Full Report
Huntress and DEFCERT partnered to help with CMMC compliance. Use their Shared Responsibility Matrix and operation plans to streamline your Level 2 assessment
Analysis Summary
# Regulation/Compliance: CMMC Level 2 (Cybersecurity Maturity Model Certification)
## Overview
CMMC is a unified cybersecurity standard for Department of Defense (DoD) acquisitions, designed to protect Controlled Unclassified Information (CUI) within the Defense Industrial Base (DIB). Level 2 focuses on the protection of CUI and aligns directly with NIST SP 800-171 requirements.
## Key Details
- **Issuing Authority:** U.S. Department of Defense (DoD)
- **Effective Date:** Phased rollout beginning in 2025 (Title 32 CFR 170)
- **Jurisdiction:** U.S. Defense Industrial Base (DIB) and global subcontractors
- **Status:** Final Rule stage (referencing 32 CFR 170)
## Requirements
### Mandatory Requirements
1. **Adherence to NIST SP 800-171:** Compliance with all 110 security controls.
2. **Asset Categorization:** Documentation and categorization of all assets (CUI Assets, Security Protection Assets, Contractor Risk Managed Assets).
3. **Scoping Documentation:** Providing evidence that External Service Providers (ESPs) and internal systems are properly scoped and managed.
4. **Shared Responsibility:** Clearly defined ownership of security controls between the contractor (OSA) and their MSP/MSSP.
### Recommended Practices
1. **Sensitive Data Mode:** Implementation of "kill switches" or logical separation to prevent service providers from accessing CUI.
2. **Interconnection Security Agreements (ISA):** Documenting how third-party platforms connect to client systems.
3. **Baseline Configurations:** Maintaining editable security settings for all platforms to satisfy configuration management requirements.
## Affected Organizations
- **Industries:** Defense contractors, aerospace, manufacturing, and technology firms supporting the DoD.
- **Organization Size:** All sizes, from small machine shops to large prime contractors.
- **Geographic Scope:** Global (any entity handling U.S. DoD CUI).
## Compliance Timeline
- **Late 2024/Early 2025:** Finalization of 32 CFR 170 (CMMC Program Rule).
- **2025:** Gradual inclusion of CMMC requirements in new DoD solicitations.
- **Ongoing:** Existing NIST SP 800-171 obligations remain in effect under DFARS 252.204-7012.
## Implementation Guidance
### Assessment Phase
- **Gap Analysis:** Map current environment against NIST 800-171A objectives.
- **Asset Identification:** Identify where CUI resides and which third-party tools have access to it.
### Implementation Phase
- **Utilize Shared Responsibility Matrix (SRM):** Identify which controls are managed by the vendor (e.g., Huntress), the partner (MSP), and the client.
- **Establish Control Evidence:** Deploy tools like "Sensitive Data Mode" to ensure service providers do not inadvertently become "CUI Assets."
### Validation Phase
- **C3PAO Assessment:** Engage a Third-Party Assessment Organization to verify the implementation of all Level 2 controls.
- **Security Operations Approvals:** Document and sign off on all technical decisions and configuration baselines.
## Technical Requirements
- **Requirement 3.1.3 & 3.1.20:** Control of external system connections and interconnections.
- **Requirement 3.4.1 & 3.4.2:** Establishment and maintenance of baseline security configurations.
- **NIST SP 800-171A:** Objective-based evidence for every control.
## Penalties & Enforcement
- **Fines:** Potential for False Claims Act (FCA) litigation for misrepresenting compliance status.
- **Other Consequences:** Loss of current DoD contracts and eligibility for future awards.
- **Enforcement:** Audits by DIBCAC (DoD) and assessments by C3PAOs.
## Related Standards
- **NIST SP 800-171:** The foundational framework for CMMC Level 2.
- **32 CFR 170:** The federal regulation establishing the CMMC program.
- **FedRAMP:** While related to cloud security, the article notes that specific configurations (like Sensitive Data Mode) can provide alternatives for achieving compliance without full FedRAMP authorization for every tool.
## Resources
- **Official Documentation:** [https://www.acq.osd.mil/cmmc/](https://www.acq.osd.mil/cmmc/) (Defanged)
- **Guidance Documents:** Huntress Hub Shared Responsibility Matrix; DEFCERT Operations Plan.
- **Tools:** Huntress Managed Security Platform; NIST 800-171 Review Templates.
## Practical Recommendations
- **Document Everything:** Use Interconnection Security Agreements to formalize relationships with MSPs.
- **Categorize Assets Early:** Ensure your C3PAO agrees with your asset scoping before the final assessment begins to avoid costly delays.
- **Adopt a "Shared" Mindset:** Recognize that compliance is a three-way partnership between the Software Vendor, the MSP, and the Contractor.