โ† All CCA Flashcard Decks

CCA Contractor & Supplier Requirements Flashcards

6 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CCA Contractor & Supplier Requirements flashcards as text
  1. Which DFARS clause requires defense contractors to implement NIST SP 800-171 and report cyber incidents?

    Answer: DFARS 252.204-7012

    DFARS 252.204-7012 requires defense contractors to implement NIST SP 800-171 security requirements and report cyber incidents involving covered contractor information systems within 72 hours.

  2. Under CMMC rules, when must a prime contractor flow down CMMC requirements to its subcontractors?

    Answer: When the subcontractor will process, store, or transmit CUI or FCI in support of the prime contract

    Prime contractors must flow down CMMC requirements to subcontractors that will handle CUI or FCI in performance of the contract, ensuring the full supply chain protects sensitive information.

  3. What is the purpose of the CMMC Model and how does it relate to NIST SP 800-171?

    Answer: CMMC Level 2 is based on the 110 security requirements in NIST SP 800-171, adding a third-party assessment mandate

    CMMC Level 2 maps directly to the 110 security requirements of NIST SP 800-171 but adds the requirement for third-party assessment by a C3PAO rather than allowing self-attestation.

  4. What obligation does a defense contractor have when it discovers a cyber incident affecting CUI under DFARS 252.204-7012?

    Answer: Report the incident to the DoD within 72 hours of discovery

    DFARS 252.204-7012 requires contractors to report cyber incidents involving covered contractor information systems to the DoD via the DIBNet portal within 72 hours of discovery.

  5. How does CMMC affect a defense contractor that only handles Federal Contract Information (FCI) but not CUI?

    Answer: FCI-only contractors must meet CMMC Level 1, which requires implementation of basic safeguarding requirements from FAR 52.204-21

    Contractors handling only FCI must meet CMMC Level 1, which consists of 17 basic safeguarding practices aligned to FAR 52.204-21 and allows annual self-attestation.

  6. Which entity is responsible for authorizing C3PAOs to conduct CMMC assessments?

    Answer: The CMMC Accreditation Body (CMMC-AB), also known as The Cyber AB

    The Cyber AB (formerly CMMC-AB) is the accreditation body that authorizes C3PAOs to conduct official CMMC assessments and certifies CCA assessors.