achieving-cmmc-level-2-compliance

Compare original and translation side by side

🇺🇸

Original

English
🇨🇳

Translation

Chinese

Achieving CMMC Level 2 Compliance

实现CMMC Level 2合规

When to Use

使用场景

  • When an organization in the Defense Industrial Base (DIB) stores, processes, or transmits Controlled Unclassified Information (CUI) under a DoD contract.
  • When a contract includes DFARS 252.204-7012 (safeguarding/incident reporting), -7019/-7020 (NIST 800-171 self-assessment + SPRS), or the new -7021 (CMMC requirement).
  • When preparing for a C3PAO third-party assessment or a DoD-led assessment.
  • When you must compute, post, or improve an SPRS score based on the NIST SP 800-171 DoD Assessment Methodology.
  • When authoring or remediating a System Security Plan (SSP) and POA&M for the 110 requirements.
  • When scoping which assets fall inside the CUI/FCI boundary (CUI assets, security-protection assets, contractor risk-managed assets, out-of-scope).
  • 当国防工业基础(Defense Industrial Base, DIB)内的组织在DoD合同下存储、处理或传输受控非机密信息(Controlled Unclassified Information, CUI)时。
  • 当合同包含DFARS 252.204-7012(防护/事件报告)、-7019/-7020(NIST 800-171自我评估+SPRS)或新增的-7021(CMMC要求)条款时。
  • 当准备由C3PAO进行第三方评估或DoD主导的评估时。
  • 当必须基于NIST SP 800-171 DoD评估方法计算、提交或提升SPRS分数时。
  • 当编写或修订针对110项要求的系统安全计划(System Security Plan, SSP)和POA&M时。
  • 当界定哪些资产属于CUI/FCI边界范围时(包括CUI资产、安全防护资产、承包商风险管理资产、非范围资产)。

Prerequisites

先决条件

  • Knowledge of which contracts carry CUI and the CUI categories involved (check the contract and the DoD CUI Registry).
  • An asset inventory and network diagram so you can define the CMMC assessment scope before assessing controls.
  • The NIST SP 800-171 Rev 2 requirements and the DoD Assessment Methodology scoring weights.
  • A documented SSP (its absence is itself a failed requirement — 3.12.4).
  • Identification of any External Service Providers (ESPs) / cloud services touching CUI, and whether they meet FedRAMP Moderate (or equivalency).
  • 了解哪些合同涉及CUI以及相关的CUI类别(查看合同和DoD CUI注册表)。
  • 拥有资产清单和网络拓扑图,以便在评估控制措施前确定CMMC评估范围。
  • 熟悉NIST SP 800-171 Rev 2要求和DoD评估方法的评分权重。
  • 已记录的SSP(缺少SSP本身即视为未满足要求——3.12.4)。
  • 识别任何接触CUI的外部服务提供商(External Service Providers, ESPs)/云服务,以及它们是否符合FedRAMP中等(或等效)标准。

Workflow

工作流程

1. Determine applicability and CUI categories

1. 确定适用性和CUI类别

Confirm the contract requires CMMC Level 2 (CUI present, not just FCI). FCI-only contracts are Level 1 (the 15 FAR 52.204-21 requirements). Identify CUI categories from the contract and the DoD CUI Registry.
确认合同要求达到CMMC Level 2(存在CUI,而非仅FCI)。仅涉及FCI的合同属于Level 1(需满足15项FAR 52.204-21要求)。从合同和DoD CUI注册表中识别CUI类别。

2. Scope the environment

2. 界定环境范围

Classify every asset into one of the CMMC scoping categories:
  • CUI Assets — process/store/transmit CUI (in scope, assessed against all applicable controls).
  • Security Protection Assets — provide security to the CUI environment (in scope).
  • Contractor Risk Managed Assets — could but are not intended to handle CUI; managed by policy.
  • Specialized Assets (IoT/OT, GFE, test equipment) — documented, limited assessment.
  • Out-of-Scope — physically/logically isolated from CUI.
Minimize scope deliberately — a smaller, well-segmented CUI enclave is far cheaper to certify than a flat network.
将每个资产分类为以下CMMC范围类别之一:
  • CUI资产——处理/存储/传输CUI(属于评估范围,需针对所有适用控制措施进行评估)。
  • 安全防护资产——为CUI环境提供安全防护(属于评估范围)。
  • 承包商风险管理资产——可能但并非用于处理CUI;由政策进行管理。
  • 专用资产(IoT/OT、GFE、测试设备)——需记录在案,评估范围有限。
  • 非范围资产——在物理/逻辑上与CUI隔离。
有意缩小范围——一个更小、分段良好的CUI隔离区比扁平化网络的认证成本低得多。

