Skip to content
CBT Nuggets
DemoBook a Demo

Introduction To CMMC

The skill provides an in-depth introduction to the Cybersecurity Maturity Model Certification (CMMC), focusing on its importance for contractors working with the Department of Defense. It covers the three levels of CMMC, detailing the security requirements for each level, including the protection of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The content also explains the roles and responsibilities within organizations for achieving CMMC compliance, the assessment process, and the key terms and acronyms associated with CMMC. This foundational knowledge is crucial for understanding how to navigate and implement CMMC standards effectively.

Full skill from CMMC. Preview the IT training 23,000+ organizations trust.

55m

Skill 1 of 6 in CMMC

Introduction

Welcome to the first part of your journey toward understanding and achieving CMMC compliance. Whether you’re a small contractor, a large prime, an IT specialist, or a compliance officer, this section lays the foundation for everything that follows. In this part, you’ll learn what the Cybersecurity Maturity Model Certification (CMMC) is, why it was created, who it applies to, and how it fits into the broader landscape of government contracting and cybersecurity. You’ll also get a high-level overview of CMMC Levels 1, 2, and 3, how they relate to protecting Federal Contract Information (FCI) and Controlled Unclassified Information (CUI), and what’s at stake for your organization. Let’s get started by answering the big question: What exactly is CMMC and why does it matter?

What Is CMMC and Why Do We Need It?

In this nugget we're going to discuss what CMMC is and why we need it. We'll discuss FCI, CUI and standards included in CMMC.

Knowledge Check

What is the primary purpose of the Cybersecurity Maturity Model Certification (CMMC)?

The Three Tiers of CMMC

Within CMMC there are three tiers and each of them has different security requirements which must be met. Let's jump in and discuss these three tiers.

Knowledge Check

Which type of information does CMMC Level 1 aim to protect?

CMMC Specific Terms

Within CMMC there are many terms that are used so let's take some time to go over these terms so that for the rest of the course you'll be familiar with them as we see them in action.

Knowledge Check

Which of the following terms is a formal document that lists security gaps and the steps an organization will take to resolve them to achieve CMMC compliance?

Common Roles In CMMC Compliance

Within organizations we have several roles from executives to managers and directors and of course administrators and much much more. Let's jump in and discuss some of these roles and what they're responsible for in CMMC compliance.

Knowledge Check

Which role is responsible for performing background checks?

Validation

Congratulations on completing this skill. Now it's time for a validation challenge to show that you're familiar with the content we've covered in this skill. Todays challenge is a set of validation questions so let's get started!

Question 1

Knowledge Check

CMMC only applies to companies that handle classified government information.

Question 2

Knowledge Check

What does the acronym “CMMC” stand for?

Question 3

Knowledge Check

How many tiers are there in the CMMC 2.0 model?

Question 4

Knowledge Check

CMMC Level 2 is based on all 110 controls in NIST SP 800-171.

Question 5

Knowledge Check

All levels of CMMC require an annual _______________ ? (fill in the blank)

View Transcript

What Is CMMC and Why Do We Need It?

0:00Welcome to the first nugget in the CMMC compliance readiness course here at CBT Nugget. So what are

0:05we going to talk about? Well in this nugget we're going to talk about what CMMC is, why it's

0:10necessary, who's in charge of it, some of the standards that are included in CMMC, and we're

0:16also going to take a look at the official website and documentation to get started. So let's go

0:21ahead and jump in. All right so CMMC, the Cybersecurity Maturity Model Certification,

0:29what is it? That's the first question we're going to answer. So the answer is right here,

0:34this nice lady down here tells us it is a DoD cybersecurity framework that is key,

0:40framework, and of course DoD, and it's to help ensure that the DIB, that's our defense industrial

0:47base and all you out there know there, those are the companies providing support services to

0:51the DoD. So contractors, right? Absolutely. Okay, and the goal is for CMMC to make sure that the

0:58DIB contractors meet a specific level of cybersecurity standards. So why? Why? That's

1:04the big question, and the answer is bad guys. That's right, because they are out there. Those

1:13bad actors are out there, and they're continuously attacking companies, right? They're after the

1:20secrets, government secrets, DoD sensitive information. They're after intellectual property,

1:25of course, looking to steal that IP. Now the thing is the DoD, the government, military,

1:33they all follow the standards, right? They have their own rules that they follow. However,

1:37the supporting contractors for the DIB basically need to meet a certain level of security, and it's

1:44based on the type of information being handled by them, and we're going to get into all that,

1:48but that's why it's there. It's to make sure that the DIB is going to be able to stand up to those

1:54attackers and provide reasonable cybersecurity protection. So that's why this is important,

2:01because these folks out here, the bad guys, those attackers, they're using AI. They're getting

2:06smarter. They're getting more cunning, and they've got lots of backing, those nation-state actors out

2:10there, plenty of resources to get things done. So now that we know what it is and why we need it,

2:16let's talk about who oversees the CMMC program. Who manages it? You know, what is my chain of

2:23command in this instance? Well, let's start at the top. So at the top, we've got the DoD's CIO, Chief

2:31Information Officer, and they oversee the program. So what they do is provide oversight, which is

2:38basically the governance of the program, and they are overall responsible for implementing and

2:44enforcing CMMC. So all you folks out there know that overall responsible, that's going to go to

2:51the top, and that's why it's the DoD CIO. I love those acronyms. All right, super. So who's next?

2:57Well, next we have the CMMC Program Management Office, and that is who actually administers the

3:04CMMC program. All right, super. So now that we know who's in the middle, who's the boots on the ground?

