PART 170—CYBERSECURITY MATURITY MODEL CERTIFICATION (CMMC) PROGRAM Authority: 5 U.S.C. 301; Sec. 1648, Pub. L. 116-92, 133 Stat. 1198. Source: 89 FR 83214, Oct. 15, 2024, unless otherwise noted. Subpart A—General Information. § 170.1 Purpose. (a) This part describes the Cybersecurity Maturity Model Certification (CMMC) Program of the Department of Defense (DoD) and establishes requirements for defense contractors and subcontractors to implement prescribed cybersecurity standards for safeguarding Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). This part (the CMMC Program) also establishes requirements for conducting an assessment of compliance with the applicable prescribed cybersecurity standard for contractor information systems that: process, store, or transmit FCI or CUI; provide security protections for systems which process, store, or transmit CUI; or are not logically or physically isolated from systems which process, store, or transmit CUI. (b) The CMMC Program provides DoD with a viable means of conducting the volume of assessments necessary to verify contractor and subcontractor implementation of required cybersecurity requirements. (c) The CMMC Program is designed to ensure defense contractors are properly safeguarding FCI and CUI that is processed, stored, or transmitted on defense contractor information systems. FCI and CUI must be protected to meet evolving threats and safeguard nonpublic, unclassified information that supports and enables the warfighter. The CMMC Program provides a consistent methodology to assess a defense contractor's implementation of required cybersecurity requirements. The CMMC Program utilizes the security standards set forth in the 48 CFR 52.204-21; National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, Basic Safeguarding of Covered Contractor Information Systems, Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171, (d) The CMMC Program balances the need to safeguard FCI and CUI and the requirement to share information appropriately with defense contractors in order to develop capabilities for the DoD. The CMMC Program is designed to ensure implementation of cybersecurity practices for defense contractors and to provide DoD with increased assurance that FCI and CUI information will be adequately safeguarded when residing on or transiting contractor information systems. (e) The CMMC Program creates no right or benefit, substantive or procedural, enforceable by law or in equity by any party against the United States, its departments, agencies, or entities, its officers, employees, or agents, or any other person. § 170.2 Incorporation by reference. Certain material is incorporated by reference into this part with the approval of the Director of the Federal Register under 5 U.S.C. 552(a) and 1 CFR part 51. Material approved for incorporation by reference (IBR) is available for inspection at the Department of Defense (DoD) and at the National Archives and Records Administration (NARA). Contact DoD online: https://DoDcio.defense.gov/CMMC/ [email protected] www.archives.gov/federal-register/cfr/ibr-locations [email protected] (a) National Institute of Standards and Technology, U.S. Department of Commerce, 100 Bureau Drive, Gaithersburg, MD 20899; phone: (301) 975-8443; website: https://csrc.nist.gov/publications/ (1) FIPS PUB 200, Minimum Security Requirements for Federal Information and Information Systems, March 2006 (FIPS PUB 200 Mar2006); IBR approved for § 170.4(b). (2) FIPS PUB 201-3, Personal Identity Verification (PIV) of Federal Employees and Contractors, January 2022 (FIPS PUB 201-3 Jan2022); IBR approved for § 170.4(b). (3) SP 800-37, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, Revision 2, December 2018 (NIST SP 800-37 R2); IBR approved for § 170.4(b). (4) SP 800-39, Managing Information Security Risk: Organization, Mission, and Information System View, March 2011 (NIST SP 800-39 Mar2011); IBR approved for § 170.4(b). (5) SP 800-53, Security and Privacy Controls for Information Systems and Organizations, Revision 5, September 2020 (includes updates as of December 10, 2020) (NIST SP 800-53 R5); IBR approved for § 170.4(b). (6) SP 800-82r3, Guide to Operational Technology (OT) Security, September 2023 (NIST SP 800-82r3); IBR approved for § 170.4(b). (7) SP 800-115, Technical Guide to Information Security Testing and Assessment, September 2008 (NIST SP 800-115 Sept2008); IBR approved for § 170.4(b). (8) SP 800-160, Volume 2, Developing Cyber-Resilient Systems: A Systems Security Engineering Approach, Revision 1, December 2021 (NIST SP 800-160 V2R1); IBR approved for § 170.4(b). (9) SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, Revision 2, February 2020 (includes updates as of January 28, 2021), (NIST SP 800-171 R2); IBR approved for §§ 170.4(b) and 170.14(a) through (c). (10) SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information, June 2018 (NIST SP 800-171A Jun2018); IBR approved for §§ 170.11(a), 170.14(d), 170.15(c), 170.16(c), 170.17(c), and 170.18(c). (11) SP 800-172, Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171, February 2021 (NIST SP 800-172 Feb2021); IBR approved for §§ 170.4(b), 170.5(a), and 170.14(a) and (c). (12) SP 800-172A, Assessing Enhanced Security Requirements for Controlled Unclassified Information, March 2022 (NIST SP 800-172A Mar2022); IBR approved for §§ 170.4(b), 170.14(d), and 170.18(c). (b) International Organization for Standardization (ISO) Chemin de Blandonnet 8, CP 401—1214 Vernier, Geneva, Switzerland; phone: +41 22 749 01 11; website: www.iso.org/popular-standards.html (1) ISO/IEC 17011:2017(E), Conformity assessment—Requirements for accreditation bodies accrediting conformity assessment bodies, Second edition, November 2017 (ISO/IEC 17011:2017(E)); IBR approved for §§ 170.8(b)(3), 170.9(b)(13), and 170.10(b)(4). (2) ISO/IEC 17020:2012(E), Conformity assessment—Requirement for the operation of various types of bodies performing inspection, Second edition, March 1, 2012 (ISO/IEC 17020:2012(E)); IBR approved for §§ 170.8(a), (b)(1), (b)(3) and 170.9(b)(2) and (b)(13). (3) ISO/IEC 17024:2012(E), Conformity assessment—General requirements for bodies operating certification of persons, second edition, July 1, 2012 (ISO/IEC 17024:2012(E)); IBR approved for §§ 170.8(b)(2) and 170.10(a) and (b)(4), (7), and (8). Note 1 to paragraph ( b The ISO/IEC standards incorporated by reference in this part may be viewed at no cost in “read only” format at https://ibr.ansi.org § 170.3 Applicability. (a) The requirements of this part apply to: (1) All DoD contract and subcontract awardees that will process, store, or transmit information, in performance of the DoD contract, that meets the standards for FCI or CUI on contractor information systems; and, (2) Private-sector businesses or other entities comprising the CMMC Assessment and Certification Ecosystem, as specified in subpart C of this part. (b) The requirements of this part do not apply to Federal information systems operated by contractors or subcontractors on behalf of the Government. (c) CMMC Program requirements apply to all DoD solicitations and contracts pursuant to which a defense contractor or subcontractor will process, store, or transmit FCI or CUI on unclassified contractor information systems, including those for the acquisition of commercial items (except those exclusively for COTS items) valued at greater than the micro-purchase threshold except under the following circumstances: (1) The procurement occurs during Implementation Phase 1, 2, or 3 as described in paragraph (e) of this section, in which case CMMC Program requirements apply in accordance with the requirements for the relevant phase-in period; or (2) Application of CMMC Program requirements to a procurement or class of procurements may be waived in advance of the solicitation at the discretion of DoD in accordance with all applicable policies, procedures, and approval requirements. (d) DoD Program Managers or requiring activities are responsible for selecting the CMMC Status that will apply for a particular procurement or contract based upon the type of information, FCI or CUI, that will be processed on, stored on, or transmitted through a contractor information system. Application of the CMMC Status for subcontractors will be determined in accordance with § 170.23. (e) DoD is utilizing a phased approach for the inclusion of CMMC Program requirements in solicitations and contracts. Implementation of CMMC Program requirements will occur over four (4) phases: (1) Phase 1. (2) Phase 2. (3) Phase 3. (4) Phase 4, full implementation. § 170.4 Acronyms and definitions. (a) Acronyms. AC—Access Control APT—Advanced Persistent Threat AT—Awareness and Training C3PAO—CMMC Third-Party Assessment Organization CA—Security Assessment CAICO—CMMC Assessors and Instructors Certification Organization CAGE—Commercial and Government Entity CCA—CMMC-Certified Assessor CCI—CMMC-Certified Instructor CCP—CMMC-Certified Professional CFR—Code of Federal Regulations CIO—Chief Information Officer CM—Configuration Management CMMC—Cybersecurity Maturity Model Certification CMMC PMO—CMMC Program Management Office CNC—Computerized Numerical Control CoPC—Code of Professional Conduct CSP—Cloud Service Provider CUI—Controlled Unclassified Information DCMA—Defense Contract Management Agency DD—Represents any two-character CMMC Domain acronym DFARS—Defense Federal Acquisition Regulation Supplement DIB—Defense Industrial Base DIBCAC—DCMA's Defense Industrial Base Cybersecurity Assessment Center DoD—Department of Defense DoDI—Department of Defense Instruction eMASS—Enterprise Mission Assurance Support Service ESP—External Service Provider FAR—Federal Acquisition Regulation FCI—Federal Contract Information FedRAMP—Federal Risk and