Does CMMC Apply to Your Company?

What Defense Contractors and Subcontractors Need to Know

For defense contractors and subcontractors, the first CMMC question is not which cybersecurity controls to implement. It is whether CMMC applies to your organization and what level your contracts will require.

CMMC requirements apply to Department of  War solicitations and contracts when a defense contractor or subcontractor will process, store or transmit Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) on its unclassified contractor information systems.

That includes subcontractors when protected information flows down from a prime contractor.

The Cybersecurity Maturity Model Certification (CMMC) builds on cybersecurity requirements already established through DFARS 252.204-7012, 252.204-7019 and 252.204-7020, as well as FAR 52.204-21. Its purpose is to strengthen the cybersecurity posture of the Defense Industrial Base (DIB) and better protect sensitive unclassified information.

CMMC establishes how contractors will demonstrate compliance with applicable security requirements based on NIST SP 800-171. Depending on the contract requirements, defense contractors and subcontractors must demonstrate compliance through self-assessment or third-party assessment at the time of contract award.

Where Contractors May Encounter CMMC Requirements

CMMC requirements can arise through:

  • New DoW solicitations
  • The exercise of an option period
  • Subcontractor flow-down requirements when protected information flows down

For subcontractors, this makes the information received from a prime contractor particularly important. CMMC requirements apply when a defense contractor or subcontractor will process, store or transmit FCI or CUI on its unclassified contractor information systems.

Your CMMC Requirement Depends on the Information You Handle

CMMC establishes three levels based on the information being protected and the applicable security requirements. The required level also determines how an organization demonstrates compliance.

Level 1: Basic Safeguarding of FCI

CMMC Level 1 addresses the basic safeguarding of Federal Contract Information.

Organizations subject to Level 1 requirements conduct an annual self-assessment and affirmation of their compliance with 17 “basic cyber hygiene” requirements, with results entered into the Supplier Performance Risk System (SPRS).

Level 2: Protecting CUI

CMMC Level 2 is designed to protect Controlled Unclassified Information and verifies compliance with NIST SP 800-171.

This is an important distinction for contractors handling CUI because Level 2 can involve two different assessment paths. Depending on the contract requirements, an organization will be subject to either a self-assessment or a triennial assessment performed by a Certified Third-Party Assessment Organization (C3PAO), along with annual affirmation in SPRS.

Contractors should therefore not assume that a self-assessment will satisfy their CMMC requirement. When a contract calls for a third-party assessment, a C3PAO assessment is required.  The DoW has temporarily put the requirement for C3PAO assessment on hold, but these assessments are still being performed and can serve as a stronger indication of compliance to a contracting officer or a prime contractor.  Some prime contractors are pushing their subs to obtain the 3rd party certification.

Level 3: Protecting CUI Against Advanced Persistent Threats

CMMC Level 3 is designed to protect CUI against advanced persistent threats when the information is highly sensitive, and its compromise could harm national security.

Level 3 requires both a C3PAO assessment and a DoW assessment.

You May Have Compliance Obligations even without CMMC.

CMMC simply adjusts and expands options for self and independent evaluation of compliance with NIST SP 800-171, which is required by DFARS 252.204-7012.  The DoW can also assess your compliance through 252.204-7019 at any time.  The risk here is that if there is a significant difference between your self-reported score and a DoW assessment, they can pursue damages under the False Claims Act.