Do I Need to Complete the Self-Assessment?
According to Katie Arrington, the only companies doing business with the DoD who are exempt from the December 1, 2020 deadlines are those conducting micro purchases (purchases < $10,000) and Commercial Off-the-Shelf (COTS), which are items that are sold, leased, or licensed to the general public. EVEN IF YOUR CONTRACT DOESN’T MENTION DFARS, if you in any way, shape or form handle, store, transmit, view, create or touch CUI, you will need to complete this self-attestment. For more information, we strongly urge you to watch the webinar hosted by projectspectrum.io entitled “Cyber Circuits Essential CMMC News: Your Questions Answered.” Also, it may help to read the DoD’s “Network Penetration Reporting and Contracting for Cloud Services (DFARS Case 2013-D018) Frequently Asked Questions (FAQs) regarding the implementation of DFARS Subpart 204.73 and PGI Subpart 204.73 DFARS Subpart 239.76 and PGI Subpart 239.76.” (Please Note: The FAQs use “CDI” instead of “CUI” but ALL CDI is also CUI.) Here are FAQs 4 and 5, regarding who needs to comply with DFARS:- Q4: When must the requirements in DFARS clause 252.204-7012 be implemented?
- A4: The requirements in DFARS clause 252.204-7012 must be implemented when CDI is processed, stored, or transmits through an information system that is owned, or operated by or for, the contractor, or when performance of the contract involves operationally critical support. The contracting officer shall indicate in the solicitation/contract when performance of the contract will involve, or is expected to involve, CDI or operationally critical support. All CDI provided to the contractor by the Government will be marked or otherwise identified in the contract, task order, or delivery order.
- Q5: When and how should DFARS clause 252.204-7012 flow down to subcontractors?
- A5: DFARS clause 252.204-7012 flows down to subcontractors without alteration, except to identify the parties, when performance will involve operationally critical support or CDI. Them [sic.] contractor should consult with the contracting officer to determine if the information required for subcontractor performance is covered defense information and if it retains its identity as covered defense information which would require flow-down of the clause. Flow-down is a requirement of the terms of the contract with the Government, which should be enforced by the prime contractor as a result of compliance with these terms. If a subcontractor does not agree to comply with the terms of clause 252.204-7012 then CDI should not be on that subcontractor’s information system.
How Does This Impact CMMC Compliance?
Speaking of CMMC, here’s where a lot of the confusion has come from. As we have mentioned, the DoD expects everyone (save COTS and micro purchases) to be NIST 800-171 compliant, and they must enter their self-assessment in SPRS by the end of this month… BUT, most contractors are not expected to have to be CMMC Maturity Level (ML) 3 compliant; only ML 1. So therein lies the rub:- NIST SP 800-171 is the basis of CMMC ML 3.
- NIST SP 800-171 is 110 security controls.
- CMMC ML 3 is the 110 controls + 20 more
Recouping Your Costs
A common question is, “Is the government going to pay for CMMC compliance?” I know we are mostly focusing on DFARS right now, but the two are definitely related because the answer is, “Kind of.” If you have been a contractor or vendor and have a current contract, and are expected to be CMMC ML 3 compliant, the government will allow for the cost of the actual audit, as well as the cost of adding the 20 additional security controls to your cyber security portfolio… But that’s it. Because it is assumed that you already have the original 110 security controls in place from NIST 800-171 - since you took the contract. And they won’t pay for the costs up front; they are to be built into your contract and billed. So essentially, the government is paying for your cyber security measures, but they will not be double-charged for it.How to Complete Self-Assessment in SPRS
You will be scoring yourself out of a possible 110; 1 point for each security control that you have in place. The DoD expects that since you are already compliant with NIST SP 800-171, it should only take half-an-hour, plus the 25 minutes it takes to upload the information to the SPRS, which requires the completion of 6 fields:- System Security Plan Name
- CAGE code associated with the plan
- A brief description of the plan architecture
- Date of the assessment
- Total score
- Date a score of 110 will be achieved