CMMC Final Rule Basics: What You Need to Know
Discover the key details in the CMMC Final Rule, including streamlined assessments and implementation timelines. This guide is essential for defense contractors preparing for compliance in the evolving cybersecurity landscape.
Editors note: This CMMC Final Rule blog has been updated to reflect the latest information as a result of the publication of final Title 32 Rule: Cybersecurity Maturity Model Certification (CMMC) Program.
The Federal Register published the Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) Program final rule in 32 CFR on October 15, 2024. After years of debate, evolution, and general confusion, we finally have a final rule in the 32 CFR. This proposed rule was complemented by the proposed rule in 48 CFR, which when finalized will codify CMMC into contracts. To read more about the 48 CFR proposed rule, check out our blog on the topic.
CFR 32 part 170 and its supplemental documents clock in at over 470 pages and offer much detail around the CMMC Program implementation. Overall, if you follow CMMC regularly, there were very few surprises. All the basics around CMMC stayed true to the CMMC 2.0 program structure announced in November 2021. The “surprise” in the final rule was the level of clarity provided to many open questions around the program.
This post covers the basics of the rule and serves as a primer for additional content that will follow this post. We will build off this baseline with more insight and commentary as CMMC goes into effect and matures.
Here’s what you need to know:
CMMC Nomenclature
First things, first, the final rule updated the nomenclature for the CMMC program. The following table lists the term and its meaning.
|
Term |
Meaning |
|
OSA |
Organization Seeking Assessment |
|
OSC |
Organization Seeking Certification |
|
C3PAO |
Certified Third Party Assessment Organization |
|
Level 1 (Self) |
CMMC Status that requires the OSA to implement CMMC Level 1 requirements and complete a self-assessment |
|
Level 2 (Self) |
CMMC Status that requires the OSA to implement CMMC Level 2 requirements and complete a self-assessment |
|
Level 2 (C3PAO) |
CMMC Status that requires the OSC to implement CMMC Level 2 requirements and complete a third-party assessment from a C3PAO |
|
Level 3 (DIBCAC) |
CMMC Status that requires the OSA to implement CMMC Level 2 requirements and complete a third-party assessment from the DIBCAC (DoD agency) |
|
Conditional [CMMC Level] |
CMMC Status that denotes an OSA has conducted an assessment and reached a minimum score, but has open items it must still resolve. |
|
Final [CMMC Level] |
CMMC Status that denotes that an OSA has achieved a perfect score in its assessment. |
|
Certificate of CMMC Status |
If a C3PAO deems the OSC to have met the requirements for assessment, then they will be awarded a Certificate of CMMC Status. Note this certificate is only valid for the specific assessed network, and not for the organization as a whole. |
|
Operational Plan of Action |
A formal artifact that identifies temporary vulnerabilities and deficiencies and documents how they will be addressed. |
|
Plan of Action & Milestones (POA&M) |
Used (when possible) to turn a Conditional [CMMC Level] into a Final [CMMC Level]. It identifies tasks that need to be accomplished, the resources required to accomplish the plan, milestones for meeting the tasks, and scheduled completion dates. |
|
Customer Responsibility Matrix (CRM) |
A document that describes the responsibilities of the OSA and the external service provider with respect to the services provided. |
CMMC Final Rule & Program Overview
This section outlines the overall program as well as the underlying process and regulations.
Protecting FCI and CUI
There is a long and well documented need for defense contractors to protect sensitive information. The CMMC Program is meant to “ensure defense contractors and subcontractors have…implemented required security measures to expand application of existing security requirements for Federal Contract Information (FCI) and add new Controlled Unclassified Information (CUI) security requirements for certain priority programs.”
Understanding the Different CMMC Rulemaking Processes
There are references in the proposed rule to the Code of Federal Regulations (CFR) and in particular 32 CFR and 48 CFR.
The final rule that was published in October 2024 is a change to Title 32 of the CFR. Without falling into a black hole of federal rulemaking process and nuance, the CFR includes the permanent regulations established by the agencies and executive departments of the U.S. federal government. Title 32 of the CFR includes the regulations dealing with national defense. The DoD’s proposed rule in 32 CFR establishes the basis of the CMMC program and will be effective on December 16, 2024.
Rulemaking in 32 CFR is complemented by additional rulemaking in a change to Title 48. Title 48 of the CFR deals with government procurement and is where the Federal Acquisition Regulation (FAR) and Defense Federal Acquisition Regulation Supplement (DFARS) are established. Technically speaking, rulemaking in 48 CFR will include the actual changes to the contract language for CMMC program requirements, such as DFARS 252.204-7021. The Title 48 proposed rule was published August 14, 2024. The industry widely believes that the final CFR 48 rule will be published in Spring 2025.
