Resources

CMMC essentials for manufacturers

A practical starting point drawn from the CMMC Playbook and official government sources. This page is informational and does not replace guidance from a qualified assessor or consultant.

Start your CMMC readiness questionnaire

Tell us about your company, contracts, and current security posture. The Task Force will review your responses and follow up with tailored guidance.

Fill out questionnaire

A CMMC compliance program, step by step

  1. 1Identify your data — know where FCI and CUI live.
  2. 2Inventory your assets — people, technology, processes, and physical.
  3. 3Define your scope — what is in and out of the assessment boundary.
  4. 4Perform a gap assessment against the 320 assessment objectives in NIST 800-171A.
  5. 5Create your POA&M and remediation roadmap.
  6. 6Remediate and collect evidence — policies, configurations, logs, training records.
  7. 7Validate that each gap is fully closed with adequate evidence.
  8. 8Assess and certify with a C3PAO (or self-assess where permitted).
  9. 9Maintain the program with recurring reviews and annual affirmations.

Official links

Key terms

FCI — Federal Contract Information

Information not intended for public release that is provided by or generated for the Government under a contract. Almost everything created under a government contract, including drafts and emails, is FCI. Triggers CMMC Level 1.

CUI — Controlled Unclassified Information

Information requiring safeguarding under law, regulation, or government-wide policy. Common examples: engineering drawings, technical reports and manuals, specifications and standards, research and engineering data. Triggers CMMC Level 2.

CUI Specified

A subset of CUI with more restrictive handling requirements. ITAR-controlled information that also qualifies as CUI often falls here.

SPRS — Supplier Performance Risk System

Where NIST 800-171 self-assessment scores are submitted. Scores range from -203 to 110 based on implemented requirements.

SSP — System Security Plan

The document describing your system boundary, environment, and how each requirement is implemented. Required for assessment.

POA&M — Plan of Action and Milestones

Documents deficiencies, remediation actions, timelines, and responsible parties for closing gaps.

C3PAO

A CMMC Third Party Assessment Organization authorized to perform Level 2 certification assessments.

Identifying CUI

Documents must carry 'CUI' or 'CONTROLLED' in the header or banner. When direct marking isn't feasible, it may be indicated in contract language, related documents, or on the container.

Choosing help carefully

Registered Practitioners (RP/RPA) receive CMMC training but less than Certified CMMC Professionals (CCP) or Certified CMMC Assessors (CCA). Verify that any consultant has substantial defense industry experience and understands the certification assessment process. Certified individuals and organizations are listed in the Cyber AB Marketplace.