Get Your Free SPRS Score

Get Your Free SPRS Score

Book a personalized demo to unify tasks, pass audits, and scale.

CMMC Level 3 Requirements and DIBCAC Assessments

CMMC Level 3 Requirements and DIBCAC Assessments
Facebook
Twitter
Pinterest
LinkedIn

When you read through the posts on the Ignyte blog focusing on CMMC, you'll see that just about everything we talk about, unless otherwise specified, refers to CMMC Level 2.

This is because it's the impact level that the vast majority of DoD contractors are going to need.

CMMC Level 1 is the lowest level, protecting the least sensitive of the sensitive information the government has to offer. If all you're handling is Federal Contract Information (FCI), Level 1 is enough for you.

CMMC Level 2 is where the real requirements, as well as the real information, start to matter. Level 2 secures Controlled Unclassified Information (CUI), the stuff that can be truly damaging if it leaks, though it's not damaging enough to earn a classification level or a SECRET designation.

Level 3 is even higher up the chain, because it focuses on protecting sensitive information and technical data that, if leaked, could present a serious strategic advantage for adversaries. Only a small number of DoD contractors touch this information, so covering CMMC Level 3 is a small audience by default.

It is, however, worth looking into for those who either need it or think they may need it, based on the direction they want to take their business. So, let's talk about it. What are the CMMC Level 3 requirements? What are DIBCAC assessments? What do you need to know about the highest tier of the program?

BLUF - Bottom Line Up Front

CMMC Level 2 applies to most DoD contractors; Level 1 covers only Federal Contract Information. Level 3 adds NIST SP 800-171 controls plus SP 800-172 extras (dynamic access, centralized alerts, threat detection, automated integrity checks). DoD sets stricter ODPs, POA&M items must be closed before Level 3 review, and scoring treats every control equally. Level 3 uses a DIBCAC assessment. Need arises for new tech, large CUI volume, provider systems, or nation-level threats.

Who Needs CMMC Level 3?

First, who does CMMC Level 3 apply to in the first place? CMMC doesn't encompass or protect information more sensitive than CUI, right?

Who Needs CMMC Level 3

The fact is, CUI comes in a lot of different forms, across 20 different index groups and a wide range of categories. As you might imagine, despite being both forms of CUI, there can be a lot of difference between things like data on company mergers or individual net worth, and naval nuclear propulsion or other nuclear information.

The DoD, at last count, estimates that only around 1% of DoD contractors ever handle the kind of information that needs more than a Level 2 protection boundary.

There has historically been a lot of confusion over what makes a particular kind of CUI need CMMC Level 3 or just Level 2. It can be written in a federal contract, so you'd know if you're applying for an RFP, but that's a little late to start recognizing the need.

At the same time, the DoD has been very cautious about it, even going so far as to send a memo cautioning DoD program managers not to blanket require CMMC Level 3 when it's not necessary. Basically, they want to avoid overusing it and making it meaningless.

It's also a small element of security through minimization. The fewer entities have CMMC Level 3, the fewer threat surfaces exist for attackers to try to breach, and the harder it is to get a foothold in the internal processes of a Level 3 security barrier.

For obvious reasons, nothing in the requirements is secret; it's just that the implementation can be fairly specific, so protecting it can be done in numerous ways.

Broadly, there are three main reasons why you might be required to have CMMC Level 3 certification, other than "just because the DoD says so when you bid."

The first is any contract that involves newly emerging or unique technology. If the government is working on something cutting-edge, they want the strongest applicable protection. Anything more sensitive than CUI is likely to be kept out of the hands of contractors at all, but specific kinds of CUI relating to emerging tech can be the purview of Level 3.

The second is when you're handling CUI that may not be particularly sensitive, but you're handling a lot of it. If a breach of your systems represents a very significant loss of data, Level 3 might be more appropriate just to secure it on the basis of volume alone.

The third is cases where your system isn't necessarily protecting CUI directly so much as contributing to the protection of other contractors. If your company offers a service that is used in CMMC compliance, and many different DoD contractors are using you as part of their operations, you have to adhere to a higher standard; otherwise, a breach in your system represents a widespread breach across many systems, greatly increasing the threat.

Finally, a lot of it centers around not just the kind of information being protected, but also the kind of threats being pointed at you. APTs, also known as Advanced Persistent Threats, are continuous and evolving attacks that try to exploit any foothold they can get.

APTs are frequently nation-level actors, adversarial groups like those in China, Russia, Iran, or North Korea, which would benefit greatly from obtaining advanced data from our DoD ecosystem. They tend to be better-funded, longer-term, and more advanced than your average botnet DDoS or parking lot USB phishing attempt. They can be highly sophisticated, technical, and multifaceted, all pushing for the same goals.

What Are the Added Requirements for CMMC Level 3?

So, what makes Level 3 different from Level 2?

Added Security Controls

One of the big ones is simply which NIST documents apply. CMMC Level 1 and 2 require implementation of NIST SP 800-171 security controls. This document has 110 security controls across various domains, and forms the basis of most of the government's information security platforms.

Added Security Controls

CMMC Level 3 requires that a contractor implement all 110 security controls from NIST SP 800-171. But that's not all.

