Regulations and Frameworks for Defense Organizations
Several overlapping frameworks may apply to your defense organization depending on contract role, data handled, customer requirements, and jurisdiction. Not all apply to every organization — use this guide to identify which are relevant to you.
- Level 1 (17 practices covering FCI) — annual self-assessment and affirmation, no third-party assessment required; applicable to all DoD contractors handling FCI
- Level 2 (110 practices covering CUI on NIST SP 800-171) — triennial third-party assessment by a C3PAO (CMMC Third-Party Assessment Organization) under 32 CFR Part 170, required for CUI exposure by October 2026
- Level 3 (highest-priority programs, 134 practices on NIST SP 800-172) — DoD-led DIBCAC assessment for the highest-priority assets
- MSP / MSSP validation only for Level 3 — the DoD does not independently certify a contractor's external service provider at Levels 1 / 2; the contractor must attest to flow-down
- Plan of Action and Milestones (POA&M) for any unmet practice — pre-existing governance expectation, not a deferral
- NIST SP 800-171 control family mapping: AC (access control), AU (audit and accountability), AT (awareness and training), CM (configuration management), IA (identification & authentication), IR (incident response), MA (maintenance), MP (media protection), PS (personnel security), PE (physical and environmental), SC (system and communications protection), SI (system and information integrity) — full 14-family coverage as the CMMC L2 sampling unit
- NIST SP 800-172 (enhanced security requirements for Level 3) — for highest-priority programs handling critical CUI; penetration-test-grade controls over L2 baseline
- CUI awareness training records — annual CUI handling + marking + destruction + spillage cadence training for every employee handling CUI
- Flow-down to subcontractors: any Tier 1–3 subcontractor handling CUI must itself operate at CMMC Level 2 — the prime cannot contractually waive it
- Pre-2026 contracting: bidders on DoD contracts that include CMMC requirements must self-attest to Level 1 or Level 2 in the DD Form 254 / DFARS offer flowdown
Penalty: Loss of DoD contract eligibility on C3PAO assessment failure under 32 CFR Part 170; flow-down exclusion from DoD prime contractor contracts; potential DFARS cyber-incident False Claims Act exposure for material misrepresentations in self-attestation; cyber-insurance exclusions for missing MFA on CUI-touching accounts + missing CUI-system network segmentation; downstream subcontractor survival threatened when a prime is removed.
- CUI marking on every document, email, and file containing CUI: CUI//SP-XXXX banner line + designated CUI category (e.g. CUI//SP-PRIVCY, CUI//SP-PROP) + dissemination controls (e.g. NOFORN, ORCON)
- CUI destruction methods per 32 CFR Part 2002 + the CUI category — burning, cross-cut shredding, degaussing, NIST SP 800-88 sanitization; no general recycling of CUI-bearing media
- CUI spillage immediate containment + NARA spillage notification + DFARS cyber-incident cadence trigger — the moment a non-authorized person accesses CUI, the 72-hour DFARS clock starts
- CUI access controls — limited to authorized persons with a lawful government purpose; documented need-to-know reasoning
- CUI covered defense information (CDI) — defense information specifically protected by DFARS and ITAR/EAR — a subset of CUI with additional handling requirements
- CUI destruction at end-of-life — every CUI-bearing laptop, smartphone, USB drive, server, and backup tape must be sanitized per CUI category before disposal or reuse
- Annual CUI awareness training — every employee handling CUI must complete annual awareness training with documented training records (NARA CUI Training requirements + agency-specific training)
- CUI transmission safeguards — TLS 1.2+ for CUI in transit; FIPS-validated cryptography when CUI traverses federal systems or FedRAMP-authorized cloud; email encryption for CUI-bearing messages
- CUI incident reporting — any actual or suspected unauthorized disclosure of CUI must be reported to the originating agency and tracked through NARA CUI spillage procedures
- Controlled environments — CUI must be processed, stored, and handled in environments that meet the safeguarding requirements of 32 CFR Part 2002 (physical and logical safeguards)
Penalty: Federal contract loss of eligibility for mishandling CUI; NARA CUI Registry follow-up + agency-specific CUI program review; DFARS cyber-incident cadence triggers False Claims Act exposure when material misrepresentation occurred in self-attestation; potential OCI (Organizational Conflict of Interest) restrictions on follow-on contracts; loss of CUI-handling authority under 32 CFR Part 2002.
