โ† All CCA Flashcard Decks

CMMC Certification Levels & Requirements Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CMMC Certification Levels & Requirements flashcards as text
  1. What is the maximum number of days allowed to close a Plan of Action & Milestones (POA&M) item to achieve a final CMMC Level 2 certification after receiving conditional status?

    Answer: 180 days

    Under CMMC 2.0, contractors with conditional CMMC status must close all POA&M items within 180 days to achieve final certification and maintain contract eligibility.

  2. Which NIST publication provides the enhanced security requirements that underpin CMMC Level 3 (Expert)?

    Answer: NIST SP 800-172

    CMMC Level 3 builds on Level 2 (NIST SP 800-171) by adding requirements from NIST SP 800-172, which addresses enhanced security measures to counter Advanced Persistent Threats (APTs).

  3. How many domains are included in the CMMC 2.0 model?

    Answer: 14

    CMMC 2.0 includes 14 domains (e.g., AC, AT, AU, CM, IA, IR, MA, MP, PE, PS, RA, CA, SC, SI) that map to the control families in NIST SP 800-171.

  4. What is the primary purpose of DFARS clause 252.204-7012 in relation to cybersecurity?

    Answer: To establish adequate security safeguards and mandate 72-hour cyber incident reporting for CUI

    DFARS 252.204-7012 requires contractors to implement adequate security to protect covered defense information (CUI) and mandates reporting of cyber incidents to DoD within 72 hours.

  5. Which CMMC level specifically addresses protecting CUI against Advanced Persistent Threats (APTs)?

    Answer: Level 3

    CMMC Level 3 (Expert) is specifically designed to protect CUI against APTs by adding practices from NIST SP 800-172 on top of the Level 2 baseline.

  6. What annual action is required of CMMC Level 2 contractors regardless of whether they undergo self-assessment or third-party assessment?

    Answer: Senior official affirmation confirming continued compliance with cybersecurity requirements

    CMMC 2.0 requires an annual affirmation by a senior company official attesting to compliance with required cybersecurity practices, creating executive-level accountability between triennial assessments.

  7. Under CMMC 2.0, which Level 2 contractors may be permitted to use self-assessment rather than a third-party C3PAO assessment?

    Answer: Contractors on non-prioritized acquisition programs that do not involve CUI

    Some CMMC Level 2 contracts involving lower-risk programs may allow self-assessment; however, prioritized acquisition programs handling sensitive CUI require a C3PAO third-party assessment.