Welcome to the CMMC Knowledgebase. Search for CMMC, resources, tools, sources, sites, and platforms using the search box below.
We add more to the database weekly, check back often.
If you cannot find an answer then contact us or click the chat button on the lower right..
-
Artificial Intelligence (AI)
-
CMMC Fundamentals
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
SPRS & Self-Assessment
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
32 CFR Part 170: The CMMC Program Rule Explained
The CMMC Program Rule—officially 32 CFR Part 170—is the regulatory foundation of CMMC. Published in the Federal Register and codified in the Code of Federal Regulations, this rule transforms CMMC from a DoD initiative into a binding federal regulation. Understanding the rule helps you know exactly what is legally required.
32 CFR Part 170 means Title 32 of the Code of Federal Regulations, Part 170—the specific section establishing CMMC requirements.
CMMC stands for Cybersecurity Maturity Model Certification—the DoD’s mandatory cybersecurity program for defense contractors.
This guide explains the key provisions of the CMMC Program Rule and what they mean for defense contractors.
What the Program Rule Establishes
32 CFR Part 170 creates the official, legally binding CMMC framework. The rule:
- Defines the three CMMC levels and their requirements
- Establishes assessment types and procedures
- Sets certification validity periods
- Creates requirements for assessors and assessment organizations
- Defines roles for the CMMC ecosystem participants
- Establishes affirmation and reporting requirements
Before this rule, CMMC existed as DoD policy. With the rule’s publication, CMMC became a federal regulation with the force of law.
Structure of the Rule
The rule is organized into subparts:
Subpart A: General
Establishes purpose, applicability, and definitions. Key definitions include:
- CMMC Assessment: The evaluation of a contractor’s implementation of security requirements
- CMMC Status: The contractor’s current certification level and date
- Controlled Unclassified Information (CUI): Information requiring safeguarding per law, regulation, or policy
- External Service Provider (ESP): Organizations providing services involving contractor data or systems
Subpart B: CMMC Levels and Assessment Requirements
Defines what each level requires and how assessment works.
Subpart C: Assessment and Certification
Details the assessment process, scoring, and certification outcomes.
Subpart D: CMMC Ecosystem
Establishes requirements for C3PAOs, assessors, and the accreditation body.
Level 1 Requirements Under the Rule
The rule establishes Level 1 as follows:
Security Requirements
Level 1 requires implementation of the 15 security requirements in FAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems).
FAR stands for Federal Acquisition Regulation—the primary rules governing federal contracting.
Assessment Type
Level 1 uses self-assessment:
- Contractor evaluates own compliance
- Results entered into SPRS (Supplier Performance Risk System)
- Senior official affirms accuracy
- Annual reaffirmation required
No POA&M Allowed
Level 1 does not permit POA&M. All 15 requirements must be implemented before affirmation.
POA&M stands for Plan of Action and Milestones—documents tracking gaps and remediation.
Applicability
Level 1 applies to contractors handling FCI (Federal Contract Information) but not CUI.
FCI stands for Federal Contract Information—information provided by or generated for the government under contract.
Level 2 Requirements Under the Rule
Level 2 has more complexity:
Security Requirements
Level 2 requires implementation of all 110 security requirements in NIST SP 800-171 Revision 2.
Assessment Types
Level 2 has two assessment paths:
Self-Assessment (Level 2 Self)
- Contractor evaluates own compliance
- Results entered into SPRS
- Senior official affirms accuracy
- Annual reaffirmation required
- Applies when contracts do not require C3PAO assessment
C3PAO Assessment (Level 2 C3PAO)
- A third-party assessment organization evaluates compliance
- Follows NIST SP 800-171A assessment procedures
- Results reported to DoD
- Three-year certification with annual affirmation
- Required when contracts specify C3PAO assessment
C3PAO stands for Certified Third-Party Assessment Organization.
POA&M and Conditional Certification
For Level 2 C3PAO assessments:
- Contractors meeting 80%+ of requirements may receive conditional certification
- Remaining gaps documented in POA&M
- 180 days to close all POA&M items
- Certain controls cannot be on POA&M
Applicability
Level 2 applies to contractors handling CUI.
Level 3 Requirements Under the Rule
Level 3 is the highest level:
Security Requirements
Level 3 requires:
- All 110 NIST SP 800-171 Rev 2 requirements
- Additional requirements from NIST SP 800-172 (Enhanced Security)
Assessment Type
Level 3 uses government-led assessment:
- Conducted by the Defense Contract Management Agency (DCMA) DIBCAC
- More rigorous than the C3PAO assessment
- Required for most sensitive programs
DIBCAC stands for Defense Industrial Base Cybersecurity Assessment Center.
Prerequisite
Contractors must achieve Level 2 C3PAO certification before Level 3 assessment.
Applicability
Level 3 applies to contractors handling the most sensitive CUI on critical programs. This affects a small subset of the defense industrial base.