3:12Well, that would be the CyberAB, just like that, and this is formerly known as the

3:21CMMC Accreditation Body. Okay, so again, this is going to be our boots on the ground folks. These

3:30are going to be implementing and overseeing the CMMC ecosystem. So I'll put that up here.

3:36CMMC ecosystem. So these are the folks making it happen. So here we see our chain of command,

3:43if you will. So now let's talk about what CMMC focuses on protecting. Okay, and it's aimed at

3:51protecting two specific types of data, FCI and CUI. Now, FCI, let's talk about these, is information

4:00it's really not intended for public release. Okay, it's provided by or generated for the government.

4:08All right, and it's under a contract to develop or deliver a product or service. Now, FCI, this is

4:16contract information. So when we're talking about the contract, so we're talking about the contract

4:22between the DOD and the prime, which is the primary contractor, it's going to have some

4:30information in it within that contract. Of course, it does lots of information. Some of that is

4:36sensitive information. Aha, so we need to protect FCI data and CUI data. So FCI is related to the

4:46contract information that's in the contract that's sensitive. Now, CUI is different. CUI is more

4:53sensitive than FCI. Okay, so let's talk about CUI. Now again, sensitive information, and it is

5:01unclassified, but sensitive to the government, and may be provided by the government or generated

5:06by a contractor on behalf of the government. So either one of these, FCI or CUI, the data that

5:12we're trying to protect could be coming from the government or the contractor is generating it

5:17for the government, either way. So we know now FCI and CUI are the two types of data that we're

5:24concerned about, and we need to protect. The FCI comes from data in the contract that's sensitive.

5:30CUI isn't in the contract necessarily, but is unclassified, but very sensitive data to the

5:36government, and we need to protect that as the DIB. All right, super. So now let's jump out and take a

5:44look at the official CMMC website and just tool around a little bit and take a look. All right,

5:49here we are. We are at dodcio.defense.gov slash cmmc slash about, and you'll see right here this

5:56is the Chief Information Officer, CIO, of the Department of, now Department of War, previously

6:02Department of Defense. Who knows if it'll go back, but I will say in the course I just use DOD for

6:07everything because the name changes and such. We're sticking with DOD throughout the course.

6:11All right, so under the CMMC tab we have the about, and that's the page we're on right now,

6:14but there's also resource documentation, FAQs. If you need to contact the folks at CMMC,

6:19you can do that through here. FAQs are great because it helps you to, we'll just jump over

6:23there real quick, take a look at this, and you can see all these questions that are being asked

6:28and answered. So you could just search through here for certain key terms that you're interested

6:33in. So let's go back here. So here's our about page again, and let's go ahead and scroll down

6:37here, and I'm not going to read through all this. I just want to give you this URL so you have it,

6:41and we'll just quickly go over this site. So it talks about CMMC, about how it's a three-tiered

6:46model you can see here on the right. If we scroll down, we talk about FCI and CUI that we just

6:50discussed in the last slide, and then the three tiers here, and they go into each one and what's

6:56required and such, and then go on down here, and we talk about more information. And again,

7:01we're going to go through all this stuff in the course, so you don't have to go read this stuff

7:04right now. Okay, just giving you some resources. Now I do want to go over here to the resource

7:10documentation. This is a page you will be familiar with. You're going to be on it a lot because it

7:15has a lot of documentation, especially when we go through the different levels. We've got scoping

7:19guides, and we're going to talk about scoping, and self-assessments, and all this stuff.

7:22Talk about different standards. A lot of resources on here, and we'll be using some of these throughout

7:28the course. So now that we know where this is, you're going to stick this in your pocket because

7:33you're going to want to use that as you go through this compliance journey. All right, super. So now

7:39we've got that out of the way, let's talk about the three different standards that are part of CMMC.

7:45All right, so what we're going to start with here is the CMMC reference standard

7:51FAR 52. Here we go. I'm going to put a little box around it.

7:56.204-21. So this is basic safeguarding of covered contractor information systems. So this is your

8:04contractor's information systems, and what are covered. So we have to safeguard this information.

8:09So what we have here is a standard, and the standard outlines, actually in this instance,

8:1615 different security controls or security requirements. We're going to talk about those

8:20as we get into the course, and there's 15 of them that need to be met, and all of them must be met.

8:27There's no options here at this stage, because actually this is level one, or you might hear me

8:34call it tier one, but it's level one of the CMMC. There's three levels as we saw when we were on the

8:40primary website, and this is the bottom level. This is the lowest level, and it has 15 different

8:49security requirements that have to be fulfilled, and we're going to go over that stuff. So don't

8:52worry about it too much yet. We're just kind of getting introduced to everybody right now,

8:55and that includes the standards. Then when we get up to level two of the CMMC, we come across

9:04NIST SP-800-171-REV2, and it is protecting CUI. Look at that, CUI, Controlled Unclassified

9:12Information in Non-Federal Systems and Organizations. Non-federal, meaning it's not a

9:17federal agency or system or organization. It's its own thing. It's a contractor's out there, the DIB.

9:24So what we're talking about here is this standard, and here there's 110 different security controls

9:30you've got to have in place. So 110 of those controls are in there. So I tell you what,

9:35let's go ahead and pull up the NIST 800-171-REV2 and take a look at it real quick. All right,

9:40here we are on csrc.nist.gov. I just went out and googled NIST SP-800-171-REV2, and it brings me

9:47here. So this is the NIST page. Super cool. Now here's what I want to show you though. You can

9:52come down here, and you can access the standard right here. So I'm going to go ahead and do that

9:57in another tab, or you can download a copy. But over here, Supplemental Materials. These are going

10:01to come in super handy, folks. This is your security requirements spreadsheet, and this is

10:07just XLS format for your Excel versus CSV. There's also a CUI plan of action template and a CUI SSP

10:14template. So this is for your POAM plan of action and milestones, and we're going to get into all

10:21that stuff. So right now, again, we're just introducing you to the ideas of these various

10:26components of CMMC and the standards and documentation where you can find them.