Referenced Rules and Clauses
The proposed rule references multiple regulations, rules, and clauses. However, the core of the proposed rule builds off several existing FAR and DFARS clauses.
FAR clause 52.204-21, Basic Safeguarding of Covered Contractor Information Systems, outlines 15 basic security requirements that can be mapped to a subset of the requirements in NIST SP 800-171, rev. 2. This is the required level for protection for FCI.
DFARS clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, is the cornerstone of DoD efforts to protect CUI data. Specifically, the clause:
- Requires contractors to provide “adequate security” for all covered contractor covered information systems1
- Mandates implementation of NIST SP 800-171 on all covered contractor information systems
- Requires that Cloud Service Providers used by the contractor to store, process, or transmit CUI be FedRAMP-Authorized at the Moderate baseline or meet equivalent security requirements
- Specifies cyber incident reporting and related requirements in clauses (c) through (g)
DFARS clause 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements, requires contractors to conduct a self-assessment according to “NIST SP 800-171 DoD Assessment Methodology.” This methodology is based on NIST SP 800-171A. Self-assessment scores must be reported to the Supplier Performance Risk System (SPRS) and be less than three years old.
DFARS clause 252.204-7020, NIST SP 800-171 DoD Assessment Requirements, establishes the DoD’s right to:
- Directly conduct higher-level assessments of contractors’ cybersecurity compliance beyond the self-assessment requirement in DFARS 252.204-7019 (i.e., to review the contractor’s System Security Plan and self-assessment documentation, or to directly assess the contractor’s implementation of NIST SP 800-171)
- Requires contractors to give DoD assessors full access to facilities, systems, and personnel
DFARS 252.204-7021, Cybersecurity Maturity Model Certification Requirements, paves the way for the rollout of the CMMC Program. Originally issued as an interim final rule in 2020, this clause will be updated with 48 CFR (DFARS Case 2019-D041). To learn more about this proposed rule, check out our blog on this topic.
Three Levels of CMMC
The CMMC proposed rule includes three maturity levels aimed at protecting FCI (Level 1), CUI (Level 2), and defending against advanced persistent threats such as nation-state actors (Level 3).
|
Level |
Purpose |
Explanation |
|
Level 1 |
Basic safeguarding of Federal Contract Information (FCI) |
Provides foundational cybersecurity practices to protect Federal Contract Information (FCI) with 15 essential practices as defined in FAR clause 52.204-21. |
|
Level 2 |
Broad protection of Controlled Unclassified Information (CUI) |
Broadly safeguards Controlled Unclassified Information (CUI) by aligning with NIST SP 800-171 Rev 2 standards, incorporating 110 controls. |
|
Level 3 |
Protection of CUI against Advanced Persistent Threats (APTs) |
Focuses on reducing risks posed by APTs, with advanced cybersecurity measures to protect CUI. This level applies to contractors playing key roles in defense and incorporates an additional 24 controls from NIST SP 800-172. |
As a reminder, the agency responsible for overseeing the federal CUI program, the U.S. National Archives and Records Administration (NARA), highlights the difference between FCI and CUI this way: “While FCI is any information that is ‘not intended for public release,’ CUI is information that requires safeguarding.” [emphasis added]
More details on the differences between CUI and FCI can be found in this blog post.
Types of CMMC Assessments
The Final CMMC rule requires different types of assessments based on the sensitivity of the information being protected and the required CMMC Level. Contracting officers and program managers will use DoD policy to determine the level of data protection required based on the type of information expected to be processed, stored, or transmitted as part of the fulfillment of the contract.
Level 1 Self-Assessment:
The only assessment available for Level 1 is a self-assessment. The assessments are based on the security requirements in FAR 52.204-21. Self-assessments must be performed annually, and scores must be entered into SPRS. Assessments are affirmed by a senior official of the contractor. Note that unlike in Level 2 and 3, the Level 1 self-assessment is pass/fail. Failure to fully meet the requirements of any one of the requirements will result in a failed assessment with no eligibility for a “Plan of Action & Milestone (POA&M)” to remediate the issue. Once passed, the contractor will have achieved a CMMC Status of Level 1 (Self) and be eligible for any contracts with such a requirement.
