Cybersecurity Compliance (and CMMC)

  1. Learn about NIST 800-171 requirements (currently applicable to all levels of DoD contractors including – including lower tier subcontractors):
  2. Learn about Cybersecurity Maturity Model Certification (CMMC):
  3. Follow the CMMC AB (accreditation body) for news:
    • Contact your local APEX Accelerator counselor to make sure you understand how it applies to you and the process. Virginia clients email if you don’t know your counselor.
    • Create a System Security Plan (SSP) – template available on link #1 above from NIST
    • If applicable create a Plan of Action and Milestones (POAM) – template available on link #1 from NIST (look under Documentation)
    • Perform your Basic (self) Assessment against NIST 800-171 – instructions and documents available on link #1 above from NIST (look under documentation)
    • Perform your self-assessment for CMMC:
    • Publish your results from the NIST 800-171 Basic (self) Assessment into the Supplier Performance Risk Management System (SPRS): and review FAQ:
    • If applicable, locate an official Certified 3rd Party Assessment Organization (C3PAO) to perform a CMMC 2.0 level 2 assessment (get multiple quotes on the open market to see how much it will cost for the assessment):

Other resources:

Posted in:

Leave a Comment (0) →