CCA CMMC Certification Levels & Requirements 2 — Questions and Answers
Question 1: What is the maximum number of days allowed to close a Plan of Action & Milestones (POA&M) item to achieve a final CMMC Level 2 certification after receiving conditional status?
- 90 days
- 120 days
- 180 days (Correct answer)
- 365 days
Correct answer: 180 days
Under CMMC 2.0, contractors with conditional CMMC status must close all POA&M items within 180 days to achieve final certification and maintain contract eligibility.
Question 2: Which NIST publication provides the enhanced security requirements that underpin CMMC Level 3 (Expert)?
- NIST SP 800-53 Rev 5
- NIST SP 800-171 Rev 2
- NIST SP 800-172 (Correct answer)
- NIST SP 800-161
Correct answer: NIST SP 800-172
CMMC Level 3 builds on Level 2 (NIST SP 800-171) by adding requirements from NIST SP 800-172, which addresses enhanced security measures to counter Advanced Persistent Threats (APTs).
Question 3: How many domains are included in the CMMC 2.0 model?
- 14 (Correct answer)
- 17
- 20
- 24
Correct answer: 14
CMMC 2.0 includes 14 domains (e.g., AC, AT, AU, CM, IA, IR, MA, MP, PE, PS, RA, CA, SC, SI) that map to the control families in NIST SP 800-171.
Question 4: What is the primary purpose of DFARS clause 252.204-7012 in relation to cybersecurity?
- To define CMMC certification levels and timelines
- To establish adequate security safeguards and mandate 72-hour cyber incident reporting for CUI (Correct answer)
- To require annual self-assessments for all DoD contractors
- To authorize C3PAOs to conduct CMMC assessments
Correct answer: To establish adequate security safeguards and mandate 72-hour cyber incident reporting for CUI
DFARS 252.204-7012 requires contractors to implement adequate security to protect covered defense information (CUI) and mandates reporting of cyber incidents to DoD within 72 hours.
Question 5: Which CMMC level specifically addresses protecting CUI against Advanced Persistent Threats (APTs)?
- Level 1
- Level 2
- Level 3 (Correct answer)
- Levels 2 and 3 equally
Correct answer: Level 3
CMMC Level 3 (Expert) is specifically designed to protect CUI against APTs by adding practices from NIST SP 800-172 on top of the Level 2 baseline.
Question 6: What annual action is required of CMMC Level 2 contractors regardless of whether they undergo self-assessment or third-party assessment?
- Submission of an updated System Security Plan (SSP) to the Cyber AB
- Senior official affirmation confirming continued compliance with cybersecurity requirements (Correct answer)
- Third-party auditor sign-off on the current security posture
- Contracting Officer's Representative (COR) verification of assessment results
Correct answer: Senior official affirmation confirming continued compliance with cybersecurity requirements
CMMC 2.0 requires an annual affirmation by a senior company official attesting to compliance with required cybersecurity practices, creating executive-level accountability between triennial assessments.
Question 7: Under CMMC 2.0, which Level 2 contractors may be permitted to use self-assessment rather than a third-party C3PAO assessment?
- Only contractors with fewer than 50 employees
- Contractors on non-prioritized acquisition programs that do not involve CUI (Correct answer)
- All Level 2 contractors if they have a clean prior assessment record
- Contractors that have maintained CMMC Level 1 certification for at least three years
Correct answer: Contractors on non-prioritized acquisition programs that do not involve CUI
Some CMMC Level 2 contracts involving lower-risk programs may allow self-assessment; however, prioritized acquisition programs handling sensitive CUI require a C3PAO third-party assessment.
What is the maximum number of days allowed to close a Plan of Action & Milestones (POA&M) item to achieve a final CMMC Level 2 certification after receiving conditional status?