32 CFR Part 170
PART 170—CYBERSECURITY MATURITY MODEL CERTIFICATION (CMMC) PROGRAM
- PART 170—CYBERSECURITY MATURITY MODEL CERTIFICATION (CMMC) PROGRAM
- Subtitle A—Department of Defense › Chapter I—Office of the Secretary of Defense › Subchapter G—Defense Contracting
- Subpart A—General Information.
- § 170.1 Purpose.
- § 170.2 Incorporation by reference.
- § 170.3 Applicability.
- § 170.4 Acronyms and definitions.
- § 170.5 Policy.
- Subpart B—Government Roles and Responsibilities.
- § 170.6 CMMC PMO.
- § 170.7 DCMA DIBCAC.
- Subpart C—CMMC Assessment and Certification Ecosystem.
- § 170.8 Accreditation Body.
- § 170.9 CMMC Third-Party Assessment Organizations (C3PAOs).
- § 170.10 CMMC Assessor and Instructor Certification Organization (CAICO).
- § 170.11 CMMC Certified Assessor (CCA).
- § 170.12 CMMC Instructor.
- § 170.13 CMMC Certified Professional (CCP).
- Subpart D—Key Elements of the CMMC Program
- § 170.14 CMMC Model.
- § 170.15 CMMC Level 1 self-assessment and affirmation requirements.
- § 170.16 CMMC Level 2 self-assessment and affirmation requirements.
- § 170.17 CMMC Level 2 certification assessment and affirmation requirements.
- § 170.18 CMMC Level 3 certification assessment and affirmation requirements.
- § 170.19 CMMC scoping.
- § 170.20 Standards acceptance.
- § 170.21 Plan of Action and Milestones requirements.
- § 170.22 Affirmation.
- § 170.23 Application to subcontractors.
- § 170.24 CMMC Scoring Methodology.
- Appendix A to Part 170—Guidance