โ† All CCA Flashcard Decks

CCA Contractor & Supplier Requirements Flashcards

6 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CCA Contractor & Supplier Requirements flashcards as text
  1. What is the consequence for a defense contractor that falsely self-attests to CMMC compliance?

    Answer: Potential liability under the False Claims Act, including significant financial penalties and exclusion from federal contracts

    False CMMC self-attestations can constitute False Claims Act violations, exposing contractors to treble damages, civil penalties, and potential debarment from government contracting.

  2. What is the role of a Registered Practitioner Organization (RPO) in the CMMC ecosystem?

    Answer: To provide CMMC consulting and implementation support to organizations seeking certification, but not to conduct assessments

    RPOs provide consulting, advisory, and implementation support to help OSCs prepare for CMMC assessments but are not authorized to conduct official certification assessments.

  3. Under CMMC, what specific obligation does a contractor have if it discovers that a subcontractor handling CUI has suffered a cyber incident?

    Answer: The prime contractor must ensure the subcontractor reports the incident to DoD and may need to report itself if its own covered systems are affected

    Prime contractors are responsible for ensuring subcontractors comply with CMMC requirements, including incident reporting, and the prime may have its own reporting obligations if the incident affects covered information on its systems.

  4. Which part of the Defense Federal Acquisition Regulation Supplement introduced the requirement for CMMC in new DoD contracts?

    Answer: DFARS 252.204-7021

    DFARS 252.204-7021 is the clause that imposes CMMC requirements as a condition of contract award for DoD contracts requiring CMMC compliance.

  5. What is the DoD's primary objective in implementing CMMC across the Defense Industrial Base (DIB)?

    Answer: To protect CUI and FCI from adversaries by verifying that DIB companies have implemented required cybersecurity practices

    CMMC's primary objective is to protect sensitive defense information by verifying that DIB companies have actually implemented required cybersecurity practices, moving beyond self-attestation to third-party verification.

  6. How does CMMC handle a scenario where an OSC uses an external IT managed service provider (MSP) that accesses CUI-handling systems?

    Answer: The MSP must be included in the assessment scope or have its own CMMC certification, depending on the nature of its access

    MSPs with privileged access to CUI-handling systems must be scoped into the assessment or demonstrate their own CMMC compliance, as their access creates direct risk to the CUI environment.