RSI Security

Everything You Need to Do to Prepare for CMMC 2.0 Compliance

Organizations that work closely with the US Military as contractors or vendors often come into contact with sensitive information. Compliance with the CMMC 2.0 standard is required to ensure all critical data is protected. Careful scoping, implementation, and assessment are essential.

Is your organization prepared for CMMC 2.0 compliance? Book a consultation to find out!

 

How to Prepare for CMMC 2.0 Compliance

Defense Industrial Base (DIB) organizations that partner with the Department of Defense (DoD) need to achieve Cybersecurity Maturity Model Certification (CMMC). However, the CMMC is a large and complex framework that is challenging for many to grasp, much less implement.

There are three essential components to effective CMMC 2.0 preparation:

Working with a CMMC advisory partner will streamline all parts of the process.

 

 

Understanding the Regulatory Context

The first step to complying with CMMC is understanding whether and to what extent it may apply to your organization. CMMC is applicable to DoD contractors who come into contact with certain protected types of information—Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Most organizations that process just FCI need CMMC 2.0 Level 1, whereas those that process both FCI and CUI generally need Level 2. Level 3 is reserved for organizations that process the most CUI and/or are subject to the highest levels of risk.

The most recent edition of the CMMC framework, CMMC 2.0 or CMMC v2, was published in December of 2021. It is a comprehensive guide that builds on other governmental texts, such as the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171. All controls in CMMC are adapted from NIST, and implementation at Level 2 includes controls that span all of SP 800-171’s requirements. Level 3 will be based on another framework—see below.

 

Planning and Implementing Controls

Next up is planning for and installing controls commensurate to the CMMC 2.0 requirements for your desired level. Note that the specific level required may change over time as an entity takes on greater data processing responsibilities. A contract that calls for CMMC Level 1 in the short term may require Level 2 compliance later on or upon renewal. For this reason, preparing for complete implementation is ideal even for organizations that only need Level 1 at present.

See below for a complete list of requirements for each level.

Required Controls for CMMC 2.0 Level 1

CMMC 2.0 Level 1 includes 17 practices adapted from NIST SP 800-171 (v2). The controls correspond to NIST’s “basic security requirements,” breaking down in CMMC as follows:

 

 

 

Required Controls for CMMC 2.0 Level 2

CMMC 2.0 Level 2 covers all controls from NIST SP 800-171 (v2), 110 in total, including all the requirements from Level 1 plus additional practices added in previously untouched categories:

 

Likely Requirements for CMMC Level 3

The specific controls for CMMC 2.0 Level 3 have not yet been determined. However, the DoD has made it known that these controls will be adapted from NIST SP 800-172, much like Level 1 and Level 2 are adapted from NIST SP 800-171. That framework comprises 35 “enhanced” security requirements that build on the protections outlined across NIST SP 800-171. Any organizations that figure to need CMMC 2.0 Level 3 should prepare to implement all 35.

 

Conducting an Official CMMC Assessment

The final step of CMMC 2.0 preparation involves planning for the assessment that will actually grant certification. As with implementation, the specific requirements vary greatly be level.

At CMMC Level 1, organizations are eligible to self-assess annually for compliance. The DoD provides self-assessment guidance, and Level 1 entities are generally not required to work with an outside assessor or advisor. However, working with a provider can facilitate the audit.

At CMMC Level 2, some entities can self-assess. However, most are required to work with a certified third-party assessment organization (C3PAO) triennially. The DoD provides guidance on Level 2 assessments for preparation, but you’ll need to find a C3PAO to certify—it’s the only way to certify for organizations at Level 2 that do not qualify for self-assessment. RSI Security is a C3PAO fully recognized and listed by the CyberAB; we can facilitate your certification process.

At CMMC Level 3, organizations need to conduct triennial government-led assessments. The specific scope of these assessments is not yet known, but it will likely mirror that of Level 2.

 

Streamline Your CMMC 2.0 Prep Today

Ultimately, preparing for CMMC 2.0 compliance starts with understanding what the rules are, whether they apply, and how they’ve changed. Then, you’ll need to create and execute a plan for implementation. And assessment, whether self-led or assisted, will grant certification.

RSI Security helps DIB organizations prepare for long-term DoD compliance. As a C3PAO and advisor, we understand that discipline now will unlock the freedom to grow in the future. And we’re committed to helping you rethink cyberdefenses for seamless, long-term compliance.

To learn more about our CMMC 2.0 DoD compliance services, contact RSI Security today!

 

Exit mobile version