
Gain an overview of the CMMC model v2.0, including the regulations, certification process, and the DoD mandates that protect controlled information, with references to the NIST risk management framework.
Explore CMMC v2.0 background, highlighting DoD contractors must obtain third-party certification of safeguarding covered defense information and cyber incident reporting, aligned with DFARS 252.204-7012 and 800 171 controls, to bid.
Explore the two key information types protected by the CMMC v2.0: federal contract information and controlled unclassified information (CUI or QE), defined under 48 CFR and Executive Order 13556.
Review 32 CFR 2002 and the National Archives CUI categories to understand CUI and the QE program, including marking and protection under subparts A–C for CMMC compliance.
Explore how NIST SP 800-171 and 800-172 align with CMK standards, detailing security controls, assessment guidance, and mappings to 853, ISO/IEC 27001, CIS controls, HIPAA, and PCI.
Learn the CMMC model v2.0 implementation across three levels—17, 110, and 145 controls—covering 14 domains and the roles of cyber AB registered practitioners and certified third-party assessment organizations.
Explore how CMMC controls drawn from NIST catalogs are implemented across levels one to three, guided by 801-71 and 801-72, with 14 control families and DFARS clauses.
Discover the cmmc ecosystem, where the cyber ab and DoD origin shape assessment and certification, and third-party assessor organizations, registered provider organizations, and licensed partner publishers enable compliance.
Explore official DoD and cyber lab resources to understand CMMC policy, training, and how to achieve certification, including assessors, practitioners, instructors, and service providers.
Explore the CMMC version 2.0 certification process, including assessment, documentation and evidence, and a plan of action and milestones toward government contracts.
Explore the CMMC v2.0 assessment process, from level 1 self-assessment to level 3 government-led reviews, with scoping, segmentation, and access controls to protect FCI and QE.
Prepare and maintain documentation and evidence for a cmmc assessment, including policies, system security plans, infrastructure diagrams, and logs to demonstrate nist controls.
In recent years, there have been numerous detrimental breaches of both classified and unclassified government data, leading to the unauthorized exposure of sensitive information. To safeguard this data, the Federal government has implemented measures, enforcing legal and contractual obligations on defense contractors through the Cybersecurity Maturity Model Certification (CMMC). This course is specifically crafted for security professionals seeking an introductory understanding of the recently imposed CMMC requirements by the U.S. Government on its supply and service providers.
Within the Cybersecurity Maturity Model Certification (CMMC) course, you will dive into the fundamentals of CMMC, exploring its origins and significance. Initially, you'll examine key U.S. Government regulations, such as the Defense Federal Acquisition Regulations, that necessitate the application of CMMC to Department of Defense contractors. Subsequently, you'll explore the NIST Special Publication 800-171 series. The course then provides insight into the structure of the CMMC model, encompassing its levels, controls, and practices. Lastly, you'll gain a comprehensive understanding of the challenges and processes involved in achieving all three levels of the CMMC Maturity Model.
Upon completing this course, you will have a comprehensive understanding of how the CMMC relates to various scenarios encountered by defense contractors, enriching your expertise in this critical area.