10:31Okay, so we're actually going to pull these up later on and use them. But for now, actually,

10:35let's jump over to the standard, and here we go. So let's go ahead and scroll down here on the left,

10:42trying to get to where we're into the standard here. Let's scroll on down quite a bit. Okay,

10:46here we go. So there you go. This is the standard, and there are, again, 110 different controls that

10:53have to be addressed. All of them have an ID number, and it's like this one here, 3.2.2,

10:58ensure that personnel are trained to carry out their assigned information security related duties

11:03and responsibilities. So you have to make sure that's being done. So that's one of the 110.

11:08Okay, and that's just an example. All right, so as you can see, we can scroll through here,

11:12and there's just a bunch of them in there. All right, so let's go ahead and jump back here.

11:17So that was your NIST SP-800-171-NRF2. I've got one more to look at, and that is going to be for

11:23our level three CMMC, and that's the NIST SP-800-172. Previously, if I go back, we're

11:31looking at SP-800-171. Now we're going to 172, and this is enhanced security requirements for

11:40protecting CUI. All right, so it's a supplemental to 800-171. Okay, and in the standard, there are

11:48actually 39 security requirements in there, but you only need to meet 24 of them for level three.

11:55So the 24 are outlined in the CMMC assessment guide for level three. So if I go back here real

12:03quick to our website, there we go. Then I go back to over here to our CMMC, and this is our

12:11documentation. If you look down here, we see a scoping guide and an assessment guide for our

12:16CMMC level three. So what we do is open up this one right here, and if we scroll down the table of

12:23contents, you're going to come down here and right here. These are requirement descriptions. This is

12:27where you're going to find those 24 different requirements that are in the NIST SP-800-172

12:32standard. All right, so there you go, and we're going to get into this as we go through the

12:36course. So let's jump back here real quick and wrap this up. So now we know what CMMC is, who's

12:42responsible for it, what it impacts as far as our DIB folks, and that there are three different levels

12:50and three different standards associated with those levels. So there you go. That is our

12:55introductory to the CMMC. Next up, we're going to talk about the three tiers of CMMC. So I'll see

13:01you there shortly.

The Three Tiers of CMMC

0:00Now that we know what CMMC is, why we need it, some of the standards involved,

0:04it's time to jump into those three tiers. We briefly discussed them in the last nugget.

0:09Now it's time to dive into them and get a little more familiar, if you will.

0:13All right, as I said, this is a three-tiered model. We've got Level 1, Level 2, and Level 3,

0:20and each of them build on the previous level. So in order to get to Level 2, you first have to

0:26complete Level 1. Then you can work on Level 2, and if you need to do Level 3,

0:30it's at that point you're going to build on your progress. So now you're asking yourself,

0:36well, what level do I need to be? And that's a great question, and that's going to be defined

0:41in the solicitation. And that solicitation is the formal announcement of the government procurement

0:49opportunity. So it's really that opportunity. When it's announced, it's going to be in there.

0:54There's actually a CMMC clause that's going to specify the applicable CMMC level that you need

1:03to be compliant with. All right, so this makes CMMC compliance a mandatory condition for contract

1:11awards, not just a general requirement. And the level of CMMC is based on the sensitivity

1:18of the data that's involved in whatever this contract is. Okay, so that's what's really going

1:23to be the driving factor. And you're going to find that in the CMMC clause within that solicitation.

1:29That's where you're going to find out what levels CMMC is required for that contract. And this does

1:34include not only the prime contractors, but also subcontractors if sensitive data is flowing down

1:40to them through the prime contractor. And contracts that are requiring the handling of CUI are going

1:46to require higher levels, meaning level 2 and level 3. There is no CUI involved in level 1.

1:54That is only FCI data. Okay, just kind of put that out there. Now let's go ahead and dive into each

2:01of these. We're going to start with level 1. So level 1, again, has 15 different security requirements

2:09defined by the FAR 52.204-21. And it is an annual self-assessment and an annual affirmation. So

2:17what does this mean? Well, it means that you create a self-assessment and you go through

2:23and you verify that you are meeting all 15 of those security requirements. And then the

2:30affirmation is really just a senior person in the organization, generally a C-level executive,

2:36signing off that, yes, we are compliant. All right, that's what that attestation is. And again,

2:42it is annually. And this level is basic cybersecurity hygiene.

2:49That's what level 1 is. Now, I said this is an annual self-assessment. There is a note to that.

2:56So if there are significant changes in the environment where the company itself maybe

3:02goes through an acquisition or merger, boundaries change within network environments, things like

3:08that, well, then you will need to reassess your environment when that happens. Okay, so you don't

3:14get to wait a full year if you have significant changes. You need to go ahead and address that.

3:20So again, this level only deals with FCI data. There's no CUI in level 1. So keep that in mind.

3:29So if you're going to be working with CUI, that means you're going to be level 2 or 3.

3:33But for FCI data, again, that's our contract information that's sensitive. We're at level 1.

3:40And the idea of level 1 is to make sure that we are implementing these 15 security requirements,

3:46but there's not too much burden. And that's kind of a key here. Not too much burden on the company

3:54or the contractor that's going through this. It's not that difficult to go through level 1,

3:59okay, because it's just got the 15 requirements and they're pretty basic. They're standard and

4:03everybody should be doing these anyway. So the companies that are going to be level 1 or tier

4:091 organizations, these are companies that provide things like general repair services.

