To understand the elements covered by NIST 171, DFARS 252.204-7012, and CMMC, this article will cover three broad areas.

  • Part I: The history of CUI, regulatory bodies FARS, DFARS, and USD(A&S), recent changes to The Interim DFARS Rule, and DoD Certification guidance, now (CMMC 2.0).
  • Part II: NIST SP 800-171 includes NIST SP 800-171A, and NIST SP 800-172, related standards representing the foundation and methods for scoping, tailoring, and selection of NIST 171 security requirements. These related standards are FIPS PUB 199 & FIPS PUB 200, and NIST SP 800-53 & NIST SP 800-53B (soon to be 800-53C).
  • Part III: NIST 171 Assessment as mandated by DFARS and addressed by the Cybersecurity Maturity Model Certificate (CMMC) DoD certification, with model details to assist in building functional GRC to manage the data elements in the assessment.

You may be wondering if there's a cheat sheet based on your compliance role. I don't think so, but just to be certain, here's a summary of what I think you need to know based on the role you might play. If that's not a concern, go right ahead and jump to Part I.

Our Roles in Understanding What Seems to be Redundant

The proliferation of partially correct online information is confusing. If you’ve been researching this topic, the terms NIST SP 800-171 DoD Assessment Methodology, CMMC Certification, and DFARS 252.204-7012 Strategically Implementing Cybersecurity Contract Clauses are strewn about and used nearly interchangeably. Understanding the three main elements, the standards, the regulations, the governing audit body, and guidance, begins with defining our role as, for example, the Supplier’s Internal Compliance Professional, a DoD Assessor, as Legal or Executive Management for the Offering, or as DCMA contract administration.

Security and Compliance Professionals: For Security and Compliance Professionals, a challenge to anyone’s understanding of NIST SP 800- 171 compliance is the relationship it shares with several critical frameworks representing the Foundation of Assessment and the Catalog of Controls that feed into a broader spectrum of Federal compliances. Another challenge is if the Department of Defense (DoD) Cybersecurity Maturity Model Certification, CMMC, uses different words meant to connect and translate into a measurable program the array of NIST Special Publications 171r2, 171A, 172, and the NIST Handbook 162. Good News. It is.

DoD Contract Officer and DCMA: The multiple provisions and clauses in DFARS guidance mainly pertain to the responsibilities of the DoD Contract Officer, to Compliance Program Management, and for operations of the Defense Contract Management Agency. DFARS is written for those agencies and the assessors who oversee their implementation. Vendors should read and understand the clauses and provisions of DFARS to assure they are handled fairly.

DoD Certified Assessor: The current CMMC model is redundant and identical to NIST SP 800-171 Methodologies and serves as Audit Guidance for the DoD Certified Assessor. For professionals who are not required to use a CMMC third-party assessor, and where the Basic and Moderate Assessments only need them to self-report the Basic or Basic plus Derived 110 security requirements into the SPRS, their review of the CMMC 2.0 may be entirely bypassed. (See Table 1 – Minimum Knowledge)

Certified Assessors will reference the vendor-supplied information in the SPRS and interpret that content according to the DoD-certified Assessor guidance, as noted in the following table across rows for Compliance professionals for Medium and High Assessment.

Table 1- Minimum Knowledge Requirement Based on User Role – Note *CMMC Rule is due to reissue in 2022, CMMC Level 3 guidance to follow soon after. The generally accepted expectation is that CMMC Level 3 will implement NIST SP 800-172.

Domains of Knowledge to the Right

NIST Frameworks (The SP-800 series)

DFARS Guidance 

Certified Assessor Requirement Level

Use Case Below

NIST 171, 171A-Low, 171A-Medium, 171A-High, 172, DoD NIST 171 Assessment MethodologyNIST.HB.162 Assessors Handbook

DFARS 2019-D041, DFARS 252.204-7012, DFARS 252.204-7019, DFARS provision 252.204-7008, *CMMC Rule

CMMC L1, L2, L3, CMMC L1 Scoping Guide, CMMC L2 Scoping Guide, SPRS-Basic, SPRS-Derived, DoD NIST 171 Assessment Methodology, NIST.HB.162 Assessors Handbook

?‍?Compliance Professionals – Basic Assessment

NIST 171, 171A-Low, NIST.HB.162 Assessors Handbook (for low)

DFARS 252.204-7012

SPRS, DoD NIST 171 Assessment Methodology, NIST.HB.162 Assessors Handbook

?️‍♀️Compliance Professionals – Medium Assessment

NIST 171, 171A-Medium, NIST.HB.162 Assessors Handbook

DFARS 252.204-7012

SPRS, DoD NIST 171 Assessment Methodology, NIST.HB.162 Assessors Handbook, CMMC L2, CMMC Level 2 Scoping Guide

?‍?Compliance Professionals – High Assessment

NIST 171, 171A-High, 172, NIST.HB.162 Assessors Handbook

DFARS 252.204-7012, DFARS 252.204-7019, *CMMC Rule

CMMC L1, L2, L3 (content is the same as NIST 172), NIST.HB.162 Assessors Handbook

?‍?Assessors – externally accredited, DoD certified NIST

NIST 171, 171A-all, 172, NIST.HB.162 Assessors Handbook

DFARS 2019-D041, DFARS 252.204-7012, DFARS 252.204-7019, *CMMC Rule

CMMC L1, L2, L3, SPRS-Basic, and Derived, NIST.HB.162 Assessors Handbook

?‍♂️Executives / Legal

NIST 171 (Chapter 3)

DFARS 2019-D041, DFARS 252.204-7012

N/A

?‍⚖️DCMA (Contract Administrator)

DoD NIST 171 Assessment Methodology

DFARS 2019-D041, DFARS 252.204-7012 DFARS 252.204-7019

SPRS System – Review system results as provided by an assessor

 

Main Menu