Assessment and Scoring Provisions
The rule establishes assessment mechanics:
Scoring Methodology
Assessments use the DoD Assessment Methodology:
- Each control is assessed as MET or NOT MET
- NOT MET controls result in point deductions
- A perfect score is 110 points
- Score determines certification eligibility
Assessment Objectives
Assessors evaluate using NIST SP 800-171A, which defines:
- Assessment objectives for each requirement
- Assessment methods (examine, interview, test)
- Evidence needed to demonstrate compliance
Conditional Certification Threshold
The rule establishes 80% as the threshold for conditional certification:
- Score of 80+ with POA&M: Conditional certification
- Score below 80: Not certified
- All controls met: Full certification
Affirmation Requirements
The rule requires ongoing affirmation:
Senior Official Affirmation
A senior official must affirm:
- Assessment results are accurate
- Security requirements are implemented
- The organization remains in compliance
Annual Reaffirmation
All certified contractors must reaffirm annually:
- Confirms continued compliance
- Updates SPRS status
- Required to maintain certification
Consequences of False Affirmation
False affirmation can result in:
- False Claims Act liability
- Contract termination
- Suspension or debarment
- Criminal penalties in severe cases
The affirmation requirement creates executive accountability for cybersecurity compliance.
External Service Provider Requirements
The rule addresses ESPs:
ESP stands for External Service Provider—organizations providing IT services to contractors.
ESP Obligations
ESPs must:
- Meet FedRAMP Moderate requirements, or
- Be assessed alongside the contractor, or
- Obtain their own CMMC certification
FedRAMP stands for Federal Risk and Authorization Management Program.
Documentation Requirements
Contractors must:
- Document all ESPs in their System Security Plan
- Describe the services ESPs provide
- Explain how ESPs satisfy security requirements
- Define shared responsibilities
CMMC Ecosystem Provisions
The rule establishes requirements for the assessment ecosystem:
CMMC Accreditation Body (Cyber AB)
The Cyber AB:
- Accredits C3PAOs
- Certifies individual assessors
- Maintains quality standards
- Manages the CMMC ecosystem
C3PAO Requirements
C3PAOs must:
- Maintain accreditation
- Employ certified assessors
- Follow assessment procedures
- Report results accurately
- Avoid conflicts of interest
Assessor Requirements
Individual assessors must:
- Complete required training
- Pass certification examinations
- Maintain continuing education
- Follow professional standards
Relationship to DFARS
32 CFR Part 170 establishes the CMMC program; DFARS implements it in contracts:
DFARS 252.204-7021
This clause adds CMMC requirements to contracts:
- Specifies the required CMMC level
- Indicates assessment type (self or C3PAO)
- Flows down to subcontractors
- Establishes compliance timeline
How They Work Together
- 32 CFR Part 170 defines what CMMC is
- DFARS clauses put CMMC into contracts
- Contracts trigger compliance obligations
Without the DFARS clause in your contract, CMMC certification is not contractually required—but the rule exists whether or not your current contracts reference it.
Implementation and Effective Dates
The rule became effective upon publication in the Federal Register (October 2024). However, CMMC requirements appear in contracts through phased implementation under DFARS:
Phase 1 (Starting December 2024)
- Level 1 self-assessment
- Level 2 self-assessment
- Voluntary inclusion in contracts
Phase 2 (Starting 2025)
- Level 2 C3PAO assessment for certain contracts
- Broader contract inclusion
Phase 3 (2026)
- Level 3 assessment
- Full implementation across applicable contracts
Phase 4 (2027-2028)
- Complete rollout
- All applicable contracts include CMMC requirements
How to Access the Rule
The official rule text is available at:
- Federal Register: federalregister.gov (search for CMMC or 32 CFR 170)
- eCFR: ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170
- DoD CIO CMMC Website: dodcio.defense.gov/CMMC
The eCFR version is updated with any amendments and is the current, authoritative text.
Key Takeaways
32 CFR Part 170 is the official CMMC Program Rule, establishing CMMC as a federal regulation. The rule defines three levels: assessment requirements, scoring methodology, certification validity, affirmation requirements, and ecosystem participant obligations.
Level 1 requires self-assessment of 15 FAR 52.204-21 requirements. Level 2 requires 110 NIST SP 800-171 controls with either self-assessment or C3PAO assessment, depending on contract requirements. Level 3 adds NIST SP 800-172 requirements with a government-led assessment.
The rule creates executive accountability through affirmation requirements and establishes consequences for false statements. Understanding the rule helps you know exactly what is legally required for your certification level.
Related Articles:
- CMMC 2.0 vs CMMC 1.0: What Changed
- CMMC Implementation Timeline and Phased Rollout
- CMMC Level 2 C3PAO Assessment: What to Expect
- 32 CFR Part 170 – Full Text
- DFARS 252.204-7021
- NIST SP 800-171 Rev 2
Official Sources: This article is based on 32 CFR Part 170 (CMMC Program Rule), DFARS CMMC acquisition clauses, and DoD CMMC implementation guidance.
Regulatory compliance can be complex. Contact Greypike for expert guidance on what 32 CFR Part 170 means for your specific situation. For Level 1 compliance, Obolix aligns directly with the rule requirements—our platform enables you to become compliant in a week or less.