<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-06-24-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>0790-AL49</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202204</PUBLICATION_ID>
            <PUBLICATION_TITLE>Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>0790</CODE>
            <NAME>Office of the Secretary</NAME>
            <ACRONYM>OS</ACRONYM>
        </AGENCY>
        <PARENT_AGENCY>
            <CODE>0700</CODE>
            <NAME>Department of Defense</NAME>
            <ACRONYM>DOD</ACRONYM>
        </PARENT_AGENCY>
        <RULE_TITLE>Cybersecurity Maturity Model Certification (CMMC) Framework</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 DoD Assessment Methodology employed to assess contractor implementation of the cybersecurity requirements in NIST SP 800-171, Protecting Controlled Unclassified Information (CUI) In Nonfederal Systems and Organizations, required by DFARS 252.204-7012. The verification of contractor implementation of NIST SP 800-171 security requirements is addressed under DFARS provision 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements, and DFARS clause 252.204-7020, NIST SP 800-171 DoD Assessment Requirements.</p>
<p>The Cybersecurity Maturity Model Certification (CMMC) Framework, version 2.0. CMMC 2.0 is a newly approved DoD certification process to help assess a DIB contractor&rsquo;s compliance with and implementation of cybersecurity requirements to safeguard FCI and CUI transiting non-federal systems and mitigate the threats posed by Advanced Persistent Threats--adversaries with sophisticated levels of expertise and significant resources.</p>
<p>This rule is related to DFARS clause 252.204-7021, Cybersecurity Maturity Model Certification Requirements, which specifies the CMMC requirement at the level specified for a contract and for the duration of the contract with the DIB contractor. This rule will specify the CMMC requirements, at CMMC Level 1, 2, or 3, with which DIB contractors must comply in advance of a contract award, as well as the process for obtaining and maintaining CMMC certification, as required for a designated DoD contract.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Economically Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Final Rule Stage</RULE_STAGE>
        <MAJOR>Yes</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>Private Sector</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>32 CFR 170</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>5 U.S.C. 301</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>Pub. L. 116-92, sec. 1648</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>No</RPLAN_ENTRY>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>Interim Final Rule</TTBL_ACTION>
                <TTBL_DATE>03/00/2023</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>Yes</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>Businesses</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>Federal</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>Undetermined</FEDERALISM>
        <ENERGY_AFFECTED>No</ENERGY_AFFECTED>
        <PRINT_PAPER>Yes</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>Yes</INTERNATIONAL_INTEREST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Diane</FIRST_NAME>
                <LAST_NAME>Knight</LAST_NAME>
                <MIDDLE_NAME>L.</MIDDLE_NAME>
                <TITLE>Senior Management and Program Analyst</TITLE>
                <AGENCY>
                    <CODE>0790</CODE>
                    <NAME>Office of the Secretary</NAME>
                    <ACRONYM>OS</ACRONYM>
                </AGENCY>
                <PHONE>202 770-9100</PHONE>
                <EMAIL>diane.l.knight10.civ@mail.mil</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>4800 Mark Center Drive, Suite 12E08,</STREET_ADDRESS>
                    <CITY>Alexandria</CITY>
                    <STATE>VA</STATE>
                    <ZIP>22350</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