Authorization Management Program GFE—Government Furnished Equipment IA—Identification and Authentication ICS—Industrial Control System IIoT—Industrial Internet of Things IoT—Internet of Things IR—Incident Response IS—Information System IEC—International Electrotechnical Commission ISO/IEC—International Organization for Standardization/International Electrotechnical Commission IT—Information Technology L#—CMMC Level Number MA—Maintenance MP—Media Protection MSSP—Managed Security Service Provider NARA—National Archives and Records Administration NAICS—North American Industry Classification System NIST—National Institute of Standards and Technology N/A—Not Applicable ODP—Organization-Defined Parameter OSA—Organization Seeking Assessment OSC—Organization Seeking Certification OT—Operational Technology PI—Provisional Instructor PIEE—Procurement Integrated Enterprise Environment PII—Personally Identifiable Information PLC—Programmable Logic Controller POA&M—Plan of Action and Milestones PRA—Paperwork Reduction Act RM—Risk Management SAM—System of Award Management SC—System and Communications Protection SCADA—Supervisory Control and Data Acquisition SI—System and Information Integrity SIEM—Security Information and Event Management SP—Special Publication SPD—Security Protection Data SPRS—Supplier Performance Risk System SSP—System Security Plan (b) Definitions. Access Control (AC) e.g., Accreditation Accreditation Body Advanced Persistent Threat (APT) e.g., Affirming Official Assessment (i) Level 1 self-assessment (ii) Level 2 self-assessment (iii) Level 2 certification assessment (iv) Level 3 certification assessment (v) POA&M closeout self-assessment (vi) POA&M closeout certification assessment Assessment Findings Report Assessment objective Assessment Team Asset e.g., e.g., Asset Categories Authentication Authorized Capability Cloud Service Provider (CSP) e.g., CMMC Assessment and Certification Ecosystem CMMC Assessment Scope CMMC Assessor and Instructor Certification Organization (CAICO) CMMC Instantiation of eMASS CMMC Security Requirements CMMC Status (i) Final Level 1 (Self) (ii) Conditional Level 2 (Self) (iii) Final Level 2 (Self) (iv) Conditional Level 2 (C3PAO) (v) Final Level 2 (C3PAO) (vi) Conditional Level 3 (DIBCAC) (vii) Final Level 3 (DIBCAC) CMMC Status Date CMMC Third-Party Assessment Organization (C3PAO) Contractor Contractor Risk Managed Assets Controlled Unclassified Information (CUI) Controlled Unclassified Information (CUI) Assets DCMA DIBCAC High Assessment (i) Consists of: (A) A review of a contractor's Basic Assessment; (B) A thorough document review; (C) Verification, examination, and demonstration of a contractor's system security plan to validate that NIST SP 800-171 R2 security requirements have been implemented as described in the contractor's system security plan; and (D) Discussions with the contractor to obtain additional information or clarification, as needed; and (ii) Results in a confidence level of “High” in the resulting score. (Source: 48 CFR 252.204-7020). Defense Industrial Base (DIB) DoD Assessment Methodology (DoDAM) Enduring Exception s r Enterprise e.g., External Service Provider (ESP) e.g., Federal Contract Information (FCI) Government Furnished Equipment (GFE) Industrial Control Systems (ICS) e.g., e.g., Information System (IS) Internet of Things (IoT) Operational plan of action e.g., e.g., Operational Technology (OT) Organization-defined Organization-Defined Parameters (ODPs) Note 1 to ODPs: Organization Seeking Assessment (OSA) Organization Seeking Certification (OSC) Out-of-Scope Assets Security Protection Assets Periodically Personally Identifiable Information Plan of Action and Milestones (POA&M) Prime Contractor Process, store, or transmit e.g., e.g., e.g., Restricted Information Systems e.g., e.g., Risk (i) The adverse impacts that would arise if the circumstance or event occurs; and (ii) The likelihood of occurrence, as defined in NIST SP 800-53 R5 (incorporated by reference, see § 170.2). Risk Assessment Security Protection Assets (SPA) Security Protection Data (SPD) Specialized Assets Subcontractor Supervisory Control and Data Acquisition (SCADA) e.g., System Security Plan (SSP) Temporary deficiency Test Equipment User § 170.5 Policy. (a) Protection of FCI and CUI on contractor information systems is of paramount importance to the DoD and can directly impact its ability to successfully conduct essential missions and functions. It is DoD policy that defense contractors and subcontractors shall be required to safeguard FCI and CUI that is processed, stored, or transmitted on contractor information systems by applying specified security requirements. In addition, defense contractors and subcontractors may be required to implement additional safeguards defined in NIST SP 800-172 Feb2021 (incorporated by reference, see § 170.2), implementing DoD specified parameters to meet CMMC Level 3 security requirements (see table 1 to § 170.14(c)(4)). These additional requirements are necessary to protect CUI being processed, stored, or transmitted in contractor information systems, when designated by a requirement for CMMC Status of Level 3 (DIBCAC) as defined by a DoD program manager or requiring activity. In general, the Department will identify a requirement for a CMMC Status of Level 3 (DIBCAC) for solicitations and resulting contracts supporting its most critical programs and technologies. (b) Program managers and requiring activities are responsible for identifying the CMMC Status that will apply to a procurement. Selection of the applicable CMMC Status will be based on factors including but not limited to: (1) Criticality of the associated mission capability; (2) Type of acquisition program or technology; (3) Threat of loss of the FCI or CUI to be shared or generated in relation to the effort; (4) Impacts from exploitation of information security deficiencies; and (5) Other relevant policies and factors, including Milestone Decision Authority guidance. (c) In accordance with the implementation plan described in § 170.3, CMMC Program requirements will apply to new DoD solicitations and contracts, and shall flow down to subcontractors who will process, store, or transmit FCI or CUI in performance of the subcontract, as described in § 170.23. (d) In very limited circumstances, and in accordance with all applicable policies, procedures, and requirements, a Service Acquisition Executive or Component Acquisition Executive in the DoD, or as delegated, may elect to waive inclusion of CMMC Program requirements in a solicitation or contract. In such cases, contractors and subcontractors will remain obligated to comply with all applicable cybersecurity and information security requirements. (e) The CMMC Program does not alter any separately applicable requirements to protect FCI or CUI, including those requirements in accordance with 48 CFR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems, Safeguarding Covered Defense Information and Cyber Incident Reporting, Subpart B—Government Roles and Responsibilities. § 170.6 CMMC PMO. (a) The Office of the Department of Defense Chief Information Officer (DoD CIO) Office of the Deputy CIO for Cybersecurity (DoD CIO(CS)) provides oversight of the CMMC Program and is responsible for establishing CMMC assessment, accreditation, and training requirements as well as developing and updating CMMC Program policies and implementing guidance. (b) The CMMC PMO is responsible for monitoring the CMMC AB's performance of roles assigned in this rule and acting as necessary to address problems pertaining to effective performance. (c) The CMMC PMO retains, on behalf of the DoD CIO(CS), the prerogative to review decisions of the CMMC Accreditation Body as part of its oversight of the CMMC program and evaluate any alleged conflicts of interest purported to influence the CMMC Accreditation Body's objectivity. (d) The CMMC PMO is responsible for sponsoring necessary DCSA activities including FOCI risk assessment and Tier 3 security background investigations for the CMMC Ecosystem members as specified in §§ 170.8(b)(4) and (5), 170.9(b)(3) through (5), 170.11(b)(3) and (4), and 170.13(b)(3) and (4). (e) The CMMC PMO is responsible for investigating and acting upon indications that an active CMMC Status has been called into question. Indications that may trigger investigative evaluations include, but are not limited to, reports from the CMMC Accreditation Body, a C3PAO, or anyone knowledgeable of the security processes and activities of the OSA. Investigative evaluations include, but are not limited to, reviewing pertinent assessment information, and exercising the right to conduct a DCMA DIBCAC assessment of the OSA, as provided for under the 48 CFR 252.204-7020. (f) If a subsequent DCMA DIBCAC assessment shows that adherence to the provisions of this rule and the required CMMC Status have not been achieved or maintained, the DIBCAC results will take precedence over any pre-existing CMMC Status recorded in SPRS, or its successor capability. The DoD will update SPRS to reflect that the OSA is out of compliance and does not meet DoD CMMC requirements. If the OSA is working on an active contract requiring CMMC compliance, then standard contractual remedies will apply. § 170.7 DCMA DIBCAC. (a) DCMA DIBCAC assessors in support of the CMMC Program will: (1) Complete CMMC Level 2 and Level 3 training. (2) Conduct Level 3 certification assessments and upload assessment results into the CMMC instantiation of eMASS, or its successor capability. (3) Issue Certificates of CMMC Status resulting from Level 3 certification assessments. (4) Conduct Level 2 certification assessments of the Accreditation Body and prospective C3PAOs' information systems that process, store, and/or transmit CUI. (5) Create