Cage Code: 10JQ0

Resources

CMMC-ITAR Compliance & Cybersecurity Resource Hub

A comprehensive resource center designed to support organizations navigating CMMC, ITAR, DFARS, and broader cybersecurity requirements. This hub provides direct access to essential compliance documentation, industry standards, regulatory updates, best practices, and implementation guides.
Whether beginning a compliance journey or maintaining ongoing certification, this hub brings together the resources needed to simplify and support every step of the process.

Essential Compliance Resources

Welcome to the centralized hub for CMMC-related documentation and cybersecurity compliance materials. This collection includes carefully curated tools, templates, and reference documents designed to support organizations in meeting CMMC, ITAR, and related regulatory requirements. All resources are organized to simplify access and support ongoing compliance efforts.

Regulatory Frameworks

32 CFR 117

National Industrial Security Program Operating Manual (NISPOM)

32 CFR 2002

Controlled Unclassified Information

44 USC Chapter 33

Official updates on 44 USC Chapter 33

44 USC Chapter 35

Official updates on 44 USC Chapter 35

48 CFR

Defense Industry Cyber Security and Risk Management

Atomic Energy Act of 1954

Official updates on 44 USC Chapter 35

Guidance and Models

Rule Making Process

Defense Industry Cyber Security and Risk Management

Australia Essential Eight Maturity Model

Comprehensive security controls for CUI

CERT Resilience Management Model 1.2

Detailed breakdown of assessment procedures

CIS Controls Version 7.1

Detailed breakdown of assessment procedures

Cloud and Platform Resources

AWS CMMC Customer Responsibility Matrix

U.S. State Department portal for export control

AWS Configuration Guide for All CMMC Levels

Compliance requirements for DoD contractors

AWS EastWest GovCloud Executive Briefing (Nov 2020)

Guidelines for exporting controlled technology

CMMC Models and Guides

CMMC 1.02 Model (Modified Excel)

Official guidance on GCC High compliance

CMMC 2.0 Model (Modified Excel)

Directory of authorized cloud providers

CMMC Model Version 2.0

Security standards for federal cloud environments

CMMC Assessment Process (CAP) v1.0: Pre-Decisional Draft

Official guidance on GCC High compliance

CMMC Self-Assessment Guide – Level 1

Directory of authorized cloud providers

CMMC Assessment Guide – Level 2

Security standards for federal cloud environments

CMMC Glossary and Acronyms

Official guidance on GCC High compliance

CMMC Self-Assessment Scope – Level 1

Directory of authorized cloud providers

CMMC Assessment Scope – Level 2

Security standards for federal cloud environments

National Security Systems Instructions

CNSSI 1253

Categorization and Control Selection for National Security Systems

CNSSI 4009

CNSS Glossary

Contractor Guidance

Contractor Purchasing

Contractor Purchasing System Review (CPSR) Guidebook (Appendix 24)

Contractual Remedies

Contractual Remedies for DFARS 252.204-7012 Compliance

Controlled Unclassified Information (CUI)

DARS 2018-0023-001: DoD Guidance for Reviewing SSPs and NIST SP 800-171 Requirements

DARS 2018-0023-001: DoD Guidance for Reviewing SSPs and NIST SP 800-171 Requirements

DARS 2018-0023-002 Attachment 1

DARS 2018-0023-002 Attachment 1

Defense Acquisition Regulations System (DARS) Documents

CUI FAQ

Categorization and Control Selection for National Security Systems

CUI SSP Template

CNSS Glossary

CMMC Program Updates

CMMC 2.0 Updates and Way Forward

National cybersecurity initiatives and alerts

CMMC Model Overview

Official database of CUI categories

Cybersecurity Maturity Model Certification Program

Risk management framework for cybersecurity

Defense Federal Acquisition Regulation Supplement (DFARS) Clauses

DFARS 252.204-7008

Compliance with Safeguarding Covered Defense Information Controls

DFARS 252.204-7009

Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information

DFARS 252.204-7012

Safeguarding Covered Defense Information and Cyber Incident Reporting

DFARS 252.204-7012 Suppliers

Flowdown to International Suppliers

DFARS 252.204-7019

Notice of NIST SP 800-171 DoD Assessment Requirements

DFARS 252.204-7020

NIST SP 800-171 DoD Assessment Requirements

DFARS 252.204-7021

Cybersecurity Maturity Model Certification Requirement

Additional Resources

DoD Cloud Computing Security Requirements Guide (SRG)

National cybersecurity initiatives and alerts

DoD CUI Marking Guide

Official database of CUI categories

DoD CUI (CDI) Registry

Risk management framework for cybersecurity

DoD FedRAMP Equivalency

National cybersecurity initiatives and alerts

DoD Instructions and Manuals

Official database of CUI categories

Executive Orders 13526 & 13556

Risk management framework for cybersecurity

False Claims Act

Official database of CUI categories

FAR 4.1901 Definitions

Risk management framework for cybersecurity

Have Questions?

Understanding compliance requirements can be challenging. Connect with our team for clear answers and expert assistance.

Contact Our Experts

Get In Touch

Have questions or need assistance? We’re here to help! Reach out to us
and our team will get back to you as soon as possible.

img
Office Location
12110 Sunset Hills Rd Suite 600 Reston, VA 20190
United States
Please select at least one compliance option.