DoD Cybersecurity & DFARS Resources
Essential resources for Defense Federal Acquisition Regulation Supplement (DFARS) compliance

DFARS Case 2019-D041
This interim rule integrates the DoD Assessment Methodology and the Cybersecurity Maturity Model Certification (CMMC) framework into the Defense Federal Acquisition Regulation Supplement (DFARS) to assess contractor implementation of cybersecurity requirements.
View Resource
DFARS Clause 252.204-7012
Mandates that contractors implement NIST SP 800-171 security requirements to safeguard Covered Defense Information (CDI) and report cyber incidents to the Department of Defense (DoD).
View Resource
DFARS Provision 252.204-7019
Requires contractors to have a current NIST SP 800-171 DoD Assessment on record in the Supplier Performance Risk System (SPRS) to be considered for contract awards.
View Resource
DFARS Clause 252.204-7020
Obligates contractors to provide the government access to their facilities, systems, and personnel for the purpose of conducting or renewing higher-level NIST SP 800-171 DoD Assessments.
View Resource
DFARS Clause 252.204-7021
Establishes the requirement for contractors to achieve a specified CMMC level at the time of contract award and maintain that level throughout the contracts duration.
View Resource
NIST SP 800-171 Rev. 2
Outlines the security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations.
View Resource
NIST SP 800-172
Provides a set of enhanced security requirements for protecting the confidentiality, integrity, and availability of CUI in nonfederal systems and organizations from advanced persistent threats.
View Resource
DoD CUI Program
Details the Department of Defenses policies and procedures for managing Controlled Unclassified Information (CUI).
View Resource
Supplier Performance Risk System (SPRS)
Serves as the authoritative source for supplier and product performance information assessments for the DoD acquisition community.
View Resource
CMMC Accreditation Body Website
Provides information on the Cybersecurity Maturity Model Certification Accreditation Body, including a marketplace of authorized CMMC Third Party Assessment Organizations (C3PAOs).
View Resource
DoD Instruction 5200.48
Establishes policy, assigns responsibilities, and prescribes procedures for CUI throughout the DoD in accordance with Executive Order 13556.
View Resource
DoD Instruction 5000.90
Prescribes procedures for the management of cybersecurity risk by program decision authorities and program managers in the DoD acquisition processes.
View Resource
Executive Order on Cybersecurity
Outlines measures to enhance the nations cybersecurity, including protecting federal networks, improving information-sharing on cyber issues, and strengthening the ability to respond to incidents.
View ResourceGet In Touch
Have questions or need assistance? We’re here to help! Reach out to us
and our team will get back to you as soon as possible.

Contact Us
+1 (703) 239-4854
Send Us a Mail
cmmcitar@platformoneinc.com
Office Location
12110 Sunset Hills Rd Suite 600 Reston, VA 20190United States