- DFARS 252.204-7012(c)(1) — safeguarding covered defense information + cyber-incident reporting obligation
- DFARS 252.204-7012(c)(2) — 72-hour cyber-incident reporting cadence to the DoD via the DIBNet portal at https://dibnet.dod.mil following discovery (the stricter 72-hour cadence shortens typical state AG notification)
- DFARS 252.204-7012(d) — preservation of covered defense information for forensic purposes following discovery (90 days minimum)
- DFARS 252.204-7012(e) — written cyber-incident report with required fields: cyber-incident timeline, affected systems, type of CUI/CDI compromised, mitigation steps, root-cause analysis
- DFARS 252.204-7012(f) — cooperation with DoD-led damage assessment activities; provide access to contractor systems + personnel for DIB damage assessment
- NIST SP 800-171 implementation — DFARS 252.204-7012 incorporates NIST SP 800-171 as the safeguarding standard, which became the CMMC L2 sampling unit
- False Claims Act exposure — material misrepresentation in self-attestation to NIST SP 800-171 compliance before the 2026 CMMC deadline triggers FCA liability under 31 U.S.C. §§ 3729-3733
- Cloud computing requirements — if CUI is processed or stored in cloud, the cloud service provider must meet FedRAMP Moderate baseline or equivalent (DFARS 252.204-7012(b)(2)(ii)(D))
- Subcontractor flow-down — every subcontract involving CDI/CUI handling must include the same DFARS clause language verbatim
- Reporting timeline: "rapidly report" means within 72 hours of discovery; written cyber-incident report due within 30 days unless extended
Penalty: Loss of DoD contract eligibility on cyber-incident reporting failure; False Claims Act exposure on material misrepresentation in pre-2026 self-attestation to NIST SP 800-171 compliance; downstream contract exclusions; potential criminal exposure under 18 U.S.C. § 1001 for false statements in self-assessment to the federal government; cyber-insurance exclusion for missing 72-hour DFARS cadence runbook.
- AC (Access Control) — 22 controls on CUI access enforcement, account management, wireless access restrictions, mobile code + sandboxing
- AU (Audit and Accountability) — 9 controls on auditable events, content of audit records, audit review/analysis/reporting, audit reduction, time synchronization
- AT (Awareness and Training) — 3 controls on security awareness training, role-based security training, annual CUI literacy training
- CM (Configuration Management) — 9 controls on baseline configurations, configuration change control, monitoring configuration changes, least functionality
- IA (Identification & Authentication) — 11 controls on user identification, device identification, MFA enforcement on privileged accounts + network access to CUI systems
- IR (Incident Response) — 3 controls on incident response plan, incident reporting + 72-hour DFARS cadence, incident response testing
- MA (Maintenance) — 6 controls on controlled maintenance, maintenance tools, nonlocal maintenance + MFA, maintenance personnel
- MP (Media Protection) — 9 controls on media access restrictions, media marking, media storage, media transport, media sanitization per NIST SP 800-88
- PS (Personnel Security) — 8 controls on personnel screening, personnel termination, personnel transfer, access agreements
- PE (Physical and Environmental) — 6 controls on physical access authorizations, monitoring physical access, visitor control, physical access logs
- SC (System and Communications Protection) — 16 controls on boundary protection, security engineering, mobile code, CUI system segregation, transmission confidentiality/integrity
- SI (System and Information Integrity) — 7 controls on flaw remediation + 30-day critical / 60-day high cadence, malicious code protection, monitoring system input/output, security alerts
- RA + SA control family at r3 alignment — risk assessment + security assessment family overlap with NIST SP 800-171 r3 — 6 additional controls
- FIPS-validated cryptography — when CUI traverses FedRAMP-authorized cloud or federal systems; SC family SC-13 references FIPS 140-2/3 validated modules
- MFA on every CUI-touching account — IA-2(1) / IA-2(2) requires MFA on local + network access to CUI systems
- 90+ day log retention + monthly vulnerability scans with remediation within 30 days critical / 60 days high — the SI + AU family input
Penalty: C3PAO L2 assessment failure with loss of DoD contract eligibility; DFARS False Claims Act exposure on material misrepresentation in self-attestation; cyber-insurance loading for missing MFA + missing log retention + missing vulnerability remediation cadence; documented as a SIP (Special Item) at the assessment to flag critical practice gaps.
