← All CCA Flashcard Decks

CMMC Certification Levels & Requirements Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 CMMC Certification Levels & Requirements flashcards as text
  1. What is the standard CMMC term for a contractor or subcontractor that undergoes a CMMC assessment to achieve certification?

    Answer: Organization Seeking Certification (OSC)

    In CMMC terminology, an Organization Seeking Certification (OSC) is the entity—whether prime contractor or subcontractor—that undergoes the CMMC assessment process.

  2. What does the System Security Plan (SSP) primarily document for a CMMC assessment?

    Answer: The security requirements, system boundaries, and how controls are implemented

    The SSP describes how the organization implements required security controls, defines the system boundary (scope), and documents the overall security architecture that assessors will evaluate.

  3. Which of the following is NOT one of the three assessment methods defined in the CMMC Assessment Process for evaluating practices?

    Answer: Survey

    NIST SP 800-171A and the CMMC Assessment Process define three methods: Examine (review documents/artifacts), Interview (discuss with personnel), and Test (exercise mechanisms/procedures); Survey is not a defined CMMC assessment method.

  4. In the context of a CMMC assessment, what defines the 'scope' of the assessment?

    Answer: All assets, systems, and personnel that process, store, or transmit CUI and the protections around them

    CMMC assessment scope defines the boundary of what is assessed, encompassing all components, systems, and people that interact with CUI and the security controls protecting it.

  5. What is 'conditional CMMC status' and what does it allow a contractor to do?

    Answer: Provisional certification enabling contract award when open POA&Ms exist for eligible not-met practices

    Conditional CMMC status is a provisional certification that allows contract award to proceed when a contractor has open POA&Ms for certain practices, provided deficiencies are closed within 180 days.

  6. Which DoD-published document provides the specific assessment objectives and evaluation criteria for each of the 110 CMMC Level 2 practices?

    Answer: CMMC Level 2 Assessment Guide

    The CMMC Level 2 Assessment Guide, published by the DoD, specifies the assessment objectives, accepted evidence, and evaluation methods for each of the 110 Level 2 practices.

  7. If an OSC undergoes a significant change to its IT environment after receiving CMMC Level 2 certification, what is the expected course of action?

    Answer: The OSC must notify the Cyber AB and may be required to undergo a new assessment to confirm continued compliance

    Significant changes to the assessed environment (e.g., major system additions, architecture changes) can invalidate the basis of the original certification, requiring notification to the Cyber AB and potentially a new assessment.