Requirements for NIST 171 Assessments via SPRS and CMMC

The Defense Federal Acquisition Regulation Supplement, or DFARS, raises stakes on U.S. Department of Defense (DoD) contractors who must comply with NIST frameworks, including Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. DFARS Clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, is DFARS' latest mandatory addition. DFARS Clause 252.204-7012 [DFARS 7012] requires government contractors and suppliers to comply with NIST SP 800-171 SP 800-171 and to Self-Report a compliance score via the Supplier Performance Risk System (SPRS) [x]

The DFARS interim rule went into effect on November 30th, 2020, implementing a five-year strategy intended to minimize the financial impacts to the Defense Industrial Base (DIB) and disruption to the existing DoD supply chain. [xi]

Per the DFARS Interim Rule DoD, all contracts require that contractors perform at least the NIST 800-171 Basic Assessment and submit a score to the Supplier Performance Risk System (SPRS), along with the required documents POA&MS and System Security Plan (SSP) [xii], as a condition for contract award. Once the initial SPRS record has undergone review, the DoD will ask some contractors to conduct a NIST 800-171 Medium Assessment or High Assessment, conducted with oversight by DoD-trained DoD personnel.

SPRS is a Web-enabled, Department of Defense enterprise-wide application, which operates as the Defense Federal Acquisition Regulation Supplement (DFARS) primary retrieval system for supplier performance information. To gain an understanding of the extended scope of entities identified as part of the Defense Industrial Base (DOB), visit Defense Primer: U.S. Defense Industrial Base (congress.gov)

Safeguarding Covered Defense Information (CDI)

Covered Defense Information (CDI): Is a term defined in the DFAR clause 252.204-7012 Safeguarding Covered Defense Information, as unclassified controlled technical information or other information, as described in the Controlled Unclassified Information (CUI) registry that requires safeguarding or dissemination controls under and consistent with law, regulations and government-wide policies and is (1) Marked or otherwise identified in a contract, task order or delivery order on behalf of the DoD in support of the performance of a contract or (2) collected, developed, received, transmitted, used or stored by or on behalf of the contractor in support of the performance of the contract.[xiii] To learn more, review Becoming DFARS/NIST Compliant (Cybersecurity) PowerPoint Presentation (defense.gov)

DFARS Clause 252.204-7012 requires contractors and subcontractors to

  1. Provide adequate security to safeguard covered defense information that resides on or is transiting through a contractor’s internal information system or network
  2. Report cyber incidents that affect a covered contractor information system or the covered defense information residing therein or that affect the contractor’s ability to perform requirements designated as operationally critical support
  3. Submit malicious software discovered and isolated in connection with a reported cyber incident to the DoD Cyber Crime Center
  4. Submit media (if requested) and additional information to support a damage assessment
  5. Flow down the clause in subcontracts for operationally critical support or for which subcontract performance will involve covered defense information. [xiv]

Cybersecurity Maturity Model Certification (CMMC) Program (U.S. Department of Defense)

Undersecretary of Defense for Acquisition and SustainmentCMMC stands for “Cybersecurity Maturity Model Certification.” The CMMC will encompass multiple maturity levels that range from “Basic Cybersecurity Hygiene” to “Advanced/Progressive.” The intent is to incorporate CMMC into Defense Federal Acquisition Regulation Supplement (DFARS) and use it as a requirement for contract award.

CMMC-AB stands for “Cybersecurity Maturity Model Certification Accreditation Body.” The CMMC-AB establishes and oversees a qualified, trained, high-fidelity community of assessors that can deliver consistent and informative assessments to participating organizations against a defined set of controls/best practices within the Cybersecurity Maturity Model Certification (CMMC) Program.