- Supplier flow-down: every Tier 1–3 subcontractor handling CUI must operate at CMMC Level 2 — the prime cannot contractually waive it, and the prime bears FCA + flow-down exclusion consequences
- Subcontractor tiering — Tier 1 (system-integrator / OEM support with persistent CUI access) + Tier 2 (occasional CUI handlers) + Tier 3 (intermittent CUI access) with addenda matching tier risk
- Jump-server CUI access: jump-server with hardware-token MFA + session recording + time-bound credentials + no persistent VPN for every Tier 1–3 vendor with CUI access
- 72-hour breach-notification SLA: subcontractor cyber-incident must trigger DFARS DIBNet cadence within 72 hours of discovery — and tie to the prime's DFARS cyber-incident reporting obligation
- Cyber-insurance MFA + segmentation + IRP gates: insurance carriers require MFA on every CUI-touching account, CUI-system network segmentation evidence, OT-aware IRP runbook (for DIB manufacturers), and immutable + offline-tested backups as condition precedent for binding or renewal
- CUI-system network segmentation evidence: documented CUI-system vs corporate-IT segmentation with named conduits, controlled east-west traffic, and zone/conduit diagrams
- 50-state breach notification: state AG cadence (typically 30–60 days for most states) in parallel with DFARS DIBNet 72-hour cadence where the breach involves state-resident personal information
- CUI spillage immediate containment runbook: NARA CUI spillage procedure + DFARS cyber-incident cadence trigger + recursive CUI destruction across affected systems + NARA follow-up notification
- Cyber-insurance exclusions for missing MFA + missing CUI-system segmentation + missing immutable backups + missing DFARS 72-hour runbook — the four most common coverage exclusions for DIB suppliers
- C3PAO L2 attestation evidence lowers cyber-insurance pricing; missing CMMC L2 attestation evidence raises carrier loading
Penalty: Coverage exclusion for unsegmentated CUI systems; cyber-insurance loading for missing MFA + missing jump-server vendor remote access + missing OT-aware IRP + missing immutable backups; loss of DoD contract eligibility under DFARS 252.204-7012 false attestation; False Claims Act exposure on material misrepresentation in self-attestation; downstream subcontractor survival threatened when a prime is removed.
CMMC + NIST SP 800-171 + DFARS + CUI Crosswalk for DoD Contractors
For a defense contractor pursuing CMMC 2.0 alongside DFARS 252.204-7012 + 32 CFR Part 2002 CUI operating discipline + cyber-insurance readiness, the right architectural model is to treat CMMC L2 110 practices on NIST SP 800-171 + DFARS 252.204-7012 72-hour cadence + CUI marking/destruction per 32 CFR Part 2002 as the audit-ready evidence wrappers, and supplier flow-down + cyber-insurance MFA/segmentation/IRP/immutable backups as the contractual / readiness wrappers layered on top of the same CUI-aware controls. Operationally: CMMC AC (Access Control) ↔ NIST SP 800-171 AC family tests the same CUI-system vs corporate-IT segmentation + need-to-know reasoning a defense contractor implements for every CUI-touching account; CMMC IA ↔ NIST SP 800-171 IA family tests the FIPS-validated MFA on every CUI-touching account; CMMC IR ↔ NIST SP 800-171 IR family tests the DFARS 252.204-7012 72-hour cyber-incident cadence runbook with DIBNet portal access + CUI preservation + written cyber-incident report + damage-assessment cooperation; CMMC MP ↔ NIST SP 800-171 MP family tests the CUI destruction per 32 CFR Part 2002 + NIST SP 800-88 sanitization; CMMC SC ↔ NIST SP 800-171 SC family tests CUI system segregation + FIPS-validated crypto + boundary protection; CMMC SI ↔ NIST SP 800-171 SI family tests 30-day critical / 60-day high vulnerability remediation cadence; supplier flow-down tests every Tier 1–3 subcontractor CMMC L2 attestation evidence + DFARS clause language the prime cannot contractually waive. The seven highest-leverage crosswalk pairs are: CMMC L2 AC/IA ↔ CUI access governance + FIPS-validated MFA on every CUI-touching account, CMMC L2 IR ↔ DFARS 252.204-7012 72-hour cyber-incident cadence + DIBNet portal runbook, CMMC L2 SC ↔ CUI-system segmentation + FIPS-validated crypto + boundary protection, CMMC L2 MP ↔ CUI destruction per 32 CFR Part 2002 + NIST SP 800-88 sanitization, 32 CFR Part 2002 CUI spillage ↔ DFARS 72-hour cadence trigger + NARA CUI Registry notification, supplier flow-down ↔ Tier 1–3 CMMC L2 attestation + DFARS clause flow-down + 72-hour SLA, cyber-insurance gates ↔ MFA on CUI-touching accounts + CUI-system segmentation + DFARS cadence runbook + immutable backups.
