achieving-cmmc-level-2-compliance
Compare original and translation side by side
🇺🇸
Original
English🇨🇳
Translation
ChineseAchieving CMMC Level 2 Compliance
实现CMMC Level 2合规
When to Use
使用场景
- When an organization in the Defense Industrial Base (DIB) stores, processes, or transmits Controlled Unclassified Information (CUI) under a DoD contract.
- When a contract includes DFARS 252.204-7012 (safeguarding/incident reporting), -7019/-7020 (NIST 800-171 self-assessment + SPRS), or the new -7021 (CMMC requirement).
- When preparing for a C3PAO third-party assessment or a DoD-led assessment.
- When you must compute, post, or improve an SPRS score based on the NIST SP 800-171 DoD Assessment Methodology.
- When authoring or remediating a System Security Plan (SSP) and POA&M for the 110 requirements.
- When scoping which assets fall inside the CUI/FCI boundary (CUI assets, security-protection assets, contractor risk-managed assets, out-of-scope).
- 当国防工业基础(Defense Industrial Base, DIB)内的组织在DoD合同下存储、处理或传输受控非机密信息(Controlled Unclassified Information, CUI)时。
- 当合同包含DFARS 252.204-7012(防护/事件报告)、-7019/-7020(NIST 800-171自我评估+SPRS)或新增的-7021(CMMC要求)条款时。
- 当准备由C3PAO进行第三方评估或DoD主导的评估时。
- 当必须基于NIST SP 800-171 DoD评估方法计算、提交或提升SPRS分数时。
- 当编写或修订针对110项要求的系统安全计划(System Security Plan, SSP)和POA&M时。
- 当界定哪些资产属于CUI/FCI边界范围时(包括CUI资产、安全防护资产、承包商风险管理资产、非范围资产)。
Prerequisites
先决条件
- Knowledge of which contracts carry CUI and the CUI categories involved (check the contract and the DoD CUI Registry).
- An asset inventory and network diagram so you can define the CMMC assessment scope before assessing controls.
- The NIST SP 800-171 Rev 2 requirements and the DoD Assessment Methodology scoring weights.
- A documented SSP (its absence is itself a failed requirement — 3.12.4).
- Identification of any External Service Providers (ESPs) / cloud services touching CUI, and whether they meet FedRAMP Moderate (or equivalency).
- 了解哪些合同涉及CUI以及相关的CUI类别(查看合同和DoD CUI注册表)。
- 拥有资产清单和网络拓扑图,以便在评估控制措施前确定CMMC评估范围。
- 熟悉NIST SP 800-171 Rev 2要求和DoD评估方法的评分权重。
- 已记录的SSP(缺少SSP本身即视为未满足要求——3.12.4)。
- 识别任何接触CUI的外部服务提供商(External Service Providers, ESPs)/云服务,以及它们是否符合FedRAMP中等(或等效)标准。
Workflow
工作流程
1. Determine applicability and CUI categories
1. 确定适用性和CUI类别
Confirm the contract requires CMMC Level 2 (CUI present, not just FCI). FCI-only contracts are Level 1 (the 15 FAR 52.204-21 requirements). Identify CUI categories from the contract and the DoD CUI Registry.
确认合同要求达到CMMC Level 2(存在CUI,而非仅FCI)。仅涉及FCI的合同属于Level 1(需满足15项FAR 52.204-21要求)。从合同和DoD CUI注册表中识别CUI类别。
2. Scope the environment
2. 界定环境范围
Classify every asset into one of the CMMC scoping categories:
- CUI Assets — process/store/transmit CUI (in scope, assessed against all applicable controls).
- Security Protection Assets — provide security to the CUI environment (in scope).
- Contractor Risk Managed Assets — could but are not intended to handle CUI; managed by policy.
- Specialized Assets (IoT/OT, GFE, test equipment) — documented, limited assessment.
- Out-of-Scope — physically/logically isolated from CUI.
Minimize scope deliberately — a smaller, well-segmented CUI enclave is far cheaper to certify than a flat network.
将每个资产分类为以下CMMC范围类别之一:
- CUI资产——处理/存储/传输CUI(属于评估范围,需针对所有适用控制措施进行评估)。
- 安全防护资产——为CUI环境提供安全防护(属于评估范围)。
- 承包商风险管理资产——可能但并非用于处理CUI;由政策进行管理。
- 专用资产(IoT/OT、GFE、测试设备)——需记录在案,评估范围有限。
- 非范围资产——在物理/逻辑上与CUI隔离。
有意缩小范围——一个更小、分段良好的CUI隔离区比扁平化网络的认证成本低得多。
3. Implement the 110 requirements (NIST SP 800-171 Rev 2)
3. 实施110项要求(NIST SP 800-171 Rev 2)
Work the 14 families (3.1–3.14). For each requirement, implement, then write the how in the SSP. High-leverage early wins: MFA (3.5.3), FIPS-validated cryptography (3.13.11), audit logging (3.3.x), access control + least privilege (3.1.x), and incident response (3.6.x).
