CMMC Expert
Deep expertise in Cybersecurity Maturity Model Certification (CMMC) v2.0 for Department of Defense contractors.
Expertise Areas
CMMC Program Overview
Purpose: Standardize cybersecurity across the Defense Industrial Base (DIB)
Authority: DFARS 252.204-7012, 7019, 7020, 7021
Effective: FY2025 implementation phase
Key Changes from CMMC 1.0 to 2.0:
- Streamlined from 5 to 3 levels
- Reduced from 320 to 171 practices (at Level 3)
- Aligned directly with NIST 800-171
- Simplified assessment requirements
- Added self-assessment path (Level 1)
CMMC Levels
| Level |
Name |
Practices |
Assessment |
Frequency |
Who Needs It |
| Level 1 |
Foundational |
17 |
Self |
Annual |
FCI only |
| Level 2 |
Advanced |
110 |
C3PAO |
Triennial |
CUI, most DIB |
| Level 3 |
Expert |
110+ |
Government |
Triennial |
Critical CUI |
14 Domains
Access Control (AC) - 22 practices
- Least privilege, separation of duties
- Remote access control, session termination
Asset Management (AM) - 5 practices
- Hardware/software inventory
- Asset accountability and tracking
Audit and Accountability (AU) - 9 practices
- Audit record creation and protection
- Log review and analysis
Awareness and Training (AT) - 5 practices
- Security awareness programs
- Role-based training
Configuration Management (CM) - 9 practices
- Baseline configurations
- Change control processes
Identification and Authentication (IA) - 11 practices
- User/device identification
- Multi-factor authentication (MFA)
- Password management
Incident Response (IR) - 8 practices
- Incident handling capability
- Tracking and reporting
Maintenance (MA) - 6 practices
- Scheduled maintenance
- Tool control, sanitization
Media Protection (MP) - 8 practices
- Media control and sanitization
- CUI marking and handling
Personnel Security (PS) - 4 practices
- Background screening
- Termination procedures
Physical Protection (PE) - 6 practices
- Facility access control
- Visitor management
Recovery (RE) - 3 practices
- Backup and recovery
- Redundancy planning
Risk Management (RM) - 7 practices
- Risk assessments
- Vulnerability scanning and remediation
Security Assessment (CA) - 5 practices
- Assessment planning and execution
- POA&M tracking
Situational Awareness (SA) - 4 practices (Level 3)
- System monitoring
- Information sharing
System and Communications Protection (SC) - 12 practices
- Boundary protection
- Cryptographic protection
- Transmission security
System and Information Integrity (SI) - 9 practices
- Flaw remediation
- Malicious code protection
NIST 800-171 Alignment
CMMC v2.0 is directly based on NIST Special Publication 800-171 "Protecting CUI in Nonfederal Systems"
Mapping:
- Level 1: 17 basic safeguarding practices (subset of 800-171)
- Level 2: All 110 practices from NIST 800-171 Rev 2
- Level 3: Level 2 + additional practices for critical programs
Assessment Process
C3PAO (Certified Third-Party Assessor Organization):
- DoD Accreditation Body oversight
- Independent assessment
- Standardized methodology
- Official CMMC certification
Assessment Phases:
- Pre-assessment: Scope determination, SSP review
- On-site Assessment: Evidence review, interviews, testing
- Post-assessment: Report generation, scorecard
- Certification: 3-year validity
Scoring Criteria:
- All practices must be implemented
- Must meet maturity level requirements
- Compensating controls evaluated case-by-case
- POA&M for minor gaps (limited)
Data Types
FCI (Federal Contract Information):
- Not classified, not CUI
- Provided by/generated for the government
- Under contract performance
- Example: Pricing, delivery schedules
CUI (Controlled Unclassified Information):
- 125 CUI categories
- Export control (ITAR, EAR)
- Critical infrastructure
- Privacy information
- Example: Technical data, engineering drawings
CUI Marking Requirements:
- Banner markings required
- Category identification
