CMMC Program Basics · 1 of 3
Who CMMC applies to and why
In short
- CMMC applies to awardees that handle FCI or CUI on contractor systems.
- Federal systems operated for the government are outside the rule.
- The program manager or requiring activity selects the level.
1. What the CMMC Program is for
The Cybersecurity Maturity Model Certification (CMMC) Program is set out in part 170 of title 32 of the Code of Federal Regulations. It requires defense contractors and subcontractors to implement prescribed cybersecurity standards for safeguarding Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) (32 CFR 170.1(a)). It also sets requirements for assessing compliance on contractor information systems that process, store or transmit FCI or CUI. Systems that provide security protections for CUI systems, or are not logically or physically isolated from them, are covered too.
The program gives the Defense Department a way to carry out the volume of assessments needed to verify that contractors and subcontractors have implemented the required cybersecurity requirements (32 CFR 170.1(b)). The regulation states that FCI and CUI must be protected to meet evolving threats and safeguard nonpublic, unclassified information that supports and enables the warfighter (32 CFR 170.1(c)). The program uses a consistent method to assess a contractor’s implementation of the required cybersecurity requirements.
2. The standards it relies on
CMMC draws on three sources of security requirements (32 CFR 170.1(c)). They are the clause at 48 CFR 52.204-21, the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 2, and selected requirements from NIST SP 800-172 of February 2021. The program balances safeguarding FCI and CUI against the need to share information with defense contractors so they can develop capabilities for the Department (32 CFR 170.1(d)). It creates no right or benefit enforceable by law or in equity by any party against the United States or any other person (32 CFR 170.1(e)).
CMMC does not change any separately applicable requirement to protect FCI or CUI (32 CFR 170.5(e)). That includes the basic safeguarding clause at 48 CFR 52.204-21 and the covered defense information clause at Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012. The program provides a means of verifying implementation of the requirements in 48 CFR 52.204-21, NIST SP 800-171 Revision 2 and NIST SP 800-172, as applicable.
3. Who the rules reach
The part applies to all Defense contract and subcontract awardees that will process, store or transmit FCI or CUI on contractor information systems (32 CFR 170.3(a)(1)). The information must meet the standards for FCI or CUI and be handled in performance of the Defense contract (32 CFR 170.3(a)(1)). It also applies to the private-sector businesses and other entities that make up the CMMC assessment and certification ecosystem (32 CFR 170.3(a)(2)). It does not apply to federal information systems operated by contractors or subcontractors on behalf of the government (32 CFR 170.3(b)).
CMMC requirements apply to all Defense solicitations and contracts under which a contractor or subcontractor will handle FCI or CUI on unclassified contractor information systems (32 CFR 170.3(c)). That includes acquisitions of commercial items valued above the micro-purchase threshold, except those exclusively for commercially available off-the-shelf (COTS) items. The exceptions are procurements during the first three implementation phases, which follow the rules for the relevant phase. A procurement or class of procurements may also be waived in advance of the solicitation, at the Department’s discretion and under applicable policies.
4. Who picks the required status
Defense program managers or requiring activities select the CMMC status that will apply to a procurement or contract (32 CFR 170.3(d)). They base the choice on the type of information, FCI or CUI, that will be processed on, stored on or transmitted through a contractor information system. Subcontractor requirements are set under the part’s flowdown rules.
Selection depends on factors including, but not limited to, five that the regulation lists (32 CFR 170.5(b)). They are the criticality of the mission capability, the type of acquisition program or technology, the threat of loss of the FCI or CUI, the impact of exploiting security deficiencies, and other relevant policies, including milestone decision authority guidance. In general, the Department will identify a requirement for CMMC Level 3, assessed by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), for solicitations supporting its most critical programs and technologies (32 CFR 170.5(a)).
5. Policy and flowdown
Defense policy is that contractors and subcontractors must safeguard FCI and CUI on their information systems by applying specified security requirements (32 CFR 170.5(a)). They may also be required to implement additional safeguards from NIST SP 800-172, with Department-specified parameters, to meet Level 3. Those additional requirements apply when a program manager or requiring activity designates a requirement for Level 3.
Under the implementation plan, CMMC requirements apply to new Defense solicitations and contracts (32 CFR 170.5(c)). They flow down to subcontractors who will process, store or transmit FCI or CUI in performing the subcontract.
6. Two key terms and the vocabulary of status
The DFARS clause on CMMC compliance defines controlled unclassified information by reference to 32 CFR 2002.4(h) (DFARS 252.204-7021(a)). It is information the government creates or possesses, or that an entity creates or possesses for it, that a law, regulation or governmentwide policy requires or permits an agency to handle with safeguarding or dissemination controls. Federal Contract Information is defined in 48 CFR 4.1901 (32 CFR 170.4).
An Organization Seeking Assessment is the entity seeking a self-assessment or certification assessment of an information system to achieve and keep a CMMC status (32 CFR 170.4). An Organization Seeking Certification seeks a certification assessment for Level 2 by a third-party assessment organization, or Level 3 by DIBCAC, and is also an Organization Seeking Assessment. CMMC status is the result of meeting or exceeding the minimum required score for an assessment. It is stored in the Supplier Performance Risk System and, for third-party or DIBCAC assessments, also shown on a Certificate of CMMC Status. How the requirements enter contracts over time is covered in how CMMC is phased into contracts.
Key terms
| CMMC | The Defense program for verifying contractor safeguarding of FCI and CUI. |
|---|---|
| FCI | Federal Contract Information, as defined in 48 CFR 4.1901. |
| CUI | Information that law, regulation or Governmentwide policy requires or permits agencies to safeguard or control. |
| CMMC status | The result of meeting or exceeding the minimum score for an assessment. |
| Organization Seeking Certification | An entity seeking a Level 2 third-party or Level 3 DIBCAC assessment. |
Every statement above links to the document behind it. The full source list for this piece is on the sources page.
This page describes public United States government programs for general information. It is not legal, regulatory or procurement advice, and it does not address the facts of any particular case.
How Sentfore supports this
Contractors supporting programs abroad often hold Defense information on their own systems. Sentfore works at the delivery end of defense programs in difficult environments, providing secure movement, protective security, facilities and life support. Requirements can be sent through the contact page.