As the CMMC Churns
FInger Pointing and the Customer Responsibility Matrix (CRM)
Did you know your need a CRM for your CMMC Conformity Assessment?
No, not a Customer Responsibility Management application–you need a Customer Responsibility Matrix (CRM).
If you don’t know:
What a CRM is?
Why it is needed?
Which of your External Service Provider’s it applies to?
How to fill it out?
And, how it plays into your Conformity Assessment?
Well then, this video is for you. In the video, we will answer all of your questions. Our answers actually come from multiple engagements with the Defense Industrial Base Cybersecurity Assurance Center (DIBCAC), including our CMMC certification by them.
We also reference the Peak InfoSec Customer Responsibility Matrix (CRM) Template. It can be downloaded at https://peakinfosec.com/wp-content/uploads/2022/08/Peak_InfoSec_Customer_Responsibility_Matrix_Template.xlsx.
Key CMMC Organizations
- National Archives & Records Administration Controlled Unclassified Information (CUI) Homepage
- DoD CIO’s Cybersecurity Maturity Model Certification (CMMC) Home Page
- Cyber Accreditation Body (Cyber-AB)
- Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) Contractor Resource Page
- Defense Industrial Base (DIB) Cybersecurity Portal
Key Regulations
Key Acquisition References
- 48 CFR § 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems
- DFARS Clause 252.204-7008 Compliance with Safeguarding Covered Defense Information Controls.
- DFARS Clause 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
- DFARS Clause 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS Clause 252.204-7020 NIST SP 800-171 DoD Assessment Requirements.
- DFARS Clause 252.204-7021 Compliance with the Cybersecurity Maturity Model Certification Level Requirements.