Stored deterministic redline

252.204-7021 Official source correction

Cybersecurity Maturity Model Certification Requirements.

RemovedAddedMoved
  1. Changed

    252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements.

  2. Changed

    As prescribed in 204.75047503(a) and (b), useinsert the following clause:

  3. Changed

    CONTRACTOR COMPLIANCE WITH THE CYBERSECURITY MATURITY MODEL CERTIFICATION LEVEL REQUIREMENTS (NOVJAN 20252023)

  4. Changed

    (a) DefinitionsScope. AsThe usedCybersecurity inMaturity thisModel clause—Certification (CMMC) CMMC is a framework that measures a contractor’s cybersecurity maturity to include the implementation of cybersecurity practices and institutionalization of processes (see https://www.acq.osd.mil/cmmc/index.html).

  5. Removed

    “Controlled unclassified information” means information the Government creates or possesses, or information an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls (32 CFR 2002.4(h)).

  6. Moved · Changed

    (b) FrameworkRequirements. The CybersecurityContractor Maturityshall Modelhave Certificationa current (CMMCi.e. not older than 3 years) isCMMC acertificate frameworkat forthe assessingCMMC alevel contractor’srequired complianceby withthis applicablecontract informationand securitymaintain protectionsthe (seeCMMC 32certificate CFRat partthe 170)required level for the duration of the contract.

  7. Removed

    “Current” means—

  8. Moved · Changed

    (c) DuplicationSubcontracts. The CMMC assessments will not duplicate efforts from any other comparable DoD assessment, except for rare circumstances when a reassessment may be necessary, for example, when there are indications of issues with cybersecurity and/or compliance with CMMCContractor requirements.shall—

  9. Changed

    (1) WithInsert regardthe tosubstance Conditionalof Cybersecuritythis Maturityclause, Modelincluding Certificationthis paragraph (CMMCc), Status—in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services, excluding commercially available off-the-shelf items; and

  10. Removed

    (i) Not older than 180 days for Conditional Level 2 (Self) assessments and Conditional Level 2 (certified third-party assessment organization (C3PAO)) assessments, with—

  11. Changed

    (2) WithPrior regardto awarding to Finala subcontractor, ensure that the subcontractor has a current (i.e., not older than 3 years) CMMC Status—certificate at the CMMC level that is appropriate for the information that is being flowed down to the subcontractor.

  12. Removed

    (A) No changes in compliance with the requirements at 32 CFR part 170 since the Conditional CMMC Status date (see 32 CFR 170.16 and 170.17); and

  13. Removed

    (B) A corresponding affirmation of continuous compliance by an affirming official (see 32 CFR 170.4); and

  14. Removed

    (ii) Not older than 180 days for Conditional Level 3 (Defense Industrial Base Cybersecurity Assessment Center (DIBCAC)) assessments, with—

  15. Removed

    (A) No changes in compliance with the requirements at 32 CFR part 170 since the Conditional CMMC Status date (see 32 CFR 170.18); and

  16. Removed

    (B) A corresponding affirmation of continuous compliance by an affirming official;

  17. Removed

    (i) Not older than 1 year for Final Level 1 (Self), with—

  18. Removed

    (A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.15); and

  19. Removed

    (B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official;

  20. Removed

    (ii) Not older than 3 years for Final Level 2 (Self) assessments and Final Level 2 (C3PAO) assessments, with—

  21. Removed

    (A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.16 and 170.17); and

  22. Removed

    (B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official; and

  23. Removed

    (iii) Not older than 3 years for Final Level 3 (DIBCAC) assessments, with—

  24. Removed

    (A) No changes in compliance with the requirements at 32 CFR part 170 since the Final CMMC Status date (see 32 CFR 170.18); and

  25. Removed

    (B) A corresponding affirmation of continuous compliance, not older than 1 year, by an affirming official; and

  26. Removed

    (3) With regard to affirmation of continuous compliance (32 CFR 170.22), not older than 1 year with no changes in compliance with the requirements at 32 CFR part 170.

  27. Removed

    “Cybersecurity Maturity Model Certification (CMMC) status” means the result of meeting or exceeding the minimum required score for the corresponding assessment. The potential statuses are as follows:

  28. Removed

    (1) Final Level 1 (Self).

  29. Removed

    (2) Conditional Level 2 (Self).

  30. Removed

    (3) Final Level 2 (Self).

  31. Removed

    (4) Conditional Level 2 (C3PAO).

  32. Removed

    (5) Final Level 2 (C3PAO).

  33. Removed

    (6) Conditional Level 3 (DIBCAC).