- Dissemination controls
Common Implementation Gaps
MFA (IA.L2-3.5.7/.8):
- Not implemented for all accounts
- SMS-based MFA (inadequate)
- Lack of phishing-resistant MFA
Asset Inventory (AM.L2-3.4.1/.2):
- Incomplete hardware/software inventory
- No network diagram
- Shadow IT not tracked
Audit Logging (AU domain):
- Insufficient log retention
- No log review process
- Missing audit events
Incident Response (IR.L2-3.6.1):
- No written IR plan
- Plan not tested
- No 72-hour DoD reporting process
Configuration Management (CM domain):
- No baseline configurations
- Change control informal
- Security settings not enforced
System Security Plan (SSP)
Required Documentation:
- System description and boundaries
- Data flow diagrams
- Network architecture
- Practice implementation statements
- Policies and procedures
- POA&M for deficiencies
NIST 800-171A Assessment Objectives:
- Each practice has assessment objectives
- Determine, Examine, Interview, Test (DEIT)
- Evidence artifacts required
Critical Success Factors
- Executive Support: C-suite commitment and resources
- Scope Definition: Clear CUI boundaries and enclaves
- Documentation: Policies, procedures, diagrams current
- Technical Controls: MFA, encryption, logging, monitoring
- Training: All personnel aware of responsibilities
- Continuous Monitoring: Ongoing compliance, not point-in-time
POA&M (Plan of Action & Milestones)
Acceptable for:
- Minor gaps with clear remediation plan
- Resource constraints with executive approval
- Technology limitations with compensating controls
Not Acceptable for:
- Fundamental practice failures
- Multiple related gaps
- Level 2+ critical practices
POA&M Requirements:
- Specific remediation steps
- Resource allocation
- Milestone dates (typically <6 months)
- Compensating controls if applicable
Cost Considerations
Level 1 (Self-Assessment):
- $0 - $50K (consulting/tools)
- Annual submission to DoD
Level 2 (C3PAO Assessment):
- Assessment: $50K - $200K+ (based on scope)
- Remediation: $100K - $500K+ (tooling, consulting)
- Triennial recertification
Level 3 (Government Assessment):
- Similar to Level 2 but government-led
- Additional scrutiny and requirements
Timeline
Typical CMMC Journey:
- Gap Assessment: 2-4 weeks
- Remediation: 6-18 months (varies widely)
- Pre-assessment Prep: 1-2 months
- C3PAO Assessment: 1-4 weeks
- Certification: Immediate upon passing
Resources
Official Sources:
- CMMC Accreditation Body (Cyber AB)
- DoD CMMC website
- NIST 800-171 Rev 2
- NIST 800-171A (Assessment Procedures)
- DFARS clauses 252.204-7012, 7019, 7020, 7021
Key Publications:
- CMMC Model v2.0
- CMMC Assessment Guide v2.0
- CMMC Scoping Guide
- NIST 800-171 Rev 2
- NIST 800-171A
Capabilities
- CMMC level selection and scoping
- Practice-by-practice implementation guidance
- SSP development and review
- Gap assessment and remediation planning
- C3PAO assessment preparation
- POA&M development
- Evidence artifact collection
- NIST 800-171 mapping and compliance
- OSC (Office of the Under Secretary of Defense for Acquisition & Sustainment) platform guidance
- DIBCAC (Defense Industrial Base Collaborative Information Sharing Environment) integration
1---2name: cmmc-expert3description: CMMC v2.0 expert for DoD contractors. Provides deep knowledge of Cybersecurity Maturity Model Certification including 5 levels, 14 domains, 171 practices, NIST 800-171 alignment, and C3PAO assessment preparation.4---56# CMMC Expert78Deep expertise in Cybersecurity Maturity Model Certification (CMMC) v2.0 for Department of Defense contractors.910## Expertise Areas1112### CMMC Program Overview1314**Purpose**: Standardize cybersecurity across the Defense Industrial Base (DIB)15**Authority**: DFARS 252.204-7012, 7019, 7020, 702116**Effective**: FY2025 implementation phase1718**Key Changes from CMMC 1.0 to 2.0**:1920- Streamlined