Which rule is telling you to do what
Five documents, read in this order. Each one points at the next. Nothing on this list binds you until the first one does.
-
Your contract
The clause in Section I
Nothing obligates you until a clause appears in a contract or solicitation you signed. Search the document for 7012, 7019, 7020, 7021, and 52.204-21.
Points at: DFARS 252.204-7012 for CUI; FAR 52.204-21 for FCI
-
DFARS 252.204-7012
Safeguarding covered defense information
Requires adequate security on any system that processes, stores, or transmits covered defense information, and requires reporting cyber incidents to DoD within 72 hours. It also flows down to your own subcontractors.
Points at: NIST SP 800-171 Rev. 2, all 110 requirements
-
32 CFR Part 170
The CMMC Program rule
Establishes the three CMMC levels and turns self-attestation into a verified assessment. It says who checks your work and how often, and requires an affirmation in SPRS.
Points at: CMMC Levels 1, 2, and 3; assessment and affirmation requirements
-
NIST SP 800-171 Rev. 2
The 110 security requirements
The actual list of things to do, in fourteen families. This is a standard, not a regulation. It has no force until a clause points at it, and then it has all of it.
Points at: NIST SP 800-171A, the assessment objectives
-
NIST SP 800-171A
The assessment objectives
Breaks each of the 110 requirements into the specific determinations an assessor makes. This is what a score is actually built from.
Points at: The DoD Assessment Methodology and your SPRS score
Where to go from here
- Which level your contract sets, and who checks it: the levels.
- Whether the information in front of you is even in scope: the CUI worksheet.
- The 110 requirements the chain ends at: the controls, by family.
- Whether Rev. 3 changes any of this: not yet, and here is why.