CMMC, DFARS, CUI and DoD resource library.
Browse by topic, search the collection, and verify the current revision and contractual applicability with the issuing authority.
DoD CMMC Resources
Program documentation, model, scoping and assessment resources.
Program & rule · external resource ↗32 CFR Part 170
Current eCFR text establishing the CMMC Program.
Program & rule · external resource ↗Cyber AB
CMMC ecosystem roles, marketplace and credentialing information.
Acquisition.gov DFARS
Current Defense Federal Acquisition Regulation Supplement.
Contracts · external resource ↗DFARS 252.204-7008
Compliance with safeguarding covered defense information controls.
Contracts · external resource ↗DFARS 252.204-7012
Safeguarding covered defense information and cyber-incident reporting.
Contracts · external resource ↗DFARS 252.204-7019
Notice of NIST SP 800-171 DoD assessment requirements.
Contracts · external resource ↗DFARS 252.204-7020
NIST SP 800-171 DoD assessment requirements.
Contracts · external resource ↗DFARS 252.204-7021
Cybersecurity Maturity Model Certification requirement.
Contracts · external resource ↗FAR 52.204-21
Basic safeguarding of covered contractor information systems.
DoD CUI Program
Official DoD Controlled Unclassified Information program.
CUI · external resource ↗NARA CUI Registry
Government-wide CUI categories, authorities and handling guidance.
CUI · external resource ↗DoD Cyber Exchange CUI
DoD cybersecurity and CUI implementation resources.
NIST SP 800-171 Rev. 2
Earlier CUI protection requirements; confirm contractual applicability.
NIST publications · external resource ↗NIST SP 800-171 Rev. 3
Current NIST publication for protecting CUI in nonfederal systems.
NIST publications · external resource ↗NIST SP 800-171A Rev. 2
Assessment procedures aligned to SP 800-171 Rev. 2.
NIST publications · external resource ↗NIST SP 800-171A Rev. 3
Assessment procedures aligned to SP 800-171 Rev. 3.
NIST publications · external resource ↗NIST SP 800-172
Enhanced requirements for higher-value CUI environments.
NIST publications · external resource ↗NIST SP 800-30 Rev. 1
Guidance for conducting risk assessments.
NIST publications · external resource ↗NIST SP 800-53 Rev. 5
Security and privacy control catalog used across federal programs.
SPRS
Supplier Performance Risk System portal.
Tools & portals · external resource ↗CISA CSET
Downloadable Cyber Security Evaluation Tool for structured assessments.
Tools & portals · external resource ↗Project Spectrum
DoD-supported cybersecurity resources for eligible DIB organizations.
Tools & portals · external resource ↗DoD Cyber Exchange
STIGs and other DoD cybersecurity resources.
Tools & portals · external resource ↗DIB Cybersecurity Services
Voluntary DoD cyber services for eligible DIB companies.
Turn the requirement into a practical CaaS roadmap.
Share your framework, deadline, environment and business driver.