NCP 2024.1
Expanded NCP scoping beyond NIST 800-171 R2 and CMMC 2.0 to cover DFARS, FAR and ITAR requirements, and added an Evidence Request List, risk catalog and threat catalog.
What changed in this release
- The roles and responsibilities within the Cybersecurity Standardized Operating Procedures (CSOP) were upgraded to the latest version of the NIST NICE Cybersecurity Workforce Framework.
- The Unified Scoping Guide (USG) was updated, and the NCP contains that new version.
- An Excel spreadsheet from the Secure Controls Framework (SCF) was added, showing the Set Theory Relationship Mapping (STRM) between NIST 800-171 and the SCF controls, which are used as the basis for the structure of the NCP.
- The NCP - NIST 800-171 & CMMC Compliance Criteria (NC3) and Framework Mapping document now includes an Evidence Request List (ERL) that maps reasonable artifacts and evidence to controls, a risk catalog, and a threat catalog.
- The scoping of the NCP’s policies, standards and procedures was expanded to include more than just NIST 800-171 R2 and CMMC 2.0, based on common FAR requirements, ITAR implications for CUI, and evidence that C3PAOs are asking for in assessments. This covers DFARS 252.204-7008, 252.204-7012, 252.204-7019, 252.204-7020 and 252.204-7021; FAR 52.204-21, 52.204-27 and Section 889; and the International Traffic in Arms Regulation (ITAR).
Releases older than 2024 (2023 and beyond) are not covered by this errata archive and are significantly out of date. Existing customers are encouraged to repurchase the current version at 50% of the original product price.