Level 2 Self-Assessment:
Level 2 self-assessments are based on the requirements outlined in NIST SP 800-171, rev. 2 and determined by the contracting officer and program manager as part of the contracting process. Select contracts (estimated to be 4.9% of Level 2) will allow for a self-assessment even though the contract contains CUI. Level 2 self-assessments are performed annually and affirmed by an “affirming official,” which is a senior level representative from the contractor who is responsible for the organization’s compliance with CMMC. Such affirmations are provided after the assessment, and if applicable, at POA&M closeout.
Which contracts will require a CMMC Status of Level 2 (Self) rather than Level 2 (C3PAO) is still unclear but will be subject to the determination of Program Managers. If a POA&M is required, then the organization receives a CMMC Status of Conditional Level 2 until the POA&M is either closed out or expires after 180 days). Once finalized, the OSA will have achieved a CMMC Status of Final Level 2 (Self). Level 2 self-assessments will require annual affirmations from an affirming official and a full self-assessment triennially (every three years).
Level 2 Certification Assessment:
Some contracts will require a CMMC Status of Level 2 (C3PAO), which will feature the following requirements:
- Implementation of the security requirements in NIST SP 800-171, rev. 2
- Assessments performed by a CMMC Third-Party Assessment Organization (C3PAO) that has been certified by the Accreditation Body (The Cyber AB)
- Assessment results entered into CMMC Enterprise Mission Acceptance Support Service (eMASS) which electronically transmits to SPRS
- Contractors must be reassessed by a C3PAO triennially, and an affirming official of the contractor must reaffirm compliance annually.
Regardless of the assessment type, all contractors seeking Level 2 status for their environments will have limited ability to use a POA&M to remediate some assessment objectives deemed “NOT MET” in the assessment. However, many requirements constitute “automatic failure” if they are not found to be MET during the assessment. Any allowed POA&M items must be closed out within 180 days before a final certification will be issued. Contracts with this status are designated “Conditional Level 2 (Self)” or “Conditional Level 2 (C3PAO)” according to the type of assessment conducted.
Level 3 Certification Assessment:
Contracts that require a CMMC Status of Level 3 (DIBCAC) will feature the following requirements:
- CMMC Level 2 (C3PAO) certification is a prerequisite (i.e., full implementation of NIST SP 800-171, rev. 2)
- Additional Level 3 (DIBCAC) certification is based on implementation of 24 selected security requirements from NIST SP 800-172
- Assessments will be performed by the DoD DIBCAC
- Results will be entered into CMMC eMASS which electronically transmits to SPRS
- The assessment score is affirmed by an affirming official of the contractor after each assessment, including POA&M closeout, and annually thereafter
- While some select Level 3 requirements may be eligible for a POA&M, they must all be closed out within 180 days. Contractors in this status will be designated “Conditional Level 3 (DIBCAC).”
What Else Should You Know?
Timelines: One of the few surprises in the final rule involves the timeline for implementation, which was adjusted from the proposed rule. Technically, CMMC goes into effect at the latter effective date of 32 CFR or 48 CFR. It’s currently assumed that 48 CFR will be at some point early next year which will trigger the implementation process immediately.
Assuming 48 CFR goes into effect at the end of the first quarter of 2025, then the implementation timelines will be as follows:
|
Phase |
Start |
Impact |
|
Phase 1 |
April 2025 |
Level 1 (Self) and Level 2 (Self) requirements appear in new contracts. |
|
Phase 2 |
April 2026 (One year after start of Phase 1) |
Level 2 (C3PAO) requirements start to appear in new contracts. Level 2 (C3PAO) requirements start to appear in renewal and option year contracts. |
|
Phase 3 |
April 2027 (One year after the start of Phase 2) |
Level 3 (DIBCAC) requirements start to appear in new contracts. |
|
Phase 4 |
April 2028 (One year after the start of Phase 3) |
CMMC requirements appear in all applicable DoD contracts. |
Assessment achievement against multiple contracts
CMMC Statuses are awarded to an assessed environment, not holistically to the organization itself. If an organization seeks multiple contracts, either the assessment scope must be inclusive of activities required for each contract or separate assessments must be conducted.