and maintain a process for assessors to collect the list of assessment artifacts to include artifact names, their return value of the hashing algorithm, the hashing algorithm used, and upload that data into the CMMC instantiation of eMASS. (6) As authorized and in accordance with all legal requirements, enter and track, OSC appeals and updated results arising from Level 3 certification assessment activities into the CMMC instantiation of eMASS. (7) Retain all records in accordance with DCMA-MAN 4501-04. (8) Conduct an assessment of the OSA, when requested by the CMMC PMO per §§ 170.6(e) and (f), as provided for under the 48 CFR 252.204-7019 and 48 CFR 252.204-7020. (9) Identify assessments that meet the criteria in § 170.20 and verify that SPRS accurately reflects the CMMC Status. (b) An OSC, the CMMC AB, or a C3PAO may appeal the outcome of its DCMA DIBCAC conducted assessment within 21 days by submitting a written basis for appeal with the requirements in question for DCMA DIBCAC consideration. Appeals may be submitted for review by visiting www.dcma.mil/DIBCAC Subpart C—CMMC Assessment and Certification Ecosystem. § 170.8 Accreditation Body. (a) Roles and responsibilities. (b) Requirements. (1) Be US-based and be and remain a member in good standing of the Inter-American Accreditation Cooperation (IAAC) and become an International Laboratory Accreditation Cooperation (ILAC) Mutual Recognition Arrangement (MRA) signatory, with a signatory status scope of ISO/IEC 17020:2012(E) (incorporated by reference, see § 170.2). (2) Be and remain a member in good standing of the International Accreditation Forum (IAF) with mutual recognition arrangement signatory status scope of ISO/IEC 17024:2012(E) (incorporated by reference, see § 170.2). (3) Achieve and maintain full compliance with ISO/IEC 17011:2017(E) (incorporated by reference, see § 170.2) and complete a peer assessment by other ILAC signatories for competence in accrediting conformity assessment bodies to ISO/IEC 17020:2012(E) (incorporated by reference, see § 170.2), both within 24 months of DoD approval. (i) Prior to achieving full compliance as set forth in this paragraph (b)(3), the Accreditation Body shall: (A) Authorize C3PAOs who meet all requirements set forth in § 170.9 as well as administrative requirements as determined by the Accreditation Body to conduct Level 2 certification assessments and issue Certificates of CMMC Status to OSCs based on the assessment results. (B) Require all C3PAOs to achieve and maintain the ISO/IEC 17020:2012(E) (incorporated by reference, see § 170.2) requirements within 27 months of authorization. (ii) The Accreditation Body shall accredit C3PAOs, in accordance with ISO/IEC 17020:2012(E) (incorporated by reference, see § 170.2), who meet all requirements set forth in § 170.9 to conduct Level 2 certification assessments and issue Certificates of CMMC Status to OSCs based on the results. (4) Ensure that the Accreditation Body's Board of Directors, professional staff, Information Technology (IT) staff, accreditation staff, and independent CMMC Certified Assessor staff complete a Tier 3 background investigation resulting in a determination of national security eligibility. This Tier 3 background investigation will not result in a security clearance and is not being executed for the purpose of government employment. The Tier 3 background investigation is initiated using the Standard Form (SF) 86 ( www.gsa.gov/reference/forms/questionnaire-for-national-security-positions (5) Comply with Foreign Ownership, Control or Influence (FOCI) by: (i) Completing the Standard Form (SF) 328 ( www.gsa.gov/reference/forms/certificate-pertaining-to-foreign-interests Certificate Pertaining to Foreign Interests, (ii) Reporting any change to the information provided on its SF 328 by resubmitting the SF 328 to DCSA within 15 business days of the change being effective. A disqualifying eligibility determination, based on the results of the change, will result in the Accreditation Body losing its authorization or accreditation under the CMMC Program. (iii) Identifying all prospective C3PAOs to the CMMC PMO. The CMMC PMO will sponsor the prospective C3PAO for a FOCI risk assessment conducted by the DCSA using the SF 328 as part of the authorization and accreditation processes. (iv) Notifying prospective C3PAOs of the CMMC PMO's eligibility determination resulting from the FOCI risk assessment. (6) Obtain a Level 2 certification assessment in accordance with the procedures specified in § 170.17(a)(1) and (c). This assessment, conducted by DCMA DIBCAC, shall meet all requirements for a Final Level 2 (C3PAO) but will not result in a CMMC Status of Level 2 (C3PAO). The Level 2 certification assessment process must be performed every three years. (7) Provide all documentation and records in English. (8) Establish, maintain, and manage an up-to-date list of authorized and accredited C3PAOs on a single publicly accessible website and provide the list of these entities and their status to the DoD through submission in the CMMC instantiation of eMASS. (9) Provide the CMMC PMO with current data on C3PAOs, including authorization and accreditation records and status in the CMMC instantiation of eMASS. This data shall include the dates associated with the authorization and accreditation of each C3PAO. (10) Provide the DoD with information about aggregate statistics pertaining to operations of the CMMC Ecosystem to include the authorization and accreditation status of C3PAOs or other information as requested. (11) Provide inputs for assessor supplemental guidance to the CMMC PMO. Participate and support coordination of these and other inputs through DoD-led Working Groups. (12) Ensure that all information about individuals is encrypted and protected in all Accreditation Body information systems and databases. (13) Provide all plans that are related to potential sources of revenue, to include but not limited to: fees, licensing, processes, membership, and/or partnerships to the Department's CMMC PMO. (14) Ensure that the CMMC Assessors and Instructors Certification Organization (CAICO) is compliant with ISO/IEC 17024:2012(E) (15) Ensure all training products, instruction, and testing materials are of high quality and subject to CAICO quality control policies and procedures, to include technical accuracy and alignment with all applicable legal, regulatory, and policy requirements. (16) Develop and maintain an internal appeals process, as required by ISO/IEC 17020:2017(E), and render a final decision on all elevated appeals. (17) Develop and maintain a comprehensive plan and schedule to comply with all ISO/IEC 17011:2017(E), and DoD requirements for Conflict of Interest, Code of Professional Conduct, and Ethics policies as set forth in the DoD contract. All policies shall apply to the Accreditation Body, and other individuals, entities, and groups within the CMMC Ecosystem who provide Level 2 certification assessments, CMMC instruction, CMMC training materials, or Certificates of CMMC Status on behalf of the Accreditation Body. All policies in this section must be approved by the CMMC PMO prior to effectivity in accordance with the following requirements. (i) Conflict of Interest (CoI) policy. (A) Include a detailed risk mitigation plan for all potential conflicts of interest that may pose a risk to compliance with ISO/IEC 17011:2017(E). (B) Require employees, Board directors, and members of any accreditation committees or appeals adjudication committees to disclose to the CMMC PMO, in writing, as soon as it is known or reasonably should be known, any actual, potential, or perceived conflict of interest with sufficient detail to allow for assessment. (C) Require employees, Board directors, and members of any accreditation committees or appeals adjudication committees who leave the board or organization to enter a “cooling off period” of one (1) year whereby they are prohibited from working with the Accreditation Body or participating in any and all CMMC activities described in Subpart C. (D) Require CMMC Ecosystem members to actively avoid participating in any activity, practice, or transaction that could result in an actual or perceived conflict of interest. (E) Require CMMC Ecosystem members to disclose to Accreditation Body leadership, in writing, any actual or potential conflict of interest as soon as it is known, or reasonably should be known. (ii) Code of Professional Conduct (CoPC) policy. (A) Describe the performance standards by which the members of the CMMC Ecosystem will be held accountable and the procedures for addressing violations of those performance standards. (B) Require the Accreditation Body to investigate and resolve any potential violations that are reported or are identified by the DoD. (C) Require the Accreditation Body to inform the DoD in writing of new investigations within 72 hours. (D) Require the Accreditation Body to report to the DoD in writing the outcome of completed investigations within 15 business days. (E) Require CMMC Ecosystem members to represent themselves and their companies accurately; to include not misrepresenting any professional credentials or status, including CMMC authorization or CMMC Status, nor exaggerating the services that they or their company are capable or authorized to deliver. (F) Require CMMC Ecosystem members to be honest and factual in all CMMC-related activities with colleagues, clients, trainees, and others with whom they interact. (G) Prohibit CMMC Ecosystem members from participating in the Level 2 certification assessment process for an assessment in which they previously served as a consultant to prepare the organization for any CMMC assessment within 3 years. (H) Require CMMC Ecosystem members to maintain the