CCA CMMC Certification Levels & Requirements 1 — Questions and Answers
Question 1: How many cybersecurity practices are required for CMMC Level 1 (Foundational)?
- 17 (Correct answer)
- 55
- 110
- 130
Correct answer: 17
CMMC Level 1 requires 17 practices across 6 domains that align with FAR clause 52.204-21, covering basic cyber hygiene to protect Federal Contract Information (FCI).
Question 2: Which NIST publication serves as the primary framework for CMMC Level 2 (Advanced) requirements?
- NIST SP 800-53
- NIST SP 800-171 (Correct answer)
- NIST SP 800-172
- NIST SP 800-137
Correct answer: NIST SP 800-171
CMMC Level 2 maps directly to the 110 security requirements in NIST SP 800-171, which are designed to protect Controlled Unclassified Information (CUI) in non-federal systems.
Question 3: What type of assessment is required for a CMMC Level 1 certification?
- Government-led assessment by DIBCAC
- Third-party assessment by a C3PAO
- Annual self-assessment affirmed by a senior official (Correct answer)
- Biennial independent verification by a CCA
Correct answer: Annual self-assessment affirmed by a senior official
CMMC Level 1 only requires an annual self-assessment affirmed by a senior company official, not a third-party or government-led assessment.
Question 4: Which organization conducts government-led assessments for CMMC Level 3 (Expert)?
- NSA Information Assurance Directorate
- CMMC Accreditation Body (Cyber AB)
- Defense Contract Audit Agency (DCAA)
- Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) (Correct answer)
Correct answer: Defense Industrial Base Cybersecurity Assessment Center (DIBCAC)
CMMC Level 3 assessments are conducted by DIBCAC (Defense Industrial Base Cybersecurity Assessment Center), a government entity under the DoD, due to the sensitive nature of Level 3 programs.
Question 5: What type of sensitive information does CMMC Level 2 specifically aim to protect?
- Classified National Security Information (CNSI)
- Federal Contract Information (FCI) only
- Controlled Unclassified Information (CUI) (Correct answer)
- Sensitive Compartmented Information (SCI)
Correct answer: Controlled Unclassified Information (CUI)
CMMC Level 2 is designed to protect Controlled Unclassified Information (CUI) in the defense supply chain, requiring the full 110 NIST SP 800-171 practices.
Question 6: Under CMMC 2.0, how often must a CMMC Level 2 contractor that requires a third-party assessment renew their certification?
- Annually
- Every two years
- Every three years (triennially) (Correct answer)
- Every five years
Correct answer: Every three years (triennially)
CMMC Level 2 third-party assessments must be renewed every three years (triennially), with annual senior official affirmations required in between assessment cycles.
Question 7: Which DoD contract clause requires contractors to implement basic safeguarding requirements specifically for Federal Contract Information (FCI)?
- DFARS 252.204-7012
- FAR 52.204-21 (Correct answer)
- DFARS 252.239-7009
- FAR 52.239-1
Correct answer: FAR 52.204-21
FAR 52.204-21 'Basic Safeguarding of Covered Contractor Information Systems' establishes the basic requirements for protecting FCI, forming the foundation of CMMC Level 1.
How many cybersecurity practices are required for CMMC Level 1 (Foundational)?