Summary
What is the CMMC compliance roadmap under DFARS Subpart 204.75? DFARS Subpart 204.75 puts CMMC level requirements into DoD contracts and uses SPRS for Level 1 and Level 2 compliance.
DFARS Subpart 204.75 puts CMMC level requirements into DoD contracts and uses SPRS for Level 1 and Level 2 compliance.
Summary
What is the CMMC compliance roadmap under DFARS Subpart 204.75? DFARS Subpart 204.75 puts CMMC level requirements into DoD contracts and uses SPRS for Level 1 and Level 2 compliance.
DFARS Subpart 204.75 prescribes the policies and procedures for including CMMC level requirements in DoD contracts, and it applies to unclassified contractor information systems. Acquisition.gov states that CMMC is a framework for assessing a contractor’s information security protections under 32 CFR part 170. The same subpart also says it does not replace other security obligations, including physical, personnel, information, technical, or general administrative security operations, and it does not affect National Industrial Security Program requirements. For execution, SPRS is the location where vendors certify CMMC Level 1 and Level 2 compliance for the defense acquisition community to review. SPRS also points users to the CMMC Level 1 and Level 2 quick entry guides, the assessment guides, and the official CMMC rule at 32 CFR Part 170. For contract language, DFARS 252.204-7021 is the clause titled Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements.
DFARS Subpart 204.75 prescribes the policies and procedures for including CMMC level requirements in DoD contracts.
The subpart applies to unclassified contractor information systems and does not replace other required security operations.
SPRS is the location for vendors to certify CMMC Level 1 and Level 2 compliance.
Use the CMMC materials linked through SPRS and the rule at 32 CFR Part 170 when preparing or reviewing the assessment.
DFARS Subpart 204.75 does not abrogate other security requirements for protecting unclassified information, and it does not affect National Industrial Security Program requirements.