confidentiality of customer and government data to preclude unauthorized disclosure. (I) Require CMMC Ecosystem members to report results and data from Level 2 certification assessments and training objectively, completely, clearly, and accurately. (J) Prohibit CMMC Ecosystem members from cheating, assisting another in cheating, or allowing cheating on CMMC examinations. (K) Require CMMC Ecosystem members to utilize official training content developed by a CMMC training organization approved by the CAICO in all CMMC certification courses. (iii) Ethics policy. (A) Require CMMC Ecosystem members to report to the Accreditation Body within 30 days of convictions, guilty pleas, or no contest pleas to crimes of fraud, larceny, embezzlement, misappropriation of funds, misrepresentation, perjury, false swearing, conspiracy to conceal, or a similar offense in any legal proceeding, civil or criminal, whether or not in connection with activities that relate to carrying out their role in the CMMC Ecosystem. (B) Prohibit harassment or discrimination by CMMC Ecosystem members in all interactions with individuals whom they encounter in connection with their roles in the CMMC Ecosystem. (C) Require CMMC Ecosystem members to have and maintain a satisfactory record of integrity and business ethics. § 170.9 CMMC Third-Party Assessment Organizations (C3PAOs). (a) Roles and responsibilities. (b) Requirements. (1) Obtain authorization or accreditation from the Accreditation Body in accordance with § 170.8(b)(3)(i) and (ii). (2) Comply with the Accreditation Body policies for Conflict of Interest, Code of Professional Conduct, and Ethics set forth in § 170.8(b)(17); and achieve and maintain compliance with ISO/IEC 17020:2012(E) (incorporated by reference, see § 170.2) within 27 months of authorization. (3) Require all C3PAO company personnel participating in the Level 2 certification assessment process to complete a Tier 3 background investigation resulting in a determination of national security eligibility. This includes the CMMC Assessment Team and the quality assurance individual. This Tier 3 background investigation will not result in a security clearance and is not being executed for the purpose of government employment. The Tier 3 background investigation is initiated using the Standard Form (SF) 86 ( www.gsa.gov/reference/forms/questionnaire-for-national-security-positions (4) Require all C3PAO company personnel participating in the Level 2 certification assessment process who are not eligible to obtain a Tier 3 background investigation to meet the equivalent of a favorably adjudicated Tier 3 background investigation. DoD will determine the Tier 3 background investigation equivalence for use with the CMMC Program only. (5) Comply with Foreign Ownership, Control or Influence (FOCI) by: (i) Completing and submitting Standard Form (SF) 328 ( www.gsa.gov/reference/forms/certificate-pertaining-to-foreign-interests Certificate Pertaining to Foreign Interests, (ii) Receiving a non-disqualifying eligibility determination from the CMMC PMO resulting from the FOCI risk assessment in order to proceed to a DCMA DIBCAC CMMC Level 2 assessment, as part of the authorization and accreditation process set forth in paragraph (b)(6) of this section. (iii) Reporting any change to the information provided on its SF 328 by resubmitting the SF 328 to DCSA within 15 business days of the change being effective. A disqualifying eligibility determination, based on the results of the change, will result in the C3PAO losing its authorization or accreditation. (6) Undergo a Level 2 certification assessment meeting all requirements for a Final Level 2 (C3PAO) in accordance with the procedures specified in § 170.17(a)(1) and (c), with the following exceptions: (i) The assessment will be conducted by DCMA DIBCAC. (ii) The assessment will not result in a CMMC Status of Level 2 (C3PAO) nor receive a Certificate of CMMC Status. (7) Provide all documentation and records in English. (8) Submit pre-assessment and planning material, final assessment reports, and CMMC certificates of assessment into the CMMC instantiation of eMASS. (9) Unless disposition is otherwise authorized by the CMMC PMO, maintain all assessment related records for a period of six (6) years. Such records include any materials generated by the C3PAO in the course of an assessment, any working papers generated from Level 2 certification assessments; and materials relating to monitoring, education, training, technical knowledge, skills, experience, and authorization of all personnel involved in assessment activities; contractual agreements with OSCs; and organizations for whom consulting services were provided. (10) Provide any requested audit information, including any out-of-cycle from ISO/IEC 17020:2012(E) requirements, to the Accreditation Body. (11) Ensure that all personally identifiable information (PII) is encrypted and protected in all C3PAO information systems and databases. (12) Meet the requirements for Assessment Team composition. An Assessment Team must include at least two people: a Lead CCA, as defined in § 170.11(b)(10), and at least one other CCA. Additional CCAs and CCPs may also participate on an Assessment Team. (13) Implement a quality assurance function that ensures the accuracy and completeness of assessment data prior to upload into the CMMC instantiation of eMASS. Any individual fulfilling the quality assurance function must be a CCA and cannot be a member of an Assessment Team for which they are performing a quality assurance role. A quality assurance individual shall manage the C3PAO's quality assurance reviews as defined in paragraph (b)(14) of this section and the appeals process as required by paragraphs (b)(19) and (20) of this section and in accordance with ISO/IEC 17020:2012(E) (incorporated by reference, see § 170.2) and ISO/IEC 17011:2017(E) (incorporated by reference, see § 170.2). (14) Conduct quality assurance reviews for each assessment, including observations of the Assessment Team's conduct and management of CMMC assessment processes. (15) Ensure that all Level 2 certification assessment activities are performed on the information system within the CMMC Assessment Scope. (16) Maintain all facilities, personnel, and equipment involved in CMMC activities that are in scope of their Level 2 certification assessment and comply with all security requirements and procedures as prescribed by the Accreditation Body. (17) Ensure that all assessment data and information uploaded into the CMMC instantiation of eMASS assessment data is compliant with the CMMC assessment data standard as set forth in eMASS CMMC Assessment Import Templates on the CMMC eMASS website: https://cmmc.emass.apps.mil (18) Issue Certificates of CMMC Status to OSCs in accordance with the Level 2 certification assessment requirements set forth in § 170.17, that include, at a minimum, all industry CAGE codes associated with the information systems addressed by the CMMC Assessment Scope, the C3PAO name, assessment unique identifier, the OSC name, and the CMMC Status date and level. (19) Address all OSC appeals arising from Level 2 certification assessment activities. If the OSC or C3PAO is not satisfied with the result of the appeal either the OSC or the C3PAO can elevate the matter to the Accreditation Body for final determination. (20) Submit assessment appeals, review records, and decision results of assessment appeals to DoD using the CMMC instantiation of eMASS. § 170.10 CMMC Assessor and Instructor Certification Organization (CAICO). (a) Roles and responsibilities. (b) Requirements. (1) Comply with the Accreditation Body policies for Conflict of Interest, Code of Professional Conduct, and Ethics set forth in § 170.8(b)(17); and achieve and maintain ISO/IEC 17024(E) accreditation within 12 months of December 16, 2024. (2) Provide all documentation and records in English. (3) Train, test, and designate PIs in accordance with the requirements of this section. Train, test, certify, and recertify CCPs, CCAs, and CCIs in accordance with the requirements of this section. (4) Ensure the instructor and assessor certification examinations are certified under ISO/IEC 17024:2012(E) (incorporated by reference, see § 170.2), by a recognized US-based accreditor who is not a member of the CMMC Accreditation Body. The US-based accreditor must be a signatory to International Laboratory Accreditation Cooperation (ILAC) or relevant International Accreditation Forum (IAF) Mutual Recognition Arrangement (MRA) and must operate in accordance with ISO/IEC 17011:2017(E) (incorporated by reference, see § 170.2). (5) Establish quality control policies and procedures for the generation of training products, instruction, and testing materials. (6) Oversee development, administration, and management pertaining to the quality of training and examination materials for CMMC assessor and instructor certification and recertification. (7) Establish and publish an authorization and certification appeals process to receive, evaluate, and make decisions on complaints and appeals in accordance with ISO/IEC 17024:2012(E) (incorporated by reference, see § 170.2). (8) Address all appeals arising from the CCA, CCI, and CCP authorizations and certifications process through use of internal processes in accordance with ISO/IEC 17024:2012(E) (incorporated by reference, see § 170.2). (9) Maintain records for a period of six (6) years of all procedures, processes, and actions related to fulfillment of the requirements set forth in this section and provide the Accreditation Body access to those records. (10) Provide the Accreditation Body information about the authorization and accreditation status of assessors, instructors, training community, and publishing