CMMC References
Our Reference Pages
Purpose-built quick-lookup pages, written Mac-first and kept current with verified-date stamps.
- CMMC Acronyms, Decoded - 60+ terms across the program, the clauses, scoping, and the Mac stack.
- CMMC Level 2 Controls List - all 110 requirements by family, with the SPRS point weight each carries.
- CMMC Key Dates & Compliance Clocks - the phase calendar and recurring deadlines, updated for the 2026 suspension.
- Who Does What in CMMC - Cyber AB, C3PAOs, DIBCAC, DCMA: who assesses, who accredits, who you actually hire.
- The DFARS Clauses Behind CMMC - 7012, 7019, 7020, 7021, and how the 2026 overhaul changed them.
The CMMC Program (Official)
Start at the source the Department maintains. These are the canonical program documents.
- DoD CIO CMMC Resources & Documentation - the official hub for scoping guides, assessment guides, and supplemental documents.
- DoD CIO About CMMC - the program overview from the office that runs it.
- CMMC Model Overview (PDF) - the levels and their requirements at a glance.
- 32 CFR Part 170 - the CMMC Program rule itself, in the eCFR.
- DFARS Subpart 204.75 (CMMC) - the acquisition-side rule that puts CMMC into contracts.
Assessment & Scoping Guides (Official)
Read the official guides before building an internal checklist or hiring an assessor. Scope first: it decides everything downstream.
- CMMC Level 1 Assessment Guide (PDF)
- CMMC Level 2 Assessment Guide (PDF) - the objective-by-objective criteria for all 110 requirements.
- Level 3 assessment guide and the Level 1-3 scoping guides - hosted on the DoD CIO documentation hub.
How the five asset categories work in practice, Mac-first: Mac Asset Classification for CMMC.
The Standards Themselves
CMMC Level 2 assesses NIST SP 800-171. Read the source, not summaries of it.
- NIST SP 800-171 Rev. 2 - the 110 requirements CMMC Level 2 enforces today.
- NIST SP 800-171A - the 320 assessment objectives; how each requirement is actually assessed.
- NIST SP 800-171 Rev. 3 and 800-171A Rev. 3 - the published successors. Not yet operative for CMMC; read for awareness, do not implement against them yet.
- NIST SP 800-18 - the original guide to writing a system security plan.
- NIST CSRC Glossary - authoritative term definitions; pairs with our acronym glossary.
Free Official Templates
NIST publishes skeletal starting points for the two core documents. They show the required shape with none of the substance filled in.
- CUI System Security Plan template (Word, from NIST)
- CUI Plan of Action & Milestones template (Word, from NIST)
The writing is still on you. When a blank template is not enough, the CMMC Operator Suite is the filled-in, Mac-first version.
Clause Texts & the CUI Program
- FAR 52.204-21 - the 15 basic safeguarding requirements behind Level 1 (renumbered 52.240-93 in the 2026 overhaul; see the clause guide).
- DFARS 252.204-7012 - the safeguarding and 72-hour incident-reporting clause that never went anywhere.
- NARA CUI Registry - the authoritative list of CUI categories and markings.
- NARA CUI FAQs - short answers on marking, handling, and decontrol.
- DoD Mandatory CUI Training - free, official, and satisfies the awareness item many small shops miss.
SPRS & Scoring
- SPRS portal - where self-assessment scores and affirmations are submitted.
- SPRS Quick Entry Guide (PDF) - the click-by-click for posting an 800-171 self-assessment score.
Scores follow the DoD Assessment Methodology weights; our controls list shows the point value of every requirement.
Assessment Ecosystem
- Cyber AB Marketplace - the roster of authorized C3PAOs and assessors.
- CMMC Assessment Process (CAP) v2.0 (PDF) - how an assessment actually runs, phase by phase.
Who these organizations are and which one you would ever hire: the ecosystem map.
Crypto Validation & Cloud Responsibility
- NIST CMVP validated modules search - verify FIPS 140 certificates by number.
- Shared responsibility documentation from Microsoft, AWS, and Google Cloud - the starting point for the shared responsibility matrix every cloud-using contractor needs.
Why "FileVault is on" is not a FIPS claim: our FIPS guide.
External links go to official government and vendor sources; we keep the list current, but agencies do move documents. Educational only, not legal advice. Verified July 2026.