CMMC Assessment Levels · 3 of 3
Level 3 assessment by DIBCAC
In short
- Final Level 2 (C3PAO) status is a prerequisite for Level 3.
- All 24 selected Level 3 requirements must be MET.
- DIBCAC outcomes may be appealed within 21 days.
1. Level 2 first
Under the Cybersecurity Maturity Model Certification (CMMC) Program, Level 3 is assessed by a Defense agency. A status of Final Level 2 by a CMMC Third-Party Assessment Organization (C3PAO) for the systems within the Level 3 scope is a prerequisite to a Level 3 certification assessment (32 CFR 170.18(a)). Level 3 recertification likewise requires a new Level 2 assessment. Achieving Level 3 also satisfies Level 1 (Self), Level 2 (Self) and Level 2 (C3PAO) for the same assessment scope.
The Level 3 assessment is performed for the Defense Department by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) of the Defense Contract Management Agency (DCMA) (32 CFR 170.18(a)(1)). The organization seeking certification must achieve a MET result for all 24 selected Level 3 requirements. The Level 3 assessment scope must be equal to, or a subset of, the scope of the organization’s Final Level 2 (C3PAO) status (32 CFR 170.18(c)(1)(i)).
2. A three-year cycle at both levels
To keep Level 3 status, the Level 3 assessment must be performed every three years for all systems within the Level 3 scope (32 CFR 170.18(a)(1)). Because Level 2 compliance is a prerequisite, a Level 2 (C3PAO) certification assessment must also be conducted every three years to maintain Level 3. The Level 3 assessment must be completed within three years of the Final Level 3 status date or, if there was a plan of action and milestones (POA&M), of the Conditional Level 3 status date.
3. Requesting and conducting the assessment
The organization, including an external service provider that volunteers for a Level 3 assessment, starts the process by emailing a request to the DIBCAC point of contact (32 CFR 170.18(c)(1)(ii)). The request must include the unique identifier of its Level 2 certification assessment. DIBCAC validates that the organization holds Level 2 (C3PAO) status and contacts it to schedule the assessment.
DIBCAC’s assessment applies National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171A, dated June 2018, together with NIST SP 800-172A, dated March 2022, within the Level 3 scoping rules (32 CFR 170.18(c)(1)(iii)). Results are scored with the CMMC scoring methodology and entered into the CMMC instance of the Enterprise Mission Assurance Support Service (eMASS), and the organization receives a CMMC Assessment Findings Report. From eMASS, the Supplier Performance Risk System (SPRS) receives the results automatically (32 CFR 170.18(a)(1)).
4. Limited checks of Level 2
For assets that changed category or assessment requirements between the Level 2 and Level 3 assessments, DIBCAC performs limited checks of Level 2 requirements (32 CFR 170.18(c)(1)(iii)). It may still perform limited checks if those upgraded asset categories were included in the Level 2 assessment. If DIBCAC finds a Level 2 requirement NOT MET, the Level 3 process may be paused for remediation, placed on hold, or immediately terminated.
A NOT MET requirement may be re-evaluated during the Level 3 assessment, or within 10 business days once the active assessment period ends, if three conditions all exist (32 CFR 170.18(c)(2)). Additional evidence must show it is MET, that evidence must not materially affect requirements already assessed, and the findings report must still be undelivered.
The Level 3 scope is also built from asset categories (32 CFR 170.19(d)(1)). At Level 3, Controlled Unclassified Information (CUI) Assets include assets that can, but are not intended to, process, store or transmit CUI. CUI Assets, Security Protection Assets and Specialized Assets all receive a limited check against Level 2 and are assessed against the applicable Level 3 requirements. Intermediary devices may give a specialized asset the capability to meet one or more requirements. An asset that falls into any in-scope category cannot be treated as out of scope.
5. Conditional status, investigations and eligibility
The organization achieves Conditional Level 3 if the assessment results in a POA&M meeting the Level 3 POA&M rules (32 CFR 170.18(a)(1)(ii)). Under those rules, the score divided by the number of Level 3 requirements must be at least 0.8 (32 CFR 170.21(a)(3)). The POA&M may not include seven named requirements, among them the security operations center, the cyber incident response team and the supply chain risk plan. DIBCAC must perform the closeout assessment and post results no later than 180 days after the conditional status date, or the conditional status expires (32 CFR 170.18(a)(1)(ii)(B)).
The Department reserves the right to conduct a further DIBCAC assessment under Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7020, with adverse results overriding any existing status (32 CFR 170.18(a)(1)(iv)). Level 3 affirmations are due with each assessment and then once a year (32 CFR 170.18(a)(2)). A contract or subcontract requiring Level 3 may be awarded only to an organization with Conditional or Final Level 3 status and an affirmation submitted in SPRS (32 CFR 170.18(b)).
6. Cloud use, evidence and appeals
An organization may use a cloud offering that meets the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline or higher, or equivalent requirements under Defense policy (32 CFR 170.18(c)(5)(i)). Using a cloud provider does not relieve it of the 24 Level 3 requirements, which apply to every environment where CUI is processed, stored or transmitted, when Level 3 (DIBCAC) is the designated status (32 CFR 170.18(c)(5)(ii)). Any requirement inherited from the provider must be shown through a customer implementation summary and responsibility matrix and a supporting body of evidence. The hashed evidence artifacts must be kept for six years from the status date (32 CFR 170.18(c)(4)).
DIBCAC assessors complete Level 2 and Level 3 training, issue Certificates of CMMC Status from Level 3 assessments, and keep records under DCMA-MAN 4501-04 (32 CFR 170.7(a)). An organization, the Accreditation Body or a C3PAO may appeal the outcome of a DIBCAC assessment within 21 days, by submitting a written basis for appeal (32 CFR 170.7(b)). A DIBCAC Quality Assurance Review Team responds in writing or asks for more documentation. The Level 3 requirements themselves are covered in how the CMMC model and its levels are built.
Key terms
| Level 3 (DIBCAC) | The Level 3 CMMC status, assessed by DCMA DIBCAC against 24 selected requirements. |
|---|---|
| Level 2 prerequisite | Final Level 2 (C3PAO) status for the systems in the Level 3 scope. |
| Limited checks | DIBCAC’s checks of Level 2 requirements for assets that changed category. |
| Body of evidence | The material showing which Level 3 requirements are met by the organization or its cloud provider. |
| Twenty-one day appeal | The time to appeal the outcome of a DIBCAC assessment. |
Every statement above links to the document behind it. The full source list for this piece is on the sources page.
This page describes public United States government programs for general information. It is not legal, regulatory or procurement advice, and it does not address the facts of any particular case.
How Sentfore supports this
The most sensitive programs call for the highest level. Sentfore works at the delivery end of defense programs in difficult environments, providing secure movement, protective security, facilities and life support. Requirements can be sent through the contact page.