RSI Security

CMMC Level 2: Aligning with NIST SP 800-171 for Advanced Security

CMMC Level 2: Aligning with NIST SP 800-171 for Advanced Security

DoD contracts that require CMMC Level 2 certification mandate full alignment with the NIST’s SP 800-171 framework. Read on to learn what that entails.

Military contractors that work with sensitive information need to prove their security chops through NIST and CMMC compliance. If a contract requires CMMC Level 2, you’ll need to implement the entirety of NIST SP 800-171, including 110 unique cybersecurity practices.

Is your organization ready for CMMC Level 2 compliance? Request a consultation to find out!

 

Achieving CMMC 2.0 Level 2 and NIST Compliance

Organizations working with the Department of Defense (DoD) need to prove that their data processing is secure before they work with sensitive military information. To that effect, they need to implement protections from the National Institute of Standards and Technology (NIST), which are the basis of the DoD’s Cybersecurity Maturity Model Certification (CMMC) program.

In particular, DoD contracts requiring CMMC Level 2 certification require implementing the entirety of NIST’s Special Publication (SP) 800-171. To do that, you need to understand:

Working with a compliance advisory partner to scope and implement controls and then plan for and conduct your assessment will make it easier and faster to be a preferred DoD contractor.

 

How CMMC 2.0 Relates to NIST DoD Standards

CMMC is a relatively new framework, but the standards that it’s built upon are not. The CMMC program is a way to integrate NIST SP 800-171 and other security practices uniformly across the defense industrial base (DIB). Sooner rather than later, all DoD contracts will require some level of CMMC compliance. Those that deal primarily in lower-stakes sensitive data, such as Federal Contract Information (FCI), will need CMMC Level 1. But those that involve Controlled Unclassified Information (CUI) need CMMC Level 2, which corresponds to all of SP 800-171.

Additionally, some organizations that process large quantities of CUI or are subject to more dangerous risk environments may need CMMC Level 3. This highest level includes all 110 of SP 800-171’s controls, along with 24 from the supplementary framework NIST SP 800-172.

 

Implementation Requirements at CMMC Level 2

If your organization needs to achieve CMMC Level 2 certification, you’ll need to implement the 15 requirements of Level 1 and then upgrade to the full suite of 110 for Level 2. In other words, this includes all of SP 800-171’s requirements. After all controls are installed, you can prepare for an assessment (see below).

Note that the CMMC 2.0 levels differ slightly from earlier versions of the framework. If you were targeting CMMC Level 3 in version 1, you may need to achieve Level 2 in the new schema.

 

 

CMMC Level 1 Prerequisites

CMMC Level 1 comprises 15 controls adapted from NIST SP 800-171. They are fundamental in scope and provide basic safeguarding of FCI. However, they’re not sufficient for CUI protection.

The Level 1 requirements that need to be in place prior to Level 2 implementation are:

More granular information can be found in the DoD’s CMMC Level 1 assessment guide.

 

CMMC Level 2 Requirements

CMMC Level 2 comprises 110 total requirements, building on Level 1’s safeguards and expanding them to account for the scope and stakes of CUI protection. At Level 2, DoD contractors work with more sensitive data and therefore need more robust assurances.

The full suite of controls aligning CMMC Level 2 and NIST breaks down as follows: 

For more granular information, see the DoD’s CMMC Level 2 assessment guide.

 

 

Assessment Requirements at CMMC Level 2

Implementation alone does not confer CMMC certification. Organizations also need to conduct formal assessments to prove that their control deployment is effective. Beyond implementation, the biggest difference when comparing CMMC Level 1 vs Level 2 is the assessment method. The former allows self-assessments, while the latter generally requires certified assessments through a third party. Crucially, while some contractors qualify for self-assessment at Level 2, the vast majority need to work with a Certified Third Party Assessment Organization (C3PAO) vetted by the Cyber AB.

Working with a C3PAO ensures the highest level of scrutiny and fidelity in audit practices. The best C3PAO partners will also help you prepare for the audit to succeed swiftly and efficiently.

 

Optimize Your CMMC Compliance Practices

If your organization needs to achieve CMMC Level 2 compliance for an existing or potential DoD contract, you’ll need to align fully with the NIST SP 800-171 framework. This means first implementing all 110 required controls and then preparing for a rigorous C3PAO assessment.

RSI Security has helped countless organizations prepare for and achieve DoD compliance through NIST and CMMC implementation. We are a C3PAO listed by the Cyber AB, and we assist in all parts of the compliance process. We know that discipline upfront helps unlock greater freedom to grow in the long run, and we’ll help you rethink your security to that effect.

To learn more about our CMMC compliance services, contact RSI Security today!

 

Contact Us Now!

Exit mobile version