How to get CMMC certified?
The Cybersecurity Maturity Model Certification (CMMC) is a US Government program that is mandatory for the US Defense Industrial Base (DIB), including prime and sub-contractors. CMMC exists to provide an independent conformity assessment for a contractor’s implementation of NIST SP 800-171 that is assessed according to the Assessment Objectives (AOs) found in NIST SP 800-171A. Therefore, from a high-level summary perspective to get CMMC certification, an Organization Seeking Certification (OSC) needs to:
- Implement appropriate evidence of due diligence and due care to demonstrate all NIST SP 800-171A AOs are addressed (e.g., policies, standards, procedures, SSP, POA&M, etc.); and
- Hire a CMMC Third-Party Assessment Organization (C3PAO) to conduct a CMMC assessment.
CMMC 2.0 Certification Levels
CMMC 2.0 is currently based on NIST SP 800-171 R2 and NIST SP 800-171A. There are three (3) CMMC 2.0 levels:
- CMMC 2.0 Level 1: Basic Safeguarding of FCI
- Requirements: Annual self-assessment and annual affirmation of compliance with the 15 security requirements in FAR clause 52.204-21.
- CMMC 2.0 Level 2: Broad Protection of CUI
- Requirements:
- Either a self-assessment or a C3PAO assessment every three years, as specified in the solicitation.
- Decided by the type of information processed, transmitted, or stored on the contractor or subcontractor information systems.
- Annual affirmation, verify compliance with the 110 security requirements in NIST SP 800-171 Revision
- Either a self-assessment or a C3PAO assessment every three years, as specified in the solicitation.
- Requirements:
- CMMC 2.0 Level 3: Higher-Level Protection of CUI Against Advanced Persistent Threats
- Requirements:
- Successfully demonstrate conformity with CMMC 2.0 Level 2.
- Undergo an assessment every three years by the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).
- Provide an annual affirmation verifying compliance with the 24 identified requirements from NIST SP 800-172.
- Requirements:
ComplianceForge CMMC Policy & Procedures Templates
ComplianceForge is a leader in CMMC policies, standards and procedures templates. If you need editable cybersecurity documentation templates, then it is worth your time to look at ComplianceForge. There is no software to install, just editable Microsoft Word and Excel templates that give you the ability to edit the cybersecurity policies, standards and procedures for your specific needs.