|
@@ -1,40 +1,48 @@
|
|
|
1
1
|
<?xml version="1.0" encoding="UTF-8"?>
|
|
2
|
-
<!DOCTYPE dita
|
|
3
|
-
|
|
4
|
-
<
|
|
5
|
-
|
|
6
|
-
|
|
7
|
-
|
|
8
|
-
ditaarch:DITAArchVersion="1.2"
|
|
9
|
-
class="- topic/topic concept/concept ">
|
|
10
|
-
<title class="- topic/title ">
|
|
11
|
-
<ph props="autonumber" class="- topic/ph ">252.204-7021</ph> Cybersecurity Maturity Model Certification Requirements.</title>
|
|
12
|
-
<conbody class="- topic/body concept/conbody ">
|
|
13
|
-
<p class="- topic/p ">As prescribed in 204.7503(a)
|
|
2
|
+
<!DOCTYPE dita PUBLIC "-//OASIS//DTD DITA Composite//EN" "ditabase.dtd">
|
|
3
|
+
<dita xmlns:ditaarch="http://dita.oasis-open.org/architecture/2005/" ditaarch:DITAArchVersion="1.2" domains="(topic task) (topic concept) (topic concept glossentry) (topic concept glossgroup) (topic reference) (topic troubleshooting++task) (topic task) (topic abbrev-d) a(props deliveryTarget) (topic equation-d) (topic hazard-d) (topic hi-d) (topic indexing-d) (topic markup-d) (topic mathml-d) (topic pr-d) (topic relmgmt-d) (topic sw-d) (topic svg-d) (topic ui-d) (topic ut-d) (topic markup-d xml-d) (topic task strictTaskbody-c) ">
|
|
4
|
+
<concept id="DFARS_252.204-7021" ditaarch:DITAArchVersion="1.2" class="- topic/topic concept/concept ">
|
|
5
|
+
<title class="- topic/title "><ph props="autonumber" class="- topic/ph ">252.204-7021</ph> Cybersecurity Maturity Model Certification Requirements.</title>
|
|
6
|
+
<conbody class="- topic/body concept/conbody ">
|
|
7
|
+
<p class="- topic/p ">As prescribed in 204.7503(a)
|
|
14
8
|
and (b), insert the following clause:</p>
|
|
15
|
-
|
|
9
|
+
<p outputclass="Ctr_SmCaps" class="- topic/p ">CYBERSECURITY
|
|
16
10
|
MATURITY MODEL CERTIFICATION REQUIREMENTS (JAN 2023)</p>
|
|
17
|
-
|
|
11
|
+
<info li_elems="0"/>
|
|
12
|
+
<ol>
|
|
13
|
+
<li>
|
|
14
|
+
<p outputclass="List1" class="- topic/p "><ph props="autonumber" class="-topic/ph">(a)</ph><i class="+ topic/ph hi-d/i ">Scope.</i> The
|
|
18
15
|
Cybersecurity Maturity Model Certification (CMMC) CMMC is a framework
|
|
19
|
-
that measures a contractor
|
|
16
|
+
that measures a contractor's cybersecurity maturity to include the
|
|
20
17
|
implementation of cybersecurity practices and institutionalization
|
|
21
|
-
of processes (see <xref href="https://www.acq.osd.mil/cmmc/index.html"
|
|
22
|
-
|
|
23
|
-
|
|
24
|
-
|
|
25
|
-
<p outputclass="List1" class="- topic/p ">(b) <i class="+ topic/ph hi-d/i ">Requirements</i>.
|
|
18
|
+
of processes (see <xref href="https://www.acq.osd.mil/cmmc/index.html" format="html" scope="external" class="- topic/xref ">https://www.acq.osd.mil/cmmc/index.html</xref>).</p>
|
|
19
|
+
</li>
|
|
20
|
+
<li>
|
|
21
|
+
<p outputclass="List1" class="- topic/p "><ph props="autonumber" class="-topic/ph">(b)</ph><i class="+ topic/ph hi-d/i ">Requirements</i>.
|
|
26
22
|
The Contractor shall have a current (i.e. not older than 3 years)
|
|
27
23
|
CMMC certificate at the CMMC level required by this contract and
|
|
28
24
|
maintain the CMMC certificate at the required level for the duration
|
|
29
25
|
of the contract.</p>
|
|
30
|
-
|
|
26
|
+
</li>
|
|
27
|
+
<li>
|
|
28
|
+
<p outputclass="List1" class="- topic/p "><ph props="autonumber" class="-topic/ph">(c)</ph><i class="+ topic/ph hi-d/i ">Subcontracts</i>.
|
|
31
29
|
The Contractor shall—</p>
|
|
32
|
-
|
|
33
|
-
|
|
30
|
+
<info li_elems="0"/>
|
|
31
|
+
<ol>
|
|
32
|
+
<li>
|
|
33
|
+
<p outputclass="List2" class="- topic/p "><ph props="autonumber" class="-topic/ph">(1)</ph> Insert the substance of this clause, including this paragraph (c), in all subcontracts and other contractual instruments, including subcontracts for the acquisition of commercial products or commercial services, excluding commercially available off-the-shelf items; and</p>
|
|
34
|
+
</li>
|
|
35
|
+
<li>
|
|
36
|
+
<p outputclass="List2" class="- topic/p "><ph props="autonumber" class="-topic/ph">(2)</ph> Prior
|
|
34
37
|
to awarding to a subcontractor, ensure that the subcontractor has
|
|
35
38
|
a current (i.e., not older than 3 years) CMMC certificate at the
|
|
36
39
|
CMMC level that is appropriate for the information that is being
|
|
37
40
|
flowed down to the subcontractor.</p>
|
|
38
|
-
|
|
39
|
-
|
|
41
|
+
</li>
|
|
42
|
+
</ol>
|
|
43
|
+
</li>
|
|
44
|
+
</ol>
|
|
45
|
+
<p outputclass="Endofclause" class="- topic/p ">(End of clause)</p>
|
|
46
|
+
</conbody>
|
|
47
|
+
</concept>
|
|
40
48
|
</dita>
|