4:15Or maybe contractors providing non-sensitive parts. So think of paper, staples, things like

4:22that, right? There's non-sensitive information in this. It's we're just dealing with parts and

4:26stuff, okay? And then also small business providing services like catering or maybe plumbing or

4:32electrical work. So again, that's what we're talking about here. You're not going to be

4:36working with weapons systems and such. This is going to be the entry level and that is our tier

4:421. All right, now let's move on to level 2. And here is where our good old buddy CUI comes to the

4:50table. This is where it first makes its entrance onto the stage and this is considered an advanced

4:57cybersecurity practices. So our level 1 was basic cybersecurity hygiene or practices. This is

5:05advanced, okay? So again, we're taking this up a notch because as you can see over here,

5:10we've got 110 different controls we need to make sure are implemented and they're in alignment

5:15with that NIST SP-800-171-Ref2. Boom! Okay, so now as we look at level 2 and the assessment process

5:22because remember level 1 was just a self-assessment every year. That's how it went. But here we have

5:27a split, okay? So we have either a C3PAO and we'll talk about that here in a minute, certification

5:35assessment every three years or a self-assessment every three years. And that's for select programs

5:41and then an annual affirmation. So every three years you're either going to have an audit by

5:47a C3PAO and again we'll get to that in a second or a self-assessment but an annual attestation.

5:53And there's some documentation that needs to go along with that because in level 1 you just have

5:57to provide your self-assessment. When you get to level 2, we're going to bring in a couple new

6:02pieces of documentation that we're going to be dealing with. Now here we have those two options

6:07that we just talked about and that's going to be defined by the type of information being

6:12processed, transmitted, and stored. Okay, so is it sensitive CUI or kind of less sensitive CUI?

6:18That's where this is going to come into play. And it's going to be in that announcement that

6:24government procurement opportunity announcement that comes out saying hey we've got this contract

6:28out for bid. Then it's going to be in there and it's going to state what your CMMC level 2

6:34requirements are. Okay, so just keep that in mind. Now the thing is I said there was some new

6:38documentation. Absolutely, we have an SSP to start with. This is a system security plan

6:46and the SSP basically defines what's in scope and provides a diagram and an explanation of

6:52what you're doing with your security. So this document really outlines what you're doing and

6:58it allows an assessor or auditor to take a look at it and realize oh this is what they're doing.

7:05They're doing this, this, and this. So now I can go verify they're doing this, this, and this as they

7:08say they are. Okay, now here's the other thing. We have POA and M. POA and M. That is your plan

7:17of action and milestones. What is that? Well here's what it is. We've got 110 of those security

7:24controls we need to get out there and implement. Do you think they're all implemented or we can

7:27just go flip a switch and it's done within 24 hours? No, the answer is no. I say now here's the

7:33thing. Plan of action milestone. This is where we are going to actually perform a gap analysis and

7:40we'll talk about this in depth when we go through the process and that's going to help us identify

7:45what controls we are missing. Okay, and it's at that point that we need to create a plan of action

7:53and milestone. So what this plan of action is is saying how we're going to address the missing

7:58controls and we're going to assign an owner to that as well as a date to get it completed by

8:06and that's our milestones. So this is a plan of how we're going to get from where we are now

8:11to where we have 110 controls in place. Now when you go through this gap analysis you're going to

8:17rank everything basically your missing controls by severity and you yourself have to come up with

8:24a severity level and we're going to get into how you do that a little later on but the idea is

8:28all of the high severities have to be addressed before you can pass assessment. However, your

8:35medium and low or moderate and low just depending on the wording used those can go into your POAM.

8:42All right, but highs cannot. You got to get those taken care of. So I said we're going to talk about

8:46C-3PO's and now it's time to talk about them. Now C-3PO is not a character in Star Wars. No,

8:54this is a little different. This is a certified third-party assessor organization.

9:01That's what they are. So what are they? They're basically auditors. That's what they are

9:06right there and they have gone through accreditation through CMMC to make sure that

9:12they are certified and they can do this. All right, and they take care of this for

9:17Tier 2. So when we're talking about Tier 2 or Level 2 CMMC, this is going to be doing your audits or

9:25your assessments. It's going to be the A-C-3-P-A-O. All right, super. So now we know what those are.

9:31Let's move on to CMMC Level 3 and this is going to be our most sensitive CUI. Okay, those are going

9:39to go straight into Level 3 and this is known as Expert Level Cybersecurity Practices. So again,

9:48Expert Level. Top of the food chain here folks. So here we have 134 controls to put in place. Now

9:55here's what I want to point out. It's actually just 24 because 110 of them come from the NIST

10:03SP-171-R2. And if I go back a slide or two slides, that's this. So you've already reached this. If

10:10you're going for Level 3, you have to complete Level 2 first. So that's why in total there's

10:15134. Yes, but 110 came from Level 2. Here we're just taking 24 additional controls from the NIST

10:23SP-172. All right, so you're not having to start over and do 134 from scratch. Now you're progressing

10:30up the chain. Here we go. All right, super. So here we go. Here we have the DIBCAC and that's

10:38your Defense Industrial Base Cybersecurity Assessment Center. And that is going to be doing

10:45the assessment or audits every three years. And of course, you'll need an annual affirmation.

