CMMC Program Basics · 3 of 3
How the CMMC model and its levels are built
In short
- Level 1 has 15 requirements, Level 2 has 110 and Level 3 adds 24.
- Level 2 is identical to NIST SP 800-171 Revision 2.
- Periodic intervals may be no more than one year.
1. Three sources, three levels
The Cybersecurity Maturity Model Certification (CMMC) Model in 32 CFR 170.14 brings together security requirements from three sources (32 CFR 170.14(a)). The first is the basic safeguarding clause at 48 CFR 52.204-21. The second is Revision 2 of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, on protecting Controlled Unclassified Information (CUI) in nonfederal systems. The third is a selection of requirements from NIST SP 800-172, published in February 2021. NIST SP 800-172 sets enhanced security requirements as a supplement to SP 800-171.
Each level draws on one source (32 CFR 170.14(c)). Level 1 uses the safeguarding requirements in 48 CFR 52.204-21. Level 2 uses NIST SP 800-171 Revision 2, and Level 3 uses selected requirements from NIST SP 800-172. Taken together, the CMMC security requirements number 15 at Level 1, from 48 CFR 52.204-21(b)(1), and 110 at Level 2, from NIST SP 800-171. Level 3 adds 24 requirements selected from NIST SP 800-172 (32 CFR 170.4).
2. Domains and numbering
The model consists of domains that map to the security requirement families defined in NIST SP 800-171 Revision 2 (32 CFR 170.14(b)). The part lists domain abbreviations such as AC for access control, AT for awareness and training, CM for configuration management, IA for identification and authentication and IR for incident response (32 CFR 170.4). Others include MA for maintenance, MP for media protection, SC for system and communications protection and SI for system and information integrity.
Each requirement has an identification number in the format DD.L#-REQ (32 CFR 170.14(c)(1)). DD is the two-letter domain abbreviation and L# is the CMMC level number. REQ is the paragraph number in 48 CFR 52.204-21, or the requirement number in NIST SP 800-171 or SP 800-172. For example, the Level 3 table lists IR.L3-3.6.2e, the incident response requirement 3.6.2e of SP 800-172 (32 CFR 170.14(c)(4)).
3. Levels 1 and 2
The security requirements in CMMC Level 1 are those in 48 CFR 52.204-21(b)(1)(i) through (xv) (32 CFR 170.14(c)(2)). That clause sets basic safeguarding requirements for covered contractor information systems. The security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 Revision 2 (32 CFR 170.14(c)(3)).
Separately, the Defense Federal Acquisition Regulation Supplement (DFARS) covered defense information clause makes covered contractor information systems not operated for the government subject to the requirements of NIST SP 800-171, unless a variance applies (DFARS 252.204-7012(b)(2)(i)). CMMC does not alter that clause (32 CFR 170.5(e)).
4. Level 3 and organization-defined parameters
The Level 3 requirements are selected from NIST SP 800-172, and where applicable the Department assigns organization-defined parameters (32 CFR 170.14(c)(4)). A table in the regulation lists the selected requirements and their parameters. Among them are restricting system access to information resources owned, provisioned or issued by the organization, and using secure information transfer solutions between security domains on connected systems.
Awareness training is required on initial hire, after a significant cyber event and at least annually, focused on social engineering, advanced persistent threat actors, breaches and suspicious behavior (32 CFR 170.14(c)(4)). The training must include practical exercises tailored by role. Configuration management requirements include an authoritative repository of approved components, and automated detection of misconfigured or unauthorized components. They also include automated discovery tools for an up-to-date inventory. Systems and components must be identified and authenticated, where possible, with cryptographically based, replay-resistant bidirectional authentication before a network connection.
Incident response at Level 3 calls for a security operations center that operates 24/7, with allowance for remote or on-call staff (32 CFR 170.14(c)(4)). It also calls for a cyber-incident response team the organization can deploy within 24 hours. Risk assessment requirements include using threat intelligence, at a minimum from open or commercial sources, and any Defense-provided sources, and threat hunting on an ongoing aperiodic basis or when indications warrant. Others cover assessing security solutions at least annually, and managing supply chain risk under a plan updated at least annually. Both also apply on receipt of relevant cyber threat information or in response to a relevant cyber incident. Penetration testing is required at least annually or after significant security changes. Software integrity is verified with root of trust mechanisms or cryptographic signatures.
5. How assessment is described
Assessment of the security requirements is prescribed by NIST SP 800-171A of June 2018 and NIST SP 800-172A of March 2022 (32 CFR 170.14(d)). The descriptive text in those documents uses the terms organization-defined and periodically. Except where an organization-defined parameter applies, organization-defined means as determined by the organization being assessed. Periodically means at regular intervals.
Within CMMC, many requirements leave the interval length to the organization, to give contractors flexibility, but the interval may be no more than one year (32 CFR 170.14(d)). The organization being assessed is the Organization Seeking Assessment, which includes any organization seeking certification (32 CFR 170.4).
Scoring differs by level (32 CFR 170.24(c)(1)). All Level 1 requirements must be fully implemented to be MET, no plan of action and milestones is permitted at Level 1, and self-assessment results are scored as MET or NOT MET in their entirety. At Level 2, the maximum score equals the total number of Level 2 requirements, and the value of each requirement NOT MET is subtracted, which may produce a negative score (32 CFR 170.24(c)(2)). Each requirement carries a value such as 1, 3 or 5, related to the NIST designation of basic or derived requirements (32 CFR 170.24(c)(2)(i)(B)).
6. Where the levels go next
The level that applies to a procurement is chosen by the program manager or requiring activity, as described in who CMMC applies to and why. How each level is assessed is covered in Level 2 self-assessment and conditional status and Level 3 assessment by DIBCAC. Selection of the level depends on factors including the criticality of the mission capability and the threat of loss of the information (32 CFR 170.5(b)).
Key terms
| CMMC Model | The set of security requirements from 52.204-21, NIST SP 800-171 and selected NIST SP 800-172 requirements. |
|---|---|
| Domain | A group of requirements mapped to a NIST SP 800-171 requirement family. |
| Level 1 | The 15 basic safeguarding requirements of 48 CFR 52.204-21(b)(1). |
| Level 2 | The 110 requirements of NIST SP 800-171 Revision 2. |
| Organization-defined parameter | A value the Department assigns to a selected NIST SP 800-172 requirement. |
Every statement above links to the document behind it. The full source list for this piece is on the sources page.
This page describes public United States government programs for general information. It is not legal, regulatory or procurement advice, and it does not address the facts of any particular case.
How Sentfore supports this
Security requirements apply wherever covered information is held. Sentfore works at the delivery end of defense programs in difficult environments, providing secure movement, protective security, facilities and life support. Requirements can be sent through the contact page.