# Peak InfoSec: Authority for CUI, NIST SP 800\-171, CMMC, and ISO > Authorized C3PAO providing CMMC assessments, NIST 800\-171 consulting, and cybersecurity training for defense contractors\. Generated by Yoast SEO v28.4, this is an llms.txt file, meant for consumption by LLMs. ## Pages - [About \- New](https://peakinfosec.com/about-us/) - [CMMC Level 2 Requirements](https://peakinfosec.com/cmmc-level-2-requirements/) - [CMMC Level 3 Requirements](https://peakinfosec.com/cmmc-level-3-requirements/) - [CMMC Level 1 Requirements](https://peakinfosec.com/cmmc-level-1-requirements/) - [CMMC \& NIST SP 800\-171 Consulting](https://peakinfosec.com/cmmc-nist-sp-800-171-consulting/) - [Careers](https://peakinfosec.com/careers/) - [CMMC 3rd Party Assessment Organization \(C3PAO\)](https://peakinfosec.com/cmmc-3rd-party-assessment-organization-c3pao/) ## Posts - [Organization\-Defined Paramenters \(ODP\)](https://peakinfosec.com/as-the-cmmc-churns/organization-defined-paramenters-odp/): NIST SP 800\-171 Revision 3 introduced 88 Organization\-Defined Parameters \(ODP\) Assessment Objectives \(AO\) out of 510 AOs\. Those ODPs were specified by the Department of War \(DOW\), which may also be mandated across the Federal government when the FAR CUI rule is published\. There are significant issues with the application of those ODPs Mobile Devices, Internet of Things \(IoT\), Industrial Control Systems \(ICS\), and Operation Technologies \(OT\)\. - [System Design Parameters Plan for NIST SP 800\-171 Rev 2](https://peakinfosec.com/template/system-design-parameters-plan-for-nist-sp-800-171-rev-2/) - [System Design Parameters Plan for NIST SP 800\-171 Rev 3](https://peakinfosec.com/template/system-design-parameters-plan-for-nist-sp-800-171-rev-3/) - [How to Survive a DIBCAC Non\-Voluntary Assessment](https://peakinfosec.com/as-the-cmmc-churns/how-to-survive-a-dibcac-non-voluntary-assessment/): Did you get a letter emailed to you from the Defense Industrial Base Cybersecurity Assurance Center \(DIBCAC\) notifying your organization they intend to conduct a "High Assessment" of your DFARS Clause 252\.204\-7012, "Safeguarding Covered Defense Information and Cyber Incident Reporting" compliance and NIST SP 800\-171, “Protecting Controlled Unclassified Information \(CUI\) in Nonfederal Systems and Organizations” implementation?  If so, "As the CMMC Churns" is perfect for you\.  This episode draws on over a dozen DIBCAC assessments/audits we have completed as Peak InfoSec\.  The episode explains the purpose of the DIBCAC audit, the consequences if it goes sideways, and 5 key survival rules to follow when preparing for your DIBCAC audit\. ## Categories - [As the CMMC Churns](https://peakinfosec.com/category/as-the-cmmc-churns/) - [Information Security](https://peakinfosec.com/category/information-security/) - [DFARS \& NIST SP 800\-171](https://peakinfosec.com/category/dfards-and-nist-sp-800-171/) - [Compliance](https://peakinfosec.com/category/compliance/) - [CMMC](https://peakinfosec.com/category/cmmc/) ## Tags - [cmmc](https://peakinfosec.com/tag/cmmc/) - [DoD](https://peakinfosec.com/tag/dod/) - [certification](https://peakinfosec.com/tag/certification/) - [NIST SP 800\-171 Rev 2](https://peakinfosec.com/tag/nist-sp-800-171-rev-2/) - [Information Security](https://peakinfosec.com/tag/information-security/) ## Optional - [Sitemap index](http://peakinfosec.com/sitemap_index.xml)