10:51And guess what else? Yes, you're going to need your SSPs that we talked about in Level 2

10:56and your POAMs. That's right. Those are still required for Level 3. So what kind of companies

11:06are going to be included in this? Well, that's a great question. How about companies that perform

11:11weapons system design and critical defense technologies? It's those type of companies

11:18that are going to have to meet CM&C Level 3. All right, moving on. Types of assessments. Well,

11:24we talked about that. We talked about doing a self-assessment for Tier 1, possibly Tier 2,

11:29but probably a C3PO and then the DIBCAC for Tier 3. But here's why we have this slide. Let's jump

11:37over here to the CM&C website. All right, here we go. Here's what I wanted to show you. Let me see

11:43if I can't zoom this in a little bit. There we go. I like that better. All right. Right here,

11:48CM&C Level 1 Scoping Guide. That's for scoping. But here you go. CM&C Level 1 Self-Assessment Guide.

11:53There's your guide for self-assessment. So let's go ahead and open this up. Take a look.

11:58There we go. Let's zoom in here a little bit. And let's go ahead and scroll down here. We've got

12:02all this great information. And there you go. Right here. This is where our 15 controls come

12:09into play. So you can go through and read about this information. But right here, that's where

12:13they are. So you can scroll through here. Let me get down to where some of them are.

12:17Methodology. Talk about testing. And we're going to go through that stuff. Don't worry about that.

12:21I'm just trying to get you to understand that you want to use these assessment guides.

12:27So right here, under Access Control, we have Authorized Access Control. It's the name of

12:32this control here. And what we need to do is limit information systems access to authorized users'

12:37processes acting on behalf of authorized users' devices. So what this is, you're controlling your

12:42access. That's right. We have to do that anyway. And that's why this is one of the Level 1 things.

12:47You've got to provide access control. And so here, they're going to talk about some examples and

12:53how you go about collecting information. And we're going to talk about that as well as what proof you

12:57need to provide and that kind of stuff. So this right here, this assessment guide, you're going

13:02to want to go through here and look at it. Now, there's also one for Level 2 and Level 3. Because

13:07with Level 2 and Level 3, you're still wanting to do a self-assessment. You don't want to wait

13:11for the audit to happen or the assessor to come on site or do a remote or whatever. You want to

13:18do a self-assessment to prepare, to find gaps, to find holes, and to fix them so that you can pass

13:24your assessment. Go through and use these. All right. Super. Now, we've talked about the assessments.

13:30Now you know where the documentation is. When does this whole thing go into effect? This is a big

13:35train headed down the hill. When's it going to get there in the station? Well, here you go.

13:41Right. Here we go. November of 2025. That's right. That's when it's going to start.

13:50So where applicable, solicitation, we talked about the solicitation dates, look at the announcement

13:56of the contract, will require Level 1 or Level 2 self-assessment. So for the year 2025

14:05through 2026, we're only going to be seeing self-assessment coming out. Okay. However,

14:11beginning in 2026, November, you're going to see Level 2 certification requirements.

14:18And then as we go into 2027, Level 3, and 2028, hey, it's at that point, it's all on the table.

14:26All levels are a go. All right. Super. So that wraps up our CMMC tiers, but that's not the last

14:34time we're going to see them. Not at all. As we go through the course, we're going to look at

14:38what you have to do in the process and the steps you go through to become ready for an assessment.

14:44And we're going to see these levels over and over again, as well as the controls

14:48that they contain and require. All right. Super. So next up, we're going to talk about some CMMC

14:54specific terms, because there's lots of acronyms out there and terms, and you really need to know

14:59what those mean as you go through your CMMC assessment process. So I'll see you there shortly.

CMMC Specific Terms

0:00As many of you know, anytime you're dealing with the government in the U.S., you've got tons of

0:06acronyms. No matter if it's DOD, military, government, it's all acronyms. And even in IT,

0:11really. Acronyms, acronyms, acronyms, and different words and phrases. And you know what? That's in

0:17the CMMC as well. So we're going to jump in and talk about some key terms that you need to be

0:22familiar with for the CMMC assessment. All right, we're starting off here. I'm going to provide you

0:27the link to this. This is the CMMC Glossary and Acronyms. And I'm going to scroll down here just

0:34to give you an idea of how many there are in here. Now, here we go. We're starting here at Access.

0:38Okay. And see if I can't, there's the scroll bar. So this gives you an idea of how many

0:44different acronyms and terms are in here. And there are a ton. Okay. So what we're going to do,

0:51and you can see down here, some acronyms and abbreviations. What we're going to do is we're

0:55going to go through and discuss some of the key terms, because a lot of these we already know,

1:00or we'll figure out when we get there. But let's talk about some of the key terms. Let's jump over

1:05here. All right. CMMC Terms to Know. First off, DIB. And if you're taking this course, I'd say you

1:13probably already know what DIB is, but just in case you don't. So we're talking about contractors

1:19and subcontractors, companies and organizations providing support to the USDOD. Pretty straightforward

1:25there. All right. So next up, DFARS. So DFARS, that's your Defense Federal Acquisition Regulation

1:32Supplement. So it provides rules for defense contractors. And here you go. CMMC requirements

1:38are often incorporated into the DFARS clauses. And that's why we know we've got that FAR clause here

1:43as part of our Tier 1. All right. Moving on. CUI. That is our Controlled Unclassified Information.

1:49We've already talked about that, but you definitely need to know what that is. Then we have

1:56CDI, Covered Defense Information. And this is a subset of CUI. So if you see CDI, it's just

2:04subset of CUI. So it's a different level of sensitivity of defense information. After your

2:11CUI, we have our FCI. And again, we've already talked about that. It's the sensitive information

2:15found in the contracts. Okay. And then lastly, on this slide, CUI assets. So a CUI asset is any

2:24asset that, this is key here, processes, stores or transmits CUI data. So any piece of asset that

2:34you have, think on your network, your servers, your email system, your network, your firewalls,

2:41they transmit this stuff. Servers store it. Applications process it. Emails process it.