3. Implement the 110 requirements (NIST SP 800-171 Rev 2)

3. 实施110项要求(NIST SP 800-171 Rev 2)

Work the 14 families (3.1–3.14). For each requirement, implement, then write the how in the SSP. High-leverage early wins: MFA (3.5.3), FIPS-validated cryptography (3.13.11), audit logging (3.3.x), access control + least privilege (3.1.x), and incident response (3.6.x).
落实14个家族(3.1–3.14)的要求。对于每项要求,先实施,然后在SSP中记录具体实施方式。早期高价值举措:MFA(3.5.3)、FIPS验证加密(3.13.11)、审计日志(3.3.x)、访问控制+最小权限(3.1.x)以及事件响应(3.6.x)。

4. Score with the DoD Assessment Methodology (SPRS)

4. 使用DoD评估方法(SPRS)评分

Start at 110 and subtract the weighted value (1, 3, or 5 points) of each unmet requirement; partial credit applies to a small number of controls (e.g., MFA, FIPS crypto). The result is the SPRS score (maximum 110; the methodology floor is −203). Post the score, the SSP date, and the assessment scope to SPRS (or eMASS for higher assessments).
初始分数为110,减去每项未满足要求的加权分值(1、3或5分);少数控制措施可获得部分学分(如MFA、FIPS加密)。最终结果即为SPRS分数(最高分110;方法学最低分为-203)。将分数、SSP日期和评估范围提交至SPRS(或针对更高评估等级提交至eMASS)。

5. Build a compliant POA&M

5. 构建合规的POA&M

Document every unmet requirement with owner, remediation, and milestone. Constraints under the CMMC rule: a Conditional status requires a score of at least 80% (≥ 88 of 110), only POA&M-eligible requirements may be deferred (the highest-weighted security requirements must be fully met — verify eligibility against 32 CFR Part 170), and all POA&M items must be closed within 180 days to convert Conditional → Final.
记录每项未满足要求的负责人、整改措施和里程碑。CMMC规则下的约束条件条件性状态要求分数至少达到80%(≥110分中的88分),仅符合POA&M资格的要求可延期(权重最高的安全要求必须完全满足——需根据32 CFR Part 170验证资格),且所有POA&M项目必须在180天内完成,才能将条件性状态转换为最终状态。

6. Assess (self or C3PAO)

6. 评估(自我评估或C3PAO评估)

  • Level 1 and a subset of Level 2 = annual self-assessment with an affirmation in SPRS.
  • Level 2 (most CUI contracts) = triennial C3PAO certification assessment.
  • Level 3 = DoD (DIBCAC) assessment on top of Level 2, adding SP 800-172 enhanced requirements. Assessors evaluate each objective as MET / NOT MET / N/A with evidence (examine/interview/test). A senior official files the annual affirmation of continued compliance.
  • Level 1和Level 2的部分要求 = 年度自我评估,并在SPRS中提交确认声明。
  • Level 2(大多数CUI合同) = 每三年一次的C3PAO认证评估。
  • Level 3 = 在Level 2基础上进行DoD(DIBCAC)评估,新增SP 800-172增强要求。 评估人员根据证据(检查/访谈/测试)将每个目标评估为已满足/未满足/不适用。高级官员需提交年度合规确认声明

7. Maintain certification

7. 维护认证

Certification is valid three years with annual affirmations. Maintain the SSP, re-score on change, keep evidence current, and feed significant changes back into the assessment.
认证有效期为三年,期间需提交年度确认声明。维护SSP,在发生变更时重新评分,保持证据更新,并将重大变更反馈至评估流程。

Key Concepts

核心概念

ConceptDefinition
FCIFederal Contract Information — Level 1 protects it (FAR 52.204-21).
CUIControlled Unclassified Information — Level 2 protects it (NIST 800-171).
110 requirementsThe SP 800-171 Rev 2 security requirements across 14 families.
SPRSSupplier Performance Risk System — where the 800-171 score is posted.
DoD Assessment MethodologyThe 1/3/5-point weighting used to compute the score from 110.
C3PAOCMMC Third-Party Assessment Organization — performs Level 2 certification.
POA&MPlan of Action & Milestones — limited, must close in 180 days for Final status.
Conditional vs FinalConditional = open POA&M (score ≥ 80%); Final = all controls met.
ESPExternal Service Provider — must meet FedRAMP Moderate / equivalency for CUI.
Scoping categoriesCUI / Security Protection / Contractor Risk Managed / Specialized / Out-of-Scope.
概念定义
FCI联邦合同信息——Level 1负责防护(FAR 52.204-21)。
CUI受控非机密信息——Level 2负责防护(NIST 800-171)。
110项要求SP 800-171 Rev 2涵盖14个家族的安全要求。
SPRS供应商绩效风险系统——用于提交800-171分数的平台。
DoD Assessment Methodology用于从110分基础计算最终分数的1/3/5分权重规则。
C3PAOCMMC第三方评估组织——负责执行Level 2认证评估。
POA&M行动计划与里程碑——范围有限,需在180天内完成以获得最终状态。
条件性vs最终状态条件性状态=存在未完成的POA&M(分数≥80%);最终状态=所有控制措施均已满足。
ESP外部服务提供商——处理CUI时必须符合FedRAMP中等或等效标准。
范围类别CUI/安全防护/承包商风险管理/专用/非范围。