Conditional Assessments & POA&Ms
The proposed rule contains some limited flexibility around the concern of CMMC being fully pass/fail. At Level 2, if the assessment results meet a minimum score of 88, if there are no unmet security requirements with a point value greater than 1 (with the exception of 3.13.11, which may be included if encryption is employed but is not FIPS-validated), and the following “can’t miss” requirements (3.1.20, 3.1.22, 3.12.4, 3.10.3, 3.10.4, and 3.10.5) are all met, the contractor has a Conditional Assessment. Depending on the type of assessment, this CMMC status is designated either “Conditional Level 2 (Self)” or “Conditional Level 2 (C3PAO).” The contractor then has 180 days to close out the POA&M, at which point the contractor must, in the case of a self-assessment, conduct a Final Self-Assessment or, in the case of a certification assessment, obtain a POA&M Closeout Assessment performed by a C3PAO to receive a Final Certification Assessment. This status is designated “Final Level 2 (C3PAO).” Note that in such cases, the renewal date of the three–year assessment period begins on the initial date the organization achieved the Conditional Level 2 status. In either case, if the POA&M is not closed out within 180 days, the Conditional Assessment will expire.
Operational Plans of Action
The final CMMC rule allows organizations to use an “operational plan of action” at any CMMC level “to address necessary information system updates, patches, or reconfiguration as threats evolve.” This is separate and distinct from the POA&M described above and is used to address when a security requirement or control was fully implemented but has since fallen out of compliance. It enables the OSA to maintain their CMMC status while seeking to resolve temporary vulnerabilities or deficiencies, for example due to necessary system updates, patches, or reconfiguration as threats evolve. Any significant changes to the information system beyond the use of operational plans of action require a new assessment and a new affirmation.
NIST SP 800-171 Rev 2
Revision 2 of NIST SP 800-171 is hard coded throughout the final rule. While the DoD anticipates that a future amendment to the rule will incorporate the current version at that time, the final rule now and for the foreseeable future remain Rev 2. The DoD went further to clarify the intent to maintain Rev 2 in a memo that resolved any doubt on this issue.
Level 3 and NIST SP 800-172
As expected, CMMC Level 3 (DIBCAC) requires contractors to meet 24 selected requirements from NIST SP 800-172. CMMC Level 2 (C3PAO) is a prerequisite for CMMC Level 3 (DIBCAC). Titled Enhanced security Requirements for Controlled Unclassified Information, NIST SP 800-172 is designed for CUI “associated with a critical program of high value asset.”
6-year Artifact Retention Requirement
The final CMMC rule mandates that artifacts be retained for six years, specifically “OSCs must retain artifacts used as evidence for the assessment for the duration of the validity period of the certificate of assessment, and at minimum, for six years from the date of certification assessment.
Discussion of Public Comments and Resulting Changes
Over half of the final rule is dedicated to the comments from the proposed rule and much of the changes made to the final version reflect the seriousness the DoD took the comment submissions. General sentiment in the industry is that the DoD provided more detail than expected and overall made many practical, smart updates.
Cost Analysis
The DoD provided an extensive analysis and justification for the costs associated with the CMMC Program. Essentially, the DoD considers the cybersecurity measures required to meet FCI and CUI protection to be sunk costs, as the requirement to implement NIST SP 800-171 has been in effect for all DoD contracts since the end of 2017. (For a history of DoD cybersecurity requirements, check out this infographic.) The cost analyses in the final rule center around the costs associated with the assessment and affirmation processes. We’ll provide additional analysis of CMMC program costs in an upcoming post.
Just the Start
The final rule in 32 CFR is just the start. In addition, the DoD published the following supporting materials on the DoD CIO website. This site has the latest versions of multiple documents including:
- CMMC Model Overview
- CMMC Level 1 Scoping Guide
- CMMC Level 1 Assessment Guide
- CMMC Level 2 Scoping Guide
- CMMC Level 2 Assessment Guide
- CMMC Level 3 Scoping Guide
- CMMC Hashing Guide
Our Commitment
For more than seven years, C3 Integrated Solutions has been committed to supporting the Defense Industrial Base with innovative technology & cybersecurity solutions, day-to-day IT management, and the professional services, consulting, and support required to protect our nation’s critical data. As one of the first MSPs to provide Microsoft GOV CLOUD services, we have developed groundbreaking services and solutions—such as the Steel Root Compliance Platform—explicitly designed to accelerate and maintain CMMC compliance. Learn more about our CMMC services.
Chat with a Consultant
[1] Information on the Department’s agenda for all rulemakings can be found at https://www.reginfo.gov/public/do/eAgendaMain and then selecting the relevant agency and rule name.
[2] Covered contractor information systems are unclassified systems that store, process or transmit CUI. Generally, these are the systems that are commonly considered “in scope” for compliance assessments.