Problem briefCMMC readiness
What does it take to keep CMMC readiness current?
Review the applicable CMMC requirement, assign the work, connect the evidence, and keep the record current for the next contract or assessment.
Requirement to review
Track the CMMC requirement from system scope through review.
- 01 Requirement Applicable
- 02 System scope Defined
- 03 Work Assigned
- 04 Evidence Reviewable
- 05 Review Current
01Source requirement
Review the governing requirement.
These pages explain the source requirement and its practical implications. A contracting officer defines solicitation requirements. Assessors, customers, and counsel make their own determinations.
- 01
CMMC requirements are contract-specific. The contract, task order, delivery order, or subcontract establishes the applicable level and scope. A generic checklist cannot establish either.
- 02
DFARS 252.204-7021 requires a contractor, where the clause applies, to maintain the required current CMMC status and complete a current annual affirmation for covered systems used in performance.
- 03
Maintain a record of requirements, accountable owners, implementation work, evidence, and changes that affect a CMMC representation.
32 CFR part 170 CMMC Program final rule official sourceNIST SP 800-171A official source
BoundaryResponsibility
Prepare the record for review.
Deep Fathom organizes the requirement, work, and evidence record. The contracting office establishes solicitation and contract requirements. A C3PAO determines assessment results. Counsel and customers make their own legal and qualification decisions.
02Decision guides
Answer the buyer question before the decision.
Short, source-backed answers for teams reviewing a requirement, making a representation, or committing time to a pursuit.
03Platform workflow
Assign the work. Keep evidence with the requirement.
Deep Fathom records requirements, accountable owners, work, evidence, and decisions so the team can prepare for the next review.
- Record applicable requirements as assigned work with accountable owners.
- Keep evidence connected to the controls and claims it supports.
- Review changes before the next assessment, affirmation, or contract deadline.
Review CMMC requirements
Review the CMMC requirement before the next deadline.
Tell our team about the solicitation, contract, customer request, or assessment date. We will show which Deep Fathom workflow can organize the requirement, assigned work, and evidence.
- The contract requirement and decision date
- The system scope, work, or evidence that needs review
- The decision the team needs to support
Request a Platform Commercial evaluation
Reviewed by our teamProvide the details listed at left. Our team will review them, clarify what the platform can support, and recommend an evaluation step.
Do not include CUI, credentials, or export-controlled data.
05Related reading
Related resources
SourcesReviewed
Read the governing material.
- DFARS 252.204-7012Safeguarding covered defense information and cyber-incident reporting clause.Official source ↗
- DFARS 252.204-7020NIST SP 800-171 DoD assessment requirements, including Basic Assessment and subcontract provisions.Official source ↗
- DFARS 252.204-7021Current CMMC status, annual affirmation, and CMMC flowdown requirements where the clause applies.Official source ↗
- NIST SP 800-171 Rev. 2The 110 security requirements incorporated by reference into 32 CFR part 170 and assessed at CMMC Level 2.Official source ↗
- NIST SP 800-171 Rev. 3The current NIST publication. DFARS 252.204-7012 points at the revision in effect at time of solicitation, while CMMC assessments are conducted against Revision 2.Official source ↗
- 32 CFR part 170 CMMC Program final ruleCMMC program requirements, assessment levels, scope, affirmations, and conditional status rules.Official source ↗
- NIST SP 800-171AAssessment procedures, including the assurance case: a body of evidence organized into an argument that a claim about a system is true.Official source ↗