Federal IT and systems integrators
How do federal IT firms and systems integrators handle CMMC and RMF together?
They run them as two programs with two scopes. CMMC and NIST SP 800-171 govern CUI on the company's own systems under DFARS 252.204-7012. RMF under NIST SP 800-37 and NIST SP 800-53 governs the federal systems the company builds or operates, and ends in an authorization decision by the agency.
CMMC Level 2, NIST SP 800-171 and RMF authorization leadership for federal IT firms and systems integrators running both programs at the same time.
Book a 30 minute callWhich regulations apply?
DFARS 252.204-7012
Requires adequate security for covered defense information by implementing NIST SP 800-171, reporting cyber incidents to DoD within 72 hours, meeting cloud security requirements equivalent to FedRAMP Moderate, and flowing the clause down to subcontractors.
DFARS 252.204-7019
Requires a current NIST SP 800-171 assessment score, no more than three years old, posted in the Supplier Performance Risk System.
DFARS 252.204-7020
Gives DoD access to assess your NIST SP 800-171 implementation and requires you to confirm your subcontractors' assessments before flowing work to them.
DFARS 252.204-7021
The contract clause that puts a CMMC level into a contract and requires the matching CMMC status and annual affirmation.
CMMC, 32 CFR part 170
The program rule that defines CMMC Levels 1, 2 and 3, how each is assessed, the scoping rules and the annual affirmation. Level 2 maps to the 110 requirements of NIST SP 800-171 Rev 2.
NIST SP 800-171 Rev 2
The 110 security requirements for protecting Controlled Unclassified Information in contractor systems, organized into 14 families and assessed with NIST SP 800-171A.
NIST SP 800-37 and NIST SP 800-53
The Risk Management Framework and the control catalog used to authorize federal information systems. Systems built or operated for an agency are authorized under this framework, with CNSS Instruction 1253 for national security systems.
FAR 52.204-21
Basic safeguarding of covered contractor information systems that hold Federal Contract Information. It lists fifteen basic safeguarding requirements and is the basis of CMMC Level 1.
Which clauses apply to you depends on your contracts. Read them, and take legal advice where the answer matters.
Where does the work usually get hard?
- The same engineers carry RMF packages for customer systems and the company's own CMMC evidence, and the two scopes blur.
- Contract deliverables, briefings and proposals often contain CUI, which puts email and document platforms at the center of the corporate scope.
- Insider threat and user activity monitoring requirements appear in contracts, and need governance and legal review as well as tooling.
- Growing firms answer prime and agency security questionnaires before they have a security leader to own the answers.
- Managed service providers and cloud services are Security Protection Assets whose responsibilities need to be written down.
Which engagements fit?
RMF, ATO and continuous authorization
RMF, ATO and continuous authorization leadership for federal programs and integrators, across NIST SP 800-53 and CNSS 1253.
CMMC Level 2 program leadership
Fractional CISO leadership for a CMMC Level 2 certification run, from the first assessment to the C3PAO visit.
Insider threat and enterprise audit
Insider threat, enterprise audit and user activity monitoring program design for federal programs and defense contractors.
vCISO and security program leadership
Virtual CISO and security program leadership for defense contractors and federal integrators, including supplier cyber readiness.
No consultant can promise the outcome of an assessment or authorization. The assessor or authorizing official decides it.
What do companies in this industry ask?
Does an ATO on a customer system count toward our CMMC status?
No. An ATO covers the federal system it was issued for. CMMC covers the contractor systems that hold CUI, and each needs its own scope and evidence.
Can the same people run both programs?
Yes, and the skills transfer. The documents, the decision makers and the scope do not, so each program needs its own plan and records.
Do integrators need an insider threat program?
Many contracts require one or require support for the customer's program. NIST SP 800-171 also requires insider threat awareness training under requirement 3.2.3.
Ready to talk it through?
BOOK A CALLPick a time for a 30 minute call with the practice.
What happens in 30 minutes
- We learn about your company, the contracts you hold or are bidding on, and what is driving your timeline.
- We talk through where you stand and which engagement fits, if any does.
- If there is a fit, we follow up with a written scope. No slides.