The CMMC program includes cyber protection standards for companies in the defense industrial base (DIB). By incorporating cybersecurity standards into acquisition programs, CMMC provides the Department with assurance that contractors and subcontractors meet DoD’s cybersecurity requirements. The DIB targets increasingly frequent and complex cyberattacks by adversaries and non-state actors. Dynamically enhancing DIB cybersecurity to meet these evolving threats and safeguarding the information that supports and enables our warfighters is a top priority for the Department. CMMC is a critical component of the Department’s extensive DIB cybersecurity effort. (Source Project Spectrum)

The Proposed Certification Standards or CMMC Levels and plans laid out by the CMMC Accreditation Body

The internal assessment of CMMC was co-chaired by: Mieke Eoyang, Deputy Assistant Secretary of Defense for Cyber Policy; David Frederick, Executive Director of U.S. Cyber Command; David McKeown, Deputy Chief Information Officer for Cybersecurity; and Jesse Salazar, Deputy Assistant Secretary of Defense for Industrial Policy; and included senior leaders from 18 components across the Department.[xiv] For up-to-the-minute information regarding CMMC approvals, visit https://www.acq.osd.mil/cmmc/index.html.

The CMMC-AB is an independent accreditation entity responsible for establishing, managing, controlling, and administering CMMC assessment, certification, training, and accreditation processes for the Defense Supply Chain according to a contract signed with the Department of Defense.

CMMC 2.0 has not released the Level Three requirement. Based on the November & December 2021 CMMC-AB Town Halls, the finalized certification is expected to appear in this graphic with one notable exception. [SP 800-171 has 31 “Basic Security Requirements” as opposed to the 17 “Practices” in CMMC 1.0. Based on the published standards for NIST SP 800-171 and 172, Figure 1 adjusts the totals for Basic and Derived to reflect the actual and current number of requirements relative to each level according to the DoD NIST 171 Assessment Methodology. A soon-to-release update to The Rule will enforce the CMMC 2.0 change.

The current DFARS CMMC Rule does not eliminate Self-Reported scoring via the Supplier Performance Risk System (SPRS). Presently, the minimum knowledge necessary to navigate the NIST 800 171 is the NIST SP 800-171 r2 plus its partner document NIST SP 800-171A, as measured according to the NIST SP 800-171 Assessment Methodology Version 1.2.1 6.24.2020.pdf (osd.mil) and reported to the SPRS.

CMMC Strategic Intent as of Dec 2021

Figure 1 Three Levels of CMMC now rely upon NIST 171 and NIST 172 Series

The Moving Target – CMMC Certifications and Securing the Defense Industrial Base CMMC 2.0

In response to the question, “What is the department’s intent regarding acceptance agreements between CMMC and other cybersecurity standards and assessments?” the answer from OUSD A&S - Cybersecurity Maturity Model Certification (CMMC) (osd.mil) [xiv]states:

“The Department is pursuing the development of acceptance standards between CMMC and other cybersecurity standards and assessments, including between CMMC Level 2 (Advanced) and the NIST SP 800-171 DoD Assessment Methodology for the high assessment confidence level, as well as CMMC Level 2 and the GSA Federal Risk and Authorization Management Program (FedRAMP) requirements for commercial cloud service offerings. Furthermore, DoD is working with international partners to coordinate potential agreements between CMMC and their respective cybersecurity programs.  Any such equivalencies or acceptance standards, if established, will be implemented as part of the rulemaking process.” [xvi]

The entirety of DFARS, CMMC, and NIST 171 is a lot to take in. Still, at its simplest, Vendors who handle CUI must understand that DFARS is a set of regulations that are satisfied by implementing a set of frameworks & standards (NIST 171 and 172 series) and are audited by a CMMC assessor according to the CMMC model that leverages all the parts of the NIST 800-171 Assessment Methodology. The Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019–D041) added Subpart 204.75, Cybersecurity Maturity Model Certification (CMMC) to specify the policy and procedures for awarding a contract or exercising an option on a contract. This model includes determining the requirement (be it Level 1 - Basic or up to Level 3 - Expert) necessary for the Offeror’s CMMC certification. Specifically, this subpart directs contracting officers to verify in SPRS that the offeror’s CMMC certification is current and meets the required level before making the award.

Main Menu