CMMC Certification Levels & Requirements Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 CMMC Certification Levels & Requirements flashcards as text
How many cybersecurity practices are required for CMMC Level 1 (Foundational)?
Answer: 17
CMMC Level 1 requires 17 practices across 6 domains that align with FAR clause 52.204-21, covering basic cyber hygiene to protect Federal Contract Information (FCI).
Which NIST publication serves as the primary framework for CMMC Level 2 (Advanced) requirements?
Answer: NIST SP 800-171
CMMC Level 2 maps directly to the 110 security requirements in NIST SP 800-171, which are designed to protect Controlled Unclassified Information (CUI) in non-federal systems.
What type of assessment is required for a CMMC Level 1 certification?
Answer: Annual self-assessment affirmed by a senior official
CMMC Level 1 only requires an annual self-assessment affirmed by a senior company official, not a third-party or government-led assessment.
Which organization conducts government-led assessments for CMMC Level 3 (Expert)?
Answer: Defense Industrial Base Cybersecurity Assessment Center (DIBCAC)
CMMC Level 3 assessments are conducted by DIBCAC (Defense Industrial Base Cybersecurity Assessment Center), a government entity under the DoD, due to the sensitive nature of Level 3 programs.
What type of sensitive information does CMMC Level 2 specifically aim to protect?
Answer: Controlled Unclassified Information (CUI)
CMMC Level 2 is designed to protect Controlled Unclassified Information (CUI) in the defense supply chain, requiring the full 110 NIST SP 800-171 practices.
Under CMMC 2.0, how often must a CMMC Level 2 contractor that requires a third-party assessment renew their certification?
Answer: Every three years (triennially)
CMMC Level 2 third-party assessments must be renewed every three years (triennially), with annual senior official affirmations required in between assessment cycles.
Which DoD contract clause requires contractors to implement basic safeguarding requirements specifically for Federal Contract Information (FCI)?
Answer: FAR 52.204-21
FAR 52.204-21 'Basic Safeguarding of Covered Contractor Information Systems' establishes the basic requirements for protecting FCI, forming the foundation of CMMC Level 1.