CMMC Level 3 also requires additional security controls outlined in NIST SP 800-172, formally known as Enhanced Security Requirements for Protecting Controlled Unclassified Information. This document contains an additional 24 security controls, such as:

  • Dynamic access control
  • Directory replication restrictions
  • Correlated audit logs across repositories
  • Centralized review and alerting
  • Threat hunting
  • Automated integrity checks

All of these address various aspects of APTs that aren't generally present in less sophisticated threats, or that tend to have a high overhead or burden compared to the value they offer to less restrictive entities, which is why they aren't necessary for Level 2.

Since the NIST publications are not limited to just specific portions of the government, the controls outlined in 800-172 can apply to other frameworks as well. Each government agency is allowed to pick what they want to require. CMMC only applies to the DoD DIB, after all. The latest version of NIST SP 800-172 says this:

"There is no expectation that all of the enhanced security requirements will be selected by federal agencies implementing this guidance. The decision to select a particular set of enhanced security requirements will be based on the mission and business needs of federal agencies and guided and informed by ongoing risk assessments."

In other words, different government agencies and contracts protecting different kinds of information and systems may require different portions of NIST SP 800-172.

CMMC Level 3 requires all of them, though.

Specifics for ODPs

One thing CMMC does is use Organization-Defined Parameters for many controls. ODPs are fields where the organization is left to decide what the appropriate level is necessary to protect a system. For example, a security control may require that the organization "limit unsuccessful logon attempts." What is the limit? You can pick. You pick the number, you pick the time period before it resets, and you pick the action that happens when the limit is reached.

Specifics For ODPs

Under CMMC Level 2, ODPs are set by the organization, but there was a memo giving a standard ideal for each for most contractors to use.

Under CMMC Level 3, the DoD specifies the ODPs, and they're stricter than the memo-specified ODPs. This applies across all of the security controls in 800-171, not just those in 172.

Stricter POA&M Timelines

Another major difference between Level 2 and Level 3 is the POA&M timeline. POA&Ms allow lower-risk security controls to be delayed for anywhere between 30 and 180 days, while the organization is still allowed to receive provisional approval to operate under CMMC certification.

Stricter POAM Timelines

Level 3 cannot even be processed unless the organization holds successful Level 2 approval, not just conditional approval. To even schedule a Level 3 assessment, a Level 2 approval needs to be available on the record. So, any POA&Ms need to be closed out for Level 2 before the Level 3 assessment can begin.

POA&Ms can still be used for some of the NIST SP 800-172 requirements, as long as they aren't on the prohibited list (which is a subsection of controls that are fully mandatory for approval.)

Stricter Scoring

With Level 2, SPRS scoring has a variable value. Some controls are worth 1 point, some are worth 3 points, and some are worth 5 points. Organizations must have a total point level within an appropriate range; otherwise, they won't pass the assessment. Variable scoring allows for some more leeway with lesser-value requirements.

Stricter Scoring

Level 3 does not have varied scoring. Every control is worth the same, so the score range is narrower, and the requirements for approval are stricter.

What is a DIBCAC Assessment?

The other big difference between CMMC Level 2 and Level 3 is the assessment.

What Is A DIBCAC Assessment

With CMMC Level 1, all that is necessary is a self-assessment, with penalties from FCA claims should you misrepresent your organization and be caught.

With CMMC Level 2, you have to submit self-assessments, but you also have to pass an external assessment conducted by a Certified Third-Party Assessing Organization, or C3PAO. C3PAOs go through your security implementation and check all of your controls and details, validate ODPs, spot-check vulnerabilities, and more. They generate a report and submit it to the DoD for evaluation and approval.

CMMC Level 3 also requires an additional external assessment, but it's not run by a C3PAO. Instead, it's run by a DoD department directly, the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center, or DIBCAC.

A C3PAO assessment can spot-check and sample certain security controls, and may only do a cursory inspection of others. The expectation of examining every single system and every single computer within an organization is a huge burden for little value, so it's just not done.

A DIBCAC assessment is much more thorough. DIBCAC only has one job, which is to oversee and enforce CMMC, including performing these assessments. DIBCAC is also the group that trains C3PAOs.

The DIBCAC assessment is also known as a High Confidence Assessment because it goes in greater detail, checks more systems more deeply, and validates every detail to a high standard.

Since the Level 2 assessment from the C3PAO is required before a DIBCAC assessment can even be scheduled, the DIBCAC assessment only focuses on the additional security controls from NIST SP 800-172 and any other specific areas that are outside the scope of Level 2. They frequently also spot-check Level 2 details, just in case, but they don't redo all of the work of the C3PAO.

How Ignyte Can Help

At Ignyte, we do a lot of work within the CMMC ecosystem. We can help in several different ways.

How Ignyte Can Help

First, as experts in CMMC, our site and blog are full of useful information and answered questions. We're also frequently available to answer your questions; just drop us a line to ask.

Second, we're one of those C3PAOs. If you're seeking Level 3 assessment, you need to pass Level 2, and we can perform that assessment for you.

Finally, the Ignyte Assurance Platform was designed from the ground up for security frameworks like FedRAMP and CMMC. It's designed to help implement, track, and prove your security posture across your required security controls. We help organizations achieve compliance much faster and with much less hassle than doing it with spreadsheets and siloed information hubs.

To see firsthand how our platform can help you achieve your security goals and become part of the overall Defense Industrial Base, contact us for a custom demo today.

Stay up to date with everything Ignyte