According to the Cybersecurity Maturity Model Certification (CMMC), all contractors and subcontractors must be certified before they can bid and work for the US Department of Defense. The CMMC framework categorizes contractors into five maturity levels based on the complexity of their cybersecurity policies.
What Is CMMC Level 2?
All DoD contractors and subcontractors are required to be at least Level 1 certified. A Level 1 certification is the foundation upon which other levels are built. Level 2 acts as the bridge to Level 3. Most Level 1 contractors will jump straight to Level 3, but they can only do this by addressing the requirements for Level 2.
CMMC Level 2 is centered on intermediate cyber hygiene. This level includes security measures for protecting controlled unclassified information (CUI). Also, Level 2 certified contractors are required to document and perform critical cybersecurity functions to enhance their defenses against cyberthreats.
What Are the CMMC Level 2 Requirements?
Level 2 of the CMMC framework includes 55 new NIST SP 800-171 controls on top of the 17 implemented at Level 1. The level 2 controls are separated into these 15 different domains:
This domain is concerned with limiting system access and includes:
This domain covers the need for DoD contractors to log and monitor the system activity of their users. This includes:
This domain requires contractors to conduct cybersecurity awareness training for system administrators, managers, and users with access to organizational systems and CUI.
All DoD contractors must create configuration settings for their organization, which entails:
This domain is focused on granting access only to authorized users and involves:
This domain requires contractors to implement an effective incident response plan, which involves:
This domain outlines the processes involved in maintaining your organizational systems such as:
This domain aims to prevent security issues by:
All employees accessing systems containing CUI must be screened. These systems must also be protected from employees who are transferred or terminated.
This domain focuses on the security of your data and facility by limiting physical access to areas and systems containing CUI. This is done by using sensors, alarms, and video cameras, and by deploying security guards.
This domain deals with backing up your data regularly so you can recover it in the event of a cyberattack, system failure, or natural disaster. After backing up your data, test it to ensure applications, operating systems, and other files are intact.
This domain is concerned with managing security risks to your company's operations and assets. It entails scanning your applications and organizational systems for weaknesses and developing a remediation plan to fix them.
This domain requires DoD contractors to create and manage an effective system security plan by:
This domain defines the security requirements for system and communication protection, such as:
DoD contractors must constantly monitor their systems for signs of a potential attack. They can do this by:
Upon meeting all the CMMC Level 2 requirements, a certified third-party assessor organization (C3PAO) will conduct an audit to ensure your company is CMMC compliant.
To help you prepare for the audit, you need the help of a reliable managed IT services provider like Charles IT. We'll conduct a gap assessment to identify potential weaknesses in your infrastructure and provide you with efficient solutions to ensure you pass your CMMC audit. Start your gap assessment now.