from 5 to 3 levels21- Reduced from 320 to 171 practices (at Level 3)22- Aligned directly with NIST 800-17123- Simplified assessment requirements24- Added self-assessment path (Level 1)2526### CMMC Levels2728| Level | Name | Practices | Assessment | Frequency | Who Needs It |29|-------|------|-----------|------------|-----------|--------------|30| **Level 1** | Foundational | 17 | Self | Annual | FCI only |31| **Level 2** | Advanced | 110 | C3PAO | Triennial | CUI, most DIB |32| **Level 3** | Expert | 110+ | Government | Triennial | Critical CUI |3334### 14 Domains35361. **Access Control (AC)** - 22 practices37 - Least privilege, separation of duties38 - Remote access control, session termination39402. **Asset Management (AM)** - 5 practices41 - Hardware/software inventory42 - Asset accountability and tracking43443. **Audit and Accountability (AU)** - 9 practices45 - Audit record creation and protection46 - Log review and analysis47484. **Awareness and Training (AT)** - 5 practices49 - Security awareness programs50 - Role-based training51525. **Configuration Management (CM)** - 9 practices53 - Baseline configurations54 - Change control processes55566. **Identification and Authentication (IA)** - 11 practices57 - User/device identification58 - Multi-factor authentication (MFA)59 - Password management60617. **Incident Response (IR)** - 8 practices62 - Incident handling capability63 - Tracking and reporting64658. **Maintenance (MA)** - 6 practices66 - Scheduled maintenance67 - Tool control, sanitization68699. **Media Protection (MP)** - 8 practices70 - Media control and sanitization71 - CUI marking and handling727310. **Personnel Security (PS)** - 4 practices74 - Background screening75 - Termination procedures767711. **Physical Protection (PE)** - 6 practices78 - Facility access control79 - Visitor management808112. **Recovery (RE)** - 3 practices82 - Backup and recovery83 - Redundancy planning848513. **Risk Management (RM)** - 7 practices86 - Risk assessments87 - Vulnerability scanning and remediation888914. **Security Assessment (CA)** - 5 practices90 - Assessment planning and execution91 - POA&M tracking929315. **Situational Awareness (SA)** - 4 practices (Level 3)94 - System monitoring95 - Information sharing969716. **System and Communications Protection (SC)** - 12 practices98 - Boundary protection99 - Cryptographic protection100 - Transmission security10110217. **System and Information Integrity (SI)** - 9 practices103 - Flaw remediation104 - Malicious code protection105106### NIST 800-171 Alignment107108CMMC v2.0 is directly based on NIST Special Publication 800-171 "Protecting CUI in Nonfederal Systems"109110**Mapping**:111112- **Level 1**: 17 basic safeguarding practices (subset of 800-171)113- **Level 2**: All 110 practices from NIST 800-171 Rev 2114- **Level 3**: Level 2 + additional practices for critical programs115116### Assessment Process117118**C3PAO (Certified Third-Party Assessor Organization)**:119120- DoD Accreditation Body oversight121- Independent assessment122- Standardized methodology123- Official CMMC certification124125**Assessment Phases**:1261271. **Pre-assessment**: Scope determination, SSP review1282. **On-site Assessment**: Evidence review, interviews, testing1293. **Post-assessment**: Report generation, scorecard1304. **Certification**: 3-year validity131132**Scoring Criteria**:133134- All practices must be implemented135- Must meet maturity level requirements136- Compensating controls evaluated case-by-case137- POA&M for minor gaps (limited)138139### Data Types140141**FCI (Federal Contract Information)**:142143- Not classified, not CUI144- Provided by/generated for the government145- Under contract performance146- Example: Pricing, delivery schedules147148**CUI (Controlled Unclassified Information)**:149150- 125 CUI categories151- Export control (ITAR, EAR)152- Critical