Resources
Below is a list of resources and reference links related to CMMC.
Useful Links
CMMC
DoD
- DoD USD A&S CMMC Model
- DoD USD A&S Assessments
- DoD USD A&S Assessment Guide:
- DFARS 254.202.7012
- DFARS 254.202.7019 Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS 254.202.7020 NIST SP 800-171 DoD Assessment Requirements
- DFARS 254.202.7021 Cybersecurity Maturity Model Certification Requirements
- DoD CUI Program Home
- DoD CUI Awareness and Marking
- DoD CUI Mandatory Training
- NARA Archives - CUI
NIST
- NIST Main List of Special Publications
- NIST Main List of NISTIRs
- SP800-171 rev2 Protecting CUI in Non-Federal Systems
- SP800-171A Assessing Security Requirements for CUI
- SP800-172
- SP800-172A Enhanced Requirements for Protecting CUI: Supplement to SP800 -171
- SP800-171 rev2 CUI POAM Template
- SP800-53 rev4 Controls for Federal Information Systems (Withdrawal Date 9/23/2021)
- SP800-53A rev4 Assessing Controls in Federal Systems
- SP800-53 rev5 Controls for Information Systems
- SP800-53A rev5 Assessing Security and Privacy Controls in Federal Information Systems
- SP800-53B Control Baselines in Federal Systems
- SP800-18 rev1 Develop SSP for Federal Systems
- SP800-30 rev1 Conducting Risk Assessment
- SP800-37 Risk Management Framework (RMF) for Information Systems
Other Reference Links