<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-04-05-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>0790-AL49</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202110</PUBLICATION_ID>
            <PUBLICATION_TITLE>The Regulatory Plan and the Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>0790</CODE>
            <NAME>Office of the Secretary</NAME>
            <ACRONYM>OS</ACRONYM>
        </AGENCY>
        <PARENT_AGENCY>
            <CODE>0700</CODE>
            <NAME>Department of Defense</NAME>
            <ACRONYM>DOD</ACRONYM>
        </PARENT_AGENCY>
        <RULE_TITLE>Cybersecurity Maturity Model Certification (CMMC) Framework</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>This rule will establish cybersecurity requirements that must be met for Defense Industrial Base (DIB) contractors to obtain requisite Cybersecurity Maturity Model Certification status. DIB contractors may need CMMC certification to qualify for award of designated future DoD contracts. The impact of the CMMC requirements, in conjunction with DFARS clause 252.204-7021, Cybersecurity Maturity Model Certification Requirements, will be a higher level of assurance that Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) will be protected at the level commensurate with the risk from cybersecurity threats, including Advanced Persistent Threats.</p>
<p>DoD implemented a two-pronged approach to assess and verify the DIB's ability to protect FCI and CUI. This rule implements:</p>
<ul>
<li>
<p>The National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 DoD Assessment Methodology employed to assess contractor implementation of the cybersecurity requirements in NIST SP 800-171, <em>Protecting Controlled Unclassified Information (CUI) In Nonfederal Systems and Organizations</em>, required by DFARS 252.204-7012. The verification of contractor implementation of NIST SP 800-171 security requirements is addressed under DFARS provision 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements, and DFARS clause 252.204-7020, NIST SP 800-171 DoD Assessment Requirements.</p>
</li>
<li>
<p>The Cybersecurity Maturity Model Certification (CMMC) Framework. CMMC is a new DoD certification process to measure a DIB contractor&rsquo;s adherence to processes and implementation of cybersecurity practices to address and mitigate the threats posed by Advanced Persistent Threats--adversaries with sophisticated levels of expertise and significant resources.</p>
<p>This rule is related to DFARS clause 252.204-7021, Cybersecurity Maturity Model Certification Requirements, which specifies the requirement for assessing that DIB contractors meet CMMC requirements. This rule will specify the CMMC requirements for which the DIB contractors will be assessed.</p>
</li>
</ul>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Economically Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>First Time Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Long-Term Actions</RULE_STAGE>
        <MAJOR>Yes</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>Private Sector</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>32 CFR 170</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>5 U.S.C. 301</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>Pub. L. 116-92, sec. 1648</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>No</RPLAN_ENTRY>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>Interim Final Rule</TTBL_ACTION>
                <TTBL_DATE>12/00/2022</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>Yes</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>Businesses</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>Federal</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>Undetermined</FEDERALISM>
        <ENERGY_AFFECTED>No</ENERGY_AFFECTED>
        <PRINT_PAPER>Yes</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>Yes</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Diane</FIRST_NAME>
                <LAST_NAME>Knight</LAST_NAME>
                <MIDDLE_NAME>L.</MIDDLE_NAME>
                <TITLE>Senior Management and Program Analyst</TITLE>
                <AGENCY>
                    <CODE>0790</CODE>
                    <NAME>Office of the Secretary</NAME>
                    <ACRONYM>OS</ACRONYM>
                </AGENCY>
                <PHONE>202 770-9100</PHONE>
                <EMAIL>diane.l.knight10.civ@mail.mil</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>4800 Mark Center Drive, Suite 12E08,</STREET_ADDRESS>
                    <CITY>Alexandria</CITY>
                    <STATE>VA</STATE>
                    <ZIP>22350</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
