) is a self-assessment to secure FCI processed, stored, or transmitted in the course of fulfilling the contract. The OSA must comply with the 15 security requirements set by FAR clause 52.204-21. All 15 requirements must be met in full—no exceptions are allowed.
Level 2 (Self) is a self-assessment to secure CUI processed, stored, or transmitted in the course of fulfilling the contract. The OSA must comply with the 110 Level 2 security requirements derived from NIST SP 800-171 R2.
Level 2 (C3PAO) differs from Level 2 (Self) in the method of verifying compliance. OSAs must hire a C3PAO to conduct an assessment of the OSA's compliance with the 110 security requirements of NIST SP 800-171 R2. OSAs can shop for C3PAOs on the CMMC Accreditation Body (AB) Marketplace.
Level 3 (DIBCAC) is a government assessment of 24 additional requirements derived from NIST SP 800-172, titled "Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171", February 2021 (NIST SP 800-172 Feb2021). The OSA must ensure that they have already achieved a CMMC Status of Final Level 2 (C3PAO) before seeking CMMC Status of Final Level 3 (DIBCAC). Once this is done, an OSA should then initiate a Level 3 certification assessment by emailing a request to Defense Contract Management Agency (DCMA) Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) point of contact found at www.dcma.mil/DIBCAC, being sure to include the Level 2 (C3PAO) certification unique identifier in the email.
For more details on Cybersecurity Maturity Model Certification (CMMC), please use the provided links: