The Cybersecurity Maturity Model Certification (CMMC) program helps the U.S. Department of Defense (DoD) verify that contractors protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
CMMC levels
CMMC has three levels. ControlMap supports CMMC workflows for Level 1 and Level 2. ControlMap does not support Level 3 workflows.
Level 1: Self-assessment against 15 safeguarding requirements for FCI. Level 1 results are submitted as a pass/fail affirmation.
Level 2: Self-assessment or assessment by a Certified Third-Party Assessment Organization (C3PAO), as applicable, against the 110 requirements in NIST SP 800-171 Revision 2. These requirements are assessed through their applicable objectives and sub-objectives.
Level 3: Assessment by the Defense Industrial Base Cybersecurity Assessment Center (DCMA DIBCAC). Level 3 builds on Level 2: an organization must first hold a Final Level 2 (C3PAO) status for the applicable assessment scope, then meet 24 selected enhanced requirements from NIST SP 800-172.
The current CMMC rule incorporates NIST SP 800-171 Revision 2. Although NIST has since published Revision 3, Revision 2 remains the version used by the current CMMC rule. For more information, see 32 CFR Part 170 and NIST SP 800-171 Revision 2.
ControlMap CMMC capabilities
ControlMap includes a CMMC framework aligned with applicable CMMC requirements and assessment objectives. It also includes NIST SP 800-171A assessment questions mapped to framework objectives.
ControlMap’s CMMC-related capabilities include:
SPRS workflows for applicable Level 1 and Level 2 self-assessments
System Security Plan (SSP) report builder
Assessment by requirement/objective, and sub-objectives
POA&M management where permitted by the applicable CMMC requirements
Shared Responsibility Matrix (SRM) identification and reporting
Evidence exporter with evidence grouped by objective
Optional hosting in an AWS GovCloud region
Links to evidence hosted outside ControlMap, which can help customers keep CUI evidence in their approved environment
These tools support assessment preparation and documentation. They do not independently establish CMMC compliance or replace a required C3PAO or DCMA's DIBCAC assessment.
Important: Do not upload CUI or other sensitive assessment data into ControlMap, regardless of the hosting region. Keep that material in your approved environment and link to it from ControlMap.
SPRS score calculator
The Supplier Performance Risk System (SPRS) score has different treatment at different CMMC levels.
Level 1: Results are submitted to SPRS as a pass/fail affirmation, not as a numeric score.
Level 2: The point-based methodology applies to the 110 NIST SP 800-171 Revision 2 requirements. The maximum score is 110, and unmet requirements result in deductions based on their weighting. The possible score range is -203 to 110.
Level 3: Level 3 uses a separate scoring methodology for its 24 enhanced requirements and is not supported in ControlMap.
In ControlMap, the SPRS score is calculated from assessment results using the applicable NIST weighting. See the CMMC scoring methodology for details.
POA&M management
A Plan of Action and Milestones (POA&M) documents permitted remediation activities, responsible parties, milestones, and target completion dates.
Important limitations apply:
Level 1 does not permit POA&Ms for unmet requirements. All applicable Level 1 requirements must be met for the assessment.
POA&Ms may be permitted for certain Level 2 and Level 3 requirements and assessment statuses, subject to the CMMC rule, contract requirements, and applicable completion deadlines.
Not every deficiency can be placed on a POA&M. Contractors must confirm whether a deficiency is eligible under the current CMMC requirements.
A POA&M is a temporary bridge, not an end state. Conditional CMMC status requires closing every eligible POA&M item through a closeout assessment within 180 days, or the conditional status expires.
A POA&M does not by itself demonstrate compliance or guarantee Final status.
ControlMap can help document eligible remediation items, but customers remain responsible for determining whether a POA&M is permitted and for meeting all applicable CMMC requirements. See the CMMC POA&M requirements for details.
System Security Plan report builder
An SSP describes the information system, its boundary, components, users, data flows, security responsibilities, and how applicable requirements are implemented.
For Level 2, the SSP should explain how the organization implements the NIST SP 800-171 Revision 2 requirements and should identify relevant system components, policies, procedures, and evidence. ControlMap’s SSP report builder helps organize this information and link relevant policies and other documentation maintained in ControlMap.
An SSP is not a substitute for implementing the requirements. Customers are responsible for ensuring that the SSP accurately reflects their environment and current implementation status.
Shared responsibility and cloud environments
Cloud services may be part of a CMMC assessment scope. Responsibility must be evaluated across the contractor, the cloud service provider, and any other service providers involved.
When a cloud service stores, processes, or transmits CUI, the applicable DFARS requirements require the provider to meet the FedRAMP Moderate security baseline or a documented DoD-recognized equivalent. Cloud services handling only FCI within a Level 1 scope are not subject to this CUI-cloud requirement, but responsibility still needs to be evaluated across the contractor, cloud provider, and other service providers.
Using a cloud service provider does not remove the contractor’s responsibility for:
Defining the assessment scope and system boundary
Identifying where FCI and CUI are stored, processed, or transmitted
Configuring and securely operating the service
Implementing applicable requirements
Maintaining required documentation and evidence
Confirming that the provider’s authorization, services, and contractual commitments are appropriate for the intended use
ControlMap’s SRM features can help identify and document shared responsibilities.
ControlMap may be hosted in supported AWS regions, including AWS GovCloud. A cloud region alone does not make a workload FedRAMP authorized, CMMC compliant, or suitable for handling CUI. For CUI, customers must confirm that the provider’s authorization, services, and contractual commitments meet the applicable FedRAMP Moderate requirement or documented equivalency requirement.
See the DFARS 252.204 clauses for the applicable contract and safeguarding requirements.
Evidence exporter
ControlMap’s evidence exporter helps organize evidence by CMMC objective for assessment preparation and review.
Evidence may include policies, procedures, screenshots, system records, reports, and links to documentation stored outside ControlMap. Linking to externally hosted evidence can help customers keep CUI and other sensitive material in an approved environment rather than storing it in ControlMap.
Customers remain responsible for confirming that evidence is complete, accurate, current, accessible to the assessor, and appropriate for the applicable CMMC assessment.
CMMC reports
ControlMap reporting may include:
SSP report
SPRS report for applicable Level 1 and Level 2 self-assessment workflows
POA&M report where permitted
Shared Responsibility Matrix report
Audit evidence export
Assessment report, which tracks ControlMap assessment questions and is not the primary report for a CMMC assessment
For CMMC assessment preparation, the SSP report is the recommended primary report. Report availability and output should be validated in the customer’s ControlMap environment before relying on a report for an assessment.
Non-normative SSP example
The following simplified example illustrates the type of information an SSP may contain. It is not a complete SSP, does not represent a customer environment, and does not establish compliance.
System overview
System name: Example Defense Contractor Information System
System purpose: Supports business operations and DoD contract activities.
System boundary: Includes identified endpoints, servers, network devices, applications, cloud services, facilities, users, and service providers that store, process, or transmit FCI or CUI.
Data types: FCI and, where applicable, CUI.
System owner: The person accountable for the system and its security documentation.
Assessment scope: The components and services included in the applicable CMMC assessment.
Example requirement documentation
CMMC / NIST SP 800-171 requirement |
Status |
Example implementation description |
Evidence |
|---|---|---|---|
AC.L2-3.1.1 — Limit system access to authorized users, processes, or devices |
Implemented |
Access is provisioned through documented approvals and reviewed periodically. |
Access review record |
IA.L2-3.5.3 — Use multifactor authentication |
Partially implemented |
MFA is enabled for defined users and services; remaining gaps are documented for review. |
MFA configuration report |
AU.L2-3.3.1 — Create and retain system audit logs and records |
Implemented |
Defined system components generate audit records that are centrally collected and retained according to policy. |
Logging configuration and retention record |
SC.L2-3.13.8 — Implement cryptographic mechanisms to protect CUI during transmission |
Implemented |
Approved cryptographic mechanisms protect CUI during transmission, such as through approved TLS configurations. |
Configuration standard and system evidence |
SC.L2-3.13.16 — Protect the confidentiality of CUI at rest |
Implemented |
Encryption at rest protects CUI on storage devices. |
Encryption configuration and key-management record |
The actual identifiers, implementation statements, scope, evidence, and assessment status must match the organization’s environment and the applicable CMMC requirements. Customers should use the current CMMC rule, NIST publications, and assessor guidance when preparing their SSP and assessment materials.