RSI Security

Your Complete CMMC Assessment Guide 

cybersecurity awareness training 

Any company that takes on lucrative contracts with the US Department of Defense (DoD) and becomes part of the Defense Industrial Base sector (DIB) needs to keep its cybersecurity practices up to date. You will also need to adhere to the Cybersecurity Maturity Model Certification (CMMC), including self-assessment and outside auditing, to confirm your compliance. This CMMC assessment guide will break down what it takes to get started.

 

Complete CMMC Assessment Guide

CMMC is a publication of the Office of the Under Secretary of Defense for Acquisition and Sustainment (OUSD-A&S). It simplifies the adopting practices required by the Defense Federal Acquisition Regulation Supplement (DFARS), including all of Special Publication 800-171.

Implementing and assessing all requirements for compliance can be highly complex. In this guide, we’ll walk you through everything you need to know to be fully compliant, including:

By the time we’re done, you’ll be well prepared to get started with assessment and certification or move on to the next stage in your cybersecurity journey. But first, let’s cover some basic CMMC definitions.

 

CMMC Framework Basics: Levels and Domains

At the CMMC’s core are 17 “Domains.” Each targets several “Capabilities” (43 total) across its “Practices,” or controls (171 total). These controls are implemented gradually across five “Maturity Levels.” These elements of the CMMC core break down as follows:

Maturity Levels:

At each Level, new and existing Practices are held to “process maturity” standards, measuring how integrated it is across the company. Practices must be revisited and upgraded at each successive level.

Cybersecurity Domains:

Now, let’s discuss all of the Levels’ general focuses, practice and process maturity goals, and the control breakdowns to prepare for assessment at every level. All content in the sections below is sourced directly from CMMC V1.02, unless otherwise noted.

 

Assess your CMMC Compliance

 

CMMC Level 1 Overview: Safeguarding FCI

The first CMMC Maturity Level focuses on safeguards for federal contract information (FCI), one of the two types of data CMMC is designed to protect. Its Practice goals constitute “basic Cyber hygiene,” and Processes at Level 1 must be merely “performed” (not measured).

In total, CMMC Level 1 comprises 17 practices, encompassing six Domains. This is the second-fewest Practices of any Level, and combined with the relatively lenient Process goal, CMMC basic assessment at Level 1 is designed for accessibility. Let’s take a closer look at what it entails.

 

Breakdown of Level 1 Controls by Domain

The 17 Practices added at Level 1 break down as follows:

 

CMMC Level 2 Overview: Preparing for CUI

The second CMMC Maturity Level focuses less on any inherent goal and more on a transitional one, preparing for complete protection of controlled unclassified information at Level 3. Its Practices’ goals constitute “intermediate cyber hygiene,” and Processes must be performed and “documented.”

Level 2 adds 55 new Practices, the second most of any Level, for a running total of 72. Since all these Practices need to be documented, this is the first Level at which Process Maturity requires official measurement and CMMC assessment tools. Let’s take a closer look.

 

Download our CMMC Whitepaper: Best Cybersecurity Practices for DoD Contractors

 

Here are a few more articles to help you learn more about CMMC :

 

Breakdown of Level 2 Controls by Domain

The 55 Practices added at Level 2 break down as follows:

 

CMMC Level 3 Overview: Protecting CUI

The third CMMC Maturity Level focuses on the full protection of CUI, which coincides with the implementation of all NIST SP 800-171 controls. Practices goals for Level 3 constitute “good cyber hygiene,” and Processes at Level 3 must be documented and actively “managed.”

Level 3 adds 58 new Practices, the most of any Level, making the running total now 130. Plus, the management of all 130 controls makes Level 3 a milestone in compliance and security. The final two Levels will move far beyond cyber hygiene and into advanced proactive measures.

 

Breakdown of Level 3 Controls by Domain

The 58 Practices added at Level 3 break down as follows:

 

CMMC Level 4 Overview: Preparing for APT

The fourth CMMC Maturity Level focuses on further optimizing CUI protection and moving into proactive measures to counteract advanced persistent threats. Its Practice goals constitute “proactive” measures, and Processes at Level 4 must be managed and “reviewed.”

Level 4 adds on 26 Practices. Practices’ running total is now 156, all of which now require a deeper level of regular institution-wide review and corrective action to ensure ongoing security.

 

Breakdown of Level 4 Controls by Domain

The 26 Practices added at Level 4 break down as follows:

 

CMMC Level 5 Overview: Preventing APT

The fifth and final CMMC Maturity Level focuses almost entirely on the most advanced protections for APT available. The final stage of Practices constitute advanced and progressive measures, and Processes at Level 5 must be reviewed and continuously “optimized.”

Level 5 adds only 15 new Practices, the fewest of any level, bringing the final total to 171. But the final Process goal includes keeping Practices up to date and actively seeking out ways to improve and perfect them over time. Let’s take a look at the final slate of Practices.

 

Breakdown of Level 5 Controls by Domain

The 15 Practices added at Level 5 break down as follows:

 

Professional Compliance and Cybersecurity

Across all of these levels, implementing and assessing all required controls can be challenging, especially for smaller to medium-sized companies with more modest IT budgets. RSI Security offers a suite of CMMC compliance advisory services to help your company achieve certification. This CMMC assessment guide is far from the only resource we offer; contact RSI Security today to see how easy CMMC compliance can be!

 


Speak with a CMMC compliance expert today – Schedule a free consultation

Exit mobile version