Tools & Systems

工具与系统

  • NIST SP 800-171 Rev 2 — the 110 requirements (and 800-171A for assessment objectives).
  • DoD NIST SP 800-171 Assessment Methodology — the scoring weights.
  • 32 CFR Part 170 (CMMC Program rule) and 48 CFR / DFARS 252.204-7021 (acquisition rule).
  • SPRS — score posting; SAM.gov for registration.
  • SP 800-172 / 800-172A — enhanced requirements for Level 3.
  • GRC / compliance tooling — to manage the SSP, POA&M, and evidence (e.g., Xacta, RegScale, FutureFeed-style trackers).
  • NIST SP 800-171 Rev 2——110项要求(以及用于评估目标的800-171A)。
  • DoD NIST SP 800-171评估方法——评分权重规则。
  • 32 CFR Part 170(CMMC项目规则)和48 CFR / DFARS 252.204-7021(采购规则)。
  • SPRS——分数提交平台;SAM.gov用于注册。
  • SP 800-172 / 800-172A——Level 3的增强要求。
  • GRC/合规工具——用于管理SSP、POA&M和证据(例如Xacta、RegScale、FutureFeed类跟踪工具)。

Common Scenarios

常见场景

  • Prime flows CUI to a sub. The sub needs its own Level 2 scope, SSP, SPRS score, and (most likely) C3PAO certification.
  • Score is below 88. Prioritize the highest-weighted unmet requirements (5-point, then 3-point) to clear the conditional threshold and shrink the POA&M.
  • Cloud holds CUI. Confirm the service is FedRAMP Moderate authorized or meets equivalency; document the responsibility split.
  • Flat network. Re-scope into a segmented CUI enclave to cut the assessment surface before spending on controls.
  • Annual affirmation due. A senior official affirms continued compliance in SPRS; let it lapse and you risk contract eligibility.
  • 主承包商向分包商传输CUI:分包商需要自己的Level 2范围、SSP、SPRS分数,并且(很可能)需要C3PAO认证。
  • 分数低于88分:优先处理权重最高的未满足要求(5分,其次是3分),以达到条件性认证阈值并缩小POA&M范围。
  • 云存储CUI:确认服务已获得FedRAMP中等授权或符合等效标准;记录责任划分。
  • 扁平化网络:重新界定范围为分段的CUI隔离区,在投入控制措施前减少评估面。
  • 年度确认声明到期:高级官员需在SPRS中确认持续合规;逾期未提交可能会失去合同资格。

Output Format

输出格式

Produce a CMMC Level 2 Readiness Report using
assets/template.md
, containing:
  1. Applicability & CUI categories — why Level 2 applies.
  2. Scope — assets by scoping category and the CUI boundary diagram reference.
  3. Control status by family — met / not met / N/A across the 14 families.
  4. SPRS score — computed score, deductions, and the gap to 110 and to the 88 threshold.
  5. POA&M — unmet requirements, eligibility check, owners, 180-day milestones.
  6. Assessment path — self vs C3PAO, target date, affirmation owner.
  7. Remediation roadmap — sequenced by point value and effort.
Use
scripts/process.py
to compute the SPRS score from a control-status JSON, flag POA&M-eligibility concerns, and report the gap to the conditional-certification threshold.
使用
assets/template.md
生成CMMC Level 2就绪报告,内容包括:
  1. 适用性与CUI类别——说明为何适用Level 2。
  2. 范围——按范围类别划分的资产以及CUI边界图参考。
  3. 按家族划分的控制状态——14个家族的已满足/未满足/不适用状态。
  4. SPRS分数——计算得出的分数、扣分情况,以及与满分110分和88分阈值的差距。
  5. POA&M——未满足要求、资格检查、负责人、180天里程碑。
  6. 评估路径——自我评估vs C3PAO评估、目标日期、确认声明负责人。
  7. 整改路线图——按分值和工作量排序。
使用
scripts/process.py
从控制状态JSON计算SPRS分数,标记POA&M资格问题,并报告与条件性认证阈值的差距。