CMMC + NIST SP 800-171 + DFARS + CUI Crosswalk for DoD Contractors
| CMMC practice | NIST SP 800-171 control | Implementation / evidence |
| AC.L2-3.1.1–3.1.22 | 3.1 Access Control | CUI system boundary, least-privilege roles, approved access list, and quarterly access reviews. |
| AT.L2-3.2.1–3.2.3 | 3.2 Awareness and Training | Annual CUI/security awareness records plus role-based training completion for privileged users. |
| AU.L2-3.3.1–3.3.9 | 3.3 Audit and Accountability | Centralized audit logs, synchronized time, defined review cadence, and retained review tickets. |
| CM.L2-3.4.1–3.4.9 | 3.4 Configuration Management | Approved secure baselines, asset inventory, change tickets, and configuration monitoring results. |
| IA.L2-3.5.1–3.5.11 | 3.5 Identification and Authentication | Unique IDs, phishing-resistant or FIPS-validated MFA, service-account ownership, and access logs. |
| IR.L2-3.6.1–3.6.3 | 3.6 Incident Response | CUI-aware IRP, tabletop results, DIBNet contact/runbook, and documented 72-hour escalation procedure. |
| MA.L2-3.7.1–3.7.6 | 3.7 Maintenance | Approved maintenance requests, technician authorization, MFA-protected remote sessions, and session records. |
| MP.L2-3.8.1–3.8.9 | 3.8 Media Protection | CUI media register, marking and chain-of-custody records, transport approvals, and sanitization certificates. |
| PS.L2-3.9.1–3.9.2 | 3.9 Personnel Security | Screening records, signed access agreements, and termination/transfer checklists revoking CUI access. |
| PE.L2-3.10.1–3.10.6 | 3.10 Physical Protection | Badge authorization list, visitor logs, facility monitoring, and physical access review records. |
| RA.L2-3.11.1–3.11.3 | 3.11 Risk Assessment | CUI risk assessment, vulnerability scan reports, threat tracking, and documented remediation priorities. |
| CA.L2-3.12.1–3.12.4 | 3.12 Security Assessment | System security plan, POA&M, assessment results, and management review of corrective actions. |
| SC.L2-3.13.1–3.13.16 | 3.13 System and Communications Protection | CUI/IT segmentation diagram, boundary rules, encrypted transmissions, and firewall review evidence. |
| SI.L2-3.14.1–3.14.7 | 3.14 System and Information Integrity | Vulnerability remediation tickets, malware protection alerts, integrity monitoring, and scan cadence reports. |
- CMMC L2 AC + IA families ↔ CUI access governance + need-to-know reasoning + FIPS-validated MFA on every CUI-touching account — the AC/lA family sampling unit a C3PAO L2 assessor will sample
- CMMC L2 IR family ↔ DFARS 252.204-7012 72-hour cyber-incident cadence + DIBNet portal runbook + CUI preservation + written cyber-incident report + damage-assessment cooperation
- CMMC L2 SC family ↔ CUI-system segmentation + FIPS-validated crypto when CUI traverses FedRAMP-authorized cloud + boundary protection + controlled east-west traffic
- CMMC L2 MP family ↔ CUI destruction per 32 CFR Part 2002 + NIST SP 800-88 sanitization + CUI media marking + CUI media transport safeguards
- 32 CFR Part 2002 CUI spillage ↔ DFARS 72-hour cadence trigger + NARA CUI Registry notification + recursive CUI destruction across affected systems
- Supplier flow-down ↔ Tier 1–3 CMMC L2 attestation + DFARS 252.204-7012 clause flow-down + 72-hour breach-notification SLA + jump-server MFA + session recording + time-bound credentials
- Cyber-insurance gates ↔ MFA on CUI-touching accounts + CUI-system segmentation + DFARS 72-hour cadence runbook + immutable CUI media backups with NIST SP 800-88 sanitization at end-of-life
Defense-vs-Manufacturing Side-by-Side Compliance Posture Row
