Skip to main content
Greypike's CMMC Knowledge Base

Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.

If you cannot find an answer then contact us or click the chat button on the lower right..

< All Topics
Print

32 CFR Part 170: The CMMC Program Rule Explained

The CMMC Program Rule—officially 32 CFR Part 170—is the regulatory foundation of CMMC. Published in the Federal Register and codified in the Code of Federal Regulations, this rule transforms CMMC from a DoD initiative into a binding federal regulation. Understanding the rule helps you know exactly what is legally required.

32 CFR Part 170 means Title 32 of the Code of Federal Regulations, Part 170—the specific section establishing CMMC requirements.

CMMC stands for Cybersecurity Maturity Model Certification—the DoD’s mandatory cybersecurity program for defense contractors.

This guide explains the key provisions of the CMMC Program Rule and what they mean for defense contractors.

What the Program Rule Establishes

32 CFR Part 170 creates the official, legally binding CMMC framework. The rule:

  • Defines the three CMMC levels and their requirements
  • Establishes assessment types and procedures
  • Sets certification validity periods
  • Creates requirements for assessors and assessment organizations
  • Defines roles for the CMMC ecosystem participants
  • Establishes affirmation and reporting requirements

Before this rule, CMMC existed as DoD policy. With the rule’s publication, CMMC became a federal regulation with the force of law.

Structure of the Rule

The rule is organized into subparts:

Subpart A: General

Establishes purpose, applicability, and definitions. Key definitions include:

  • CMMC Assessment: The evaluation of a contractor’s implementation of security requirements
  • CMMC Status: The contractor’s current certification level and date
  • Controlled Unclassified Information (CUI): Information requiring safeguarding per law, regulation, or policy
  • External Service Provider (ESP): Organizations providing services involving contractor data or systems

Subpart B: CMMC Levels and Assessment Requirements

Defines what each level requires and how assessment works.

Subpart C: Assessment and Certification

Details the assessment process, scoring, and certification outcomes.

Subpart D: CMMC Ecosystem

Establishes requirements for C3PAOs, assessors, and the accreditation body.

Level 1 Requirements Under the Rule

The rule establishes Level 1 as follows:

Security Requirements

Level 1 requires implementation of the 15 security requirements in FAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems).

FAR stands for Federal Acquisition Regulation—the primary rules governing federal contracting.

Assessment Type

Level 1 uses self-assessment:

  • Contractor evaluates own compliance
  • Results entered into SPRS (Supplier Performance Risk System)
  • Senior official affirms accuracy
  • Annual reaffirmation required

No POA&M Allowed

Level 1 does not permit POA&M. All 15 requirements must be implemented before affirmation.

POA&M stands for Plan of Action and Milestones—documents tracking gaps and remediation.

Applicability

Level 1 applies to contractors handling FCI (Federal Contract Information) but not CUI.

FCI stands for Federal Contract Information—information provided by or generated for the government under contract.

Level 2 Requirements Under the Rule

Level 2 has more complexity:

Security Requirements

Level 2 requires implementation of all 110 security requirements in NIST SP 800-171 Revision 2.

Assessment Types

Level 2 has two assessment paths:

Self-Assessment (Level 2 Self)

  • Contractor evaluates own compliance
  • Results entered into SPRS
  • Senior official affirms accuracy
  • Annual reaffirmation required
  • Applies when contracts do not require C3PAO assessment

C3PAO Assessment (Level 2 C3PAO)

  • A third-party assessment organization evaluates compliance
  • Follows NIST SP 800-171A assessment procedures
  • Results reported to DoD
  • Three-year certification with annual affirmation
  • Required when contracts specify C3PAO assessment

C3PAO stands for Certified Third-Party Assessment Organization.

POA&M and Conditional Certification

For Level 2 C3PAO assessments:

  • Contractors meeting 80%+ of requirements may receive conditional certification
  • Remaining gaps documented in POA&M
  • 180 days to close all POA&M items
  • Certain controls cannot be on POA&M

Applicability

Level 2 applies to contractors handling CUI.

Level 3 Requirements Under the Rule

Level 3 is the highest level:

Security Requirements

Level 3 requires:

  • All 110 NIST SP 800-171 Rev 2 requirements
  • Additional requirements from NIST SP 800-172 (Enhanced Security)

Assessment Type

Level 3 uses government-led assessment:

  • Conducted by the Defense Contract Management Agency (DCMA) DIBCAC
  • More rigorous than the C3PAO assessment
  • Required for most sensitive programs

DIBCAC stands for Defense Industrial Base Cybersecurity Assessment Center.

Prerequisite

Contractors must achieve Level 2 C3PAO certification before Level 3 assessment.

Applicability

Level 3 applies to contractors handling the most sensitive CUI on critical programs. This affects a small subset of the defense industrial base.