2:47You know what I'm saying here? You need to go through, and we'll talk about this when we go

2:50through our scoping section. We're going to find out how to scope and identify what our different

2:56types of assets are. Okay. Super. Moving on. Next up, we have SIPRS. And that is your Supplier

3:06Performance Risk System. So this is the DOD authoritative system for assessing and monitoring

3:13suppliers' performance, including cybersecurity risk. So this is where your DOD contractors,

3:19or DIB, are going to upload your self-assessments to. Yes, absolutely. Okay. And we'll get into all

3:26that a little later on. Then we have C3PAO. And we did just talk about that. That's your

3:31Certified Third-Party Assessor Organization. That's who's going to be providing the assessments

3:35for Tier 2 compliance. All right. So that's our SIPRS and C3PAO. Next up, we have the DCMA,

3:45Defense Contract Management Agency. And they're responsible for administrating contracts for DOD

3:53and its partners. And they are a major part of the U.S. defense acquisition process. So basically,

3:59they're out there administering the contracts. So that's your DCMA. Then we have the CyberAB.

4:06And we did talk about them earlier. And we said they were the boots on the ground. And they're

4:11authorized by the DOD to carry out the CMMC program. They're the accreditation body that

4:18takes care of the CMMC program and make sure it's functioning properly. All right. Next up, OSC,

4:24Organization Seeking Certification. Hey, that's you. That's our DIB folks, our Contractors Seeking

4:31CMMC Certification. Or you might also see it listed as OSA. And that is Organization Seeking

4:39Assessment. So that is your OSC slash OSA. All right. Next up, CMMC Assessment Process. That's

4:46our CAP. So this is a document used by our C3PAOs. Those are level 2 assessors. All right. And

4:52they're going to use that document to perform the final certification of your Tier 2 CMMC for your

4:59Organization Seeking Certification, your OSCs. All right. Super. Love burning through these.

5:05Knocking them out. Next up is our POAM. And this is your Plan of Action and Milestones, as we've

5:10already talked about. But it is a formal document. It's required for Tier 2 and Tier 3 of your CMMC.

5:19And it's going to list your security gaps and then steps that the organization is going to

5:23take to resolve them and achieve compliance. Pretty straightforward there. Next up, we have SRM.

5:30And this is a Shared Responsibility Matrix. And its document defines who's responsible

5:37for fulfilling CMMC requirements. Now, this comes into play when you are using some type of

5:44service provider. And it could be a cloud service provider. So you're using cloud services.

5:50Or it could be that you're using a managed security provider or a managed service provider.

5:54Anytime you have someone who has access to your environment where SCI or CUI lives,

6:02then you're going to need to have this Shared Responsibility Matrix. And what it's going to do,

6:05we're going to see one here later on in the course. Basically, we have all these different

6:09responsibilities listed out. So these are responsibilities here. And then who is responsible

6:15for them? Is it the contractor or is it the service provider? This way, everybody knows

6:21who's responsible for what. All right, moving on. SSP. We did talk about this already. Our System

6:28Security Plan. Again, a formal document detailing the organization's cybersecurity controls

6:34and policies for protecting CUI. Now, you'll see FCI is not on here. That's because an SSP

6:41is not required for Level 1. Now, it is best practice to go through and do that, especially

6:46if you're going to go to Level 2 or even 3. Well, when you're doing your Level 1, you need to go

6:51ahead and start that process. All right. So basically, it's a blueprint of how security

6:56requirements are implemented, monitored, and managed. That's it. All right. Super. Next up,

7:02SPA. And that is your Security Protection Asset. It's any assets that provide security functions

7:10or capabilities to protect CUI. Well, what would that be? Well, think of this. Firewall, your SIEM,

7:16EDR, your Endpoint Protection, Identity and Access Management. Any security tool that is there to

7:23provide security functions and capabilities to protect CUI, that's what SPA is. SPA, Security

7:29Protection Asset. All right. We've got one more down here. And this is SPD. And this is Security

7:36Protection Data. Data that is processed or stored by a PSA. Well, we know this is the PSA. So any

7:43data that is processed or stored by a SPA, it's going to be considered Security Protection Data.

7:51So what are some examples of this? Well, how about log data? Absolutely. Your firewalls, EDR, IEM,

7:58all of those generate logs and we send those logs to a SIEM. And we're going to talk about these

8:03things if you're not familiar with all of them. But the idea is any data that is processed or stored

8:09by one of these Security Protection Assets is Security Protection Data. So log data is a big

8:16one there. All right. Moving on. CCA. That's our Certified CMMC Assessor. Okay. So this is a

8:24professional certified by the Cyber AB to conduct formal CMMC assessment. So that's what a CCA is.

8:33They are certified, okay, by Cyber AB. And that's important because we're going to hear in a minute

8:39talk about another types of folks who are not actually certified. Then we have CCP. So this

8:47is your Certified CMMC Professional. So this is individual, again, certified to help organizations

8:54prepare for CMMC assessment. So here we have Assessors or Auditors. And here we have,

9:02well, really Helpers. They're there to help you get certified. They're there to answer questions.

9:06They're there to look at your paperwork and make sure everything's up to date and you're doing what

9:10you need to be doing. So those are a couple of terms there. Okay. Moving on. We have RP. So an

9:17RP is a Registered Practitioner, non-certified. So again, if I go back, CCA and CCP are certified.

9:26These are not. RP, Registered Practitioner. Now, they are professionals who provide

9:32consulting services for OSCs. That's their organization seeking certification.