Defense contracting and manufacturing both handle CUI when overlapping on the defense industrial base, both increasingly field SOC 2 enterprise procurement demands where commercial buyers reach back into the supply chain, and both operate inside a layered compliance regime with a customer-driven input — but the regulatory regime, primary-data class, threat profile, and enforcement patterns diverge in ways that shape a very different control program. Both are operationally CUI-aware vs. OT-aware equivalents: where the manufacturer controls analytically protect OT systems + CUI + IP and respond to ransomware crossing IT/OT + supply-chain OT compromise, the defense contractor controls analytically protect CUI systems + CDI + national-security export-controlled technical data and respond to nation-state APT targeting CUI + CUI exfiltration to foreign intelligence services + ransomware on CUI systems. Use the comparison below to understand where the manufacturer's instinct for OT-aware controls breaks down for a defense contractor — and where the controls, despite different vocabulary, are operationally just as audit-ready as the OT-aware playbook's.
- Primary regime — Defense: CMMC 2.0 L1/L2/L3 + 32 CFR Part 2002 CUI + DFARS 252.204-7012 72-hour cyber-incident cadence + NIST SP 800-171 110 CUI controls + supplier flow-down + cyber-insurance + state breach notification ↔ Manufacturing: NIST CSF 2.0 OT-aware + SOC 2 CC6/CC7/CC9.2 + CMMC 2.0 (for DoD-touching manufacturers) + IEC 62443 customer-driven OT + cyber-insurance + 50-state breach
- Breach-notification cadence — Defense: DFARS 252.204-7012 72-hour cyber-incident cadence to DoD via DIBNet portal + state AG for PII breach + 32 CFR Part 2002 NARA CUI spillage notification ↔ Manufacturing: state AG (typically 30–60 days) + DFARS cyber-incident 72-hour for DoD-touching manufacturers
- Primary-data class — Defense: CUI + CDI + ITAR/EAR export-controlled technical data + National Security Information (NSI) + Critical Infrastructure Information ↔ Manufacturing: trade-secret process IP + CUI + CAD/ladder logic + OT process IP
- Carve-out — Defense: CUI marking per 32 CFR Part 2002 + NARA CUI Registry drives every disclosure decision + ITAR/EAR license controls on export-controlled technical data ↔ Manufacturing: trade-secret + patent-pending protection (with CMMC CUI as the regulated subset)
- SOC 2 driver — Defense: DoD prime contract eligibility under 32 CFR Part 170 + C3PAO L2 assessment cadence + FedRAMP-authorized cloud for federal system CUI ↔ Manufacturing: enterprise OEM / automotive / energy buyers + defense industrial base prime contract eligibility
- Threat profile — Defense: nation-state APT targeting CUI + CUI exfiltration to foreign intelligence services + ransomware on CUI systems + insider threat from CUI-handling staff + IT/OT CUI-system compromise on DIB manufacturers ↔ Manufacturing: ransomware crossing IT/OT boundary + supply-chain OT compromise + nation-state IP theft + OT-aware supply chain attack
- Regulator enforcement — Defense: C3PAO L2 assessment failure + DoD contract loss of eligibility + DFARS False Claims Act exposure on material misrepresentation + NARA CUI Registry follow-up + ITAR/EAR violations on export-controlled disclosure ↔ Manufacturing: C3PAO L2 failure + DoD contract loss of eligibility + IEC 62443 contractual breach + cyber-insurance exclusion
- Cyber-insurance expectation overlap — Defense: MFA on every CUI-touching account + CUI-system segmentation + DFARS 72-hour cadence runbook + immutable CUI media backups ↔ Manufacturing: OT-vendor addenda inventory + jump-server MFA + IT/OT segmentation evidence + immutable SCADA backups — both verticals centered on the same contractual mechanics (addenda + breach-notification SLA + MFA + immutable backups) despite different operational vocabulary
Frequently Asked Questions
Q: What cybersecurity standards apply to a small or mid-size DoD contractor handling CUI?