partners. (11) Ensure separation of duties between individuals involved in testing activities, training activities, and certification activities. (12) Safeguard and require any CAICO training support service providers, as applicable, to safeguard the confidentiality of applicant, candidate, and certificate-holder information and ensure the overall security of the certification process. (13) Ensure that all PII is encrypted and protected in all CAICO information systems and databases and those of any CAICO training support service providers. (14) Ensure the security of assessor and instructor examinations and the fair and credible administration of examinations. (15) Neither disclose nor allow any CAICO training support service providers, as applicable, to disclose CMMC data or metrics related to authorization or certification activities to any entity other than the Accreditation Body and DoD, except as required by law. (16) Require retraining and redesignation of PIs upon significant change to DoD's CMMC Program requirements. Require retraining and recertification of CCPs, CCAs, and CCIs upon significant change to DoD's CMMC Program requirements, as determined by the DoD or the CAICO. (17) Require CMMC Ecosystem members to report to the CAICO within 30 days of convictions, guilty pleas, or no contest pleas to crimes of fraud, larceny, embezzlement, misappropriation of funds, misrepresentation, perjury, false swearing, conspiracy to conceal, or a similar offense in any legal proceeding, civil or criminal, whether or not in connection with activities that relate to carrying out their role in the CMMC Ecosystem. § 170.11 CMMC Certified Assessor (CCA). (a) Roles and responsibilities. (b) Requirements. (1) Obtain and maintain certification from the CAICO in accordance with the requirements set forth in § 170.10. Certification is valid for 3 years from the date of issuance. (2) Comply with the Accreditation Body policies for Conflict of Interest, Code of Professional Conduct, and Ethics set forth in § 170.8(b)(17). (3) Complete a Tier 3 background investigation resulting in a determination of national security eligibility. This Tier 3 background investigation will not result in a security clearance and is not being executed for the purpose of government employment. The Tier 3 background investigation is initiated using the Standard Form (SF) 86 ( www.gsa.gov/reference/forms/questionnaire-for-national-security-positions (4) Meet the equivalent of a favorably adjudicated Tier 3 background investigation when not eligible for a Tier 3 background investigation. DoD will determine the Tier 3 background investigation equivalence for use with the CMMC Program only. (5) Provide all documentation and records in English. (6) Be a CCP who has at least 3 years of cybersecurity experience, at least 1 year of assessment or audit experience, and at least one foundational qualification, aligned to at least the Intermediate Proficiency Level of the DoD Cyberspace Workforce Framework's Security Control Assessor (612) Work Role, from DoD Manual 8140.03, Cyberspace Workforce Qualification and Management Program https://dodcio.defense.gov/Portals/0/Documents/Library/DoDM-8140-03.pdf https://public.cyber.mil/dcwf-work-role/security-control-assessor/ (7) Only use IT, cloud, cybersecurity services, and end-point devices provided by the authorized/accredited C3PAO that has been engaged to perform that OSA's Level 2 certification assessment and which has undergone a Level 2 certification assessment by DCMA DIBCAC (or higher) for all assessment activities. Individual assessors are prohibited from using any other IT, including IT that is personally owned, to include internal and external cloud services and end-point devices, to process, store, or transmit CMMC assessment reports or any other CMMC assessment-related information. The evaluation of assessment evidence within the OSC environment, using OSC tools, is permitted. (8) Immediately notify the responsible C3PAO of any breach or potential breach of security to any CMMC-related assessment materials under the assessors' purview. (9) Not share any information about an OSC obtained during CMMC pre-assessment and assessment activities with any person not involved with that specific assessment, except as otherwise required by law. (10) Qualify as a Lead CCA by having at least 5 years of cybersecurity experience, 5 years of management experience, 3 years of assessment or audit experience, and at least one foundational qualification aligned to Advanced Proficiency Level of the DoD Cyberspace Workforce Framework's Security Control Assessor (612) Work Role, from DoD Manual 8140.03, Cyberspace Workforce Qualification and Management Program https://dodcio.defense.gov/Portals/0/Documents/Library/DoDM-8140-03.pdf https://public.cyber.mil/dcwf-work-role/security-control-assessor/. § 170.12 CMMC Instructor. (a) CMMC Provisional Instructor (PI) roles and responsibilities. (b) CMMC Certified Instructor (CCI) roles and responsibilities. (c) Requirements. (1) Obtain and maintain instructor designation or certification, as appropriate, from the CAICO in accordance with the requirements set forth in § 170.10. (2) Obtain and maintain CCP or CCA certification to deliver CCP training. (3) Obtain and maintain a CCA certification to deliver CCA training. (4) Comply with the Accreditation Body policies for Conflict of Interest, Code of Professional Conduct, and Ethics set forth in § 170.8(b)(17). (5) Provide all documentation and records in English. (6) Provide the Accreditation Body and the CAICO annually with accurate information detailing their qualifications, training experience, professional affiliations, and certifications, and, upon reasonable request, submit documentation verifying this information. (7) Not provide CMMC consulting services while serving as a CMMC instructor; however, subject to the Code of Professional Conduct and Conflict of Interest policies, can serve on an assessment team. (8) Not participate in the development of exam objectives and/or exam content or act as an exam proctor while at the same time serving as a CCI. (9) Keep confidential all information obtained or created during the performance of CMMC training activities, including trainee records, except as required by law. (10) Not disclose any CMMC-related data or metrics that is PII, FCI, or CUI to anyone without prior coordination with and approval from DoD. (11) Notify the Accreditation Body or the CAICO if required by law or authorized by contractual commitments to release confidential information. (12) Not share with anyone any CMMC training-related information not previously publicly disclosed. § 170.13 CMMC Certified Professional (CCP). (a) Roles and responsibilities. (b) Requirements. (1) Obtain and maintain certification from the CAICO in accordance with the requirements set forth in § 170.10. Certification is valid for 3 years from the date of issuance. (2) Comply with the Accreditation Body policies for Conflict of Interest, Code of Professional Conduct, and Ethics as set forth in § 170.8(b)(17). (3) Complete a Tier 3 background investigation resulting in a determination of national security eligibility. This Tier 3 background investigation will not result in a security clearance and is not being executed for the purpose of government employment. The Tier 3 background investigation is initiated using the Standard Form (SF) 86 ( www.gsa.gov/reference/forms/questionnaire-for-national-security-positions (4) Meet the equivalent of a favorably adjudicated Tier 3 background investigation when not eligible to obtain a Tier 3 background investigation. DoD will determine the Tier 3 background investigation equivalence for use with the CMMC Program only. (5) Provide all documentation and records in English. (6) Not share any information about an OSC obtained during CMMC pre-assessment and assessment activities with any person not involved with that specific assessment, except as otherwise required by law. Subpart D—Key Elements of the CMMC Program § 170.14 CMMC Model. (a) Overview. (1) 48 CFR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems; (2) NIST SP 800-171 R2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (3) Selected security requirements from NIST SP 800-172 Feb2021, Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171 (b) CMMC domains. (c) CMMC level requirements. (1) Numbering. (i) DD is the two-letter domain abbreviation; (ii) L# is the CMMC level number; and (iii) REQ is the 48 CFR 52.204-21 paragraph number, NIST SP 800-171 R2 requirement number, or NIST SP 800-172 Feb2021 requirement number. (2) CMMC Level 1 security requirements. (3) CMMC Level 2 security requirements. (4) CMMC Level 3 security requirements. Table 1 to § 170.14( c Security requirement No.