Requirement guide CMMC readiness
What is required for CMMC Level 2?
For Level 2, review whether the scoped systems, practices, evidence, current status, and affirmations support the specific contractual requirement. An existing policy or earlier score is insufficient on its own. Keep the relationship available for review before an assessment or award deadline.
Decision basis: DFARS 252.204-702132 CFR part 170 CMMC Program final ruleNIST SP 800-171 Rev. 2
What to confirm
Use the governing requirement and current rule to determine the assessment type, permitted POA&M treatment, and timing.
Organize the requirement, work, and evidence.
Deep Fathom records the source requirement, accountable owner, assigned work, supporting evidence, and review history. The team can then review the specific requirement instead of searching across disconnected documents.
Review CMMC requirementsSources
- DFARS 252.204-7021Current CMMC status, annual affirmation, and CMMC flowdown requirements where the clause applies.Official source ↗
- 32 CFR part 170 CMMC Program final ruleCMMC program requirements, assessment levels, scope, affirmations, and conditional status rules.Official source ↗
- NIST SP 800-171 Rev. 2The 110 security requirements incorporated by reference into 32 CFR part 170 and assessed at CMMC Level 2.Official source ↗