CCA CCA Contractor & Supplier Requirements 1 — Questions and Answers
Question 1: Which DFARS clause requires defense contractors to implement NIST SP 800-171 and report cyber incidents?
- DFARS 252.204-7000
- DFARS 252.204-7012 (Correct answer)
- DFARS 252.239-7010
- DFARS 252.204-7020
Correct answer: DFARS 252.204-7012
DFARS 252.204-7012 requires defense contractors to implement NIST SP 800-171 security requirements and report cyber incidents involving covered contractor information systems within 72 hours.
Question 2: Under CMMC rules, when must a prime contractor flow down CMMC requirements to its subcontractors?
- Never — CMMC only applies to prime contractors
- When the subcontractor will process, store, or transmit CUI or FCI in support of the prime contract (Correct answer)
- Only when the subcontract value exceeds $1 million
- Only for subcontractors with prior CMMC assessments
Correct answer: When the subcontractor will process, store, or transmit CUI or FCI in support of the prime contract
Prime contractors must flow down CMMC requirements to subcontractors that will handle CUI or FCI in performance of the contract, ensuring the full supply chain protects sensitive information.
Question 3: What is the purpose of the CMMC Model and how does it relate to NIST SP 800-171?
- CMMC replaces NIST SP 800-171 entirely with new requirements
- CMMC Level 2 is based on the 110 security requirements in NIST SP 800-171, adding a third-party assessment mandate (Correct answer)
- CMMC only applies to large contractors while NIST SP 800-171 applies to small businesses
- CMMC is a voluntary framework while NIST SP 800-171 is mandatory
Correct answer: CMMC Level 2 is based on the 110 security requirements in NIST SP 800-171, adding a third-party assessment mandate
CMMC Level 2 maps directly to the 110 security requirements of NIST SP 800-171 but adds the requirement for third-party assessment by a C3PAO rather than allowing self-attestation.
Question 4: What obligation does a defense contractor have when it discovers a cyber incident affecting CUI under DFARS 252.204-7012?
- Report the incident to the DoD within 72 hours of discovery (Correct answer)
- Report the incident to CISA within 24 hours
- Document the incident internally with no reporting required
- Only report incidents that resulted in confirmed data exfiltration
Correct answer: Report the incident to the DoD within 72 hours of discovery
DFARS 252.204-7012 requires contractors to report cyber incidents involving covered contractor information systems to the DoD via the DIBNet portal within 72 hours of discovery.
Question 5: How does CMMC affect a defense contractor that only handles Federal Contract Information (FCI) but not CUI?
- FCI-only contractors are exempt from all CMMC requirements
- FCI-only contractors must meet CMMC Level 1, which requires implementation of basic safeguarding requirements from FAR 52.204-21 (Correct answer)
- FCI-only contractors must meet CMMC Level 2 with third-party assessment
- FCI is governed by a separate framework unrelated to CMMC
Correct answer: FCI-only contractors must meet CMMC Level 1, which requires implementation of basic safeguarding requirements from FAR 52.204-21
Contractors handling only FCI must meet CMMC Level 1, which consists of 17 basic safeguarding practices aligned to FAR 52.204-21 and allows annual self-attestation.
Question 6: Which entity is responsible for authorizing C3PAOs to conduct CMMC assessments?
- The Department of Defense directly
- The CMMC Accreditation Body (CMMC-AB), also known as The Cyber AB (Correct answer)
- NIST
- The Cybersecurity and Infrastructure Security Agency (CISA)
Correct answer: The CMMC Accreditation Body (CMMC-AB), also known as The Cyber AB
The Cyber AB (formerly CMMC-AB) is the accreditation body that authorizes C3PAOs to conduct official CMMC assessments and certifies CCA assessors.
Which DFARS clause requires defense contractors to implement NIST SP 800-171 and report cyber incidents?