* CMMC Level 3 security requirements (i) AC.L3-3.1.2e Restrict access to systems and system components to only those information resources that are owned, provisioned, or issued by the organization. (ii) AC.L3-3.1.3e Employ secure information transfer solutions (iii) AT.L3-3.2.1e Provide awareness training upon initial hire, following a significant cyber event, and at least annually , at least annually (iv) AT.L3-3.2.2e Include practical exercises in awareness training for all users, tailored by roles, to include general users, users with specialized roles, and privileged users, (v) CM.L3-3.4.1e Establish and maintain an authoritative source and repository to provide a trusted source and accountability for approved and implemented system components. (vi) CM.L3-3.4.2e Employ automated mechanisms to detect misconfigured or unauthorized system components; after detection, remove the components or place the components in a quarantine or remediation network (vii) CM.L3-3.4.3e Employ automated discovery and management tools to maintain an up-to-date, complete, accurate, and readily available inventory of system components. (viii) IA.L3-3.5.1e Identify and authenticate systems and system components, where possible, (ix) IA.L3-3.5.3e Employ automated or manual/procedural mechanisms to prohibit system components from connecting to organizational systems unless the components are known, authenticated, in a properly configured state, or in a trust profile. (x) IR.L3-3.6.1e Establish and maintain a security operations center capability that operates 24/7, with allowance for remote/on-call staff. (xi) IR.L3-3.6.2e Establish and maintain a cyber-incident response team that can be deployed by the organization within 24 hours. (xii) PS.L3-3.9.2e Ensure that organizational systems are protected if adverse information develops or is obtained about individuals with access to CUI. (xiii) RA.L3-3.11.1e Employ threat intelligence, at a minimum from open or commercial sources, and any DoD-provided sources, (xiv) RA.L3-3.11.2e Conduct cyber threat hunting activities on an on-going aperiodic basis or when indications warrant, organizational systems (xv) RA.L3-3.11.3e Employ advanced automation and analytics capabilities in support of analysts to predict and identify risks to organizations, systems, and system components. (xvi) RA.L3-3.11.4e Document or reference in the system security plan the security solution selected, the rationale for the security solution, and the risk determination. (xvii) RA.L3-3.11.5e Assess the effectiveness of security solutions at least annually or upon receipt of relevant cyber threat information, or in response to a relevant cyber incident, (xviii) RA.L3-3.11.6e Assess, respond to, and monitor supply chain risks associated with organizational systems and system components. (xix) RA.L3-3.11.7e Develop a plan for managing supply chain risks associated with organizational systems and system components; update the plan at least annually, and upon receipt of relevant cyber threat information, or in response to a relevant cyber incident. (xx) CA.L3-3.12.1e Conduct penetration testing at least annually or when significant security changes are made to the system, (xxi) SC.L3-3.13.4e Employ physical isolation techniques or logical isolation techniques or both (xxii) SI.L3-3.14.1e Verify the integrity of security critical and essential software (xxiii) SI.L3-3.14.3e Ensure that specialized assets including IoT, IIoT, OT, GFE, Restricted Information Systems, and test equipment (xxiv) SI.L3-3.14.6e Use threat indicator information and effective mitigations obtained from, at a minimum, open or commercial sources, and any DoD-provided sources, * Roman numerals in parentheses before the Security Requirement are for numbering purposes only. The numerals are not part of the naming convention for the requirement. (d) Implementation. § 170.15 CMMC Level 1 self-assessment and affirmation requirements. (a) Level 1 self-assessment. (1) Level 1 self-assessment requirements. (i) Inputs to SPRS. (A) CMMC Level. (B) CMMC Status Date. (C) CMMC Assessment Scope. (D) All industry CAGE code(s) associated with the information system(s) addressed by the CMMC Assessment Scope. (E) Compliance result. (ii) [Reserved] (2) Affirmation. (b) Contract eligibility. (c) Procedures Level 1 self-assessment. (i) The Level 1 self-assessment must be performed using the objectives defined in NIST SP 800-171A Jun2018 (incorporated by reference, see § 170.2) for the security requirement that maps to the CMMC Level 1 security requirement as specified in table 1 to paragraph (c)(1)(ii) of this section. In any case where an objective addresses CUI, FCI should be substituted for CUI in the objective. (ii) Mapping table for CMMC Level 1 security requirements to the NIST SP 800-171A Jun2018 objectives. Table 2 to § 170.15 (c)(1)(ii) CMMC Level 1 security requirements as set forth in § 170.14(c)(2) NIST SP 800-171A Jun2018 AC.L1-b.1.i 3.1.1 AC.L1-b.1.ii 3.1.2 AC.L1-b.1.iii 3.1.20 AC.L1-b.1.iv 3.1.22 IA.L1-b.1.v 3.5.1 IA.L1-b.1.vi 3.5.2 MP.L1-b.1.vii 3.8.3 PE.L1-b.1.viii 3.10.1 First phrase of PE.L1-b.1.ix (FAR b.1.ix *) 3.10.3 Second phrase of PE.L1-b.1.ix (FAR b.1.ix *) 3.10.4 Third phrase of PE.L1-b.1.ix (FAR b.1.ix *) 3.10.5 SC.L1-b.1.x 3.13.1 SC.L1-b.1.xi 3.13.5 SI.L1-b.1.xii 3.14.1 SI.L1-b.1.xiii 3.14.2 SI.L1-b.1.xiv 3.14.4 SI.L1-b.1.xv 3.14.5 * Three of the 48 CFR 52.204-21 requirements were broken apart by “phrase” when NIST SP 800-171 R2 was developed. (iii) Additional guidance can be found in the guidance document listed in paragraph (b) of appendix A to this part. (2) Artifact retention. § 170.16 CMMC Level 2 self-assessment and affirmation requirements. (a) Level 2 self-assessment. (1) Level 2 self-assessment requirements. (i) Inputs to SPRS. (A) CMMC Level. (B) CMMC Status Date. (C) CMMC Assessment Scope. (D) All industry CAGE code(s) associated with the information system(s) addressed by the CMMC Assessment Scope. (E) Overall Level 2 self-assessment score ( e.g., (F) POA&M usage and compliance status, if applicable. (ii) Conditional Level 2 (Self). (A) Plan of Action and Milestones. (B) POA&M closeout. (iii) Final Level 2 (Self). (iv) CMMC Status investigation. (2) Affirmation. (b) Contract eligibility. (1) The OSA must achieve, as specified in paragraph (a)(1) of this section, a CMMC Status of either Conditional Level 2 (Self) or Final Level 2 (Self). (2) The OSA must submit an affirmation of compliance into SPRS, as specified in paragraph (a)(2) of this section. (c) Procedures Level 2 self-assessment of the OSA. (2) Level 2 self-assessment with the use of Cloud Service Provider (CSP). (i) The CSP product or service offering is FedRAMP Authorized at the FedRAMP Moderate (or higher) baseline in accordance with the FedRAMP Marketplace; or (ii) The CSP product or service offering is not FedRAMP Authorized at the FedRAMP Moderate (or higher) baseline but meets security requirements equivalent to those established by the FedRAMP Moderate (or higher) baseline. FedRAMP Moderate or FedRAMP Moderate equivalent is in accordance with DoD Policy. (iii) In accordance with § 170.19(c)(2), the OSA's on-premises infrastructure connecting to the CSP's product or service offering is part of the CMMC Assessment Scope, which will also be assessed. As such, the security requirements from the Customer Responsibility Matrix (CRM) must be documented or referred to in the OSA's System Security Plan (SSP). (3) Level 2 self-assessment with the use of an External Service Provider (ESP), not a CSP. (i) The use of the ESP, its relationship to the OSA, and the services provided are documented in the OSA's SSP and described in the ESP's service description and CRM. (ii) The ESP services used to meet OSA requirements are assessed within the scope of the OSA's assessment against all Level 2 security requirements. (iii) In accordance with § 170.19(c)(2), the OSA's on-premises infrastructure connecting to the ESP's product or service offering is part of the CMMC Assessment Scope, which will also be assessed. As such, the security requirements from the CRM must be documented or referred to in the OSA's SSP. (4) Artifact retention. § 170.17 CMMC Level 2 certification assessment and affirmation requirements. (a) Level 2 certification assessment. (1) Level 2 certification assessment requirements. (i) Inputs into the CMMC instantiation of eMASS. (A) Date and level of the assessment. (B) C3PAO name. (C) Assessment unique identifier. (D) For each Assessor conducting the assessment, name and business contact information. (E) All industry CAGE codes associated with the information systems addressed by the CMMC Assessment Scope. (F) The name, date, and version of the SSP. (G) CMMC Status Date. (H) Assessment result for each requirement objective. (I) POA&M usage and compliance, as applicable. (J) List of the artifact names, the return value of the hashing algorithm, and the hashing algorithm used. (ii) Conditional Level 2 (C3PAO). (A) Plan of Action and Milestones. (B) POA&M closeout. (iii) Final Level 2 (C3PAO). (iv) CMMC Status investigation. (2) Affirmation. (b) Contract eligibility. (1) The OSC must achieve, as specified in paragraph (a)(1) of this section, a CMMC Status of either Conditional Level 2 (C3PAO) or Final Level 2 (C3PAO). (2) The OSC must submit an affirmation of compliance into SPRS, as specified in paragraph (a)(2) of this section. (c) Procedures Level 2 certification assessment of the OSC. (2) Security requirement re-evaluation. (i) Additional evidence is available to demonstrate the security requirement has been MET; (ii) Cannot change or limit the effectiveness of other requirements that have been scored MET; and (iii) The CMMC Assessment Findings Report has not been delivered. (3) POA&M. (4) Artifact retention and integrity. (5) Level 2 certification assessment with the use of Cloud Service Provider (CSP). (i) The CSP product or service offering is FedRAMP Authorized at the FedRAMP Moderate (or higher) baseline in accordance with the FedRAMP Marketplace; or (ii) The CSP product or service offering is not FedRAMP Authorized at the FedRAMP Moderate (or higher) baseline but meets security requirements equivalent to those established by the FedRAMP Moderate (or higher) baseline. FedRAMP Moderate or FedRAMP Moderate equivalent is in accordance with DoD Policy. (iii) In accordance with § 170.19(c)(2), the OSC's on-premises infrastructure connecting to the CSP's product or service offering is part of the CMMC Assessment Scope. As such, the security requirements from the CRM must be documented or referred to in the OSC's SSP. (6) Level 2 certification assessment with the use of an External Service Provider (ESP), not a CSP. (i) The use of the ESP, its relationship to the OSA, and the