In November 2021, the Office of the Under Secretary of Defense for Acquisition and Sustainment in the United States Department of Defense (DoD) released v2.0 of the Cybersecurity Maturity Model Certification (CMMC), a comprehensive framework to protect the defense industrial base from increasingly frequent and complex cyberattacks and to ensure that our entire national defense supply chain is secure and resilient.
CMMC requires companies to achieve certification against cybersecurity and controlled unclassified information (CUI) handling best practices, with that certification eventually determining whether a company can be awarded a contract by the DoD.
All DoD suppliers must be certified in one of three levels, from Level 1 (Foundational) to Level 3 (Expert), based on the security requirements for controlled unclassified information (CUI) from FAR Clause 204-21, the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 and additional controls from NIST SP 800-172 Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171.
Companies and Certified Third-Party Audit Organizations (C3PAOs) can leverage the Prevalent Third-Party Risk Management Platform with built-in questionnaires to assess against all three levels of CMMC certification.
Level 1 – Self-assessment performed by the supplier against 17 controls. This level of certification is considered foundational and for suppliers managing information that is not critical to national security.
Level 2 – A more advanced level of certification performed by third-party auditors against 110 controls in the NIST SP 800-171 standard. This level is considered for companies that have controlled unclassified information (CUI).
Level 3 – Considered an expert level for the highest-priority DoD suppliers, this level builds on Level 2 by adding a subset of NIST SP 800-172 controls on top. The federal government will conduct the audits for companies at this level.
Prevalent for CMMC Auditors
CMMC certified auditors can use the Prevalent Third-Party Risk Management Platform with all three levels of CMMC controls questionnaires included.
Prevalent for CMMC Responders
Suppliers and DoD contractors can use the Prevalent Third-Party Risk Management Platform to conduct a Level 1 and Level 2 self-assessments.
Align Your TPRM Program with ISO, NIST, SOC 2 and More
Download this guide to review specific requirements from 11 different cybersecurity authorities, identify TPRM capabilities that map to each requirement, and uncover best practices for ensuring compliance.
Meeting CMMC TPRM Requirements
Please see the table below for a summary of CMMC requirements by level, organized by NIST SP 800-171r2 Relevant Security Controls, that are included as built-in questionnaires in the Prevalent Platform. Information on Level 3 will be released by the US DoD at a later date and will contain a subset of the security requirements specified in NIST SP 800-172.
Access Control | |
---|---|
Level 1 3.1.1 Authorized Access Control |
Level 2 3.1.3 Control CUI Flow |
Awareness & Training | |
---|---|
Level 1 N/A |
Level 2 3.2.1 Role-Based Risk Awareness |
Audit & Accountability | |
---|---|
Level 1 N/A |
Level 2 3.3.1 System Auditing |
Configuration Management | |
---|---|
Level 1 N/A |
Level 2 3.4.1 System Baselining |
Identification and Authentication | |
---|---|
Level 1 3.5.1 Identification |
Level 2 3.5.3 Multi-factor Authentication |
Incident Response | |
---|---|
Level 1 N/A |
Level 2 3.6.1 Incident Handling |
Maintenance | |
---|---|
Level 1 N/A |
Level 2 3.7.1 Perform Maintenance |
Media Protection | |
---|---|
Level 1 3.8.3 Media Disposal |
Level 2 3.8.1 Media Protection |
Personnel Security | |
---|---|
Level 1 N/A |
Level 2 3.9.1 Screen Individuals |
Physical Protection | |
---|---|
Level 1 3.10.1 Limit Physical Access |
Level 2 3.10.2 Monitor Facility |
Risk Assessment | |
---|---|
Level 1 N/A |
Level 2 3.11.1 Risk Assessments |
Security Assessment | |
---|---|
Level 1 N/A |
Level 2 3.12.1 Security Control Assessment |
System and Communications Protection | |
---|---|
Level 1 3.13.1 Boundary Protection |
Level 2 3.13.2 Security Engineering |
System and Information Integrity | |
---|---|
Level 1 3.14.1 Flaw Remediation |
Level 2 3.14.3 Security Alerts & Advisories |
The Prevalent Third-Party Risk Management Platform offers built-in questionnaires for each level of CMMC certification. This enables the DoD to assess high-priority suppliers; auditors to assess their clients; and suppliers to assess themselves and their suppliers for compliance against each level.
C3PAOs and the federal government can:
Any DoD supplier can conduct a Level 1 or Level 2 self-assessment to:
CMMC v2.0 streamlines certification levels, eliminates proprietary maturity layers, and adjusts third-party risk assessment responsibilities. Learn...
In this webinar, Jeff Dalton, Board Director with the CMMC Accreditation Body and Chairman of its...
Benchmark your TPRM program against requirements from 11 cybersecurity authorities.