252.204-7021 Cybersecurity Maturity Model Certification Requirements.
Current normalized text
252.204-7021 Cybersecurity Maturity Model Certification Requirements.
As prescribed in 204.7503(a) and (b), insert the following clause:
CYBERSECURITY MATURITY MODEL CERTIFICATION REQUIREMENTS (JAN 2023)
- (a)
Scope. The Cybersecurity Maturity Model Certification (CMMC) CMMC is a framework that measures a contractor’s cybersecurity maturity to include the implementation of cybersecurity practices and institutionalization of processes (see https://www.acq.osd.mil/cmmc/index.html).
- (b)
Requirements. The Contractor shall have a current (i.e. not older than 3 years) CMMC certificate at the CMMC level required by this contract and maintain the CMMC certificate at the required level for the duration of the contract.
- (c)
Subcontracts. The Contractor shall—
- (1)
Insert the substance of this clause, including this paragraph (c), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services, excluding commercially available off-the-shelf items; and
- (2)
Prior to awarding to a subcontractor, ensure that the subcontractor has a current (i.e., not older than 3 years) CMMC certificate at the CMMC level that is appropriate for the information that is being flowed down to the subcontractor.
Source and use
Source attribution. Official source material is published by Acquisition.gov. ClauseSignal presents a normalized record from accepted public source snapshots and links back to that source.
Informational disclaimer. ClauseSignal provides informational monitoring of public FAR and DFARS source material. It does not provide legal advice, determine whether a clause applies to your circumstances, issue certifications, or claim affiliation with or endorsement by the U.S. Government. Review the official source before making decisions.