services provided are documented in the OSA's SSP and described in the ESP's service description and customer responsibility matrix. (ii) The ESP services used to meet OSA requirements are assessed within the scope of the OSA's assessment against all Level 2 security requirements. (iii) In accordance with § 170.19(c)(2), the OSA's on-premises infrastructure connecting to the ESP's product or service offering is part of the CMMC Assessment Scope, which will also be assessed. As such, the security requirements from the CRM must be documented or referred to in the OSA's SSP. § 170.18 CMMC Level 3 certification assessment and affirmation requirements. (a) Level 3 certification assessment. (1) Level 3 certification assessment requirements. www.dcma.mil/DIBCAC (i) Inputs into the CMMC instantiation of eMASS. (A) Date and level of the assessment. (B) For each Assessor(s) conducting the assessment, name and government organization information. (C) All industry CAGE code(s) associated with the information system(s) addressed by the CMMC Assessment Scope. (D) The name, date, and version of the system security plan(s) (SSP). (E) CMMC Status Date. (F) Result for each security requirement objective. (G) POA&M usage and compliance, as applicable. (H) List of the artifact names, the return value of the hashing algorithm, and the hashing algorithm used. (ii) Conditional Level 3 (DIBCAC). (A) Plan of Action and Milestones. (B) POA&M closeout. (iii) Final Level 3 (DIBCAC). (iv) CMMC Status investigation. (2) Affirmation. (b) Contract eligibility. (1) The OSC must achieve, as specified in paragraph (a)(1) of this section, a CMMC Status of either Conditional Level 3 (DIBCAC) or Final Level 3 (DIBCAC). (2) The OSC must submit an affirmation of compliance into SPRS, as specified in paragraph (a)(2) of this section. (c) Procedures Level 3 certification assessment of the OSC. (i) Final Level 2 (C3PAO). (ii) Initiating the Final Level 3 (DIBCAC). www.dcma.mil/DIBCAC (iii) Conducting the Final Level 3 (DIBCAC). i.e., i.e., (2) Security requirement re-evaluation. (i) Additional evidence is available to demonstrate the security requirement has been MET; (ii) The additional evidence does not materially impact previously assessed security requirements; and (iii) The CMMC Assessment Findings Report has not been delivered. (3) POA&M. (4) Artifact retention and integrity. (5) Level 3 certification assessment with the use of Cloud Service Provider (CSP). (i) The OSC may utilize a CSP product or service offering that meets the FedRAMP Moderate (or higher) baseline. If the CSP's product or service offering is not FedRAMP Authorized at the FedRAMP Moderate (or higher) baseline, the product or service offering must meet security requirements equivalent to those established by the FedRAMP Moderate (or higher) baseline in accordance with DoD Policy. (ii) Use of a CSP does not relieve an OSC of its obligation to implement the 24 Level 3 security requirements. These 24 requirements apply to every environment where the CUI data is processed, stored, or transmitted, when Level 3 (DIBCAC) is the designated CMMC Status. If any of these 24 requirements are inherited from a CSP, the OSC must demonstrate that protection during a Level 3 certification assessment via a Customer Implementation Summary/Customer Responsibility Matrix (CIS/CRM) and associated Body of Evidence (BOE). The BOE must clearly indicate whether the OSC or the CSP is responsible for meeting each requirement and which requirements are implemented by the OSC versus inherited from the CSP. (iii) In accordance with § 170.19(d)(2), the OSC's on-premises infrastructure connecting to the CSP's product or service offering is part of the CMMC Assessment Scope. As such, the security requirements from the CRM must be documented or referred to in the OSC's SSP. (6) Level 3 certification assessment with the use of an ESP, not a CSP. (i) The use of the ESP, its relationship to the OSC, and the services provided are documented in the OSC's SSP and described in the ESP's service description and customer responsibility matrix. (ii) The ESP services used to meet OSC requirements are assessed within the scope of the OSC's assessment against all Level 2 and Level 3 security requirements. (iii) In accordance with § 170.19(d)(2), the OSC's on-premises infrastructure connecting to the ESP's product or service offering is part of the CMMC Assessment Scope, which will also be assessed. As such, the security requirements from the CRM must be documented or referred to in the OSC's SSP. § 170.19 CMMC scoping. (a) Scoping requirement. (2) The requirements for defining the CMMC Assessment Scope for CMMC Levels 1, 2, and 3 are set forth in this section. Additional guidance regarding scoping can be found in the guidance documents listed in paragraphs (e) through (g) of appendix A to this part. (b) CMMC Level 1 scoping. (1) Assets in scope for Level 1 self-assessment. (2) Assets not in scope for Level 1 self-assessment Out-of-Scope Assets. (ii) Specialized Assets. (3) Level 1 self-assessment scoping considerations. (c) CMMC Level 2 Scoping. (1) The CMMC Assessment Scope for CMMC Level 2 is based on the specification of asset categories and their respective requirements as defined in table 3 to this paragraph (c)(1). Additional information is available in the guidance document listed in paragraph (f) of appendix A to this part. Table 3 to § 170.19 (c)(1) Asset category Asset description OSA requirements CMMC assessment requirements Assets that are in the Level 2 CMMC Assessment Scope Controlled Unclassified Information (CUI) Assets • Assets that process, store, or transmit CUI • Document in the asset inventory • Assess against all Level 2 security requirements. Security Protection Assets • Assets that provide security functions or capabilities to the OSA's CMMC Assessment Scope • Document in the asset inventory • Assess against Level 2 security requirements that are relevant to the capabilities provided. Contractor Risk Managed Assets • Assets that can, but are not intended to, process, store, or transmit CUI because of security policy, procedures, and practices in place • Document in the asset inventory • Review the SSP: • The limited check(s) shall not materially increase the assessment duration nor the assessment cost. • The limited check(s) will be assessed against CMMC security requirements. Specialized Assets • Assets that can process, store, or transmit CUI but are unable to be fully secured, including: Internet of Things (IoT) devices, Industrial Internet of Things (IIoT) devices, Operational Technology (OT), Government Furnished Equipment (GFE), Restricted Information Systems, and Test Equipment • Document in the asset inventory • Review the SSP. Assets that are not in the Level 2 CMMC Assessment Scope Out-of-Scope Assets • Assets that cannot process, store, or transmit CUI; and do not provide security protections for CUI Assets • Prepare to justify the inability of an Out-of-Scope Asset to process, store, or transmit CUI • None. • Assets that are physically or logically separated from CUI assets • Assets that fall into any in-scope asset category cannot be considered an Out-of-Scope Asset • An endpoint hosting a VDI client configured to not allow any processing, storage, or transmission of CUI beyond the Keyboard/Video/Mouse sent to the VDI client is considered an Out-of-Scope Asset (2)(i) Table 4 to this paragraph (c)(2)(i) defines the requirements to be met when utilizing an External Service Provider (ESP). The OSA must consider whether the ESP is a Cloud Service Provider (CSP) and whether the ESP processes, stores, or transmits CUI and/or Security Protection Data (SPD). Table 4 to § 170.19 (c)(2)(i) When the ESP processes, stores, or transmits: When utilizing an ESP that is: A CSP Not a CSP CUI (with or without SPD) The CSP shall meet the FedRAMP requirements in 48 CFR 252.204-7012 The services provided by the ESP are in the OSA's assessment scope and shall be assessed as part of the OSA's assessment. SPD (without CUI) The services provided by the CSP are in the OSA's assessment scope and shall be assessed as Security Protection Assets The services provided by the ESP are in the OSA's assessment scope and shall be assessed as Security Protection Assets. Neither CUI nor SPD A service provider that does not process CUI or SPD does not meet the CMMC definition of an ESP A service provider that does not process CUI or SPD does not meet the CMMC definition of an ESP. (ii) The use of an ESP, its relationship to the OSA, and the services provided need to be documented in the OSA's SSP and described in the ESP's service description and customer responsibility matrix (CRM), which describes the responsibilities of the OSA and ESP with respect to the services provided. Note that the ESP may voluntarily undergo a CMMC certification assessment to reduce the ESP's effort required during the OSA's assessment. The minimum assessment type for the ESP is dictated by the OSA's DoD contract requirement. (d) CMMC Level 3 scoping. (1) The CMMC Assessment Scope for Level 3 is based on the specification of asset categories and their respective requirements as set forth in table 5 to this paragraph (d)(1). Additional information is available in the guidance document listed in paragraph (g) of appendix A to this part. Table 5 to § 170.19 (d)(1) Asset category Asset description OSC requirements CMMC assessment requirements Assets that are in the Level 3 CMMC Assessment Scope Controlled Unclassified Information (CUI) Assets • Assets that process, store, or transmit CUI • Document in the asset inventory • Limited check against Level 2 and assess against all Level 3 CMMC security requirements. Security Protection Assets • Assets that provide security functions or