落实14个家族(3.1–3.14)的要求。对于每项要求,先实施,然后在SSP中记录具体实施方式。早期高价值举措:MFA(3.5.3)、FIPS验证加密(3.13.11)、审计日志(3.3.x)、访问控制+最小权限(3.1.x)以及事件响应(3.6.x)。
4. Score with the DoD Assessment Methodology (SPRS)
4. 使用DoD评估方法(SPRS)评分
Start at 110 and subtract the weighted value (1, 3, or 5 points) of each unmet requirement; partial credit applies to a small number of controls (e.g., MFA, FIPS crypto). The result is the SPRS score (maximum 110; the methodology floor is −203). Post the score, the SSP date, and the assessment scope to SPRS (or eMASS for higher assessments).
初始分数为110,减去每项未满足要求的加权分值(1、3或5分);少数控制措施可获得部分学分(如MFA、FIPS加密)。最终结果即为SPRS分数(最高分110;方法学最低分为-203)。将分数、SSP日期和评估范围提交至SPRS(或针对更高评估等级提交至eMASS)。
5. Build a compliant POA&M
5. 构建合规的POA&M
Document every unmet requirement with owner, remediation, and milestone. Constraints under the CMMC rule: a Conditional status requires a score of at least 80% (≥ 88 of 110), only POA&M-eligible requirements may be deferred (the highest-weighted security requirements must be fully met — verify eligibility against 32 CFR Part 170), and all POA&M items must be closed within 180 days to convert Conditional → Final.
记录每项未满足要求的负责人、整改措施和里程碑。CMMC规则下的约束条件:条件性状态要求分数至少达到80%(≥110分中的88分),仅符合POA&M资格的要求可延期(权重最高的安全要求必须完全满足——需根据32 CFR Part 170验证资格),且所有POA&M项目必须在180天内完成,才能将条件性状态转换为最终状态。
6. Assess (self or C3PAO)
6. 评估(自我评估或C3PAO评估)
- Level 1 and a subset of Level 2 = annual self-assessment with an affirmation in SPRS.
- Level 2 (most CUI contracts) = triennial C3PAO certification assessment.
- Level 3 = DoD (DIBCAC) assessment on top of Level 2, adding SP 800-172 enhanced requirements. Assessors evaluate each objective as MET / NOT MET / N/A with evidence (examine/interview/test). A senior official files the annual affirmation of continued compliance.
- Level 1和Level 2的部分要求 = 年度自我评估,并在SPRS中提交确认声明。
- Level 2(大多数CUI合同) = 每三年一次的C3PAO认证评估。
- Level 3 = 在Level 2基础上进行DoD(DIBCAC)评估,新增SP 800-172增强要求。 评估人员根据证据(检查/访谈/测试)将每个目标评估为已满足/未满足/不适用。高级官员需提交年度合规确认声明。
7. Maintain certification
7. 维护认证
Certification is valid three years with annual affirmations. Maintain the SSP, re-score on change, keep evidence current, and feed significant changes back into the assessment.
认证有效期为三年,期间需提交年度确认声明。维护SSP,在发生变更时重新评分,保持证据更新,并将重大变更反馈至评估流程。
Key Concepts
核心概念
| Concept | Definition |
|---|---|
| FCI | Federal Contract Information — Level 1 protects it (FAR 52.204-21). |
| CUI | Controlled Unclassified Information — Level 2 protects it (NIST 800-171). |
| 110 requirements | The SP 800-171 Rev 2 security requirements across 14 families. |
| SPRS | Supplier Performance Risk System — where the 800-171 score is posted. |
| DoD Assessment Methodology | The 1/3/5-point weighting used to compute the score from 110. |
| C3PAO | CMMC Third-Party Assessment Organization — performs Level 2 certification. |
| POA&M | Plan of Action & Milestones — limited, must close in 180 days for Final status. |
| Conditional vs Final | Conditional = open POA&M (score ≥ 80%); Final = all controls met. |
| ESP | External Service Provider — must meet FedRAMP Moderate / equivalency for CUI. |
| Scoping categories | CUI / Security Protection / Contractor Risk Managed / Specialized / Out-of-Scope. |
| 概念 | 定义 |
|---|---|
| FCI | 联邦合同信息——Level 1负责防护(FAR 52.204-21)。 |
| CUI | 受控非机密信息——Level 2负责防护(NIST 800-171)。 |
| 110项要求 | SP 800-171 Rev 2涵盖14个家族的安全要求。 |
| SPRS | 供应商绩效风险系统——用于提交800-171分数的平台。 |
| DoD Assessment Methodology | 用于从110分基础计算最终分数的1/3/5分权重规则。 |
| C3PAO | CMMC第三方评估组织——负责执行Level 2认证评估。 |
| POA&M | 行动计划与里程碑——范围有限,需在180天内完成以获得最终状态。 |
| 条件性vs最终状态 | 条件性状态=存在未完成的POA&M(分数≥80%);最终状态=所有控制措施均已满足。 |
| ESP | 外部服务提供商——处理CUI时必须符合FedRAMP中等或等效标准。 |
| 范围类别 | CUI/安全防护/承包商风险管理/专用/非范围。 |
Tools & Systems
工具与系统
- NIST SP 800-171 Rev 2 — the 110 requirements (and 800-171A for assessment objectives).
