BREAKING NEWS from “As the CMMC Churns”….
The Cyber-AB, with DoD’s implicit blessing, is now allowing Authorized C3PAOs to conduct formal NIST SP 800-171 Assessments for organizations both inside and outside of the Defense Industrial Base.
This is great news because DIBCAC Joint Voluntary Surveillance Assessments (JVSA) are constricted by DoD Lawyers to Prime contractors and companies identified in the DoD contract.
NIST SP 800-171 Assessments by an Authorized C3PAO now provide organizations with a separate method to demonstrate conformity to their DIB partners and grow their business. This extends to International DIB companies, MSPs, MSSP, and even some Cloud Service Providers will benefit.
Catch-22 is that DoD doesn’t want this to bollix up CMMC while it is in rulemaking. So, officially from the Cyber-AB, “Assessments of the conformity to the NIST SP 800-171 Standard by Authorized CMMC Third-Party Assessment Organizations (C3PAO) do not convey any reciprocity or advanced standing with the United States Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) initiative, nor will they result in a certification recognized by the DoD of the CMMC Accreditation Body Inc.”
Key CMMC Organizations
- National Archives & Records Administration Controlled Unclassified Information (CUI) Homepage
- DoD CIO’s Cybersecurity Maturity Model Certification (CMMC) Home Page
- Cyber Accreditation Body (Cyber-AB)
- Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) Contractor Resource Page
- Defense Industrial Base (DIB) Cybersecurity Portal
Key Regulations
Key Acquisition References
- 48 CFR § 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems
- DFARS Clause 252.204-7008 Compliance with Safeguarding Covered Defense Information Controls.
- DFARS Clause 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
- DFARS Clause 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS Clause 252.204-7020 NIST SP 800-171 DoD Assessment Requirements.
- DFARS Clause 252.204-7021 Compliance with the Cybersecurity Maturity Model Certification Level Requirements.