Regulatory Framework Alignment

Built on Industry Standards

Our services are structured around established regulatory frameworks and industry standards, ensuring your organization meets compliance requirements through proven methodologies and assessment-aligned implementation.

CMMC
Level 2
Primary Framework

Cybersecurity Maturity Model Certification

CMMC Level 2 represents the baseline cybersecurity standard for Defense Industrial Base contractors handling Controlled Unclassified Information (CUI). Our services are designed to support organizations through the assessment preparation and certification process.

CMMC Level 2 requires implementation of all 110 security requirements derived from NIST SP 800-171, along with documented processes and practices demonstrating organizational maturity in cybersecurity governance.

110
Security Requirements
14
Control Domains
Foundation Standard

NIST SP 800-171 Rev. 2

NIST Special Publication 800-171 Revision 2 provides the technical foundation for CMMC Level 2, establishing security requirements for protecting Controlled Unclassified Information in nonfederal systems and organizations.

Our implementation support services focus on translating these 110 security requirements into documented policies, technical controls, and operational procedures aligned to your organization's scope and risk profile.

Access Control (AC)
Awareness and Training (AT)
Audit and Accountability (AU)
Configuration Management (CM)
Identification and Authentication (IA)
Incident Response (IR)
Maintenance (MA)
Media Protection (MP)
Personnel Security (PS)
Physical Protection (PE)
Risk Assessment (RA)
Security Assessment (CA)
System and Communications Protection (SC)
System and Information Integrity (SI)
NIST
SP 800-171
Revision 2
Security Requirements110
Control Families14
Assessment Objectives320+
Contractual Requirements

DFARS Compliance Clauses

Defense Federal Acquisition Regulation Supplement clauses establish contractual obligations for cybersecurity implementation and reporting within the defense supply chain.

Regulatory status reflects DFARS cybersecurity updates effective November 10, 2025 (CMMC 2.0 final rule implementation) and February 1, 2026 clause restructuring — including elimination of DFARS 252.204-7019 as a standalone provision and renumbering of DFARS 252.204-7020.

DFARS 252.204-7012

Safeguarding Covered Defense Information and Cyber Incident Reporting

Requires contractors to implement NIST SP 800-171 security requirements for protecting Covered Defense Information (CDI) and to report cyber incidents affecting CDI within 72 hours. This clause remains a foundational cybersecurity requirement for DoD contractors.

DFARS 252.204-7019 (Retired as Standalone Clause)

Former NIST SP 800-171 Assessment Posting Requirement

Previously required contractors to conduct and post a Basic NIST SP 800-171 self-assessment score in the Supplier Performance Risk System (SPRS) prior to award. This solicitation provision has been eliminated as a standalone clause. Its assessment-posting requirements have been incorporated into the CMMC implementation framework and associated DFARS clauses, including DFARS 252.204-7021. SPRS remains the system of record for documenting CMMC and NIST SP 800-171 assessment results.

Former DFARS 252.204-7020 (Renumbered to DFARS 252.240-7997)

DoD Assessment Requirements Transitioned

The DoD assessment requirements previously captured under DFARS 252.204-7020 have been renumbered and integrated within updated DFARS structures aligned to CMMC implementation. Assessment validation now aligns directly with CMMC assessment mechanisms rather than legacy Basic/Medium/High assessment categories.

DFARS 252.204-7021

Cybersecurity Maturity Model Certification (CMMC) Requirements

Requires contractors to achieve and maintain the CMMC level specified in the contract. Certification is verified through third-party assessment (when required) and recorded within SPRS. This clause operationalizes CMMC as the compliance mechanism for demonstrating NIST SP 800-171 alignment.

Framework Relationships

Integrated Compliance Architecture

Understanding the relationships between frameworks enables efficient implementation and reduces redundant effort across compliance initiatives.

CMMC
Level 2
Primary Standard
NIST
SP 800-171
Technical Foundation
DFARS
252.204-7012/19/20/21
Contractual Requirements
RMF
Risk Management
Conceptual Alignment
ISO
17020
Future C3PAO Alignment
Risk Management Framework

RMF Conceptual Alignment

While CMMC and NIST SP 800-171 provide specific security requirements, the Risk Management Framework (RMF) offers a structured process for integrating security and risk management activities into the system development lifecycle.

Our consulting services incorporate RMF principles to help organizations establish repeatable processes for categorization, control selection, implementation, assessment, authorization, and continuous monitoring.

1
Categorize
System and information categorization
2
Select
Control selection and tailoring
3
Implement
Control implementation and documentation
4
Assess
Control assessment and validation
5
Authorize
Risk acceptance and authorization
6
Monitor
Continuous monitoring and improvement
RMF
Lifecycle
Future Assessment Ecosystem

ISO/IEC 17020 Alignment

As the CMMC assessment ecosystem matures, 11th Hour Assurance Group is positioned to align with ISO/IEC 17020 standards for inspection bodies, supporting future C3PAO (CMMC Third-Party Assessment Organization) requirements.

Impartiality

Independent assessment processes free from conflicts of interest

Competence

Qualified assessors with demonstrated technical expertise

Consistency

Standardized assessment methodologies and reporting

Navigate Compliance with Confidence

Our framework-aligned approach ensures your compliance efforts are structured, efficient, and assessment-ready.

protected by reCAPTCHA