9:38And they have agreed to the Cyber AB Code of Professional Conduct and are affiliated with

9:44a Registered Provider Organization, an RPO. So what's an RPO, you ask? Well, let's find out.

9:52Here we go. RPO. So Registered Provider Organization authorized by the Cyber AB. So

9:57they are legit folks. They're legit. Okay. And they represent themselves as focused on CMMC.

10:06So they understand what it is. They have agreed to the Cyber AB Code of Professional Conduct

10:11and they deliver non-certified CMMC consulting services. And they're going to be listed on the

10:17Cyber AB Marketplace. All right. So that's your RP and RPO. Moving on. Prime. So a prime, we're

10:25talking about contractors. Your prime contractor are primary contractors. That's right. So they're

10:32the one who the contracts are going to be awarded to. They're going to be selected by the government

10:36to deliver those products or services. But here's the thing. When we have our prime up here,

10:42oftentimes they're using subcontractors for various tasks or services. And if they're passing

10:52CUI or FCI, depending on your level, data down to subs, then those subcontractors also have to be

11:00compliant at the same level as the prime because they were receiving that sensitive information.

11:06So if we go down here and look, the next is subs, which are subcontractors. Organization that

11:12primes hire to help provide services and products and such. So there you go. Moving on. Our final

11:19slide here, ESP. That's our external service provider. And this is any external entity

11:24providing IT or cybersecurity services. And here's the and, and manages or processes CUI

11:33or SPD. And remember the SPD was our data that is being stored or processed by our security

11:40appliances or services. And this is on behalf of a DoD contractor. So anybody who is being hired by

11:48a DoD contractor to provide IT or cybersecurity services, and here's key. They manage or process

11:55CUI or SPD. So if they fall within those parameters, they're an ESP. Guess what that means?

12:04CMC compliance is required. And it's going to be at the same level as the contractor that they're

12:10doing that work for. All right. And let's go ahead and wrap this up finally with a note. And all it

12:15does is say the same thing. They got to be the same level CMC compliance as the DoD contractor

12:20they're providing those services to. Now, oftentimes these are going to be like IT managed service

12:25providers or managed security service providers. That's generally where this comes into play

12:30because those organizations are providing IT or cybersecurity services to contractors.

12:35And if they are managing or processing CUI or SPD data in their roles, well, then there you go,

12:42they're going to need to get compliant. All right. Super. That wraps up our CMC Terms to Know.

Common Roles In CMMC Compliance

0:00Now it's time to talk about roles. That's right. Who's responsible for what as far as CMMC

0:06assessment goes within my organization? What's my IT manager supposed to do? What's my

0:11compliance manager supposed to do? What are we doing here? Well, that's what we're going to

0:15talk about. We're going to talk about different roles within your organization and their primary

0:19responsibilities as far as CMMC assessment. All right, here we are. We're starting off with

0:27our compliance officer or CMMC program manager, either one. So we're going to talk about their

0:32primary responsibilities. Now we've got four of them, so let's start here. Number one,

0:37leads CMMC compliance strategy and execution. All right, that's pretty handy, I'd say.

0:44Number two, coordinates with all departments because you can imagine there's going to be

0:48lots of stakeholders in this, lots of folks involved, so coordination needs to happen.

0:52Also, they interface with C3PAOs and consultants. Of course, if you're going to hire consultants

0:58to help you with this process, well, your compliance officer or your CMMC program manager,

1:03they're going to be interfacing with them as well as the C3PAOs for your level two. All right, lastly,

1:09they maintain documentation. Oh yeah, here's our good documentation. Our SSP, our POAM,

1:16you're going to have policies. You're also going to have, put up here, self-assessments because we're

1:22all going to be performing those. Very important. So those are the primary responsibilities for your

1:27compliance officer or your CMMC program manager. Moving on, what about your IT manager or IT

1:32director? Who's over your IT? We need to talk about their primary responsibilities as it pertains to

1:37CMMC. So number one, implement technical security controls. So here we're talking about firewalls,

1:43access controls, patching, right? They're going to make sure this is being done. They're not

1:47necessarily doing it themselves, but then again, those of us in smaller companies or SMB market,

1:54we wear lots of hats. Yes, we do. All right, what about number two? Here we go. Maintain system and

2:00networks used to process FCI and CUI. Yeah, of course, that's their job, maintaining the systems

2:05and networks. That makes total sense. What else? Well, they work with compliance teams to enforce

2:10policies. Of course, who else is going to do it? The IT is going to be doing that. You got it.

2:16All right, super. Let's move on. Next up, we have sysadmins and network admins and their primary

2:24responsibilities. So we're starting off. Here we go. They are enforcing lease privilege and access

2:30controls. Remember, lease privilege is very important. That's what we need to practice,

2:35and we generally do that using role-based access controls or RBAC. So our sysadmins and network

2:42admins, they're the ones that are going to be enforcing this. They're going to be putting those

2:47controls into place. Now, of course, up here, our IT manager director, they're going to make sure it

2:52happens, but the folks actually doing it are going to be our admins. We know that. All right, moving

2:57on. Here we go. Number two, manage user accounts, logs, and backups. That's right. We're going to

3:03manage your user accounts. We're going to make sure that we're logging as we should be and that

3:07we have data backups. Very important roles there and responsibilities. And lastly, they're going to

3:13support vulnerability scanning and patching. So yes, part of our controls are going to be

3:18performing vulnerability scans, and when we identify vulnerabilities, we need to remediate

3:23them via patching. All right, super. Who else is on this list? Well, how about the ISSO? Yes,

3:30your information system security officer. So your information security officer has some

3:35responsibilities, as you could imagine. Let's talk about the first one here. Ensure ongoing

3:40security monitoring and response. So yes. Now, here what they're doing is ensuring. So they

3:47are performing kind of oversight, making sure it's being done because you have to have ongoing

3:54security monitoring and response. That's very important. Ongoing security is not set it and

4:00forget it. You have to manage it. All right, super. So what's another responsibility of the ISO?

