Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Cybersecurity Maturity Model Certification (CMMC) Program

FR Abstract
With this final rule, DoD establishes the Cybersecurity Maturity Model Certification (CMMC) Program in order to verify contractors have implemented required security measures necessary to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The mechanisms discussed in this rule will allow the Department to confirm a defense contractor or subcontractor has implemented the security requirements for a specified CMMC level and is maintaining that status (meaning level and assessment type) across the contract period of performance. This rule will be updated as needed, using the appropriate rulemaking process, to address evolving cybersecurity standards, requirements, threats, and other relevant changes.
Incorporation
FR Document Number
2024-22905
Federal Register Volume
89
Federal Register Year
2024-10-15
Federal Register Start Page
83092
Federal Register End Page
83237
CFR Citation
32 CFR 170
FR Citation
89 FR 83092
CFR title
32
CFR Part
170
Document Number
FIPS PUB 200
Document Edition
2006
Standard Title
Federal Information Processing Standard Publication 200: Minimum Security Requirements for Federal Information and Information Systems
Excerpts
methodology provided in the rule. Section 170.2 Incorporation by Reference Section 170.2 addresses the standards and guidelines that are incorporated by reference. The Director of the Federal Register under 5 U.S.C. 552(a) and 1 CFR part 51 approves any materials that are incorporated by reference. Materials that are incorporated by reference in this rule are reasonably available. Information on how to access the documents is detailed in § 170.2. Materials that are incorporated by reference in this rule are from the NIST (see § 170.2(a)), the Committee
Record Source
www.federalregister.gov