- DoD NIST SP 800-171 Assessment Methodology — the scoring weights.
- 32 CFR Part 170 (CMMC Program rule) and 48 CFR / DFARS 252.204-7021 (acquisition rule).
- SPRS — score posting; SAM.gov for registration.
- SP 800-172 / 800-172A — enhanced requirements for Level 3.
- GRC / compliance tooling — to manage the SSP, POA&M, and evidence (e.g., Xacta, RegScale, FutureFeed-style trackers).
- NIST SP 800-171 Rev 2——110项要求(以及用于评估目标的800-171A)。
- DoD NIST SP 800-171评估方法——评分权重规则。
- 32 CFR Part 170(CMMC项目规则)和48 CFR / DFARS 252.204-7021(采购规则)。
- SPRS——分数提交平台;SAM.gov用于注册。
- SP 800-172 / 800-172A——Level 3的增强要求。
- GRC/合规工具——用于管理SSP、POA&M和证据(例如Xacta、RegScale、FutureFeed类跟踪工具)。
Common Scenarios
常见场景
- Prime flows CUI to a sub. The sub needs its own Level 2 scope, SSP, SPRS score, and (most likely) C3PAO certification.
- Score is below 88. Prioritize the highest-weighted unmet requirements (5-point, then 3-point) to clear the conditional threshold and shrink the POA&M.
- Cloud holds CUI. Confirm the service is FedRAMP Moderate authorized or meets equivalency; document the responsibility split.
- Flat network. Re-scope into a segmented CUI enclave to cut the assessment surface before spending on controls.
- Annual affirmation due. A senior official affirms continued compliance in SPRS; let it lapse and you risk contract eligibility.
- 主承包商向分包商传输CUI:分包商需要自己的Level 2范围、SSP、SPRS分数,并且(很可能)需要C3PAO认证。
- 分数低于88分:优先处理权重最高的未满足要求(5分,其次是3分),以达到条件性认证阈值并缩小POA&M范围。
- 云存储CUI:确认服务已获得FedRAMP中等授权或符合等效标准;记录责任划分。
- 扁平化网络:重新界定范围为分段的CUI隔离区,在投入控制措施前减少评估面。
- 年度确认声明到期:高级官员需在SPRS中确认持续合规;逾期未提交可能会失去合同资格。
Output Format
输出格式
Produce a CMMC Level 2 Readiness Report using , containing:
assets/template.md- Applicability & CUI categories — why Level 2 applies.
- Scope — assets by scoping category and the CUI boundary diagram reference.
- Control status by family — met / not met / N/A across the 14 families.
- SPRS score — computed score, deductions, and the gap to 110 and to the 88 threshold.
- POA&M — unmet requirements, eligibility check, owners, 180-day milestones.
- Assessment path — self vs C3PAO, target date, affirmation owner.
- Remediation roadmap — sequenced by point value and effort.
Use to compute the SPRS score from a control-status JSON, flag POA&M-eligibility concerns, and report the gap to the conditional-certification threshold.
scripts/process.py使用生成CMMC Level 2就绪报告,内容包括:
assets/template.md- 适用性与CUI类别——说明为何适用Level 2。
- 范围——按范围类别划分的资产以及CUI边界图参考。
- 按家族划分的控制状态——14个家族的已满足/未满足/不适用状态。
- SPRS分数——计算得出的分数、扣分情况,以及与满分110分和88分阈值的差距。
- POA&M——未满足要求、资格检查、负责人、180天里程碑。
- 评估路径——自我评估vs C3PAO评估、目标日期、确认声明负责人。
- 整改路线图——按分值和工作量排序。
使用从控制状态JSON计算SPRS分数,标记POA&M资格问题,并报告与条件性认证阈值的差距。
scripts/process.py