CMMC Level and Assessment Requirements for Defense Contractors
ID: 54598eb4-359b-5cbb-bf83-b0ef09052a74
STIX ID: report--54598eb4-359b-5cbb-bf83-b0ef09052a74
Feed Name: TrustedSec blog
This guidance explains how CMMC 2.0 maps to the types of information contractors handle—FCI (Level 1, self-assessment), CUI (Level 2, self-assessment or C3PAO certification depending on CUI category), and CUI with enhanced protections (Level 3, DIBCAC)—and summarizes definitions, assessment requirements, NIST control baselines (SP 800-171/172), and recommended compliance actions such as documenting System Security Plans and POA&Ms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