Five overlapping obligations apply. (1) CMMC 2.0 (Level 1 — 17 practices for FCI + Level 2 — 110 practices on NIST SP 800-171 for CUI under 32 CFR Part 170 + Level 3 — 134 practices on NIST SP 800-172 for highest-priority) is the contractual cybersecurity framework the DoD applies across the DIB. (2) CUI under 32 CFR Part 2002 + the NARA CUI Registry applies to every CUI-handling contractor with marking, destruction, spillage, and awareness-training operating discipline. (3) DFARS 252.204-7012 applies to every CDI/CUI-handling contractor with a 72-hour cyber-incident reporting cadence to DoD via the DIBNet portal + CUI preservation + written cyber-incident report + DFARS FCA exposure on material misrepresentation. (4) NIST SP 800-171 (110 controls for CMMC L2 — full 14-family coverage) is the CUI control set the C3PAO L2 assessment samples against. (5) Supplier flow-down under DFARS 252.204-7012 + cyber-insurance readiness + state breach-notification laws round out the layered regime. The right architectural model is to treat CMMC L2 110 practices + NIST SP 800-171 control families + DFARS 72-hour cadence + CUI marking/destruction as the audit-ready wrappers around a CUI-aware operating program, with Tier 1–3 supplier flow-down evidence and cyber-insurance MFA/segmentation/IRP/immutable backups layering on top.
Q: What does CMMC Level 2 require and when does the C3PAO assessment hit (October 2026 deadline)?
CMMC Level 2 covers 110 practices on NIST SP 800-171 across 14 control families (AC, AU, AT, CM, IA, IR, MA, MP, PS, PE, SC, SI + RA/SA family overlap at r3 alignment). CMMC 2.0 has three levels: Level 1 (17 practices for FCI, annual self-assessment and affirmation); Level 2 (110 practices for CUI, triennial C3PAO third-party assessment under 32 CFR Part 170 — required for CUI exposure by October 2026); Level 3 (134 practices on NIST SP 800-172 for highest-priority programs, DoD-led DIBCAC assessment — note MSP/MSSP validation only applies at Level 3). The October 2026 deadline hits Level 2 — defense suppliers handling CUI must be C3PAO-assessed by that point or risk loss of contract eligibility. For a DIB contractor, the C3PAO will sample the same controls a NIST SP 800-171 auditor samples: CUI access (AC, IA), CUI-aware IRP + DFARS 72-hour cadence (IR), OT-aware change windows where the CUI system controls OT (CM), CUI-system segmentation (SC), and CUI marking + destruction per 32 CFR Part 2002 (MP). The pre-2026 contracting path requires self-attestation + DD Form 254 / DFARS offer flowdown.
Q: What is CUI and how do 32 CFR Part 2002 + the NARA CUI Registry control marking, destruction, and spillage?
