Skip to main content
Federal statute32 C.F.R. Part 170

Cybersecurity Maturity Model Certification Program

Cybersecurity Maturity Model Certification Program Short Answer 32 C.F.R.

Last reviewedJune 28, 2026Version v1

# Cybersecurity Maturity Model Certification Program

Short Answer

32 C.F.R. Part 170 is the DoD regulation establishing the CMMC Program. It matters because it defines the assessment levels, assessment types, affirmations, POA&M limits, status rules, and phased implementation structure that DFARS 252.204-7021 uses in DoD contracts.

Why this matters for government contractors

Contractors often talk about CMMC as if it were only a certification label. 32 C.F.R. Part 170 is more precise: it is the program rule that tells DoD and contractors how CMMC works. It is designed to verify implementation of safeguarding requirements for Federal Contract Information and Controlled Unclassified Information on defense contractor systems.

The rule matters for contractors because it ties CMMC levels to specific underlying security requirements. Level 1 uses the FAR 52.204-21 safeguarding requirements. Level 2 uses NIST SP 800-171 Rev. 2 under the current CMMC rule. Level 3 uses selected requirements from NIST SP 800-172 as incorporated by the rule. Contractors should not assume that publication of newer NIST revisions automatically changes their current CMMC assessment criteria unless the rule, clause, contract, or authorized transition guidance says so.

What the regulation does

Part 170 defines the CMMC Program, applicability, terminology, model structure, assessment requirements, affirmation requirements, scoring/status concepts, POA&M rules, and ecosystem roles. It establishes Level 1 self-assessment for basic FCI safeguarding, Level 2 self-assessment or C3PAO assessment depending on acquisition risk, and Level 3 government assessment for higher-risk CUI environments.

It also addresses phased implementation. During phase-in, DoD may include requirements at different levels and at different points in the procurement lifecycle. That phase structure makes it especially important for FMR to treat CMMC as conditional on DoD procurement context, data type, clause inclusion, and required status.

How it reaches contractors

Part 170 establishes the program, but contractors usually encounter CMMC through a solicitation, contract, task order, delivery order, or subcontract that references CMMC status. DFARS 252.204-7021 is the acquisition clause that operationalizes the program. Subcontractors may be covered when their work involves FCI or CUI on unclassified contractor information systems.

Procurement and cybersecurity significance

CMMC affects eligibility, proposal strategy, teaming, subcontractor selection, system segmentation, cloud decisions, and compliance evidence. Contractors must understand which systems are in scope and should resist the temptation to describe the entire company as “CMMC certified” when the status actually applies to a defined assessment scope.

Relationship to other GovConCyber requirements

Part 170 should cross-link to DFARS 252.204-7021, FAR 52.204-21, NIST SP 800-171, NIST SP 800-172, DFARS 252.204-7012, DFARS 252.204-7019/7020, SPRS, and the requirements-frameworks CMMC page. The statute/legal-authority page should focus on legal effect and contract triggers, while the framework page should explain control-level implementation.

What contractors should do

  • Identify whether the procurement is DoD and whether FCI or CUI will be processed, stored, or transmitted.
  • Read the solicitation for the required CMMC level and status.
  • Determine the assessment type and whether C3PAO or government assessment is required.
  • Confirm the applicable NIST revision and CMMC criteria for the contract.
  • Maintain annual affirmations and POA&M closure evidence.
  • Flow requirements to covered subcontractors and verify their status before award.

Current status

Current DoD regulation. The page should state that Part 170 is separate from the DFARS acquisition implementation and should avoid treating NIST SP 800-171 Rev. 3 or NIST SP 800-172 Rev. 3 as automatically substituted into current CMMC criteria unless formally incorporated.

Primary citations

  • 32 C.F.R. Part 170.
  • 32 C.F.R. §§ 170.3, 170.5, 170.14–170.24.
  • DFARS 252.204-7021.

---

Source type: federal_regulation. Implementation status: in_force.