Get Ready To Meet CMMC Requirements
Completing your Cybersecurity Maturity Model Certification (CMMC) requires an assessment from a Certified Third-Party Assessment Organization (C3PAO). ABS Quality Evaluations (ABS QE) can help you ensure that your information systems meet the required CMMC standards.
The Importance of CMMC Compliance
The U.S. Department of Defense (DoD) developed the Cybersecurity Maturity Model Certification (CMMC) 2.0 program to reinforce the importance of DIB cybersecurity to ensure the safety of highly sensitive information.
In 2022, the Defense Contract Management Agency (DCMA) reported that out of 300 assessments completed by the Defense Industrial Cybersecurity Assessment Center (DIBCAC) in recent years, only 25% were found compliant with the 110 requirements of NIST SP 800-171.
Early Adopters of CMMC
Becoming a CMMC early adopter gives your organization a competitive advantage and a better position to face future contract bids while improving your cybersecurity. Early adopters that enter now the Joint Surveillance Voluntary Assessment Program (JSVAP) can achieve placeholder certification that, once rulemaking is finalized, will automatically convert to a three-year Level 2 certification.
Are You Ready for an Audit?
About the Joint Surveillance Voluntary Assessment Program (JSVAP)
Stay ahead of the compliance curve with the Joint Surveillance Voluntary Assessment Program (JSVAP), a pilot program to promote CMMC early adoption. Organizations, like yours, seeking certification must collaborate with a Certified Third-Party Assessor Organization (C3PAO), such as ABS QE, as well as a Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) assessment team. Once completed with a passing score (and after final rule publication) the certification will immediately turn into a three-year, Level 2 CMMC certification for the organization.
CMMC Questions? Join Our Experts for Free Guidance
Join us on August 8th at 10 am CDT, in the webinar "Everything You Need to Know About the CMMC Ecosystem (Part One)". Our team of experts will explore a holistic overview of the CMMC ecosystem today, including the current state, ongoing timeline, and revised CMMC model.
The Steps to CMMC Compliance
You may only need Level 1 compliance today, but future contracts may require Level 2 or even Level 3 certification, including a third-party assessment. Your cybersecurity matures as you build on the controls you have. Managing your CMMC timeline will help you compete for future contracts.
- Determine CMMC level and the assessment scope.
- Implement controls in accordance with the appropriate assessment guide and NIST Special Publications.
- Develop adequate documentation as evidence of control implementation.
- Assess posture with a self-assessment, gap assessment or readiness review by a Certified
Third-Party Organization (C3PAO).
-
- Create a Plan of Action and Milestones (POA&M) for remediation.
- Enter score in Supplier Performance Risk System (SPRS).
- Contact with a C3PAO for joint surveillance voluntary assessment program assistance.
- Achieve a DIBCAC high score and continue maturing your cybersecurity program.
How ABS QE Can Prepare You for Your CMMC Assessment
Why ABS Quality Evaluations?
We're a global leader in Certified Performance.
ABS QE is a Certified Third-Party Assessor Organization (C3PAO) authorized by the Cyber Accreditation Body (Cyber AB) and a licensed training provider (LTP) certified by the Cybersecurity Assessor and Instructor Certification Organization (CAICO) to provide CMMC assessment services and training.
Our cybersecurity services include CMMC training, self-assessments, readiness reviews, gap assessments, Joint Surveillance Voluntary Assessment Program (JSVAP) assistance and certifications for ISO/IEC 20000, ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27017, ISO/IEC 27018 and ISO/IEC 27701, among others.
Frequently Asked Questions (FAQ)
Should we just complete Level 1 certification because it is easier?
The level of compliance is dependent upon the type of information your organization is protecting and should be indicated in contractual documents and requirements. However, Level 2 certification is the most common level for DIB contractors and better prepares your organization for the future.
Should we just complete Level 1 certification because it is easier?
Why do we need a third party if we can conduct a self-assessment internally?
While self-assessments are an option, they leave room for critical errors that can ultimately bring your business and operations to a costly halt. Ask yourself: can you ensure your people are qualified and have the bandwidth to conduct an independent, impeccable self-assessment while maintaining operations? A C3PAO will have the independence, experience and competencies necessary to provide an unbiased and accurate assessment.
Why do we need a third party if we can conduct a self-assessment internally?
We already have good cybersecurity systems in place; why do we need an assessment?
Although your organization may have a substantial cybersecurity system in place, CMMC 2.0 requirements are complex and time-consuming. Becoming an early adopter and identifying areas for remediation now is better than when you are pursuing certification as you would have to go back and fix them, potentially slowing your day-to-day operations. If you are found non-compliant or submit a false Supplier Performance Risk System (SPRS) score due to an insufficient self-assessment, you could be subject to fines, penalties, suspension or loss of contracts and also be found in violation of the False Claims Act.
We already have good cybersecurity systems in place; why do we need an assessment?
Why do I need to start my CMMC assessment now - don't we have a few years to comply?
Between fiscal years 2019 and 2020, DIBCAC assessed 110 companies to test their compliance with CMMC. Of those companies, only 16% met their satisfactory level. As of October 2021, the number has increased, but only to 22%. Starting the process now will allow you and your organization to identify areas for improvement before you attempt to achieve certification. Becoming an early adopter removes the strain and potential monetary consequences of needing to wait in a very long line for compliance.
Why do I need to start my CMMC assessment now - don't we have a few years to comply?
What is a CMMC Gap Assessment and what steps are included?
ABS QE can perform a Gap Assessment related to CMMC compliance. The Gap Assessment will be a mock assessment. An Executive Summary and Assessment Report will be provided as deliverables addressing each of the 110 security controls as part of the standard. No advice or remediation recommendations are provided. During the assessment, controls will be marked as "met", "not met" or "N/A" with no additional advice provided. It will be up to the organization to remediate its own environment. This option allows ABS QE to later perform a CMMC Certification audit if desired.
The assessment will consist of the following steps:
- Validate CMMC Assessment Scope
- Create an inventory of cybersecurity practices against the CMMC model
- Collect, examine and analyze evidence
- Conduct interviews and assess responses
- Observe tests and analyze results
- Identify and document evidence gaps
- Score organization's practices and validate preliminary results
- Determine final practice results
- Create, finalize and record recommended final findings
What is a CMMC Gap Assessment and what steps are included?
What is a CMMC Readiness Review and what areas are assessed?
ABS QE can perform a basic readiness review related to CMMC compliance. Compared to a gap assessment, a readiness review is more limited in scope as it does not review controls and evidence for compliance but for completion. During the review, items will be marked as "met", "not met" or "N/A" with no additional advice provided. This option allows ABS QE to later perform a CMMC certification audit.
During the review, the following areas will be assessed:
- System Security Plan (SSP) review against the 110 CMMC controls and objectives
- Controlled Unclassified Information (CUI) data flow
- Network topology and diagram review
- Hardware and software asset list review
- Confirm a Plan of Action & Milestones (POA&M)
- Define and complete the verification of the CMMC scope
- Shared responsibility matrix review
- Ensure roles are defined and assigned
- SPRS confirmation
What is a CMMC Readiness Review and what areas are assessed?