CUI (Controlled Unclassified Information) is government-created or government-possessed information that requires safeguarding or dissemination controls under federal law, regulation, or government-wide policy. 32 CFR Part 2002 is the implementing regulation; the NARA CUI Registry at https://www.archives.gov/cui is the authoritative list of CUI categories and applicable controls. Operationally: (1) MARKING — every CUI document, email, and file bears a CUI//SP-XXXX banner with a designated CUI category (e.g. CUI//SP-PRIVCY for privacy, CUI//SP-PROP for proprietary) plus applicable dissemination controls (e.g. NOFORN, ORCON). (2) DESTRUCTION — CUI must be destroyed using methods appropriate to the CUI category — burning, cross-cut shredding, degaussing, or NIST SP 800-88 sanitization; no general recycling of CUI-bearing media. (3) SPILLAGE — the moment a non-authorized person accesses CUI, the contractor triggers: immediate containment, NARA CUI spillage notification, DFARS 252.204-7012 72-hour cyber-incident reporting cadence to DoD, recursive CUI destruction across affected systems, and NARA follow-up. (4) AWARENESS TRAINING — every employee handling CUI must complete annual awareness training with documented training records. Covered Defense Information (CDI) is the subset of CUI protected specifically under DFARS and ITAR/EAR with additional handling requirements.
Q: What does NIST SP 800-171 map to under CMMC — the 110-practice 14-family coverage?
NIST SP 800-171 provides the 110-practice CUI control family that CMMC L2 is sampled against during the C3PAO triennial assessment under 32 CFR Part 170. The 14 control families (plus the RA/SA family overlap at r3 alignment) cover: AC (Access Control — 22 controls), AU (Audit and Accountability — 9 controls + 90-day log retention minimum), AT (Awareness and Training — 3 controls including annual CUI awareness training), CM (Configuration Management — 9 controls), IA (Identification & Authentication — 11 controls including MFA enforcement per IA-2(1)/IA-2(2)), IR (Incident Response — 3 controls including the 72-hour DFARS cadence), MA (Maintenance — 6 controls), MP (Media Protection — 9 controls including NIST SP 800-88 sanitization per CUI category), PS (Personnel Security — 8 controls), PE (Physical and Environmental — 6 controls), SC (System and Communications Protection — 16 controls including boundary protection, CUI system segregation, FIPS-validated crypto), SI (System and Information Integrity — 7 controls including 30-day critical / 60-day high vulnerability remediation cadence). NIST SP 800-171 r3 added overlay families (RA + SA) for risk assessment + security assessment to mirror NIST SP 800-53. SOC 2 CC6 ↔ NIST SP 800-171 AC + IA; SOC 2 CC7.4 ↔ NIST SP 800-171 IR; SOC 2 CC9.2 ↔ NIST SP 800-171 AC/IA/IR vendor-risk input.
Q: How does the DFARS 252.204-7012 72-hour cyber-incident reporting cadence work for DoD primes and subcontractors?
DFARS 252.204-7012(c)(2) requires the contractor to "rapidly report" cyber-incidents to the DoD — operationally interpreted as within 72 hours of discovery — via the DIBNet portal at https://dibnet.dod.mil. The triggering event is any cyber-incident affecting a contractor information system that processes, stores, or transmits CDI/CUI. The reporting flow has four components: (1) DFARS 252.204-7012(c)(2) — initial 72-hour cyber-incident notification via DIBNet; (2) DFARS 252.204-7012(d) — preservation of CDI for forensic purposes for at least 90 days following discovery; (3) DFARS 252.204-7012(e) — written cyber-incident report with required fields (timeline, affected systems, type of CDI/CUI compromised, mitigation steps, root-cause analysis) due within 30 days unless extended; (4) DFARS 252.204-7012(f) — cooperation with DoD-led damage assessment activities. For Tier 1–3 subcontractors, the prime's DFARS clause includes flow-down language that delegates the 72-hour cadence to the subcontractor when its information systems are the affected systems, with the prime coordinating the upward reporting to DIBNet. False Claims Act exposure under 31 U.S.C. §§ 3729-3733 applies to material misrepresentation in self-attestation to NIST SP 800-171 compliance.
Q: How do I tier Tier 1–3 subcontractors under supplier flow-down for CMMC + DFARS?
