Cage Code: 10JQ0

Important Hyperlinks

DoD Cybersecurity & DFARS Resources

Essential resources for Defense Federal Acquisition Regulation Supplement (DFARS) compliance

DFARS Core RequirementsDFARS Core Requirements

DFARS Case 2019-D041

This interim rule integrates the DoD Assessment Methodology and the Cybersecurity Maturity Model Certification (CMMC) framework into the Defense Federal Acquisition Regulation Supplement (DFARS) to assess contractor implementation of cybersecurity requirements.

View Resource
DFARS Core RequirementsDFARS Core Requirements

DFARS Clause 252.204-7012

Mandates that contractors implement NIST SP 800-171 security requirements to safeguard Covered Defense Information (CDI) and report cyber incidents to the Department of Defense (DoD).

View Resource
DFARS Core RequirementsDFARS Core Requirements

DFARS Provision 252.204-7019

Requires contractors to have a current NIST SP 800-171 DoD Assessment on record in the Supplier Performance Risk System (SPRS) to be considered for contract awards.

View Resource
DFARS Core RequirementsDFARS Core Requirements

DFARS Clause 252.204-7020

Obligates contractors to provide the government access to their facilities, systems, and personnel for the purpose of conducting or renewing higher-level NIST SP 800-171 DoD Assessments.

View Resource
DFARS Core RequirementsDFARS Core Requirements

DFARS Clause 252.204-7021

Establishes the requirement for contractors to achieve a specified CMMC level at the time of contract award and maintain that level throughout the contracts duration.

View Resource
NIST GuidelinesNIST Guidelines

NIST SP 800-171 Rev. 2

Outlines the security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations.

View Resource
NIST GuidelinesNIST Guidelines

NIST SP 800-172

Provides a set of enhanced security requirements for protecting the confidentiality, integrity, and availability of CUI in nonfederal systems and organizations from advanced persistent threats.

View Resource
Programs & SystemsPrograms & Systems

DoD CUI Program

Details the Department of Defenses policies and procedures for managing Controlled Unclassified Information (CUI).

View Resource
Programs & SystemsPrograms & Systems

Supplier Performance Risk System (SPRS)

Serves as the authoritative source for supplier and product performance information assessments for the DoD acquisition community.

View Resource
Certification & ComplianceCertification & Compliance

CMMC Accreditation Body Website

Provides information on the Cybersecurity Maturity Model Certification Accreditation Body, including a marketplace of authorized CMMC Third Party Assessment Organizations (C3PAOs).

View Resource
DoD InstructionsDoD Instructions

DoD Instruction 5200.48

Establishes policy, assigns responsibilities, and prescribes procedures for CUI throughout the DoD in accordance with Executive Order 13556.

View Resource
DoD InstructionsDoD Instructions

DoD Instruction 5000.90

Prescribes procedures for the management of cybersecurity risk by program decision authorities and program managers in the DoD acquisition processes.

View Resource
Certification & ComplianceCertification & Compliance

Executive Order on Cybersecurity

Outlines measures to enhance the nations cybersecurity, including protecting federal networks, improving information-sharing on cyber issues, and strengthening the ability to respond to incidents.

View Resource

For the latest updates and detailed information, please refer to the official DoD Cybersecurity documentation.

Get In Touch

Have questions or need assistance? We’re here to help! Reach out to us
and our team will get back to you as soon as possible.

img
Office Location
12110 Sunset Hills Rd Suite 600 Reston, VA 20190
United States
Please select at least one compliance option.