Is your organization confused about where to apply NIST SP 800-171 requirements?
How does the DoD’s CMMC Assessment Guide in?
This entry into As the CMMC Churns is the 1st part in a two-parter where we lay out the confusion between the NIST SP 800-171 “Scope of Applicability” that organizations are required to apply and the CMMC Assessment Scoping Guide’s “CMMC Assessment Scope.” This part specifically looks at the NIST SP 800-171 “Scope of Applicability” and how it applies to an organization.
Our next part will look at the “CMMC Assessment Scope” and its relationship to the “Scope of Applicability.”
Key CMMC Organizations
- National Archives & Records Administration Controlled Unclassified Information (CUI) Homepage
- DoD CIO’s Cybersecurity Maturity Model Certification (CMMC) Home Page
- Cyber Accreditation Body (Cyber-AB)
- Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) Contractor Resource Page
- Defense Industrial Base (DIB) Cybersecurity Portal
Key Regulations
Key Acquisition References
- 48 CFR § 52.204-21 – Basic Safeguarding of Covered Contractor Information Systems
- DFARS Clause 252.204-7008 Compliance with Safeguarding Covered Defense Information Controls.
- DFARS Clause 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting.
- DFARS Clause 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS Clause 252.204-7020 NIST SP 800-171 DoD Assessment Requirements.
- DFARS Clause 252.204-7021 Compliance with the Cybersecurity Maturity Model Certification Level Requirements.