Supplier flow-down operates under DFARS 252.204-7012 + 32 CFR Part 170 (CMMC 2.0) — every subcontract involving CDI/CUI handling must include the DFARS clause verbatim. Three-tier model maps to CUI access depth: TIER 1 (highest) — system integrators + OEM support with persistent CUI access or engineering workstation access — required CMMC Level 2 attestation evidence + DFARS 252.204-7012 clause flow-down + 72-hour breach-notification SLA tied to DFARS cadence + jump-server access with hardware-token MFA + session recording + time-bound credentials + no persistent VPN. TIER 2 — occasional CUI handlers during warranty / engineering windows — required CMMC Level 2 attestation evidence + jump-server with MFA + session recording + time-bound credentials. TIER 3 — intermittent CUI-handling subcontractors — required CMMC Level 2 attestation evidence + jump-server with non-persistent credentials. The flow-down package must include: (1) CMMC Level 2 attestation evidence; (2) DFARS 252.204-7012 clause language to cascade the 72-hour cadence; (3) 72-hour breach-notification SLA tied to DFARS DIBNet timing; (4) MFA enforcement, session recording, time-bound credentials, no persistent VPN; (5) downstream flow-down clauses for Tier 2/3 subcontractors; (6) C3PAO L2 readiness evidence + a recent (within 12 months) C3PAO assessment report or self-attestation if pre-assessment.
Q: What cyber-insurance controls are required for DIB suppliers and which gaps cause exclusions?
Cyber-insurance carriers writing DIB suppliers increasingly require four control categories as condition precedent for binding or renewal: (1) MFA on every CUI-touching account (FIPS-validated hardware-token MFA on admin + privileged accounts, TOTP on standard CUI-handling accounts — no SMS); (2) CUI-system network segmentation with documented CUI-system vs corporate-IT segmentation evidence + named conduits + controlled east-west traffic + zone/conduit diagrams; (3) immutable backups with monthly tested-offline backups of every CUI-handling system + quarterly restore test signed off by operations + NIST SP 800-88 sanitization of decommissioned CUI media; (4) CUI-aware IRP runbook with named owners + DFARS 252.204-7012 72-hour cyber-incident reporting cadence documented + DIBNet portal access + CUI spillage immediate containment + recursive CUI destruction across affected systems. Beyond these four, carriers also evaluate jump-server CUI access controls (hardware-token MFA + session recording + time-bound credentials + no persistent VPN) and OT-aware continuous monitoring (Dragos / Claroty / Nozomi class) for DIB manufacturers on the IT/OT boundary. The most common coverage exclusions for DIB suppliers are missing MFA on CUI-touching accounts, missing CUI-system segmentation, missing DFARS 72-hour cadence runbook, and missing immutable backups of CUI media. CMMC L2 attestation evidence lowers insurance rather than raising it; pre-2026 False Claims Act exposure is excluded by most carriers.
Q: What is the minimum-viable program for a small DIB subcontractor before a CMMC Level 2 self-attestation?
For a small DIB subcontractor before CMMC Level 2 self-attestation, the minimum-viable program is the seven-control baseline every C3PAO L2 assessor will sample on. (1) CUI marking + destruction per 32 CFR Part 2002 — every CUI document, email, file marked CUI//SP-XXXX + designated category + cross-cut shredding + degaussing + NIST SP 800-88 sanitization at end-of-life. (2) CUI access scoping + boundary evidence — documented need-to-know reasoning + CUI-system vs corporate-IT segmentation + named conduits + zone/conduit diagrams. (3) DFARS 252.204-7012 72-hour cyber-incident cadence runbook — DIBNet portal access + preservation of CUI + written cyber-incident report + cooperation with DoD-led damage assessment. (4) Multi-factor authentication on every CUI-touching account — FIPS-validated hardware-token MFA on admin + privileged accounts, TOTP on standard CUI-handling accounts — no SMS. (5) Supplier flow-down contractual evidence — Tier 1–3 CMMC L2 attestation evidence + DFARS 252.204-7012 flow-down + 72-hour breach-notification SLA + jump-server + session recording. (6) Separation of CUI systems from corporate IT — dedicated accounts + dedicated devices + no shared administrative credentials. (7) Annual CUI awareness training records — every employee handling CUI with documented training completion. With these seven controls in place, your C3PAO L2 assessor will have the NIST SP 800-171 sampling unit evidence drawn together — and the DFARS 72-hour cadence + cyber-insurance gates are documented into the same CUI-aware program.