4:06Perform risk assessments and incident response. Risk assessments are a big part of this, as well

4:13as incident response because incidents happen. No matter how hard you try, how many controls you put

4:18in place, it just takes one wrong click and an incident can happen. So you just got to be ready

4:24for it. All right. What about the final responsibility of the ISO? We have implement

4:30security policies at the system level. And of course, they're just making sure it's being done.

4:35But again, our security policies have to be implemented at the system level. So on our

4:40system, because our policy is a document with a bunch of words, but we got to put those words

4:46into action and that's done at the system level. Okay, moving on. You got your HR manager or your

4:53personnel security lead, whoever is filling that role, got some responsibilities, as you can imagine.

4:58And we're starting off with coordinate background checks and security training, background checks.

5:04Absolutely. We've got to vet personnel that we're bringing into our organization, our company. We

5:08need to make sure they're trusted individuals. And before they can actually do anything at work,

5:13they need to complete security training during their onboarding phase. So when they're being

5:19onboarded, they're going to go through that security training. All right. Responsibility

5:24number two, we have maintained personnel security documentation. So anytime security training is

5:30done, we need to record that information. And we do that because we can use this record here,

5:36that when we record their training as proof that we are performing security training, we need to

5:42make sure we document that as well as what was found in the background checks and so on and so

5:47forth. All right. So finally, HR, what do we get? Onboarding, offboarding procedures. Yes, we've got

5:54to have those procedures and supporting CMMC requirements. And that's kind of part of it here.

6:00Onboarding and offboarding is part of the security controls we're going to have to make sure

6:05is implemented. All right, moving on. Procurement or your contract manager, whoever's overseeing

6:11that. A couple of responsibilities here. Number one, ensure that vendors and subcontractors meet

6:18flow down CMMC FAR requirements. So what this means is flow down. This means as your prime

6:24contractor up here, if you're using subs, then that's your flow down. And that flow down is

6:30the flow of FCI and CUI data as it flows down. Those subs out there have to meet those CMMC

6:40and FAR requirements. They've got to be CMMC certified. All right. And then secondly,

6:46review and manage cybersecurity clauses in contracts. That is super important. And generally,

6:52this is also going to include the legal team when it comes to your contracts, because we've got to

6:59verify what clauses are in there and make sure that we're able to meet those clauses and that

7:05those clauses meet our needs as well when we're dealing with subs. All right. Super. All right.

7:11Let's move on now. Your executive sponsors, that's going to be your CIO, your COO, your COO.

7:18They also have responsibilities in this. Let's talk about that. Number one, champion. I love

7:24that word. Champion. Client's efforts at the leadership level, because support for CMMC,

7:30it's got to come from the top. And that's just with everything security. When it comes to cyber,

7:36that comes from the top. It is a top down evolution and it gets support from the top.

7:43Otherwise, it's just not going to happen. And you're going to be fighting that uphill battle.

7:47Not something I would want to do. All right. What else are they responsible for? Well,

7:52allocating budget and resources. That's kind of pretty important. We can't do a whole lot

7:57if we don't have resources. All right. And then finally, ensure alignment with business objectives.

8:02This is another key objective here. When you're doing this, you need to make sure whatever you're

8:09doing, as far as when you're creating policies and deciding on risk assessments and you're

8:15implementing new solutions or stuff, it needs to be in alignment with business objectives. That's

8:20just a core fundamental of cybersecurity. All right. Then we have MSPs or MSSPs. So,

8:28your managed service provider or managed security service provider. Now, we talked about these

8:33earlier and we referred to these as ESPs and that was external service providers. And that was if

8:41they managed systems that processed or stored CUI and FCI. So, what are some of the responsibilities

8:48that they have? Let's talk about that. Here we go. Number one, provide technology and cybersecurity

8:53services. Yes, because that's what they're being hired for. That's a no-brainer. All right. What

8:57about number two? Support monitoring. Yeah, we do have to do monitoring, logging, and incident

9:04response. So, if any of these happen, they need to be in support of them. And if they're providing

9:08those services, of course, we depend on them to do that. And we need to make sure they are doing

9:14that. And then lastly, there we go. They may help prepare documentation for assessment. Yes,

9:20absolutely. If they're managing your network environment, they're going to provide a diagram.

9:24They're going to help you with documentation for that assessment. All right. Let's review this.

9:29This is our final one here. So, here we go. This is our roles over here on the far left.

9:35These are primary responsibilities in the center and key CMMC domains. Domains, what's that? Aha,

9:44there are 14 different domains. And these are just categories in which the security requirements

9:50are put into. So, we've got 14 different categories. And in the next two skills that

9:55we're going to be going over, we're going to be covering each of these domains. We're going to

10:00go through and identify what that domain is, why we need it, and then how can we go about

10:09making sure that we can address the security controls in this domain, as well as some common

10:14pitfalls. So, we're going to take a look at those. And that's coming up in the next couple of skills.

10:19So, there you go. That wraps up our CMMC compliance roles.

Team training path

Turn this skill into assignable team training

This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.

What's next?

Ready to keep going?

For your team

Bring this training to your team

See how CBT Nuggets helps IT teams close skills gaps, hit compliance targets, and prove training ROI.

Book a Demo
Just need CMMC?

Learning on your own? Browse individual plans ($49/month, billed annually)

Not ready to buy?
with no purchase required. Already have an account?
Book a Demo