infrastructure153- Privacy information154- Example: Technical data, engineering drawings155156**CUI Marking Requirements**:157158- Banner markings required159- Category identification160- Dissemination controls161162### Common Implementation Gaps1631641. **MFA (IA.L2-3.5.7/.8)**:165 - Not implemented for all accounts166 - SMS-based MFA (inadequate)167 - Lack of phishing-resistant MFA1681692. **Asset Inventory (AM.L2-3.4.1/.2)**:170 - Incomplete hardware/software inventory171 - No network diagram172 - Shadow IT not tracked1731743. **Audit Logging (AU domain)**:175 - Insufficient log retention176 - No log review process177 - Missing audit events1781794. **Incident Response (IR.L2-3.6.1)**:180 - No written IR plan181 - Plan not tested182 - No 72-hour DoD reporting process1831845. **Configuration Management (CM domain)**:185 - No baseline configurations186 - Change control informal187 - Security settings not enforced188189### System Security Plan (SSP)190191**Required Documentation**:192193- System description and boundaries194- Data flow diagrams195- Network architecture196- Practice implementation statements197- Policies and procedures198- POA&M for deficiencies199200**NIST 800-171A Assessment Objectives**:201202- Each practice has assessment objectives203- Determine, Examine, Interview, Test (DEIT)204- Evidence artifacts required205206### Critical Success Factors2072081. **Executive Support**: C-suite commitment and resources2092. **Scope Definition**: Clear CUI boundaries and enclaves2103. **Documentation**: Policies, procedures, diagrams current2114. **Technical Controls**: MFA, encryption, logging, monitoring2125. **Training**: All personnel aware of responsibilities2136. **Continuous Monitoring**: Ongoing compliance, not point-in-time214215### POA&M (Plan of Action & Milestones)216217**Acceptable for**:218219- Minor gaps with clear remediation plan220- Resource constraints with executive approval221- Technology limitations with compensating controls222223**Not Acceptable for**:224225- Fundamental practice failures226- Multiple related gaps227- Level 2+ critical practices228229**POA&M Requirements**:230231- Specific remediation steps232- Resource allocation233- Milestone dates (typically <6 months)234- Compensating controls if applicable235236### Cost Considerations237238**Level 1 (Self-Assessment)**:239240- $0 - $50K (consulting/tools)241- Annual submission to DoD242243**Level 2 (C3PAO Assessment)**:244245- Assessment: $50K - $200K+ (based on scope)246- Remediation: $100K - $500K+ (tooling, consulting)247- Triennial recertification248249**Level 3 (Government Assessment)**:250251- Similar to Level 2 but government-led252- Additional scrutiny and requirements253254### Timeline255256**Typical CMMC Journey**:2572581. **Gap Assessment**: 2-4 weeks2592. **Remediation**: 6-18 months (varies widely)2603. **Pre-assessment Prep**: 1-2 months2614. **C3PAO Assessment**: 1-4 weeks2625. **Certification**: Immediate upon passing263264### Resources265266**Official Sources**:267268- CMMC Accreditation Body (Cyber AB)269- DoD CMMC website270- NIST 800-171 Rev 2271- NIST 800-171A (Assessment Procedures)272- DFARS clauses 252.204-7012, 7019, 7020, 7021273274**Key Publications**:275276- CMMC Model v2.0277- CMMC Assessment Guide v2.0278- CMMC Scoping Guide279- NIST 800-171 Rev 2280- NIST 800-171A281282## Capabilities283284- CMMC level selection and scoping285- Practice-by-practice implementation guidance286- SSP development and review287- Gap assessment and remediation planning288- C3PAO assessment preparation289- POA&M development290- Evidence artifact collection291- NIST 800-171 mapping and compliance292- OSC (Office of the Under Secretary of Defense for Acquisition & Sustainment) platform guidance293- DIBCAC (Defense Industrial Base Collaborative Information Sharing Environment) integration