Assessment and Scoring Provisions

The rule establishes assessment mechanics:

Scoring Methodology

Assessments use the DoD Assessment Methodology:

  • Each control is assessed as MET or NOT MET
  • NOT MET controls result in point deductions
  • A perfect score is 110 points
  • Score determines certification eligibility

Assessment Objectives

Assessors evaluate using NIST SP 800-171A, which defines:

  • Assessment objectives for each requirement
  • Assessment methods (examine, interview, test)
  • Evidence needed to demonstrate compliance

Conditional Certification Threshold

The rule establishes 80% as the threshold for conditional certification:

  • Score of 80+ with POA&M: Conditional certification
  • Score below 80: Not certified
  • All controls met: Full certification

Affirmation Requirements

The rule requires ongoing affirmation:

Senior Official Affirmation

A senior official must affirm:

  • Assessment results are accurate
  • Security requirements are implemented
  • The organization remains in compliance

Annual Reaffirmation

All certified contractors must reaffirm annually:

  • Confirms continued compliance
  • Updates SPRS status
  • Required to maintain certification

Consequences of False Affirmation

False affirmation can result in:

  • False Claims Act liability
  • Contract termination
  • Suspension or debarment
  • Criminal penalties in severe cases

The affirmation requirement creates executive accountability for cybersecurity compliance.

External Service Provider Requirements

The rule addresses ESPs:

ESP stands for External Service Provider—organizations providing IT services to contractors.

ESP Obligations

ESPs must:

  • Meet FedRAMP Moderate requirements, or
  • Be assessed alongside the contractor, or
  • Obtain their own CMMC certification

FedRAMP stands for Federal Risk and Authorization Management Program.

Documentation Requirements

Contractors must:

  • Document all ESPs in their System Security Plan
  • Describe the services ESPs provide
  • Explain how ESPs satisfy security requirements
  • Define shared responsibilities

CMMC Ecosystem Provisions

The rule establishes requirements for the assessment ecosystem:

CMMC Accreditation Body (Cyber AB)

The Cyber AB:

  • Accredits C3PAOs
  • Certifies individual assessors
  • Maintains quality standards
  • Manages the CMMC ecosystem

C3PAO Requirements

C3PAOs must:

  • Maintain accreditation
  • Employ certified assessors
  • Follow assessment procedures
  • Report results accurately
  • Avoid conflicts of interest

Assessor Requirements

Individual assessors must:

  • Complete required training
  • Pass certification examinations
  • Maintain continuing education
  • Follow professional standards

Relationship to DFARS

32 CFR Part 170 establishes the CMMC program; DFARS implements it in contracts:

DFARS 252.204-7021

This clause adds CMMC requirements to contracts:

  • Specifies the required CMMC level
  • Indicates assessment type (self or C3PAO)
  • Flows down to subcontractors
  • Establishes compliance timeline

How They Work Together

  • 32 CFR Part 170 defines what CMMC is
  • DFARS clauses put CMMC into contracts
  • Contracts trigger compliance obligations

Without the DFARS clause in your contract, CMMC certification is not contractually required—but the rule exists whether or not your current contracts reference it.

Implementation and Effective Dates

The rule became effective upon publication in the Federal Register (October 2024). However, CMMC requirements appear in contracts through phased implementation under DFARS:

Phase 1 (Starting December 2024)

  • Level 1 self-assessment
  • Level 2 self-assessment
  • Voluntary inclusion in contracts

Phase 2 (Starting 2025)

  • Level 2 C3PAO assessment for certain contracts
  • Broader contract inclusion

Phase 3 (2026)

  • Level 3 assessment
  • Full implementation across applicable contracts

Phase 4 (2027-2028)

  • Complete rollout
  • All applicable contracts include CMMC requirements

How to Access the Rule

The official rule text is available at:

  • Federal Register: federalregister.gov (search for CMMC or 32 CFR 170)
  • eCFR: ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170
  • DoD CIO CMMC Website: dodcio.defense.gov/CMMC

The eCFR version is updated with any amendments and is the current, authoritative text.

Key Takeaways

32 CFR Part 170 is the official CMMC Program Rule, establishing CMMC as a federal regulation. The rule defines three levels: assessment requirements, scoring methodology, certification validity, affirmation requirements, and ecosystem participant obligations.

Level 1 requires self-assessment of 15 FAR 52.204-21 requirements. Level 2 requires 110 NIST SP 800-171 controls with either self-assessment or C3PAO assessment, depending on contract requirements. Level 3 adds NIST SP 800-172 requirements with a government-led assessment.

The rule creates executive accountability through affirmation requirements and establishes consequences for false statements. Understanding the rule helps you know exactly what is legally required for your certification level.

Related Articles:

Official Sources: This article is based on 32 CFR Part 170 (CMMC Program Rule), DFARS CMMC acquisition clauses, and DoD CMMC implementation guidance.

Regulatory compliance can be complex. Contact Greypike for expert guidance on what 32 CFR Part 170 means for your specific situation. For Level 1 compliance, Obolix aligns directly with the rule requirements—our platform enables you to become compliant in a week or less.

Table of Contents