capabilities to the OSC's CMMC Assessment Scope, irrespective of whether or not these assets process, store, or transmit CUI • Document in the asset inventory • Limited check against Level 2 and assess against all Level 3 CMMC security requirements that are relevant to the capabilities provided. Specialized Assets • Assets that can process, store, or transmit CUI but are unable to be fully secured, including: Internet of Things (IoT) devices, Industrial Internet of Things (IIoT) devices, Operational Technology (OT), Government Furnished Equipment (GFE), Restricted Information Systems, and Test Equipment • Document in the asset inventory • Limited check against Level 2 and assess against all Level 3 CMMC security requirements. Assets that are not in the Level 3 CMMC Assessment Scope Out-of-Scope Assets • Assets that cannot process, store, or transmit CUI; and do not provide security protections for CUI Assets • Prepare to justify the inability of an Out-of-Scope Asset to process, store, or transmit CUI • None. • Assets that are physically or logically separated from CUI assets • Assets that fall into any in-scope asset category cannot be considered an Out-of-Scope Asset • An endpoint hosting a VDI client configured to not allow any processing, storage, or transmission of CUI beyond the Keyboard/Video/Mouse sent to the VDI client is considered an Out-of-Scope Asset (2)(i) Table 6 to this paragraph (d)(2)(i) defines the requirements to be met when utilizing an External Service Provider (ESP). The OSA must consider whether the ESP is a Cloud Service Provider (CSP) and whether the ESP processes, stores, or transmits CUI and/or Security Protection Data (SPD). Table 6 to § 170.19 (d)(2)(i) When the ESP processes, stores, or transmits: When utilizing an ESP that is: A CSP Not a CSP CUI (with or without SPD) The CSP shall meet the FedRAMP requirements in 48 CFR 252.204-7012 The services provided by the ESP are in the OSA's assessment scope and shall be assessed as part of the OSA's assessment. SPD (without CUI) The services provided by the CSP are in the OSA's assessment scope and shall be assessed as Security Protection Assets The services provided by the ESP are in the OSA's assessment scope and shall be assessed as Security Protection Assets. Neither CUI nor SPD A service provider that does not process CUI or SPD does not meet the CMMC definition of an ESP A service provider that does not process CUI or SPD does not meet the CMMC definition of an ESP. (ii) The use of an ESP, its relationship to the OSC, and the services provided need to be documented in the OSC's SSP and described in the ESP's service description and customer responsibility matrix (CRM), which describes the responsibilities of the OSC and ESP with respect to the services provided. Note that the ESP may voluntarily undergo a CMMC certification assessment to reduce the ESP's effort required during the OSA's assessment. The minimum. The minimum assessment type for the ESP is dictated by the OSC's DoD contract requirement. (e) Relationship between Level 2 and Level 3 CMMC Assessment Scope. e.g., www.dcma.mil/DIBCAC/ § 170.20 Standards acceptance. (a) NIST SP 800-171 R2 DoD assessments. (1) DCMA DIBCAC High Assessment. (2) [Reserved]. (b) [Reserved]. § 170.21 Plan of Action and Milestones requirements. (a) POA&M. (1) Level 1 self-assessment. (2) Level 2 self-assessment and Level 2 certification assessment. (i) The assessment score divided by the total number of CMMC Level 2 security requirements is greater than or equal to 0.8; (ii) None of the security requirements included in the POA&M have a point value of greater than 1 as specified in the CMMC Scoring Methodology set forth in § 170.24, except SC.L2-3.13.11 CUI Encryption may be included on a POA&M if encryption is employed but it is not FIPS-validated, which would result in a point value of 3; and (iii) None of the following security requirements are included in the POA&M: (A) AC.L2-3.1.20 External Connections (CUI Data). (B) AC.L2-3.1.22 Control Public Information (CUI Data). (C) CA.L2-3.12.4 System Security Plan. (D) PE.L2-3.10.3 Escort Visitors (CUI Data). (E) PE.L2-3.10.4 Physical Access Logs (CUI Data). (F) PE.L2-3.10.5 Manage Physical Access (CUI Data). (3) Level 3 certification assessment. (i) The assessment score divided by the total number of CMMC Level 3 security requirements is greater than or equal to 0.8; and (ii) The POA&M does not include any of following security requirements: (A) IR.L3-3.6.1e Security Operations Center. (B) IR.L3-3.6.2e Cyber Incident Response Team. (C) RA.L3-3.11.1e Threat-Informed Risk Assessment. (D) RA.L3-3.11.6e Supply Chain Risk Response. (E) RA.L3-3.11.7e Supply Chain Risk Plan. (F) RA.L3-3.11.4e Security Solution Rationale. (G) SI.L3-3.14.3e Specialized Asset Security. (b) POA&M closeout assessment. (1) Level 2 self-assessment. (2) Level 2 certification assessment. (3) Level 3 certification assessment. § 170.22 Affirmation. (a) General. (1) Affirming Official. (2) Affirmation content. (i) Name, title, and contact information for the Affirming Official; and (ii) Affirmation statement attesting that the OSA has implemented and will maintain implementation of all applicable CMMC security requirements to their CMMC Status for all information systems within the relevant CMMC Assessment Scope. (3) Affirmation submission. (i) Upon achievement of a Conditional CMMC Status, as applicable; (ii) Upon achievement of a Final CMMC Status; (iii) Annually following a Final CMMC Status Date; and (iv) Following a POA&M closeout assessment, as applicable. (b) Submission procedures. (1) Level 1 self-assessment. (2) Level 2 self-assessment. (3) Level 2 certification assessment. (4) Level 3 certification assessment. § 170.23 Application to subcontractors. (a) CMMC requirements apply to prime contractors and subcontractors throughout the supply chain at all tiers that will process, store, or transmit any FCI or CUI on contractor information systems in the performance of the DoD contract or subcontract. Prime contractors shall comply and shall require subcontractors to comply with and to flow down CMMC requirements, such that compliance will be required throughout the supply chain at all tiers with the applicable CMMC level and assessment type for each subcontract as follows: (1) If a subcontractor will only process, store, or transmit FCI (and not CUI) in performance of the subcontract, then a CMMC Status of Level 1 (Self) is required for the subcontractor. (2) If a subcontractor will process, store, or transmit CUI in performance of the subcontract, then a CMMC Status of Level 2 (Self) is the minimum requirement for the subcontractor. (3) If a subcontractor will process, store, or transmit CUI in performance of the subcontract and the associated prime contract has a requirement for a CMMC Status of Level 2 (C3PAO), then the CMMC Status of Level 2 (C3PAO) is the minimum requirement for the subcontractor. (4) If a subcontractor will process, store, or transmit CUI in performance of the subcontract and the associated prime contract has a requirement for the CMMC Status of Level 3 (DIBCAC), then the CMMC Status of Level 2 (C3PAO) is the minimum requirement for the subcontractor. (b) As with any solicitation or contract, the DoD may provide specific guidance pertaining to flow-down. § 170.24 CMMC Scoring Methodology. (a) General. e.g., (b) Assessment findings. (1) Met. (i) Enduring exceptions when described, along with any mitigations, in the system security plan shall be assessed as MET. (ii) Temporary deficiencies that are appropriately addressed in operational plans of action ( i.e., (2) Not Met. (3) Not Applicable (N/A). (c) Scoring. (1) CMMC Level 1. (2) CMMC Level 2 Scoring Methodology. (i) Procedures. (B) In the CMMC Level 2 Scoring Methodology, each security requirement has a value ( e.g., ( 1 ( i Basic security requirements. ( ii Derived security requirements. ( 2 ( i Basic security requirements. ( ii Derived security requirements. ( 3 ( 4 ( i ( ii ( 5 an assessment could not be completed due to incomplete information and noncompliance with 48 CFR 252.204-7012. ( 6 ( 7 ( 8 (ii) CMMC Level 2 Scoring Table. Table 7 to § 170.24 (c)(2)(ii) CMMC Level 2 requirement categories Point value Basic Security Requirements: If not implemented, could lead to significant exploitation of the network, or exfiltration of CUI 5 If not implemented, has specific and confined effect on the security of the network and its data 3 Derived Security Requirements: If not implemented, could lead to significant exploitation of the network, or exfiltration of CUI 5 If not completely or properly implemented, could be partially effective and points adjusted depending on how the security requirement is implemented: 3 or 5 —Partially effective implementation—3 points. —Non-effective (not implemented at all)—5 points. If not implemented, has specific and confined effect on the security of the network and its data 3 If not implemented, has a limited or indirect effect on the security of the network and its data 1 (3) CMMC Level 3 assessment scoring methodology. Appendix A to Part 170—Guidance Guidance documents include: (a) “CMMC Model Overview” available at https://DoDcio.defense.gov/CMMC/ (b) “CMMC Assessment Guide—Level 1” available at https://DoDcio.defense.gov/CMMC/ (c) “CMMC Assessment Guide—Level 2” available at https://DoDcio.defense.gov/CMMC/ (d) “CMMC Assessment Guide—Level 3” available at https://DoDcio.defense.gov/CMMC/ (e) “CMMC Scoping Guide—Level 1” available at https://DoDcio.defense.gov/CMMC/ (f) “CMMC Scoping Guide—Level 2” available at https://DoDcio.defense.gov/CMMC/ (g) “CMMC Scoping Guide—Level 3” available at https://DoDcio.defense.gov/CMMC/ (h) “CMMC Hashing Guide” available at https://DoDcio.defense.gov/CMMC/.