CMMC References
Our Reference Pages
Purpose-built quick-lookup pages, written Mac-first and kept current with verified-date stamps.
- CMMC Acronyms, Decoded - 60+ terms across the program, the clauses, scoping, and the Mac stack.
- CMMC Level 2 Controls List - all 110 requirements by family, with the SPRS point weight each carries.
- CMMC Key Dates & Compliance Clocks - the phase calendar and recurring deadlines, updated for the 2026 suspension.
- Who Does What in CMMC - Cyber AB, C3PAOs, DIBCAC, DCMA: who assesses, who accredits, who you actually hire.
- The DFARS Clauses Behind CMMC - 7012, 7019, 7020, 7021, and how the 2026 overhaul changed them.
- Can You Use AI in a CUI Environment? - the clause, the CSP fork, and the two routes to approving an AI service.
The CMMC Program (Official)
Start at the source the Department maintains. These are the canonical program documents.
The CMMC program office now publishes as the Department of War CIO (DoW CIO), formerly the DoD CIO. Links below use whichever host has been verified to serve the current document; both hosts currently mirror the same files. Rows re-verified in this pass carry a date.
- DoW CIO CMMC Resources & Documentation (formerly DoD CIO) - the official hub for scoping guides, assessment guides, and supplemental documents. Verified 2026-08-13.
- DoW CIO About CMMC - the program overview from the office that runs it. Verified 2026-08-13.
- CMMC FAQ (revised 2026-07-13) (PDF) - the official Q&A, updated the day of the suspension to reflect it. Verified 2026-08-13.
- CMMC Model Overview (PDF) - the levels and their requirements at a glance.
- 32 CFR Part 170 - the CMMC Program rule itself, in the eCFR.
- DFARS Subpart 204.75 (CMMC) - the acquisition-side rule that puts CMMC into contracts.
Assessment & Scoping Guides (Official)
Read the official guides before building an internal checklist or hiring an assessor. Scope first: it decides everything downstream.
- CMMC Level 1 Assessment Guide (PDF)
- CMMC Level 2 Assessment Guide (PDF) - the objective-by-objective criteria for all 110 requirements. Verified 2026-08-13.
- Level 3 assessment guide and the Level 1-3 scoping guides - hosted on the DoW CIO documentation hub.
How the five asset categories work in practice, Mac-first: Mac Asset Classification for CMMC.
The Standards Themselves
CMMC Level 2 assesses NIST SP 800-171. Read the source, not summaries of it.
- NIST SP 800-171 Rev. 2 - the 110 requirements CMMC Level 2 enforces today.
- NIST SP 800-171A - the 320 assessment objectives; how each requirement is actually assessed.
- NIST SP 800-171 Rev. 3 and 800-171A Rev. 3 - the published successors. Not yet operative for CMMC; read for awareness, do not implement against them yet.
- NIST SP 800-18 - the original guide to writing a system security plan.
- NIST CSRC Glossary - authoritative term definitions; pairs with our acronym glossary.
Free Official Templates
NIST publishes skeletal starting points for the two core documents. They show the required shape with none of the substance filled in.
- CUI System Security Plan template (Word, from NIST)
- CUI Plan of Action & Milestones template (Word, from NIST)
The writing is still on you. When a blank template is not enough, the CMMC Operator Suite is the filled-in, Mac-first version.
Clause Texts & the CUI Program
- FAR 52.204-21 - the 15 basic safeguarding requirements behind Level 1 (renumbered 52.240-93 in the 2026 overhaul; see the clause guide).
- DFARS 252.204-7012 - the safeguarding and 72-hour incident-reporting clause that never went anywhere.
- NARA CUI Registry - the authoritative list of CUI categories and markings.
- NARA CUI FAQs - short answers on marking, handling, and decontrol.
- DoD Mandatory CUI Training - free, official, and satisfies the awareness item many small shops miss.
SPRS & Scoring
- SPRS portal - where self-assessment scores and affirmations are submitted.
- SPRS Quick Entry Guide (PDF) - the click-by-click for posting an 800-171 self-assessment score.
Scores follow the DoD Assessment Methodology weights; our controls list shows the point value of every requirement.
Assessment Ecosystem
- Cyber AB Marketplace - the roster of authorized C3PAOs and assessors.
- CMMC Assessment Process (CAP) v2.0 (PDF) - how an assessment actually runs, phase by phase.
Who these organizations are and which one you would ever hire: the ecosystem map.
Crypto Validation & Cloud Responsibility
- NIST CMVP validated modules search - verify FIPS 140 certificates by number.
- Shared responsibility documentation from Microsoft, AWS, and Google Cloud - the starting point for the shared responsibility matrix every cloud-using contractor needs.
Why "FileVault is on" is not a FIPS claim: our FIPS guide.
External links go to official government and vendor sources; we keep the list current, but agencies do move documents. Educational only, not legal advice. Verified July 2026.