  34. Removed

    (7) Final Level 3 (DIBCAC).

  35. Removed

    “Cybersecurity Maturity Model Certification unique identifier (CMMC UID)” means 10 alpha-numeric characters assigned to each CMMC assessment and reflected in theSupplier Performance Risk System (SPRS) for each contractor information system.

  36. Removed

    “Federal contract information (FCI)” means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government. It does not include information provided by the Government to the public, such as on public websites, or simple transactional information, such as information necessary to process payments.

  37. Removed

    “Plan of action and milestones” means a document that identifies tasks to be accomplished. It details resources required to accomplish the elements of the plan, any milestones in meeting the tasks, and scheduled completion dates for the milestones, as defined in National Institute of Standards and Technology Special Publication 800-115 (32 CFR 170.21).

  38. Removed

    (d) Requirements. The Contractor shall—

  39. Removed

    (1)(i) Have and maintain for the duration of the contract a current CMMC status at the following CMMC level, or higher: ___ [Contracting Officer insert: CMMC Level 1 (Self); CMMC Level 2 (Self); CMMC Level 2 (C3PAO); or CMMC Level 3 (DIBCAC) ] for all information systems used in performance of the contract, task order, or delivery order that process, store, or transmit FCI or CUI; and

  40. Removed

    unspecified ___

  41. Removed

    (ii) Consult 32 CFR 170.23 related to the flowdown of the CMMC requirements, and flow down the correct CMMC level to subcontracts and other contractual instruments;

  42. Removed

    (2) Only process, store, or transmit FCI or CUI on contractor information systems that have a CMMC status at the CMMC level requiredin paragraph (d)(1) of this clause, or higher;

  43. Removed

    (3) Complete on an annual basis, and maintain as current,an affirmation, by the affirming official (see 32 CFR 170.4), of continuous compliance with the requirements associated with the CMMC level required in paragraph (d)(1) of this clause in the Supplier Performance Risk System (SPRS) (https://piee.eb.mil) for each CMMC UID applicable to each of the contractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the contract;

  44. Removed

    (4) Ensure all subcontractors and suppliers complete prior to subcontract award, and maintain on an annual basis,an affirmation, by the affirming official (see 32 CFR 170.4), of continuous compliance with the requirements associated with the CMMC level required for the subcontract or other contractual instrument for each of the subcontractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the subcontract; and

  45. Removed

    (5) If the Contractor has a CMMC Status of Conditional, successfully close out a valid plan of action and milestones (32 CFR 170.21) to achieve a CMMC Status of Final.

  46. Removed

    (e) Reporting. The Contractor shall—

  47. Removed

    (1) Submit to the Contracting Officer—

  48. Removed

    (i) The CMMC UID(s) issued by SPRS for contractor information systems that will process, store, or transmit FCI or CUI during performance of the contract; and

  49. Removed

    (ii) Any changes in the CMMC UIDs generated in SPRS throughout the life of the contract, task order, or delivery order, if applicable;

  50. Removed

    (2) Enter into SPRS the results of a current self-assessment for each CMMC UID, not covered by a C3PAO assessment or DIBCAC assessment, applicable to each of the contractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the contract; and

  51. Removed

    (3) Complete in SPRS on an annual basis and maintain as current an affirmation of continuous compliance by the affirming official (see 32 CFR 170.4) for each self-assessment, C3PAO assessment, or DIBCAC assessment required under the contract in SPRS.

  52. Removed

    (f) Subcontracts. The Contractor shall—

  53. Removed

    (1) Insert the substance of this clause, including this paragraph ( f) and excluding paragraph (e)(1), in subcontracts and other contractual instruments, including those for the acquisition of commercial products and commercial services, excluding commercially available off-the-shelf items , if the subcontract or other contractual instrument will contain a requirement to process, store, or transmit FCI or CUI; and

  54. Removed

    (2) Prior to awarding a subcontract or other contractual instrument, ensure that the subcontractor has a current CMMC certificate or current CMMC status at the CMMC level that is appropriate for the information that is being flowed down to the subcontractor based on the requirements at 32 CFR 170.23.

  55. Removed

    (End of clause)

Source and use

Source attribution. Official source material is published by Acquisition.gov. ClauseSignal presents a normalized record from accepted public source snapshots and links back to that source.

Informational disclaimer. ClauseSignal provides informational monitoring of public FAR and DFARS source material. It does not provide legal advice, determine whether a clause applies to your circumstances, issue certifications, or claim affiliation with or endorsement by the U.S. Government. Review the official source before making decisions.