You are not confused because you are new. You are confused because it is written that way.
A free reading aid for defense contractors. The 110 security requirements, the CUI question, the chain of rules, and the Rev. 2 versus Rev. 3 status, in plain language with the original wording beside it. Unofficial, and it says so.
Start wherever you are stuck
-
I do not know if my data is CUI
At most 3 questions about one specific set of information, ending in either a determination or the exact email to send your contracting officer.
-
I need to read a specific control
All 110 requirements, each with a plain-language version, the original wording, the assessment objectives, and its scoring weight.
-
I do not know which rule applies
The chain from contract clause to regulation to standard, in the order you should read it, with what each document does and does not do.
-
I need to know my level
Level 1, 2, or 3 is set by the solicitation, not by you. What each level asks for and who checks it.
-
I heard Rev. 3 changed everything
It has not, yet. What your contract requires today, what NIST has published, and why those are different things.
The short version
- Who has to do this?
- Anyone whose contract carries DFARS 252.204-7012 or FAR 52.204-21, all the way down the supply chain.
- What is the actual work?
- Protect the data, write it down in a system security plan, score yourself, and fix the gaps on a schedule you can show.
- Why is CUI so hard to pin down?
- Because the government is supposed to mark it and often does not. Unmarked does not mean unprotected.
- What if I get it wrong?
- A wrong self-assessment posted to SPRS is a false claim. Asking your contracting officer in writing costs nothing.
The fourteen families
- AC Access Control 22
- AT Awareness and Training 3
- AU Audit and Accountability 9
- CM Configuration Management 9
- IA Identification and Authentication 11
- IR Incident Response 3
- MA Maintenance 6
- MP Media Protection 9
- PS Personnel Security 2
- PE Physical Protection 6
- RA Risk Assessment 3
- CA Security Assessment 4
- SC System and Communications Protection 16
- SI System and Information Integrity 7
Foxx Cyber
The guide is the reading. Bedrock CMMC is the doing.
Foxx Cyber publish this guide and build Bedrock CMMC: the boundary, the system security plan, the objectives and evidence, the SPRS score and the POA&M, kept in one package with a chain of custody an assessor can follow.